en-US windows computer

Set Windows File Protection scanning

Verified with Windows 11 25H2 — updated on July 12, 2026

Windows 11 25H2

Supported on: Windows Server 2003, Windows XP, and Windows 2000 only

Path in the GPO console

Computer Configuration\Administrative Templates\System\Windows File Protection

Description

This policy setting allows you to set when Windows File Protection scans protected files. This policy setting directs Windows File Protection to enumerate and scan all system files for changes. If you enable this policy setting, select a rate from the "Scanning Frequency" box. You can use this setting to direct Windows File Protection to scan files more often. -- "Do not scan during startup," the default, scans files only during setup. -- "Scan during startup" also scans files each time you start Windows XP. This setting delays each startup. If you disable or do not configure this policy setting, by default, files are scanned only during setup. Note: This policy setting affects file scanning only. It does not affect the standard background file change detection that Windows File Protection provides.

Registry

HKLM Software\Policies\Microsoft\Windows NT\Windows File Protection

More options available

Options

Scanning frequency:
SfcScan enum
  • Do not scan during startup -> 0 (default)
  • Scan during startup -> 1

Export Builder

BETA

Configure the state, scope and options, then generate .reg, PowerShell, Intune and SCCM outputs — or add the setting to a multi-setting collection.

These exports write the registry — this is not a managed GPO.

.reg file

Windows Registry Editor Version 5.00

; Exported from gporais.com
; Policy: Set Windows File Protection scanning
; State: Enabled
; Supported on: Windows Server 2003, Windows XP, and Windows 2000 only

[HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows NT\Windows File Protection]
"SfcScan"=dword:00000000
More formats (PowerShell, Intune, SCCM)

PowerShell

# Exported from gporais.com
# Policy: Set Windows File Protection scanning
# State: Enabled
# Supported on: Windows Server 2003, Windows XP, and Windows 2000 only

$path = 'HKLM:\Software\Policies\Microsoft\Windows NT\Windows File Protection'
New-Item -Path $path -Force | Out-Null
Set-ItemProperty -Path $path -Name 'SfcScan' -Value 0 -Type DWord

Building a multi-setting collection? Add this setting and generate combined .reg / PowerShell / GPO scripts.

Open the Builder

Embed this policy on your site

What to embed
Theme

Adds one script line: the theme follows your site’s appearance and the height fits the content. If your site blocks scripts, the embed follows the visitor’s system theme.

Preview