Guide · Updated
Did Windows 11 24H2 stop scan to folder? SMB signing
In short
Since version 24H2, Windows 11 Pro, Enterprise and Education require SMB signing on incoming connections too. When the printer writes into the PC’s folder and its firmware does not sign, Windows refuses it. 24H2 also removed NTLMv1, the old login method some printers still use. The ways out: a firmware that signs, sending over FTP, or removing the signing requirement on the PC, knowing what you give up. Enabling insecure guest logons does not help: it concerns the PC opening other devices’ folders.
How to recognise it
- It worked until the Windows 11 24H2 (or 25H2) update, or it never worked on a new PC with 24H2.
- User and password are right, the folder is shared, but the panel shows an authentication or connection error (for example error 1102 or 2101 on Kyocera, “Authentication with the destination has failed” on Ricoh).
- On a PC with Windows 11 Home, or Windows 10, the same printer writes without trouble.
To see the PC’s version: Win+R, winver.
Why it happens
SMB signing adds a cryptographic signature to every message, so nobody in the middle of the network can alter it or pretend to be the PC. Since Windows 11 24H2, released in autumn 2024, Microsoft requires it by default on Pro, Enterprise and Education, outbound and inbound. In scan to folder the PC is the server and the printer the client: if the printer’s firmware cannot sign, the connection is closed.
For Windows 11 Home, Microsoft’s pages disagree: the SMB signing page says Home requires neither, the 24H2 what’s-new page lists Home as requiring it. In practice, if a Home PC on 24H2 scans fine, leave it alone.
24H2 also removed NTLMv1, the old authentication protocol that some very old printers still use: on those, the login fails even without signing.
How to fix it by hand
1. A firmware that signs SMB connections
Ask your dealer or the manufacturer’s support whether there is a firmware for your model with SMB2 or SMB3 and SMB signing. It is the only fix that leaves the PC as it is.
2. Sending over FTP
The printer hands scans over FTP to a receiver on the PC and SMB no longer comes into play: the steps are in the SMB1 guide, fix 2.
3. Removing the signing requirement on the PC, knowing what you give up
Microsoft advises against disabling SMB signing. If you must, for a printer that cannot be updated, it is the server requirement that matters, because the printer connects to the PC. From PowerShell opened as administrator:
Set-SmbServerConfiguration -RequireSecuritySignature $false
The PC stays more exposed to the attacks signing prevents: do it only on a network you control, and write down where you did it.
What not to do
- Do not enable “insecure guest logons” for the printer: that setting is about the PC opening other devices’ folders (a NAS, for instance), not about a printer writing into the PC.
- Do not change client signing (
Set-SmbClientConfiguration): for scan to folder, if anything, it is the server setting. - Do not turn SMB1 back on to solve a signing problem: they are two different things, and SMB1 reopens worse ones.
Sources
- Microsoft, Control SMB signing behavior
- Microsoft, Enable insecure guest logons in SMB2 and SMB3
- Microsoft, What’s new in Windows 11, version 24H2
- Microsoft Q&A, Scan to server folder from Ricoh copier no longer working since upgrade to Server 2025