The essentials
Quick reference
One focused task per row. Jump to the related section for complete, working examples.
| Use | Syntax | Examples |
|---|---|---|
| List ordinary shares | Get-SmbShare -Special $false |
Select-Object Name, Path, ShareState, EncryptData | View examples |
| Inspect one share | Get-SmbShare -Name 'TeamData' | Format-List * | View examples |
| Inspect a remote server | Get-SmbShare -CimSession 'files01' -Special $false | View examples |
| Inspect share permissions | Get-SmbShareAccess -Name 'TeamData' | View examples |
| Inspect the folder ACL | Get-Acl -LiteralPath 'D:\Shares\TeamData' |
Format-List Owner, AccessToString | View examples |
| Create a scoped share | New-SmbShare -Name 'TeamData' -Path 'D:\Shares\TeamData' `
-ChangeAccess 'CONTOSO\File-Team' -FullAccess `
'CONTOSO\File-Admins' | View examples |
| Preview share hardening | Set-SmbShare -Name 'TeamData' -EncryptData $true `
-FolderEnumerationMode AccessBased -CachingMode None `
-WhatIf | View examples |
| Preview an access grant | Grant-SmbShareAccess -Name 'TeamData' -AccountName `
'CONTOSO\Auditors' -AccessRight Read -WhatIf | View examples |
| Preview revoking access | Revoke-SmbShareAccess -Name 'TeamData' -AccountName `
'CONTOSO\Auditors' -WhatIf | View examples |
| List server sessions | Get-SmbSession |
Select-Object SessionId, ClientComputerName, ClientUserName, NumOpens | View examples |
| List a user's open files | Get-SmbOpenFile -ClientUserName 'CONTOSO\ada' |
Select-Object FileId, SessionId, Path | View examples |
| Preview closing a file | Close-SmbOpenFile -FileId 4415226383589 -Force -WhatIf | View examples |
| Preview closing a session | Close-SmbSession -SessionId 88143542 -Force -WhatIf | View examples |
| Test SMB reachability | Test-NetConnection -ComputerName 'files01' -Port 445 `
-InformationLevel Detailed | View examples |
| Inspect client connections | Get-SmbConnection -ServerName 'files01' |
Select-Object ShareName, Dialect, Encrypted, NumOpens | View examples |
| Read SMB server events | Get-WinEvent -LogName `
'Microsoft-Windows-SMBServer/Operational' -MaxEvents `
30 | View examples |
| Preview share removal | Remove-SmbShare -Name 'TeamData' -WhatIf | View examples |
An SMB share exposes a local path through a server-side name, but effective access is constrained independently by the share security descriptor and the underlying file-system ACL. Inventory both layers before changing either one, identify active handles before maintenance, require modern transport protections where clients support them, and treat session closure or share removal as immediate remote-user impact. Most server-side changes require an elevated administrative session; a CimSession applies the command on the named remote server, not on the operator's workstation.
Step by step
Detailed examples
Review both authorization layers
Share permissions and file-system permissions are separate gates; network access must survive both, and an explicit deny can override an allow within its layer. Share Full does not bypass NTFS, access-based enumeration hides inaccessible names but does not grant access, and local console access does not exercise the share ACL. Resolve groups for the actual user token and keep broad built-in principals out unless the access model explicitly requires them.
$share = Get-SmbShare -Name 'TeamData'
$share | Select-Object Name, Path, EncryptData, FolderEnumerationMode
Get-SmbShareAccess -Name $share.Name | Format-Table AccountName, AccessControlType, AccessRight
Get-Acl -LiteralPath $share.Path | Format-List Owner, AccessToString Drain handles before disruptive maintenance
Get-SmbSession identifies authenticated server-side connections; Get-SmbOpenFile identifies individual handles. Closing a file can discard unflushed client work, and closing a session forces every handle in it closed and interrupts the remote user or application. Notify owners, stop dependent workloads, take a fresh inventory, select immutable FileId or SessionId values, use WhatIf, and re-query immediately before the approved close.
Get-SmbSession | Select-Object SessionId, ClientComputerName, ClientUserName, NumOpens
Get-SmbOpenFile -ClientUserName 'CONTOSO\ada' | Select-Object FileId, SessionId, Path
# Replace these sample IDs only with values from the immediately preceding inventory.
Close-SmbOpenFile -FileId 4415226383589 -Force -WhatIf
Close-SmbSession -SessionId 88143542 -Force -WhatIf Verify from the client and correlate server evidence
TCP 445 reachability proves neither authentication nor file authorization. Get-SmbConnection runs on the client and reports negotiated dialect, encryption, and opens for established connections; Get-SmbSession runs on the server and describes the opposite side. Test from a representative authorized client, access a harmless known file, then correlate client state and SMBClient or SMBServer event logs without weakening signing, encryption, or firewall policy as a shortcut.
Test-NetConnection -ComputerName 'files01' -Port 445 -InformationLevel Detailed
Get-SmbConnection -ServerName 'files01' |
Select-Object ServerName, ShareName, Dialect, Signed, Encrypted, NumOpens
Get-WinEvent -LogName 'Microsoft-Windows-SMBServer/Operational' -MaxEvents 30 |
Select-Object TimeCreated, Id, LevelDisplayName, Message Withdraw the namespace without confusing it with data deletion
Remove-SmbShare removes the server-side share definition and immediately breaks new and existing remote use, but it does not delete the backing directory or its files. Record the full share properties, share access entries, NTFS ACL, dependencies, DFS references, and active handles first. Preview the exact name and scope, schedule a client drain, and retain a reviewed New-SmbShare definition as the rollback path.
$share = Get-SmbShare -Name 'TeamData'
$share | Format-List Name, ScopeName, Path, Description, EncryptData, FolderEnumerationMode, CachingMode
Get-SmbShareAccess -Name $share.Name
Get-SmbOpenFile | Where-Object ShareRelativePath -ne $null | Select-Object FileId, SessionId, Path
Remove-SmbShare -Name $share.Name -WhatIf Sources and further reading
References
Authoritative documentation used to verify and expand this cheat sheet.
Help us improve
Found a typo or missing example?
Tell us what would make this cheat sheet clearer, more complete, or more useful.



