Can’t Access a Shared Folder or NAS in Windows 11? Fix It

Fix Windows 11 shared folder and NAS errors: guest access blocked, SMB signing after 24H2, SMB1-only devices, NTLM, permissions and System error 53.

Quick Answer

If Windows says security policies block unauthenticated guest access, connect to the NAS or server with a valid username and password instead of guest access. On Windows 11, version 24H2, SMB signing is required by default, so turn on SMB signing on the NAS. If the device only supports SMB1, ask its manufacturer for a firmware update that supports SMB 2.02 or later instead of reinstalling SMB1.

Common causes

  • Windows blocking unauthenticated guest access to the NAS or server
  • SMB signing required by default on Windows 11, version 24H2, and not supported by the NAS
  • A NAS or device that only supports the old SMB1 protocol
  • NTLM blocking set up on your PC for connections by IP address or to a NAS
  • Share or NTFS permissions that don’t give you access
  • The computer sharing the folder turned off
  • The TCP/IP NetBIOS Helper service stopped or running under the wrong account

Step-by-Step Solutions

Start by matching the error message you see to a step, then work through the other steps in order.

  1. Step 1: Match the error message to a step

    Find the message you see below and start with the step it points to.

    If the problem started after upgrading to Windows 11, version 24H2 and the share worked before, Microsoft says to check the security changes in that version first. Several SMB security features are enforced by default starting in 24H2.

    • “Your organization’s security policies block unauthenticated guest access”: see Sign in with an account on the NAS.
    • “This share requires the obsolete SMB1 protocol” or “The specified network name is no longer available”: see Update a NAS that only supports SMB1.
    • “System error 53 has occurred. The network path was not found”: see Check the TCP/IP NetBIOS Helper service.
    • “Access is denied” or “You do not have permission to access”: work through the steps in order.
    Good to know

    Event Viewer has SMB client logs. Open Event Viewer, then Applications and Services Logs, Microsoft, Windows, SMBClient, and look at the Connectivity and Security channels. Event ID 31017 there points to blocked guest access.

  2. Step 2: Check the other computer and your network

    The computer you’re connecting to needs to be on, and both computers need to be on the same network.

    If you can’t connect to a network drive or folder, the computer you’re trying to connect to might be turned off. Make sure it’s on.

    Make sure both computers are on the same network. For example, if they connect to the internet through a wireless router, make sure they both connect through the same router. If you’re on a Wi-Fi network, set it to Private.

    Update Windows on all the computers involved, so you aren’t missing any driver or Windows updates.

  3. Step 3: Sign in with an account on the NAS

    Microsoft’s fix for blocked guest access is to connect with a valid username and password instead of guest access.

    If you see the message about security policies blocking unauthenticated guest access, the server or NAS accepts guest sign-ins, but Windows doesn’t allow them by default. Windows 11 Pro, Enterprise and Education turn off insecure guest access by default.

    Connect with a username and password that the NAS or server accepts. If the device only offers guest access, Microsoft recommends upgrading or replacing devices that only support guest authentication.

    On Windows 11, version 24H2, SMB signing is also required by default, which causes compatibility issues with guest sign-ins when signing doesn’t succeed.

    Good to know

    Microsoft documents a setting that turns insecure guest logons back on, but recommends that you don’t enable it. It treats it only as a temporary, risk-accepted workaround, because it exposes your PC to rogue-server and man-in-the-middle attacks. Guest logons also need SMB signing and encryption turned off, which can leave you open to credential theft and relay attacks.

  4. Step 4: Turn on SMB signing on the NAS

    On Windows 11, version 24H2, connections to devices that don’t support SMB signing are rejected.

    Starting with Windows 11, version 24H2, SMB signing is required by default. If the share is on a NAS or another third-party server that doesn’t support signing, the connection is rejected.

    Microsoft’s preferred fix is to turn on SMB signing on the NAS or server. If the device can’t support signing, Microsoft says to weigh the security impact before changing the signing requirement on your PC.

    Good to know

    Guest logons don’t support SMB signing, even when your PC is set to allow guest logons.

  5. Step 5: Update a NAS that only supports SMB1

    Windows 11 doesn’t contain SMBv1 by default after a clean installation, and connecting to a device that only supports it can show an error.

    Windows 11 doesn’t contain the SMBv1 client or server by default after a clean installation. If you try to connect to a device that supports only SMBv1, you might see messages such as “This share requires the obsolete SMB1 protocol,” “The specified network name is no longer available” or System Error 64.

