The essentials

Quick reference

One focused task per row. Jump to the related section for complete, working examples.

UseSyntaxExamples
List ordinary sharesGet-SmbShare -Special $false | Select-Object Name, Path, ShareState, EncryptDataView examples
Inspect one shareGet-SmbShare -Name 'TeamData' | Format-List *View examples
Inspect a remote serverGet-SmbShare -CimSession 'files01' -Special $falseView examples
Inspect share permissionsGet-SmbShareAccess -Name 'TeamData'View examples
Inspect the folder ACLGet-Acl -LiteralPath 'D:\Shares\TeamData' | Format-List Owner, AccessToStringView examples
Create a scoped shareNew-SmbShare -Name 'TeamData' -Path 'D:\Shares\TeamData' ` -ChangeAccess 'CONTOSO\File-Team' -FullAccess ` 'CONTOSO\File-Admins'View examples
Preview share hardeningSet-SmbShare -Name 'TeamData' -EncryptData $true ` -FolderEnumerationMode AccessBased -CachingMode None ` -WhatIfView examples
Preview an access grantGrant-SmbShareAccess -Name 'TeamData' -AccountName ` 'CONTOSO\Auditors' -AccessRight Read -WhatIfView examples
Preview revoking accessRevoke-SmbShareAccess -Name 'TeamData' -AccountName ` 'CONTOSO\Auditors' -WhatIfView examples
List server sessionsGet-SmbSession | Select-Object SessionId, ClientComputerName, ClientUserName, NumOpensView examples
List a user's open filesGet-SmbOpenFile -ClientUserName 'CONTOSO\ada' | Select-Object FileId, SessionId, PathView examples
Preview closing a fileClose-SmbOpenFile -FileId 4415226383589 -Force -WhatIfView examples
Preview closing a sessionClose-SmbSession -SessionId 88143542 -Force -WhatIfView examples
Test SMB reachabilityTest-NetConnection -ComputerName 'files01' -Port 445 ` -InformationLevel DetailedView examples
Inspect client connectionsGet-SmbConnection -ServerName 'files01' | Select-Object ShareName, Dialect, Encrypted, NumOpensView examples
Read SMB server eventsGet-WinEvent -LogName ` 'Microsoft-Windows-SMBServer/Operational' -MaxEvents ` 30View examples
Preview share removalRemove-SmbShare -Name 'TeamData' -WhatIfView examples

An SMB share exposes a local path through a server-side name, but effective access is constrained independently by the share security descriptor and the underlying file-system ACL. Inventory both layers before changing either one, identify active handles before maintenance, require modern transport protections where clients support them, and treat session closure or share removal as immediate remote-user impact. Most server-side changes require an elevated administrative session; a CimSession applies the command on the named remote server, not on the operator's workstation.

Step by step

Detailed examples

01

Establish local, remote, and clustered scope before acting

Get-SmbShare reports shares hosted by the target SMB server. Special administrative shares are hidden unless requested, and a failover-cluster share can also have a ScopeName and SmbInstance that must be preserved. Server-side inspection and mutation normally require elevation. When using CimSession, confirm PSComputerName and the intended cluster scope because the same share name on another node is a different operational target.

Compare a local baseline with one remote server
Get-SmbShare -Special $false |
  Select-Object Name, ScopeName, Path, ShareState, EncryptData, FolderEnumerationMode

Get-SmbShare -Name 'TeamData' | Format-List *
Get-SmbShare -CimSession 'files01' -Special $false |
  Select-Object PSComputerName, Name, ScopeName, Path, ShareState
Back to quick reference ↑
02

Review both authorization layers

Share permissions and file-system permissions are separate gates; network access must survive both, and an explicit deny can override an allow within its layer. Share Full does not bypass NTFS, access-based enumeration hides inaccessible names but does not grant access, and local console access does not exercise the share ACL. Resolve groups for the actual user token and keep broad built-in principals out unless the access model explicitly requires them.

Capture share and NTFS permissions together
$share = Get-SmbShare -Name 'TeamData'
$share | Select-Object Name, Path, EncryptData, FolderEnumerationMode
Get-SmbShareAccess -Name $share.Name | Format-Table AccountName, AccessControlType, AccessRight
Get-Acl -LiteralPath $share.Path | Format-List Owner, AccessToString
Back to quick reference ↑
03

Validate the backing path before publishing it

New-SmbShare immediately exposes an existing fully qualified folder and requires administrative rights. Although its syntax advertises WhatIf, Microsoft documents that WhatIf does not work for this cmdlet, so do not rely on it as a preview. Validate the exact path, existing NTFS ACL, free space, name collision, identity resolution, firewall profile, and change window first. Creation affects remote discovery and access immediately; use explicit groups rather than permissive defaults.

