Set Windows File Protection scanning
Verified with Windows 11 25H2 — updated on July 12, 2026
Supported on: Windows Server 2003, Windows XP, and Windows 2000 only
Path in the GPO console
Computer Configuration\Administrative Templates\System\Windows File Protection Description
This policy setting allows you to set when Windows File Protection scans protected files. This policy setting directs Windows File Protection to enumerate and scan all system files for changes. If you enable this policy setting, select a rate from the "Scanning Frequency" box. You can use this setting to direct Windows File Protection to scan files more often. -- "Do not scan during startup," the default, scans files only during setup. -- "Scan during startup" also scans files each time you start Windows XP. This setting delays each startup. If you disable or do not configure this policy setting, by default, files are scanned only during setup. Note: This policy setting affects file scanning only. It does not affect the standard background file change detection that Windows File Protection provides.
Registry
Software\Policies\Microsoft\Windows NT\Windows File Protection Export Builder
BETAConfigure the state, scope and options, then generate .reg, PowerShell, Intune and SCCM outputs — or add the setting to a multi-setting collection.
These exports write the registry — this is not a managed GPO. ⓘ
.reg file
Windows Registry Editor Version 5.00
; Exported from gporais.com
; Policy: Set Windows File Protection scanning
; State: Enabled
; Supported on: Windows Server 2003, Windows XP, and Windows 2000 only
[HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows NT\Windows File Protection]
"SfcScan"=dword:00000000 More formats (PowerShell, Intune, SCCM)
PowerShell
# Exported from gporais.com
# Policy: Set Windows File Protection scanning
# State: Enabled
# Supported on: Windows Server 2003, Windows XP, and Windows 2000 only
$path = 'HKLM:\Software\Policies\Microsoft\Windows NT\Windows File Protection'
New-Item -Path $path -Force | Out-Null
Set-ItemProperty -Path $path -Name 'SfcScan' -Value 0 -Type DWord Intune XML
No direct Policy CSP / OMA-URI mapping for this policy. Use the Intune Remediation tab, or ingest the ADMX in Intune. Intune Remediation
# === Detection script ===
# Exported from gporais.com
# Policy: Set Windows File Protection scanning
# State: Enabled
# Supported on: Windows Server 2003, Windows XP, and Windows 2000 only
function Test-RegistryValue {
param(
[Parameter(Mandatory = $true)][string]$Path,
[Parameter(Mandatory = $true)][string]$Name,
[object]$Expected,
[ValidateSet('String', 'DWord', 'MultiString')][string]$Kind = 'String',
[switch]$Absent
)
try {
$item = Get-ItemProperty -LiteralPath $Path -Name $Name -ErrorAction Stop
} catch {
return $Absent.IsPresent
}
if ($Absent.IsPresent) { return $false }
$actual = $item.$Name
if ($Kind -eq 'DWord') { return ([int64]$actual) -eq ([int64]$Expected) }
if ($Kind -eq 'MultiString') {
$actualValues = @($actual)
$expectedValues = @($Expected)
if ($actualValues.Count -ne $expectedValues.Count) { return $false }
for ($i = 0; $i -lt $expectedValues.Count; $i++) {
if ([string]$actualValues[$i] -ne [string]$expectedValues[$i]) { return $false }
}
return $true
}
return [string]$actual -eq [string]$Expected
}
$checks = @(
(Test-RegistryValue -Path 'HKLM:\Software\Policies\Microsoft\Windows NT\Windows File Protection' -Name 'SfcScan' -Expected 0 -Kind DWord)
)
if ($checks -notcontains $false) {
Write-Output 'Compliant'
exit 0
}
Write-Output 'Non-compliant'
exit 1
# === Remediation script ===
# Exported from gporais.com
# Policy: Set Windows File Protection scanning
# State: Enabled
# Supported on: Windows Server 2003, Windows XP, and Windows 2000 only
$path = 'HKLM:\Software\Policies\Microsoft\Windows NT\Windows File Protection'
New-Item -Path $path -Force | Out-Null
Set-ItemProperty -Path $path -Name 'SfcScan' -Value 0 -Type DWord SCCM scripts
# Exported from gporais.com
# Policy: Set Windows File Protection scanning
# State: Enabled
# Supported on: Windows Server 2003, Windows XP, and Windows 2000 only
# SCCM Configuration Item guidance:
# Create a Configuration Item of type "Setting: Script".
# Discovery script: use the Detection script below.
# Remediation script: use the Remediation script below.
# Compliance rule: the Discovery script output equals 'Compliant'.
# === Detection script ===
# Exported from gporais.com
# Policy: Set Windows File Protection scanning
# State: Enabled
# Supported on: Windows Server 2003, Windows XP, and Windows 2000 only
function Test-RegistryValue {
param(
[Parameter(Mandatory = $true)][string]$Path,
[Parameter(Mandatory = $true)][string]$Name,
[object]$Expected,
[ValidateSet('String', 'DWord', 'MultiString')][string]$Kind = 'String',
[switch]$Absent
)
try {
$item = Get-ItemProperty -LiteralPath $Path -Name $Name -ErrorAction Stop
} catch {
return $Absent.IsPresent
}
if ($Absent.IsPresent) { return $false }
$actual = $item.$Name
if ($Kind -eq 'DWord') { return ([int64]$actual) -eq ([int64]$Expected) }
if ($Kind -eq 'MultiString') {
$actualValues = @($actual)
$expectedValues = @($Expected)
if ($actualValues.Count -ne $expectedValues.Count) { return $false }
for ($i = 0; $i -lt $expectedValues.Count; $i++) {
if ([string]$actualValues[$i] -ne [string]$expectedValues[$i]) { return $false }
}
return $true
}
return [string]$actual -eq [string]$Expected
}
$checks = @(
(Test-RegistryValue -Path 'HKLM:\Software\Policies\Microsoft\Windows NT\Windows File Protection' -Name 'SfcScan' -Expected 0 -Kind DWord)
)
if ($checks -notcontains $false) {
Write-Output 'Compliant'
exit 0
}
Write-Output 'Non-compliant'
exit 1
# === Remediation script ===
# Exported from gporais.com
# Policy: Set Windows File Protection scanning
# State: Enabled
# Supported on: Windows Server 2003, Windows XP, and Windows 2000 only
$path = 'HKLM:\Software\Policies\Microsoft\Windows NT\Windows File Protection'
New-Item -Path $path -Force | Out-Null
Set-ItemProperty -Path $path -Name 'SfcScan' -Value 0 -Type DWord Building a multi-setting collection? Add this setting and generate combined .reg / PowerShell / GPO scripts.