What SMB over QUIC needs on the server, the certificate rules, which editions support it and how client access control works.
From Ultra Transcenders AZ-802 by Tony Rough (coming November 2026)
SMB over QUIC replaces TCP with QUIC (built on UDP) so remote users can reach an edge file server over the internet without a VPN. All traffic, including authentication, runs inside a TLS 1.3 tunnel on UDP 443, and normal SMB features such as signing, compression, multichannel and continuous availability work inside it.
| Requirement | Detail |
|---|---|
| SMB server | Windows Server 2022 Datacenter: Azure Edition, or any edition of Windows Server 2025 |
| Client | Windows 11 |
| Firewall | Allow UDP 443 inbound; don’t open TCP 445 inbound to the internet |
| Certificate | Server Authentication EKU, SHA256 or stronger, ECDSA_P256 or RSA 2048+, private key, and a SAN DNS entry for every name clients use; trusted by clients |
| Identity | Domain-joined (recommended) with access to a DC for the file server, or local accounts on a workgroup server using NTLM |
Don’t use IP addresses in the certificate SAN: an IP name forces NTLM and doesn’t work through Azure NAT. SMB over QUIC is opt-in on the server; a client can’t force it.
On Windows Server 2025 configure SMB over QUIC with PowerShell (the Windows Admin Center method isn’t currently supported for 2025; it works for 2022 Azure Edition). The mapping must be updated whenever the certificate is renewed, because a renewed certificate has a new thumbprint.
``powershell $cert = Get-ChildItem Cert:\LocalMachine\My | Where-Object {$_.Subject -match "fs-edge"} New-SmbServerCertificateMapping -Name fs-edge.example.com -Thumbprint $cert.Thumbprint -StoreName My
This note is one section of Ultra Transcenders AZ-802: Administering Windows Server, an independent study guide that explains every topic the exam covers by technology, with comparison tables, diagrams and the common traps, plus a glossary linked to Microsoft Learn.
Due on Amazon in November 2026, in Kindle and paperback editions.
About the book · AZ-802 terms in the glossary · All AZ-802 study notes
Which operations master roles exist per forest and per domain, what each does and the placement guidance for each.
When to deploy an RODC, how staged installation works and how the allowed and denied groups decide which passwords are cached.
Which managed service account type fits a service, its requirements such as the KDS root key, and how Windows Server 2025 delegated MSAs migrate old accounts.
The LSDOU order, which GPO wins a conflict, and how Block Inheritance, Enforced and link order change the result.
How the two DHCP failover modes split or reserve addresses, what MCLT does and how relay agents fit in.
The Storage Replica topologies, when to use synchronous or asynchronous mode, log volume requirements and the Standard edition limits.
How Windows LAPS rotates and stores local administrator passwords, its policy settings, encryption and the cmdlets to retrieve them.