I just migrated a windows server VPS to a new one (Windows Server 2012 R2) and realized that even though "Turn off file and printer sharing" is selected for all available network profiles (Public/Guest, Private) within the "Network and Sharing Center", it is still possible to externally access the server's shares.
The windows firewall is enabled (and in use) for all network adapters on the system (there is just the one), the default inbound action is to block, and I ensured that all relevant inbound firewall rules are actually disabled ("File and Printer Sharing..." for ports 137, 138 UDP and 139, 445 TCP). "Password protected sharing" is selected as well.
Any idea why it is still possible to see and access the shares?
As a workaround, I am now explicitly blocking the ports, which works as expected, but this should be unnecessary in the first place.