# Keep SMB over QUIC device admission separate from user authentication

> What does an SMB over QUIC client certificate access list decide?

- Canonical URL: https://update.dsesecurity.com/updates/dse-20260908-156-keep-smb-over-quic-device-admission-separate-from-user-authentication/
- Publisher: Detection Systems & Engineering (DSE Security)
- Author: DSE Security Editorial Team
- Published: 2026-09-08T18:14:35+00:00
- Modified: 2026-09-08T18:26:31+00:00
- Last reviewed by DSE: 2026-09-08
- Resource type: Guide
- DSE priority: Information
- Topics: IT, Networks & Infrastructure
- Reading time: 1 minutes

## What you need to know

What does an SMB over QUIC client certificate access list decide?

## Potentially affected

Administrators configuring SMB over QUIC client access control on supported Windows servers.

## DSE recommendation

Prepare a certificate-to-device inventory and label each required thumbprint with its algorithm.

## Article

## Source facts

SMB over QUIC client access control permits device allowlists and blocklists without changing the authentication used for the SMB connection. The server validates the client certificate chain and its trust before checking the access list. Administrators can add a certificate hash to that server-maintained list. Microsoft distinguishes the SHA1 thumbprint used by certificate-mapping commands from the SHA256 thumbprint required for client access control. [Microsoft documentation](https://learn.microsoft.com/en-us/windows-server/storage/file-server/configure-smb-over-quic-client-access-control).

## Applicability

Check the specific server release and feature prerequisites, existing QUIC configuration, client certificate, issuing authority, and administrative permissions. Review device admission and user/share authorization as separate controls.

## DSE recommendation

Prepare a certificate-to-device inventory and label each required thumbprint with its algorithm. Have the PKI and file-service owners approve the allowed and blocked test devices. Preserve the existing mappings and access entries before changing admission policy.

## Verification

Test an allowed device, a blocked device, and a device with an untrusted certificate chain. For the admitted device, separately verify the intended user’s share permissions. Record the certificate identity and observed rejection stage so a failed device check is not misreported as a user-password problem.

## Official references

[Microsoft Learn: Configure SMB over QUIC client access control in Windows Server](https://learn.microsoft.com/en-us/windows-server/storage/file-server/configure-smb-over-quic-client-access-control). Source reviewed September 8, 2026.

## Primary reference

- Name: Configure SMB over QUIC client access control in Windows Server
- Authority: Microsoft Learn
- URL: https://learn.microsoft.com/en-us/windows-server/storage/file-server/configure-smb-over-quic-client-access-control
- Source publication date: Not stated by the source

## Citation and use

Preferred citation: “Keep SMB over QUIC device admission separate from user authentication,” DSE Security, https://update.dsesecurity.com/updates/dse-20260908-156-keep-smb-over-quic-device-admission-separate-from-user-authentication/
Publishing principles: https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/
Usage and citation policy: https://update.dsesecurity.com/usage/
Copyright © 2026 Detection Systems & Engineering. All rights reserved.
