---
title: "SMB signing guide"
canonical: "https://docs.aryaka.com/space/KNOW/1300037780/SMB%20signing%20guide"
format: markdown
---
The server message block (SMB) protocol includes security signing functionality in the form of  security signatures . This document describes the procedure to enable SMB signing on your ANAP. While we have made every effort possible to ensure accurate descriptions and screen captures at time of publication, updates to the third-party UI are beyond our control. Refer to the third-party documentation to ensure you have the most recent information. Create an Active Directory user account A new user account in local Active Directory has to be created for ANAP deployed at the site. Then the ANAP has to be trusted for delegation to all CIFS servers. Click  Start  >  Administrative Tools  >  Active Directory Users and Computers . The Active Directory Users and Computers console appears. Click the domain name where you want this user account created, then click the plus  +  icon to expand it. Right-click  Users , then select  New  >  User . Enter the first name, last name, and user logon name for the new user, and then click  Next . Enter a password, confirm the password, then select one of the following check boxes: Users must change password at next logon User cannot change password Password never expires Account is disabled Click  Next , confirm your entries, then click  Finish . Enable the Delegation tab If the Delegation tab does  not  appear in the Active Directory Properties dialog, you must raise the domain's functional level by changing domain settings under Open Active Directory Domains and Trusts. If the Delegation tab does appear, skip to the next section and continue with the configuration described there. Ensure the Delegation tab is displayed: Click  Start  >  Administrative Tools  >  Active Directory Users and Computers . The Active Directory Users and Computers console appears. Click the domain name where you want this user account created, click the plus  +  icon to expand it, then double-click the  Users  folder. The Users dialog appears. Double-click the user account name. The selected user's Properties dialog appears: Locate the Delegation tab: If the tab appears, skip to the next section and continue with the configuration from there. If the tab does not appear, continue this procedure with step 2. In the left pane of Active Directory Users and Computers console, right-click the domain name whose functional level you want to raise, and then select  Raise Domain Functional Level . A message appears when the the Active Directory domain is at its highest functional level. Enable delegation The ANAP user account must be trusted for  delegation  to CIFS services as follows. Double-click the ANAP user account. The ANAP User Properties dialog appears. Click the  Delegation  tab. Click the  Trust this user for delegation to specified services only  option. Click  Add  below the Service Type list, then add all  CIFS  services listed in the Service Type column. Click  OK . Add the ANAP to the Active Directory domain Do  not  perform the procedure described in this section until you have confirmation from Aryaka support to do so.  Log in to the ANAP user interface: Enter the ANAP's IP address in your web browser. The ANAP login page appears. Enter the credentials for the ANAP UI provided by Aryaka support, then click  Login . Note that the ANAP credentials differ from your MyAryaka credentials. Click  Active Directory Domain  in the left navigation pane. Enter the Active Directory administrator credentials then click  Join . The ANAP's status updates as its configuration is added to the Active Directory domain. When the ANAP is successfully added to the domain, the status changes to Joined. Contact  support@aryaka.com  and inform them about the domain changes made. In addition, ANAP user account details have to be encrypted and shared with Aryaka support team. In this topic