Loading...

Hardening changes coming to Common Log File System (CLFS) authentication

Hardening changes coming to Common Log File System (CLFS) authentication

A new hardening authentication mitigation has been introduced for the Common Log File System (CLFS) driver. Windows updates that include this new version of CLFS will initiate a 90 day “learning mode” period during which authentication codes will be added to log files automatically. Device behavior will change after this period. For more information, see Common Log File System (CLFS) Authentication Mitigation. When will this happen: Windows 11, version 25H2 and Windows Server 2025 updates released on or after October 28, 2025 include this change. A mitigation adoption period, referred to as “learning mode” will be in place for 90 days following installation of updates. During this time, authentication codes are automatically added to existing logfiles when they are opened. After this period ends, the CLFS driver will enter enforcement mode, requiring all logfiles to contain valid authentication codes. How this will affect your organization: The authentication mitigation for the CLFS driver adds a hash-based message authentication code (HMAC) to the underlying files of a CLFS logfile. With this, CLFS logfiles include authentication codes generated by combining file data with a system-unique cryptographic key stored in the registry, accessible only to administrators and SYSTEM accounts. Once enforcement mode begins, any logfile without a valid authentication code will fail to open. Logfiles not updated during the 90-day learning mode period must be manually authenticated by an Administrator using the fsutil clfs authenticate command line utility. What you need to do to prepare: Review systems that use CLFS logfiles and ensure they are opened during the 90-day learning mode period, so authentication codes are applied automatically. For logfiles that remain untouched during this time, plan for manual authentication before enforcement mode begins. See the Additional information section below for detailed guidance. Additional information: Common Log File System (CLFS) Authentication Mitigation CLFS Authentication Mitigation – Frequently asked questions (FAQ)​​​​​​​ Message ID: MC1216196

The post Hardening changes coming to Common Log File System (CLFS) authentication appeared first on M365 Admin.

Published on:

Learn more
Need help with this product?

We can help you with Hardening changes coming to Common Log File System (CLFS) authentication

If you want help implementing, troubleshooting, or improving this product, contact us and we’ll point you in the right direction.

M365 Admin
M365 Admin

by João Ferreira

Share post:

Related posts

External messaging limits for onmicrosoft.com-only organizations in Microsoft Teams

Microsoft Teams will impose outbound external messaging limits starting mid-September 2026 for organizations using only the default onmicrosof...

18 hours ago

Microsoft Teams: Enable agents for existing applications in your organization

For third-party applications already being used in your organization, admins can now discover and enable the corresponding Teams agents from w...

18 hours ago

Microsoft Viva: Campaigns Hub in Engage and Engage in Teams mobile

The Campaigns Hub in Viva Engage provides a centralized mobile destination where employees can discover and participate in organizational camp...

1 day ago

Planner: Conditional Coloring

Conditional Coloring highlight tasks based on selected criteria, making priorities, status, and important task details easier to spot. Product...

1 day ago

Outlook: Offline settings “Days of email to save” admin policy

Tenant admins will be able to define the default value for “Days of email to save” in Offline settings and designate whether end u...

1 day ago

Microsoft Copilot Studio: Agent Sharing amongst makers

Enables sharing of agents with other makers in the new GHCP harness. Makers can grant other makers Agent Viewer (view analytics/evaluations on...

1 day ago

OneDrive Photos on Windows: admin controls and policy support

OneDrive Photos, integrated into the OneDrive sync app for Windows 10/11, is currently available only for personal Microsoft accounts, with wo...

1 day ago

Admin app retiring in Teams, Outlook and Microsoft365.com

The Admin app for very small businesses in Teams, Outlook, and Microsoft365.com will retire by October 2026, with rollout starting August 2026...

1 day ago

Calls popout into a new window on the browser to support multi-tasking and collaboration during a meeting

Microsoft Teams for Web will introduce a Picture-in-Picture Call Monitor in October 2026, allowing users to manage meeting controls in a separ...

1 day ago

Microsoft Windows Autopatch: September 2026 Windows security update requires a restart for hotpatch-enabled devices

The September 2026 Windows security update requires a restart for hotpatch-enabled devices because it is a standard update. Devices will remai...

1 day ago

Newsletter

Get the latest Dynamics 365 and Power Platform content in your inbox

A curated digest of community blogs, product news, videos, and podcasts — delivered without the noise.

Weekly updates Unsubscribe anytime Fresh community picks
We use your email only for the newsletter and you can unsubscribe at any time.
By subscribing, you agree to the privacy policy.