    These devices are more likely running older versions of Linux, Samba or other third-party software than Windows. Contact the manufacturer of the NAS or device and ask for a software or firmware update that supports SMB 2.02 or later.

    Good to know

    Microsoft strongly recommends that you don’t reinstall SMBv1, because it has known security issues regarding ransomware and other malware. It describes turning it back on only for when the manufacturer can’t provide a supported version of SMB.

  6. Step 6: Connect by name instead of IP address

    On PCs with SMB NTLM blocking set up, connecting by IP address, to a workgroup device or to a NAS can be denied.

    If NTLM blocking for SMB is configured on your PC, you can get Access Denied when you connect by IP address, to a workgroup device, or to a NAS where Kerberos can’t be used.

    Microsoft’s fix is to connect using the server’s full name (FQDN) instead of its IP address, and to make sure name resolution is correct. An administrator can also configure an NTLM exception list for required older devices.

  7. Step 7: Check the folder’s sharing permissions

    If some users can open the share and others can’t, check the permissions on the computer that shares it.

    Microsoft points to permissions when a specific user or group is denied while others get in, or when folders are hidden. On the computer that shares the folder, check that both the Share permissions and the NTFS (Security) permissions give the user the access they need, and check Access-Based Enumeration.

    To give a specific person access from File Explorer on the sharing PC, right-click the folder, select Show more options, select Give access to, choose Specific people, then select the user on the network.

    Good to know

    If you can’t change the permissions yourself, Microsoft suggests contacting your network administrator.

  8. Step 8: Check the TCP/IP NetBIOS Helper service

    Microsoft links System error 53 to this service being stopped or running under the wrong account.

    If you see “System error 53 has occurred. The network path was not found,” the TCP/IP NetBIOS Helper service may be stopped, or running as Local System instead of Local Service.

    Select Search, enter Services and press Enter. Double-click TCP/IP NetBIOS Helper and make sure Startup type is set to Automatic. The service needs to be running as a Local Service.

  9. Step 9: Turn on network discovery and map the drive

    Turn on network discovery to see sharing devices in Network, then map the share as a drive.

    If Network in File Explorer shows “Network discovery is turned off,” select that banner, then select Turn on network discovery and file sharing. You can also select Start, then Settings, search for manage advanced sharing settings and, under Private networks, turn on Network discovery and File and printer sharing.

    Without SMB1, Network can no longer show Windows computers through the old NetBIOS browsing method, and Microsoft recommends mapping drives instead of browsing.

    To map a drive, open File Explorer with the Windows logo key + E, select This PC, then on the ribbon select More and choose Map network drive. Pick a drive letter, type the folder’s path in the Folder box or select Browse, select Reconnect at sign-in if you want it to connect every time you sign in, then select Finish.

    Good to know

    If you don’t see Map network drive on the More menu, right-click This PC in the folder pane.

Still can’t open the shared folder?

If you still can’t connect, Microsoft suggests contacting your network administrator. For a device that only supports SMB1, contact its manufacturer for a software or firmware update. If the steps above don’t help and you open a support case, Microsoft says to gather diagnostic data first so the support team can triage it.

Don’t weaken your PC’s security: Microsoft strongly recommends that you don’t reinstall SMB1, and recommends that you don’t enable insecure guest logons. SMB1 has known security issues regarding ransomware and other malware, and guest logons can let an attacker trick you into connecting to a spoofed malicious server.

Frequently Asked Questions

Why did my NAS stop working after the Windows 11 24H2 update?

Starting with Windows 11, version 24H2, several SMB security features are enforced by default, including required SMB signing. Connections to devices that don’t support signing are rejected, and guest sign-ins run into compatibility issues when signing doesn’t succeed.

Should I turn SMB1 back on to reach an old NAS?

Microsoft strongly recommends that you don’t, because SMB1 has known security issues regarding ransomware and other malware. Ask the manufacturer for a software or firmware update that supports SMB 2.02 or later.

Is it safe to enable insecure guest logons?

Microsoft recommends that you don’t. It describes them only as a temporary, risk-accepted workaround, because they expose your PC to rogue-server and man-in-the-middle attacks.

Why can’t I see my NAS or other PCs under Network?

If Network shows that network discovery is turned off, select the banner and turn it on. Without SMB1, Network also can’t show Windows computers through the old browsing method, so Microsoft recommends mapping the share as a drive.

Sources & review

This guide was checked against Microsoft’s official support instructions on October 6, 2026. Device options can change with software updates.

All Windows guides