skip to content

On NTFS, how do a directory junction, a symbolic link, and a hard link differ?

level: middleimportance: should knowfreq 48%

answer

  1. one of the three is not a reparse point
  2. same MFT record versus a stored path
  3. directory-only and absolute
  4. who resolves it: server or client
  5. only one of them needs a privilege

basics

~20 s

A hard link is a second directory name for the same file record on the same volume. Junctions and symbolic links are reparse points holding a target path: a junction is directory-only, absolute and resolved locally, while a symbolic link may target files, relative paths or remote shares.

solid answer

~50 s

Hard links sit at a different layer from the other two. A hard link is an extra filename entry pointing at the same MFT record, so both names are equally real, the data survives until the last name is removed, and it works only for files on one volume. Junctions and symbolic links are both *reparse points* — a small tag plus target data attached to a directory entry, which the I/O manager notices and redirects through. A junction (`mklink /J`) targets a directory only, stores an absolute local path, and is resolved on the machine that owns the volume — so across SMB it resolves server-side. A symbolic link (`mklink /D` or `mklink` for files) can point at a file or directory, can be relative, and can name a UNC path, but it is resolved by the client. Creating a symlink needs `SeCreateSymbolicLinkPrivilege` unless Developer Mode is on; junctions and hard links need no privilege.

code

powershell · 3 lines
powershell
New-Item -ItemType Junction -Path C:\app\current -Target C:\app\releases\v42
New-Item -ItemType SymbolicLink -Path C:\app\shared -Target \\fileserver\shared
New-Item -ItemType HardLink -Path C:\app\copy.dll -Target C:\app\lib.dll

go deeper

for a junior

Recall the three kinds and one distinguishing fact each: a hard link is another name for the same file on the same volume, a junction redirects a directory locally, and a symbolic link redirects a path and may cross to a network share.

for a middle

Explain that junctions and symlinks are reparse points carrying a target path while a hard link is a second directory entry on one MFT record, and that only symlink creation is privileged.

for a senior

Bring the operational consequences: recursive backup or scanning tools that follow reparse points loop or escape their tree, junctions resolve on the volume's own machine over SMB, and hard-linked data is counted once by the volume but many times by size-summing tools.

for a principal

Take a position on using link types as deployment machinery — atomic release switching via a junction swap versus copy-and-rename — and on the privilege and audit implications of allowing symlink creation on developer and build machines.

## Reparse points: the shared mechanism NTFS supports *reparse points* — a directory entry can carry a reparse tag plus a blob of tag-specific data. When the I/O manager walks a path and hits one, the filesystem returns a status telling the caller "this is not the end of the road", and a registered filter interprets the blob. Junctions, symbolic links and volume mount points are all built on this one mechanism, distinguished by their tag: `IO_REPARSE_TAG_MOUNT_POINT` for junctions and mount points, `IO_REPARSE_TAG_SYMLINK` for symbolic links. Hard links are *not* reparse points and belong to a different layer entirely — which is the first thing to say when an interviewer lumps all three together. ## Hard link A hard link is an additional filename in a directory that references the same MFT record as an existing name. Consequences: - Neither name is the "original"; they are peers, sharing content, size, ACL and timestamps, because there is only one file. - The file's data is released when the last name referencing the record is removed — NTFS keeps a link count exactly as Unix does. - Both names must live on the same volume, since an MFT is per-volume. - Directories cannot be hard-linked, which prevents cycles in the tree. Because both names are the same object, editing through one is visible through the other — but a program that saves by writing a temp file and renaming over the target *breaks* the link, leaving the other name pointing at the old content. That is the classic hard-link surprise, on Windows and Unix alike. ## Junction A junction ("directory junction", "soft link" in older docs) redirects a directory to another directory. Key properties: - **Directories only.** You cannot junction a file. - **Absolute local target.** The stored path is absolute and must be a local volume path; junctions cannot point at UNC shares. - **Resolved where the volume lives.** If a client opens a path over SMB and hits a junction on the server, the server resolves it against its own filesystem. A path that resolves fine locally can therefore mean something different, or fail, remotely. - **No special privilege** to create. - The target is not validated at creation, so a junction can dangle. Windows itself ships junctions for backwards compatibility — the legacy `C:\Documents and Settings` name, and the per-user compatibility entries under a profile, are junctions, deliberately ACL'd to deny listing so that recursive tools do not loop through them. ## Symbolic link A symbolic link stores a target path and is resolved by the *client* of the path. It is the closest analogue to a Unix symlink: - Can target a file or a directory, and the two are distinguished at creation time (`mklink` for a file, `mklink /D` for a directory) — get it wrong and the link misbehaves. - Can be **relative**, which junctions cannot, so a tree of relative symlinks survives being moved. - Can name a **UNC path**, so it can point across the network. - Requires `SeCreateSymbolicLinkPrivilege`, held by Administrators by default. Since Windows 10 version 1703, enabling Developer Mode lets an unelevated process create one by passing the unprivileged-create flag to `CreateSymbolicLinkW`. This privilege gate is why tooling ported from Unix often fails on Windows until the developer elevates or turns Developer Mode on. ## Volume mount points The same mount-point tag also lets a whole volume be grafted onto an empty NTFS directory instead of consuming a drive letter — created with `mountvol` or the Disk Management UI. It is how a server exposes twenty volumes without running out of letters, and it is why a directory can suddenly have completely different free space than its parent. ## Where each one bites you - **Backup and recursive tools.** A tool that follows reparse points can traverse the same data repeatedly or escape the tree it was told to copy. Well-behaved tools skip reparse points or copy the link itself. - **Disk usage.** Hard-linked files are counted once by the filesystem but often multiple times by tools that sum file sizes, which makes "the folder sizes add up to more than the disk" a common confusion. - **Cross-machine paths.** Junctions resolving server-side versus symlinks resolving client-side is the distinction that decides whether a shared path works over SMB. - **Privilege.** Build systems, package managers and version-control checkouts that create symlinks are the usual reason a developer machine needs Developer Mode. ``` mklink /J C:\app\current C:\app\releases\v42 mklink /D C:\app\shared \\fileserver\shared mklink /H C:\app\copy.dll C:\app\lib.dll ``` If you remember one sentence: hard links are another name for the same file, junctions are a local directory-only redirect resolved by the volume's owner, and symbolic links are a general path redirect resolved by whoever walks the path — and only the last one is privileged.

  • Why does creating a symbolic link on Windows usually need elevation while a junction does not?
    Symbolic-link creation is gated by `SeCreateSymbolicLinkPrivilege`, granted to Administrators by default, because a symlink can redirect a path anywhere — including to a remote share — and was judged a spoofing risk. Junctions are constrained to local directories, so they were left unprivileged. Developer Mode relaxes the symlink gate on Windows 10 1703 and later.
  • How does a hard link on NTFS behave when one of its names is deleted?
    Nothing happens to the data. Deleting a name decrements the file record's link count; the content is released only when the count reaches zero. The remaining name still opens the same file with the same content, ACL and timestamps, because there was only ever one file.
  • What breaks a hard link between two names that were supposed to stay in sync?
    An application that saves by writing a new temporary file and renaming it over the target. The rename replaces one directory entry with a brand-new file record, so that name now points at fresh content while the other name still references the original record.

saying these in an interview costs you the question

  • Says junctions and hard links are the same thing
  • Claims a junction can point at a UNC share
  • Thinks a hard link needs the original name to exist
  • Assumes a symlink can be created without privilege by default
  • Believes hard links can span two volumes

context