AB
Developer(s)Microsoft
Full nameNT File System1
IntroducedJuly 27, 1993 with Windows NT 3.1
Partition IDs0x07 (MBR)
EBD0A0A2-B9E5-4433-87C0-68B6B72699C7 (GPT)
Structures
Directory contentsB-tree variant23
File allocationBitmap
Bad blocks$BadClus (MFT Record)
Limits
Max volume size2 clusters − 1 cluster (format);
256 TB4 − 64 KB4 (Windows 10 version 1703, Windows Server 2016 or earlier implementation)2
8 PB4 − 2 MB4 (Windows 10 version 1709, Windows Server 2019 or later implementation)5
Max file size16 EB4 − 1 KB (format);
16 TB − 64 KB (Windows 7, Windows Server 2008 R2 or earlier implementation)2
256 TB − 64 KB (Windows 8, Windows Server 2012 or later implementation)6
8 PB − 2 MB (Windows 10 version 1709, Windows Server 2019 or later implementation)5
Max no. of files4,294,967,295 (2−1)2
Max filename length255 UTF-16 code units7
Allowed filename
characters
• In Win32 namespace: any UTF-16 code unit (case-insensitive) except /\:﹡"?<>| as well as NUL 7
• In POSIX namespace: any UTF-16 code unit (case-sensitive) except / as well as NUL
Features
Dates recordedCreation, modification, POSIX change, access
Date range1 January 1601 – 14 Sept 30828 or 28 May 60056 (File times are 64-bit numbers counting 100-nanosecond intervals (ten million per second) from 1601)8
Date resolution100 ns
ForksYes (see § Alternate data stream (ADS) below)
AttributesRead-only, hidden, system, archive, not content indexed, off-line, temporary, compressed, encrypted
File system
permissions
ACLs
Transparent
compression
Per-file, LZ77 (Windows NT 3.51 onward)
Transparent
encryption
Per-file,
DESX (Windows 2000 onward),
Triple DES (Windows XP onward),
AES (Windows XP Service Pack 1, Windows Server 2003 onward)
Data deduplicationYes (Windows Server 2012)9
Copy-on-writeNo
Other
Supported
operating systems
Windows NT 3.1 and later
Mac OS X 10.3 and later (read-only)
Linux kernel version 2.6 and later
Linux kernel versions 2.2–2.4 (read-only)
FreeBSD
NetBSD
OpenBSD (read-only)
ChromeOS
Solaris
ReactOS (read-only)

NT File System10

(echo:: @ )

Footnotes

  1. “Glossary”. [MS-EFSR]: Encrypting File System Remote (EFSRPC) Protocol. Microsoft. 14 November 2013.

  2. “How NTFS Works”. Windows Server 2003 Technical Reference. Microsoft. 8 October 2009. Retrieved 25 January 2025. 2 3 4

  3. “B﹡Trees – NTFS Directory Trees – Concept – NTFS Documentation”. flatcap.org. Archived from the original on 2019-05-13. Retrieved 2019-05-13.

  4. 1 byte = 8 bits
    1 KB = 1,024 bytes
    1 MB = 1,048,576 bytes
    1 GB = 1,073,741,824 bytes
    1 TB = 1,099,511,627,776 bytes
    1 PB = 1,125,899,906,842,624 bytes
    1 EB = 1,152,921,504,606,846,976 bytes 2 3 4 5

  5. “Appendix A: Product Behavior”. [MS-FSA]: File System Algorithms. Microsoft. 2018-09-12. Retrieved 2018-10-01. NTFS uses a default cluster size of 4 KB, a maximum cluster size of 64 KB on Windows 10 v1703 operating system and Windows Server 2016 and prior, and 2 MB on Windows 10 v1709 operating system and Windows Server 2019 and later, and a minimum cluster size of 512 bytes. 2

  6. “Appendix A: Product Behavior”. [MS-FSA]: File System Algorithms. Microsoft. 14 November 2013. Retrieved 2012-09-21.

  7. Russon, Richard; Fledel, Yuval. “NTFS Documentation” (PDF). Archived (PDF) from the original on 2022-10-09. Retrieved 2011-06-26. 2

  8. ntfs-3g interprets it as signed integer while ntfs3 as unsigned, though the latter seems more probable given that the signed value will either roll over into well Before Christ in the year 30828 if negative values are allowed, or become a de-facto 63-bit unsigned integer if only positive values are allowed, wasting the space for one bit. Given that NTFS is proprietary and largely only known through reverse-engineering, Microsoft has not publicly stated which is intended. ntfsdoc.pdf doesn’t specify it either. But it won’t make a difference until the year 30828 anyway.

  9. Rick Vanover (14 September 2011). “Windows Server 8 data deduplication”. Archived from the original on 2016-07-18. Retrieved 2011-12-02.

  10. Karresand, Martin; Axelsson, Stefan; Dyrkolbotn, Geir Olav (2019-07-01). “Using NTFS Cluster Allocation Behavior to Find the Location of User Data”. Digital Investigation. 29: –51–S60. doi:10.1016/j.diin.2019.04.018. hdl:11250/2631756. ISSN 1742-2876. S2CID 199004263.