Gate a reviewed share definition
$name = 'TeamData'
$path = 'D:\Shares\TeamData'
if (-not (Test-Path -LiteralPath $path -PathType Container)) { throw "Missing folder: $path" }
if (Get-SmbShare -Name $name -ErrorAction SilentlyContinue) { throw "Share already exists: $name" }
Get-Acl -LiteralPath $path | Format-List Owner, AccessToString
$params = @{ Name = $name; Path = $path; ChangeAccess = 'CONTOSO\File-Team'; FullAccess = 'CONTOSO\File-Admins' }
# After approval; New-SmbShare does not provide a working WhatIf preview:
# New-SmbShare @params
Back to quick reference ↑
04

Preview hardening and permission changes independently

Set-SmbShare can require SMB encryption for a share, use access-based enumeration, and control offline caching. Encryption protects SMB data in transit but can exclude incompatible clients and adds workload, so inventory negotiated client capabilities first. Grant and revoke operations change only the share descriptor; coordinate corresponding NTFS changes separately. WhatIf is useful here, but still review the exact trustee, remote target, and post-change effective access.

Preview three focused changes
Set-SmbShare -Name 'TeamData' -EncryptData $true -FolderEnumerationMode AccessBased -CachingMode None -WhatIf
Grant-SmbShareAccess -Name 'TeamData' -AccountName 'CONTOSO\Auditors' -AccessRight Read -WhatIf
Revoke-SmbShareAccess -Name 'TeamData' -AccountName 'CONTOSO\Auditors' -WhatIf
Get-SmbShareAccess -Name 'TeamData'
Back to quick reference ↑
05

Drain handles before disruptive maintenance

Get-SmbSession identifies authenticated server-side connections; Get-SmbOpenFile identifies individual handles. Closing a file can discard unflushed client work, and closing a session forces every handle in it closed and interrupts the remote user or application. Notify owners, stop dependent workloads, take a fresh inventory, select immutable FileId or SessionId values, use WhatIf, and re-query immediately before the approved close.

Correlate sessions and handles before a preview
Get-SmbSession | Select-Object SessionId, ClientComputerName, ClientUserName, NumOpens
Get-SmbOpenFile -ClientUserName 'CONTOSO\ada' | Select-Object FileId, SessionId, Path

# Replace these sample IDs only with values from the immediately preceding inventory.
Close-SmbOpenFile -FileId 4415226383589 -Force -WhatIf
Close-SmbSession -SessionId 88143542 -Force -WhatIf
Back to quick reference ↑
06

Verify from the client and correlate server evidence

TCP 445 reachability proves neither authentication nor file authorization. Get-SmbConnection runs on the client and reports negotiated dialect, encryption, and opens for established connections; Get-SmbSession runs on the server and describes the opposite side. Test from a representative authorized client, access a harmless known file, then correlate client state and SMBClient or SMBServer event logs without weakening signing, encryption, or firewall policy as a shortcut.

Inspect transport from both ends
Test-NetConnection -ComputerName 'files01' -Port 445 -InformationLevel Detailed
Get-SmbConnection -ServerName 'files01' |
  Select-Object ServerName, ShareName, Dialect, Signed, Encrypted, NumOpens
Get-WinEvent -LogName 'Microsoft-Windows-SMBServer/Operational' -MaxEvents 30 |
  Select-Object TimeCreated, Id, LevelDisplayName, Message
Back to quick reference ↑
07

Withdraw the namespace without confusing it with data deletion

Remove-SmbShare removes the server-side share definition and immediately breaks new and existing remote use, but it does not delete the backing directory or its files. Record the full share properties, share access entries, NTFS ACL, dependencies, DFS references, and active handles first. Preview the exact name and scope, schedule a client drain, and retain a reviewed New-SmbShare definition as the rollback path.

Capture recovery facts and preview withdrawal
$share = Get-SmbShare -Name 'TeamData'
$share | Format-List Name, ScopeName, Path, Description, EncryptData, FolderEnumerationMode, CachingMode
Get-SmbShareAccess -Name $share.Name
Get-SmbOpenFile | Where-Object ShareRelativePath -ne $null | Select-Object FileId, SessionId, Path
Remove-SmbShare -Name $share.Name -WhatIf
Back to quick reference ↑

Sources and further reading

References

Authoritative documentation used to verify and expand this cheat sheet.

  1. MicrosoftSmbShare Modulelearn.microsoft.com
  2. MicrosoftNew-SmbSharelearn.microsoft.com
  3. MicrosoftGet-SmbShareAccesslearn.microsoft.com
  4. MicrosoftClose-SmbOpenFilelearn.microsoft.com
  5. MicrosoftWhat is SMB File Sharing for Windows and Windows Server?learn.microsoft.com

Help us improve

Found a typo or missing example?

Tell us what would make this cheat sheet clearer, more complete, or more useful.

Share feedback