Windows Command #30 – net file (Windows OS)

Diagram showing two client computers opening shared files on a Windows file server, representing files listed by the net file command.

net file shows files that other computers have opened on the Windows computer where you run the command. It is a server-side view of remotely opened shared files.

This lesson follows Windows Command #29 – net session. That command answers, “Which clients have SMB sessions connected to this computer?” net file goes one level deeper and asks, “Which shared files are currently open through those connections?”

By the end: you will be able to list remotely opened files, understand file IDs and lock counts, inspect a specific entry, recognize when a file is being used over SMB, and understand why closing an open file is a maintenance action rather than a casual troubleshooting step.

Start with the basic command

net file

Run it from an elevated Command Prompt on the computer that is providing the shared files.

Client computer
      │
      │ opens \\FILE-SERVER\Practice\report.xlsx
      ▼
FILE-SERVER
      │
      ├── net session → shows the client session
      └── net file    → shows the remotely opened file

The direction matters. If LAB-PC opens a file stored on FILE-SERVER, run net file on FILE-SERVER to inspect that remote open.

Video 1: The net file command itself

CMD Networks — The net file command. This focused walkthrough demonstrates the command used in this lesson.

What does net file list?

Microsoft’s Sysinternals documentation for PsFile describes net file as a command that shows files opened on the local system by other computers. A typical listing can include:

  • File ID — a numeric identifier Windows assigns to that remote open file.
  • File path — the server-side path to the opened resource.
  • User name — the account associated with the open file.
  • Lock count — the reported number of file locks.

The exact formatting can vary by Windows version and context. Do not treat the example below as captured output from every system.

ID     Path                         User name      # Locks
17     C:\Shares\Practice\report.xlsx   LAB\alex       1

Read it as: file ID 17 represents one remote open of report.xlsx by the listed account, with one reported lock.

Why does the file have an ID?

The ID gives Windows a concise way to refer to one open file entry.

Remote open file
      ↓
Windows assigns an open-file ID
      ↓
net file lists that ID
      ↓
Administrator can inspect or, if approved, close that specific entry

This is safer than guessing based only on a filename because multiple users or sessions may interact with similarly named files.

Inspect one file ID

If the listing shows ID 17, use:

net file 17

Replace 17 with an ID from your own current listing. The ID is not a permanent identifier for the document; it represents that open-file entry.

How net file fits with the recent Windows commands

CommandQuestion it answers
net useWhat shared resources is this client connected to?
net shareWhat resources is this computer sharing?
net viewWhat shared resources can be listed on another computer?
net sessionWhat client SMB sessions are connected to this server?
net fileWhat files are remotely open on this server?
SHARE
  ↓
SESSION
  ↓
OPEN FILE

net share
net session
net file

Video 2: View open shared files on Windows Server

Active Directory Pro — View Open Files on Windows Server. This demonstrates the broader administrative task of identifying files that are currently open on Windows servers and workstations.

A lock is not automatically a problem

A reported lock can simply mean an application is actively using the file in a way that requires coordinated access. Do not assume that every locked file is stale or broken.

Before intervening, identify:

  • the file path,
  • the user,
  • the client session,
  • whether the application is still using the file,
  • whether the user has unsaved work.

A file lock is often protecting data consistency. Removing it carelessly can cause lost work or application errors.

Closing an open file changes the system

The read-only command is:

net file

Closing a file is different. The built-in syntax uses the file ID with /close:

net file 17 /close

Do not use this casually. Closing the server-side open file can interrupt the client application and can cause unsaved changes to be lost. Use it only after identifying the correct file and user, asking the user to save and close the file when possible, and following the maintenance procedure for the system.

Microsoft’s Defrag Tools networking episode demonstrates both listing open files with net file and closing a selected entry with net file NNN /close.

Reference: Microsoft Learn — Defrag Tools #129: Networking, Part 2.

SMB is the protocol context

These network-share sessions and remotely opened files normally exist in the context of SMB, the Server Message Block protocol used by Windows file sharing.

