SMB and the workstation/server services
How Windows shares and consumes files over the network — the client redirector and server driver behind every UNC path.
Related labs
Hands-on exercises for this area — in the browser or on a Windows machine.
View all labsGuided paths in this branch
Follow a short sequence step by step. Each path links to the first topic; use Read next on each page to continue.
Networking stack tour
Follow a connection from Winsock and DNS through TCP/IP, filtering (WFP/BFE), down to NDIS and the NIC.
Why it matters
Every \\server\share path, every mapped drive, and most lateral movement in a Windows network runs over SMB. It is also the classic 'integral subsystem' pair (Workstation service, Server service) from the Windows architecture diagram, and one of the least understood parts of the stack.
Mental model
A remote file share looks like an ordinary path to applications because a redirector driver makes a network protocol look like a local file system underneath the same VFS-style I/O path every other file uses.
How it works
- 1The Workstation service (LanmanWorkstation) and its kernel-mode redirector (the MUP and mrxsmb-family drivers) make a remote \\server\share path resolve through the ordinary I/O Manager path, as if it were a local volume.
- 2The Server service (LanmanServer) and its kernel-mode driver (srv2.sys) expose local file systems as network shares, authenticating and authorizing each request the same way a local access check would.
- 3The SMB protocol itself (SMB2/SMB3 today) carries the actual read/write/metadata operations, with SMB3 adding encryption and multichannel for both security and throughput.
Key terms
- Redirector
- The kernel-mode driver that makes a remote SMB share appear as an ordinary file-system path to applications.
- MUP
- Multiple UNC Provider; routes a \\server\share path to whichever redirector claims it.
- LanmanWorkstation / LanmanServer
- The user-mode services that configure and coordinate the SMB client and server respectively.
Why a mapped network drive behaves like a local one
Opening a file on a mapped drive uses the exact same CreateFile/NtCreateFile path as a local file. The redirector intercepts the request early enough that everything above it — the loader, an application's own file I/O calls — never has to know the data is coming from another machine.
Common misconception
People treat SMB as 'just a file-sharing protocol' separate from core Windows internals. In practice it's wired directly into the same I/O Manager and VFS-style path every other file access uses, which is exactly why it behaves — and fails — the way local storage does.
You should read next
Ranked from your current topic, related links, branch depth, and any active guided path.
intermediate
I/O Manager
The kernel component that builds, routes, and completes I/O requests.
Related topic
intermediate
File systems
NTFS and friends translating raw storage into directories, files, and metadata.
Related topic
intermediate
Access tokens
SIDs, privileges, impersonation, and the identity payload every process carries.
Related topic
Related topics
I/O Manager
The kernel component that builds, routes, and completes I/O requests.
File systems
NTFS and friends translating raw storage into directories, files, and metadata.
Access tokens
SIDs, privileges, impersonation, and the identity payload every process carries.
Services & background infrastructure
How Windows launches, groups, isolates, and supervises long-running background components.