Disk scan methods

MFT Scan vs. Folder Scan for Windows Storage

Understand when Windows can read the NTFS master file table (MFT), when a folder scan is used and how to check scan coverage.

By Osenpa Published Reviewed

Short answer

Disk Analyzer chooses a scan method that fits the drive and the access Windows allows. A Slow Scan is not automatically incomplete.

Wait for the result, then read any access, protection, skipped-item, or partial warning before trusting the total.

When to use this method

Use this guide when one drive takes longer to scan or the result reports access, protection, skipped, or partial coverage.

Before you start

Keep the drive connected and let the scan finish. NTFS is a common Windows file system. Its MFT is the built-in file index. A folder scan, called Slow Scan in its result-tab explanation, walks accessible folders instead.

Scan methods and coverage When the MFT method is available, when folder traversal is used and what can be missed.
What the result reports
The result identifies the scan method and shows item-level access, protection or skipped cues. A drive-level warning appears when coverage needs review.
How the method is chosen
Supported NTFS volumes can use the built-in file index; other targets and NTFS volumes without native access use compatible folder traversal.
Important limit
Damaged records, locked paths, reparse points that redirect to another location, protected locations or a disconnected drive can leave a useful but incomplete inventory.

Read the scan result in context

Choose one drive

Select the drive you want to inspect. Use Scan All only when you need several drives. You should see the chosen drive's label and capacity.

Let the scan finish

Start the scan and wait for Results. The app chooses the compatible method from the file system and available access.

Check the drive tab and messages

Focus or point to the result drive tab. If Slow Scan applies, its explanation appears there. Then look for partial, access, protection, or skipped cues. A warning means you should not treat the total as complete.

Retry only after a warning

Reconnect the drive or resolve a known access problem, then scan again. You should see the warning disappear or the reported scope change.

Osenpa Disk Analyzer result selector showing C drive and E drive marked Slow Scan
The drive tab explains why Slow Scan was used; coverage warnings appear separately.

MFT scan compared with a folder scan

Coverage and completion matter alongside speed.

Scroll the table horizontally on a narrow screen.

Question MFT scan Slow Scan, folder based
Best fit A supported NTFS volume with native access A non-NTFS file system, or an NTFS volume where native access is unavailable
How it works Reads NTFS file-system metadata Walks accessible folders and files
Typical tradeoff Often faster for a broad inventory Walks every accessible path, so duration rises with tree size and access checks
What can limit coverage Damaged records, reparse points or restricted native access Locked, protected, disconnected or inaccessible paths
Trust signal Method plus item-level access, protection or skipped cues; verify coverage when a warning reports incomplete access Method plus item-level access, protection or skipped cues; verify coverage when a warning reports incomplete access
Watch for

Scan interpretation mistakes

  • Calling every result a complete drive inventory
  • Comparing methods by speed without checking scope
  • Ignoring item-level access, protection or skipped cues
  • Treating every Slow Scan as partial even when no incomplete-coverage warning is present
Verify the result

Checkpoint: Scan result checks

  • The reported method matches the target.
  • Item-level access, protection or skipped cues have been reviewed.
  • A finished state is not treated as proof of complete coverage.
  • A result with an incomplete-coverage warning is checked with a focused rescan before its total is trusted.
Drive scan progress in Osenpa Disk Analyzer
Step by step

Osenpa Disk Analyzer

Inventory local storage with a compatible scan path, then verify coverage when the result reports an incomplete-coverage warning.