Activer/désactiver l’authentification du fichier journal CLFS
Vérifié avec Windows 11 25H2 — mis à jour le 30 juillet 2026
Pris en charge sur : Windows Server 2016, Windows 10 version 1607 ou versions supérieures
Chemin dans la console GPO
Configuration ordinateur\Modèles d'administration\Système\Système de fichiers Description
Ce paramètre de stratégie configure l’authentification des fichiers journaux CLFS, une fonctionnalité de sécurité qui vise à renforcer l’analyse des fichiers journaux. L’authentification des fichiers journaux permet au pilote CLFS de détecter les modifications malveillantes apportées aux fichiers journaux. Si des modifications sont détectées, CLFS considère que le fichier journal présente un risque pour l’analyse et renvoie une erreur à l’appelant. CLFS est en mesure de détecter les modifications en écrivant des codes d’authentification dans les fichiers journaux, qui combinent les données de fichier avec une clé de chiffrement propre au système. L’un des effets secondaires de l’authentification des fichiers journaux est que CLFS ne peut pas ouvrir les fichiers journaux créés sur d’autres systèmes, car ces fichiers contiennent des codes d’authentification créés à l’aide d’une clé de chiffrement propre au système. Pour ouvrir un fichier journal créé sur un autre système, l’administrateur doit d’abord utiliser la commande « fsutil.exe clfs authenticate » pour corriger les codes d’authentification. Si vous activez ou ne configurez pas ce paramètre, CLFS se réfère aux paramètres du registre local pour déterminer si vous devez ou non procéder à l’authentification des fichiers journaux. Par défaut, CLFS effectue l’authentification des fichiers journaux. Les paramètres du registre local pour cette fonctionnalité sont disponibles dans « HKLM:\SYSTEM\CurrentControlSet\Services\CLFS\Authentication ». Si vous désactivez ce paramètre, CLFS n’effectuera plus l’authentification des fichiers journaux. Vous pourrez déplacer et ouvrir les fichiers journaux d’un système à l’autre sans intervention de l’administration. Cependant, CLFS ouvrira et analysera tous les fichiers journaux, y compris ceux qui ont été conçus de manière malveillante et qui peuvent compromettre le système.
Registre
System\CurrentControlSet\Policies Nom de valeur : ClfsAuthenticationChecking
Activé : ClfsAuthenticationChecking = 1
Désactivé : ClfsAuthenticationChecking = 0
MDM / Intune (CSP)
./Device/Vendor/MSFT/Policy/Config/FileSystem/ClfsAuthenticationChecking Documentation Microsoft Learn Données de correspondance : Microsoft Learn (CC BY 4.0)
Générateur d'exports
BETAConfigurez l'état, la portée et les options, puis générez les sorties .reg, PowerShell, Intune et SCCM — ou ajoutez le paramètre à une collection multi-paramètres.
Ces exports écrivent le registre — ce n'est pas une GPO managée. ⓘ
Fichier .reg
Windows Registry Editor Version 5.00
; Exported from gporais.com
; Policy: Activer/désactiver l’authentification du fichier journal CLFS
; State: Enabled
; Supported on: Windows Server 2016, Windows 10 version 1607 ou versions supérieures
[HKEY_LOCAL_MACHINE\System\CurrentControlSet\Policies]
"ClfsAuthenticationChecking"=dword:00000001 Autres formats (PowerShell, Intune, SCCM)
PowerShell
# Exported from gporais.com
# Policy: Activer/désactiver l’authentification du fichier journal CLFS
# State: Enabled
# Supported on: Windows Server 2016, Windows 10 version 1607 ou versions supérieures
$path = 'HKLM:\System\CurrentControlSet\Policies'
New-Item -Path $path -Force | Out-Null
Set-ItemProperty -Path $path -Name 'ClfsAuthenticationChecking' -Value 1 -Type DWord Intune XML
OMA-URI: ./Device/Vendor/MSFT/Policy/Config/FileSystem/ClfsAuthenticationChecking
Data type: String
Value:
<enabled/> Intune Remediation
# === Detection script ===
# Exported from gporais.com
# Policy: Activer/désactiver l’authentification du fichier journal CLFS
# State: Enabled
# Supported on: Windows Server 2016, Windows 10 version 1607 ou versions supérieures
function Test-RegistryValue {
