# Windows SMB and Network Drive Troubleshooting
SMB connection problems can occur even when the server, share, and NTFS permissions are correctly configured.
The first step is identifying the failing layer.
Architecture:
Client
↓
Network
↓
TCP 445
↓
SMB
↓
Authentication
↓
Share Permission
↓
NTFS Permission
↓
Folder/File
## 1. Test TCP port 445
Run:
Test-NetConnection SERVER-IP -Port 445
Expected:
TcpTestSucceeded : True
If False, troubleshoot the network or firewall first.
## 2. System Error 1219
A common error occurs when Windows already has an SMB connection to the same server using different credentials.
Check:
net use
Remove existing connections:
net use * /delete /y
Then reconnect using one credential.
## 3. “An extended error has occurred”
This message is not specific enough to identify the root cause.
Start with:
net use \\SERVER-IP\Company /user:SERVER-NAME\username *
Then:
dir \\SERVER-IP\Company
If command-line access works but File Explorer does not, the SMB service may already be functioning and the problem may be related to the Windows Explorer/session context.
Restart Explorer:
Stop-Process -Name explorer -Force;Start-Process explorer
## 4. Test UNC before Explorer
Always separate SMB testing from Explorer testing.
Run:
dir \\SERVER-IP\Company
Then:
dir \\SERVER-IP\Company\Department
This confirms both share connectivity and folder-level permission.
## 5. Access Denied
If a department folder returns Access Denied, check:
- Windows username.
- Windows group membership.
- SMB Share Permission.
- NTFS Permission.
- Folder inheritance.
## 6. Credential Manager
Check:
cmdkey /list
Be careful when interpreting credentials.
For example:
TERMSRV/SERVER-IP
normally relates to Remote Desktop credentials and should not automatically be treated as an SMB credential.
Use:
net use
to inspect active SMB connections.
## 7. Map the network drive
Clear existing connections:
net use * /delete /y
Then:
net use X: \\SERVER-IP\Company /user:SERVER-NAME\username * /persistent:yes
Verify:
net use
Then:
dir X:\
## 8. Test with the correct department account
Finance:
fin1
Logistics:
log1
Do not use Administrator when testing department isolation.
## 9. Test write permissions
Create:
"SMB TEST" | Out-File "X:\Department\test.txt"
Read:
Get-Content "X:\Department\test.txt"
Edit:
"UPDATED" | Out-File "X:\Department\test.txt"
Delete:
Remove-Item "X:\Department\test.txt"
## 10. SMB works from PowerShell but not Explorer
Compare:
dir \\SERVER-IP\Company
with:
explorer.exe \\SERVER-IP\Company
If PowerShell works but Explorer fails, do not immediately modify NTFS permissions.
Restart Explorer and verify the current Windows user/session.
## 11. Nextcloud cannot access SMB
Check:
smbclient --version
Then:
smbclient //SERVER-IP/Company -U 'SERVER-NAME\username'
If the:
smb: \>
prompt appears, run:
ls
If the share can be listed, basic SMB connectivity is working.
## 12. Nextcloud permission chain
Nextcloud cannot bypass Windows permissions.
The complete chain is:
Nextcloud User
↓
External Storage Mount
↓
SMB Credential
↓
Windows SMB Share
↓
Windows User
↓
Windows Group
↓
NTFS Permission
↓
File
## 13. Recommended troubleshooting order
1. Test network connectivity.
2. Test TCP 445.
3. Test SMB authentication.
4. Test the UNC path.
5. Test the department folder.
6. Test write/delete permission.
7. Test network drive mapping.
8. Test File Explorer.
9. Test Nextcloud SMB connection.
10. Check application configuration.
## 14. Conclusion
SMB troubleshooting becomes much easier when each layer is tested separately.
Do not immediately modify permissions when Explorer fails.
Identify whether the problem is:
Network
→ SMB
→ Authentication
→ Share
→ NTFS
→ Explorer
→ Nextcloud
Once the failing layer is identified, the appropriate fix becomes much clearer.