What you need to know
What does an SMB over QUIC client certificate access list decide?
Potentially affected
Administrators configuring SMB over QUIC client access control on supported Windows servers.
DSE recommendation
Prepare a certificate-to-device inventory and label each required thumbprint with its algorithm.
Source facts
SMB over QUIC client access control permits device allowlists and blocklists without changing the authentication used for the SMB connection. The server validates the client certificate chain and its trust before checking the access list. Administrators can add a certificate hash to that server-maintained list. Microsoft distinguishes the SHA1 thumbprint used by certificate-mapping commands from the SHA256 thumbprint required for client access control. Microsoft documentation.
Applicability
Check the specific server release and feature prerequisites, existing QUIC configuration, client certificate, issuing authority, and administrative permissions. Review device admission and user/share authorization as separate controls.
DSE recommendation
Prepare a certificate-to-device inventory and label each required thumbprint with its algorithm. Have the PKI and file-service owners approve the allowed and blocked test devices. Preserve the existing mappings and access entries before changing admission policy.
Verification
Test an allowed device, a blocked device, and a device with an untrusted certificate chain. For the admitted device, separately verify the intended user’s share permissions. Record the certificate identity and observed rejection stage so a failed device check is not misreported as a user-password problem.
Official references
Microsoft Learn: Configure SMB over QUIC client access control in Windows Server. Source reviewed September 8, 2026.
Review the official source
Configure SMB over QUIC client access control in Windows Server · Verified September 8, 2026
Need help applying this guidance safely?
DSE can help confirm applicability, protect service continuity, and validate the result across physical security and IT systems.
Talk with DSE