Enable / disable CLFS logfile authentication
Verified with Windows 11 25H2 — updated on July 30, 2026
Supported on: At least Windows Server 2016, Windows 10 Version 1607
Path in the GPO console
Computer Configuration\Administrative Templates\System\File System Description
This policy setting configures CLFS logfile authentication, a security feature which aims to harden logfile parsing. Logfile authentication provides the ability for the CLFS driver to detect malicious modications made to logfiles. If modifications are detected, CLFS will deem the logfile as unsafe for parsing and return an error to the caller. CLFS is able to detect modifications by writing authentication codes to logfiles, which combines file data with a system-unique cryptographic key. A side effect of logfile authentication is that CLFS will fail to open logfiles that were created on other systems, as these logfiles contain authentication codes created using a system-unique cryptographic key. To open a logfile that was created on another system, an administrator must first use the "fsutil.exe clfs authenticate" command to correct the authentication codes. If you enable or do not configure this setting, CLFS will refer to local registry settings on whether logfile authentication should be done or not. By default, CLFS will do logfile authentication. The local registry settings for this feature can be found at "HKLM:\SYSTEM\CurrentControlSet\Services\CLFS\Authentication". If you disable his setting, CLFS will no longer perform logfile authentication. Logfiles will be able to be moved and opened across systems without Administrative action. However, CLFS will open and parse all logfiles, including maliciously crafted logfiles that may compromise the system.
Registry
System\CurrentControlSet\Policies Value name: ClfsAuthenticationChecking
Enabled: ClfsAuthenticationChecking = 1
Disabled: ClfsAuthenticationChecking = 0
MDM / Intune (CSP)
./Device/Vendor/MSFT/Policy/Config/FileSystem/ClfsAuthenticationChecking Microsoft Learn documentation Mapping data: Microsoft Learn (CC BY 4.0)
Export Builder
BETAConfigure the state, scope and options, then generate .reg, PowerShell, Intune and SCCM outputs — or add the setting to a multi-setting collection.
These exports write the registry — this is not a managed GPO. ⓘ
.reg file
Windows Registry Editor Version 5.00
; Exported from gporais.com
; Policy: Enable / disable CLFS logfile authentication
; State: Enabled
; Supported on: At least Windows Server 2016, Windows 10 Version 1607
[HKEY_LOCAL_MACHINE\System\CurrentControlSet\Policies]
"ClfsAuthenticationChecking"=dword:00000001 More formats (PowerShell, Intune, SCCM)
PowerShell
# Exported from gporais.com
# Policy: Enable / disable CLFS logfile authentication
# State: Enabled
# Supported on: At least Windows Server 2016, Windows 10 Version 1607
$path = 'HKLM:\System\CurrentControlSet\Policies'
New-Item -Path $path -Force | Out-Null
Set-ItemProperty -Path $path -Name 'ClfsAuthenticationChecking' -Value 1 -Type DWord Intune XML
OMA-URI: ./Device/Vendor/MSFT/Policy/Config/FileSystem/ClfsAuthenticationChecking
Data type: String
Value:
<enabled/> Intune Remediation
# === Detection script ===
# Exported from gporais.com
# Policy: Enable / disable CLFS logfile authentication
# State: Enabled
# Supported on: At least Windows Server 2016, Windows 10 Version 1607
function Test-RegistryValue {
param(
[Parameter(Mandatory = $true)][string]$Path,
[Parameter(Mandatory = $true)][string]$Name,
[object]$Expected,
[ValidateSet('String', 'DWord', 'MultiString')][string]$Kind = 'String',
[switch]$Absent
)
try {
$item = Get-ItemProperty -LiteralPath $Path -Name $Name -ErrorAction Stop
} catch {
return $Absent.IsPresent
}
if ($Absent.IsPresent) { return $false }
$actual = $item.$Name
if ($Kind -eq 'DWord') { return ([int64]$actual) -eq ([int64]$Expected) }
if ($Kind -eq 'MultiString') {
$actualValues = @($actual)
$expectedValues = @($Expected)
if ($actualValues.Count -ne $expectedValues.Count) { return $false }
for ($i = 0; $i -lt $expectedValues.Count; $i++) {
if ([string]$actualValues[$i] -ne [string]$expectedValues[$i]) { return $false }
}
return $true
}
return [string]$actual -eq [string]$Expected
}
$checks = @(
(Test-RegistryValue -Path 'HKLM:\System\CurrentControlSet\Policies' -Name 'ClfsAuthenticationChecking' -Expected 1 -Kind DWord)
)
if ($checks -notcontains $false) {
Write-Output 'Compliant'
exit 0
}
Write-Output 'Non-compliant'
exit 1
# === Remediation script ===
# Exported from gporais.com
# Policy: Enable / disable CLFS logfile authentication
# State: Enabled
# Supported on: At least Windows Server 2016, Windows 10 Version 1607
$path = 'HKLM:\System\CurrentControlSet\Policies'
New-Item -Path $path -Force | Out-Null
Set-ItemProperty -Path $path -Name 'ClfsAuthenticationChecking' -Value 1 -Type DWord SCCM scripts
# Exported from gporais.com
# Policy: Enable / disable CLFS logfile authentication
# State: Enabled
# Supported on: At least Windows Server 2016, Windows 10 Version 1607
# SCCM Configuration Item guidance:
# Create a Configuration Item of type "Setting: Script".
# Discovery script: use the Detection script below.
# Remediation script: use the Remediation script below.
# Compliance rule: the Discovery script output equals 'Compliant'.
# === Detection script ===
# Exported from gporais.com
# Policy: Enable / disable CLFS logfile authentication
# State: Enabled
# Supported on: At least Windows Server 2016, Windows 10 Version 1607
function Test-RegistryValue {
param(
[Parameter(Mandatory = $true)][string]$Path,
[Parameter(Mandatory = $true)][string]$Name,
[object]$Expected,
[ValidateSet('String', 'DWord', 'MultiString')][string]$Kind = 'String',
[switch]$Absent
)
try {
$item = Get-ItemProperty -LiteralPath $Path -Name $Name -ErrorAction Stop
} catch {
return $Absent.IsPresent
}
if ($Absent.IsPresent) { return $false }
$actual = $item.$Name
if ($Kind -eq 'DWord') { return ([int64]$actual) -eq ([int64]$Expected) }
if ($Kind -eq 'MultiString') {
$actualValues = @($actual)
$expectedValues = @($Expected)
if ($actualValues.Count -ne $expectedValues.Count) { return $false }
for ($i = 0; $i -lt $expectedValues.Count; $i++) {
if ([string]$actualValues[$i] -ne [string]$expectedValues[$i]) { return $false }
}
return $true
}
return [string]$actual -eq [string]$Expected
}
$checks = @(
(Test-RegistryValue -Path 'HKLM:\System\CurrentControlSet\Policies' -Name 'ClfsAuthenticationChecking' -Expected 1 -Kind DWord)
)
if ($checks -notcontains $false) {
Write-Output 'Compliant'
exit 0
}
Write-Output 'Non-compliant'
exit 1
# === Remediation script ===
# Exported from gporais.com
# Policy: Enable / disable CLFS logfile authentication
# State: Enabled
# Supported on: At least Windows Server 2016, Windows 10 Version 1607
$path = 'HKLM:\System\CurrentControlSet\Policies'
New-Item -Path $path -Force | Out-Null
Set-ItemProperty -Path $path -Name 'ClfsAuthenticationChecking' -Value 1 -Type DWord Building a multi-setting collection? Add this setting and generate combined .reg / PowerShell / GPO scripts.