Review the Azure Files SMB channel cipher policy

Choose Azure Files SMB channel ciphers according to policy and client compatibility.

Description

The SMB channel cipher policy limits the ciphers available for file-share connections. If your organization requires AES-256-GCM, review whether other ciphers are allowed. AES-128-CCM and AES-128-GCM are also supported encryption algorithms; allowing them does not by itself mean traffic is plaintext or the encryption is broken.

Potential impact

  • Allowing ciphers outside an organization’s requirements can violate its encryption policy.
  • Restricting access to an unsupported cipher can prevent clients from connecting to the file share.

Remediation

Set share_properties.smb.channel_encryption_type = ["AES-256-GCM"] if AES-256-GCM is required. Clients must support SMB 3.1.1 and this cipher, and their allowed cipher configuration must agree. Check enforcement of encryption in transit separately, and test mounts and normal file operations.

Examples

These excerpts compare allowed SMB ciphers. Retain the actual account name, Region and replication settings. The examples use a Standard StorageV2 account that supports share_properties.

Before

hcl
resource "azurerm_storage_account" "file_storage" {
  name                     = "appstorage002"
  resource_group_name      = azurerm_resource_group.example.name
  location                 = azurerm_resource_group.example.location
  account_tier             = "Standard"
  account_replication_type = "GRS"

  share_properties {
    smb {
      channel_encryption_type = ["AES-128-CCM", "AES-128-GCM"]
    }
  }
}

AES-128-CCM and AES-128-GCM are allowed. This is a different cipher policy from an AES-256-GCM-only requirement, not an example of absent encryption.

After

hcl
resource "azurerm_storage_account" "file_storage" {
  name                     = "protectedstore02"
  resource_group_name      = "testRG"
  location                 = "northeurope"
  account_tier             = "Standard"
  account_replication_type = "LRS"

  share_properties {
    smb {
      channel_encryption_type = ["AES-256-GCM"]
    }
  }
}

Only AES-256-GCM is allowed. Check the version and cipher configuration of supported clients, such as Windows 11 or Windows Server 2022.

References