# Use ReFS resiliency only inside a supported storage and application design

> ReFS supplies metadata integrity and documented resiliency features, while repair capability, data integrity streams, storage layout, hardware certification, and application support determine the actual outcome.

- Canonical URL: https://update.dsesecurity.com/updates/windows-refs-supported-resiliency-design/
- Publisher: Detection Systems & Engineering (DSE Security)
- Author: DSE Security Editorial Team
- Published: 2026-08-25T21:35:01+00:00
- Modified: 2026-08-25T21:43:55+00:00
- Last reviewed by DSE: 2026-08-25
- Resource type: Explainer
- DSE priority: Advisory
- Topics: Business Continuity, IT
- Reading time: 3 minutes

## What you need to know

ReFS supplies metadata integrity and documented resiliency features, while repair capability, data integrity streams, storage layout, hardware certification, and application support determine the actual outcome.

## Potentially affected

Windows Server storage designs using or evaluating ReFS for Storage Spaces, Storage Spaces Direct, basic disks, or backup targets.

## DSE recommendation

Select ReFS only for a Microsoft- and application-supported configuration, document which data is checksummed and repairable, monitor integrity events, and maintain independent tested backups.

## Article

Bottom line: ReFS is designed for integrity, availability, scale, and specific storage workloads. Its repair behavior depends on the storage configuration, alternate data copies, integrity streams, and application. Microsoft limits supported scenarios and calls for certified hardware and application compatibility. ReFS is not a universal corruption-proof file system or a backup.

## Source fact: what Microsoft documents

Microsoft’s [ReFS overview](https://learn.microsoft.com/en-us/windows-server/storage/refs/refs-overview) describes integrity streams, online repair, metadata checksums, block cloning, sparse valid data length, and scale features. In supported Storage Spaces and Storage Spaces Direct designs, ReFS can use alternate copies to repair detected metadata or data corruption when the necessary integrity and redundancy are available.

Microsoft lists supported configurations and scenarios for Storage Spaces Direct, Storage Spaces, basic disks, and backup targets. The page states that supported configurations must use Windows Server Catalog-certified hardware and meet application requirements. Capabilities differ by Windows Server version and storage design. Microsoft also calls out SAN and feature considerations where NTFS may be required, and advises contacting application and storage vendors for relevant support details.

## What the source does not establish

ReFS does not guarantee that all file data is checksummed, that every detected corruption can be repaired, or that a basic disk has an alternate copy. It does not replace backup, protect against deletion or ransomware, validate application consistency, or make unsupported hardware supportable. A clean file-system status does not prove stored application data is semantically correct.

## Applicability questions

- Which Windows Server edition and version, physical disks, controller or HBA, enclosure, firmware, and storage topology are proposed?

- Is the workload Storage Spaces Direct, Storage Spaces, a basic disk, a backup target, Hyper-V, SQL Server, or another application?

- Which data has integrity streams, and where does an alternate good copy come from?

- Does the application and hardware vendor explicitly support ReFS for this exact use?

- How are integrity warnings, scrub results, storage faults, capacity, and repair actions monitored?

## DSE recommendation: controlled next steps

The following steps are DSE recommendations based on the cited source.

- Confirm Microsoft, hardware, storage, and application support for the exact OS, firmware, topology, and workload.

- Document the protection model for metadata and file data, including integrity-stream state, redundancy, failure domains, and repair limits.

- Test representative application I/O, backup, restore, expansion, drive failure, repair, and performance before production acceptance.

- Monitor ReFS, storage, controller, and application events; route integrity or repair warnings to an owned queue.

- Maintain independent backups and prove restoration to another system. Do not count online repair as the recovery copy.

## Verification and evidence

- Preserve hardware certification, vendor support, OS/build, storage layout, ReFS settings, and acceptance approval.

- Record integrity-stream state and documented health or scrub output for representative volumes.

- Capture controlled failure-and-repair test results without risking the only copy of data.

- Demonstrate a restore from independent backup and application-level validation afterward.

## Official references

- [Resilient File System (ReFS) overview](https://learn.microsoft.com/en-us/windows-server/storage/refs/refs-overview) — Microsoft

## Primary reference

- Name: Resilient File System (ReFS) overview
- Authority: Microsoft Learn
- URL: https://learn.microsoft.com/en-us/windows-server/storage/refs/refs-overview
- Source publication date: Not stated by the source

## Citation and use

Preferred citation: “Use ReFS resiliency only inside a supported storage and application design,” DSE Security, https://update.dsesecurity.com/updates/windows-refs-supported-resiliency-design/
Publishing principles: https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/
Usage and citation policy: https://update.dsesecurity.com/usage/
Copyright © 2026 Detection Systems & Engineering. All rights reserved.
