In the wake of the recent WannaCry worm wreaking havoc across the globe, I thought I'd knock up a quick set of Configuration Manager compliance settings and a baseline to easily disable and remove SMB1 from devices within an environment.

Just as I started to gather the information I would need about the various settings, I noticed that Alex Pooley had already documented what I was about to do.

You can find his blog post with his methods here:

I've made some minor changes to some of the PowerShell, set names consistently, tested it and exported it as a cab file for easy import into other environments  .

This baseline will perform the following: