# Review the delay imposed by SMB authentication rate limiting

> How should administrators validate SMB failed-authentication throttling?

- Canonical URL: https://update.dsesecurity.com/updates/dse-20260908-164-review-the-delay-imposed-by-smb-authentication-rate-limiting/
- Publisher: Detection Systems & Engineering (DSE Security)
- Author: DSE Security Editorial Team
- Published: 2026-09-08T18:14:27+00:00
- Modified: 2026-09-08T18:26:31+00:00
- Last reviewed by DSE: 2026-09-08
- Resource type: Guide
- DSE priority: Information
- Topics: Business Continuity, IT
- Reading time: 1 minutes

## What you need to know

How should administrators validate SMB failed-authentication throttling?

## Potentially affected

Administrators of SMB servers running Windows Server 2025 or Windows 11 version 24H2 and later.

## DSE recommendation

Choose a nonprivileged test identity and agree on a small, bounded number of failed attempts with the identity owner.

## Article

## Source facts

Microsoft documents an SMB server control that delays failed authentication attempts using NTLM or PKU2U. The control is enabled by default beginning with Windows Server 2025 and Windows 11 version 24H2, with a configurable two-second default delay. Administrators can enable, disable, or configure the limiter through PowerShell or Group Policy. [Microsoft Learn](https://learn.microsoft.com/en-us/windows-server/storage/file-server/configure-smb-authentication-rate-limiter).

## Applicability

Verify the server version and the authentication method used by the test client. Distinguish this server-side delay from account lockout, SMB signing, or a policy that blocks NTLM. Review the configured value rather than assuming the documented default remains effective.

## DSE recommendation

Choose a nonprivileged test identity and agree on a small, bounded number of failed attempts with the identity owner. Record the initial limiter setting and any governing policy. Keep the exercise narrow enough to avoid locking out a real user or creating a noisy authentication incident. Decide in advance what observation would justify changing the delay, and retain a reversible configuration record.

## Verification

Compare failed-attempt timing with the effective setting, then confirm that an authorized connection still works. Record client, server, protocol, timestamps, and any account-policy response. If the observed delay differs, investigate scope and authentication behavior before weakening the control. Keep password values out of the evidence.

## Official references

[Microsoft Learn: Configure SMB authentication rate limiter for Windows](https://learn.microsoft.com/en-us/windows-server/storage/file-server/configure-smb-authentication-rate-limiter). Source reviewed September 8, 2026.

## Primary reference

- Name: Configure SMB authentication rate limiter for Windows
- Authority: Microsoft Learn
- URL: https://learn.microsoft.com/en-us/windows-server/storage/file-server/configure-smb-authentication-rate-limiter
- Source publication date: Not stated by the source

## Citation and use

Preferred citation: “Review the delay imposed by SMB authentication rate limiting,” DSE Security, https://update.dsesecurity.com/updates/dse-20260908-164-review-the-delay-imposed-by-smb-authentication-rate-limiting/
Publishing principles: https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/
Usage and citation policy: https://update.dsesecurity.com/usage/
Copyright © 2026 Detection Systems & Engineering. All rights reserved.