param(
[Parameter(Mandatory = $true)][string]$Path,
[Parameter(Mandatory = $true)][string]$Name,
[object]$Expected,
[ValidateSet('String', 'DWord', 'MultiString')][string]$Kind = 'String',
[switch]$Absent
)
try {
$item = Get-ItemProperty -LiteralPath $Path -Name $Name -ErrorAction Stop
} catch {
return $Absent.IsPresent
}
if ($Absent.IsPresent) { return $false }
$actual = $item.$Name
if ($Kind -eq 'DWord') { return ([int64]$actual) -eq ([int64]$Expected) }
if ($Kind -eq 'MultiString') {
$actualValues = @($actual)
$expectedValues = @($Expected)
if ($actualValues.Count -ne $expectedValues.Count) { return $false }
for ($i = 0; $i -lt $expectedValues.Count; $i++) {
if ([string]$actualValues[$i] -ne [string]$expectedValues[$i]) { return $false }
}
return $true
}
return [string]$actual -eq [string]$Expected
}
$checks = @(
(Test-RegistryValue -Path 'HKLM:\System\CurrentControlSet\Policies' -Name 'ClfsAuthenticationChecking' -Expected 1 -Kind DWord)
)
if ($checks -notcontains $false) {
Write-Output 'Compliant'
exit 0
}
Write-Output 'Non-compliant'
exit 1
# === Remediation script ===
# Exported from gporais.com
# Policy: Activer/désactiver l’authentification du fichier journal CLFS
# State: Enabled
# Supported on: Windows Server 2016, Windows 10 version 1607 ou versions supérieures
$path = 'HKLM:\System\CurrentControlSet\Policies'
New-Item -Path $path -Force | Out-Null
Set-ItemProperty -Path $path -Name 'ClfsAuthenticationChecking' -Value 1 -Type DWord Scripts SCCM
# Exported from gporais.com
# Policy: Activer/désactiver l’authentification du fichier journal CLFS
# State: Enabled
# Supported on: Windows Server 2016, Windows 10 version 1607 ou versions supérieures
# SCCM Configuration Item guidance:
# Create a Configuration Item of type "Setting: Script".
# Discovery script: use the Detection script below.
# Remediation script: use the Remediation script below.
# Compliance rule: the Discovery script output equals 'Compliant'.
# === Detection script ===
# Exported from gporais.com
# Policy: Activer/désactiver l’authentification du fichier journal CLFS
# State: Enabled
# Supported on: Windows Server 2016, Windows 10 version 1607 ou versions supérieures
function Test-RegistryValue {
param(
[Parameter(Mandatory = $true)][string]$Path,
[Parameter(Mandatory = $true)][string]$Name,
[object]$Expected,
[ValidateSet('String', 'DWord', 'MultiString')][string]$Kind = 'String',
[switch]$Absent
)
try {
$item = Get-ItemProperty -LiteralPath $Path -Name $Name -ErrorAction Stop
} catch {
return $Absent.IsPresent
}
if ($Absent.IsPresent) { return $false }
$actual = $item.$Name
if ($Kind -eq 'DWord') { return ([int64]$actual) -eq ([int64]$Expected) }
if ($Kind -eq 'MultiString') {
$actualValues = @($actual)
$expectedValues = @($Expected)
if ($actualValues.Count -ne $expectedValues.Count) { return $false }
for ($i = 0; $i -lt $expectedValues.Count; $i++) {
if ([string]$actualValues[$i] -ne [string]$expectedValues[$i]) { return $false }
}
return $true
}
return [string]$actual -eq [string]$Expected
}
$checks = @(
(Test-RegistryValue -Path 'HKLM:\System\CurrentControlSet\Policies' -Name 'ClfsAuthenticationChecking' -Expected 1 -Kind DWord)
)
if ($checks -notcontains $false) {
Write-Output 'Compliant'
exit 0
}
Write-Output 'Non-compliant'
exit 1
# === Remediation script ===
# Exported from gporais.com
# Policy: Activer/désactiver l’authentification du fichier journal CLFS
# State: Enabled
# Supported on: Windows Server 2016, Windows 10 version 1607 ou versions supérieures
$path = 'HKLM:\System\CurrentControlSet\Policies'
New-Item -Path $path -Force | Out-Null
Set-ItemProperty -Path $path -Name 'ClfsAuthenticationChecking' -Value 1 -Type DWord Vous construisez une collection multi-paramètres ? Ajoutez ce paramètre et générez des exports combinés (.reg, PowerShell, GPO).