Client application
      ↓
SMB connection
      ↓
SMB session
      ↓
Shared file opened on server
      ↓
net file can list the remote open

Video 3: Understand SMB before troubleshooting shared files

Tech Gee — What is the Server Message Block (SMB) Protocol? This provides the protocol background for the sessions and shared-file opens that net file helps inspect.

Modern PowerShell companion: Get-SmbOpenFile

Modern Windows Server administration also provides the PowerShell cmdlet Get-SmbOpenFile. Microsoft’s current documentation says it retrieves information about files open on behalf of SMB clients.

Get-SmbOpenFile

It can expose richer properties such as FileId, SessionId, Path, ShareRelativePath, ClientComputerName, and ClientUserName.

Reference: Microsoft Learn — Get-SmbOpenFile.

This is a PowerShell cmdlet, not a Command Prompt command. Keep the environments distinct:

EnvironmentExample
Command Promptnet file
PowerShellGet-SmbOpenFile

net file has an important limitation

Microsoft’s PsFile documentation notes that net file can truncate long path names and is oriented around the local system. That is one reason newer administrative tools can be useful when you need richer information or remote-management capabilities.

Do not confuse the age of a command with uselessness. net file remains valuable for learning the relationship between a file server, remote clients, SMB sessions, and server-side open-file state.

Safe two-computer practice lab

Use two Windows machines or VMs that you administer. One will be the file server and one the client.

StepWhereAction
1FILE-SERVERUse an existing training share such as Practice.
2LAB-PCOpen a document inside \\FILE-SERVER\Practice.
3FILE-SERVEROpen Command Prompt as administrator and run net session.
4FILE-SERVERRun net file.
5FILE-SERVERMatch the open-file information to the client and file you intentionally opened.
6LAB-PCClose the document normally.
7FILE-SERVERRun net file again and compare.

The practice exercise is intentionally observational. You do not need to use /close to understand the command.

Troubleshooting without guessing

What you seeWhat to check
Access deniedConfirm the Command Prompt is elevated and that your account has the required administrative rights.
No entriesConfirm a remote client currently has a file open from a share hosted by this computer.
You expected a local application filenet file is about files opened remotely through server sharing, not every file handle used by local processes.
The path appears shortenedOlder net file output can truncate long paths. Use a modern tool such as Get-SmbOpenFile when appropriate.
A user reports a locked fileIdentify the user, session, file, and application before considering any forced close.
The command reports the Server service is unavailableCheck the Server service and the computer’s intended file-sharing role. Do not enable services on managed systems without authorization.

Check your understanding

  1. Where should you run net file: on the client opening the shared file or on the server providing it?
  2. What does a file ID identify?
  3. Does a reported lock automatically mean something is broken?
  4. What does /close do?
  5. Why can /close cause data loss?
  6. Which modern PowerShell command provides richer SMB open-file information?
  7. How is net file different from net session?

Answers: Run net file on the server providing the share. The file ID identifies one server-side remote open-file entry. A lock is not automatically an error. /close closes the selected remote open file and removes its locks. Doing that while an application has unsaved work can interrupt the application and lose changes. Get-SmbOpenFile is the modern PowerShell companion. net session lists client sessions; net file lists remotely opened files.

What to remember

Think from broadest to most specific: share → session → open file.

net share   → what this computer shares
net session → who is connected
net file    → what remote files are open

Presentation note: Command Prompt examples use the classic console default concept of light gray (#C0C0C0) text on black. This is not presented as the default for Windows Terminal or VS Code, whose appearance depends on the selected profile and theme. Non-terminal diagrams are plain educational graphics.

BitcoinVersus.Tech

Advertisement

BitcoinVersus.Tech advertisement.

Editor’s Note:

We volunteer daily to ensure the credibility of the information on this platform is Verifiably True. If you would like to support our research initiatives, please donate here: 3C9o19EH5HSiwEPyCTmEKzxhNCbo2X6TTb

BitcoinVersus.tech is not a financial advisor. This media platform reports on financial subjects purely for informational purposes.

Leave a comment