Flamingo Raises $4.5M Seed Round

Skip to content

The dock drops both monitors at 2 pm, the webcam vanishes mid-call, and the label printer in dispatch only works after a reboot. None of it shows up as an error, because Windows did exactly what it was told: it put an idle port to sleep. This guide covers USB selective suspend, the other power switches that cut peripherals off, and when to turn them off on one PC versus a whole fleet.

What USB Selective Suspend Does

Windows ships with selective suspend on. Microsoft's driver documentation describes it plainly: the hub driver can suspend one port without touching the other ports on the hub, so a device that only needs power now and then (a fingerprint reader, a card scanner) stops drawing it while idle.

The reason it exists is bigger than the device. Any USB device that never suspends keeps the host controller's transfer schedule alive in system memory, and that memory traffic can stop the CPU from reaching its deeper idle states. On a laptop that is battery life, which is why the same page says Microsoft strongly recommends leaving selective suspend enabled.

The mechanism is a handshake. When a device goes quiet, its driver sends an idle request. The hub driver decides it is safe, calls the driver back, the driver cancels its pending I/O and moves the device to a low power state. When something needs the device again, the hub driver wakes it. That handshake is where the trouble lives: it only works if the device firmware and the driver both do their part.

Why the Dock Drops Off at 2 pm

A device that sleeps and wakes cleanly is invisible. A device that sleeps and does not come back is a ticket, and the ticket never says "power management". It says the second monitor went black, the audio interface started crackling, or the USB-to-Ethernet adapter fell back to 100 Mbps.

Docks are the usual suspect because a dock is a hub with a stack of devices behind it: a USB 3 hub, a network controller, an audio codec, often a DisplayLink or Thunderbolt video path. Each one negotiates its own idle timing. One device that handles the wake badly takes the rest of the dock with it, and the user sees "the dock disconnected", not "the audio codec missed a resume".

The pattern that gives it away is timing. Peripherals that fail after a quiet stretch (lunch, a long call where only the headset was active, a screen lock) are suspend problems. Peripherals that fail under load, or right after a driver update, are something else. Our guide to updating drivers covers that second case.

The other tell is that unplugging and replugging fixes it every time. A replug forces a fresh enumeration, which is a reset of the exact handshake that failed.

Turn It Off on One PC

The setting lives in the power plan, not in Device Manager, and it has separate values for plugged in and on battery.

In the GUI: Control Panel, Power Options, Change plan settings next to the active plan, Change advanced power settings, USB settings, USB selective suspend setting. Set Plugged in and On battery to Disabled. On a laptop it is worth leaving the battery value enabled and disabling only the plugged-in side, since the dock is only ever attached at a desk.

From an elevated prompt, the same change is a powercfg call. powercfg /query prints every subgroup and setting GUID for the active scheme; the USB settings subgroup and the selective suspend setting are listed there, and powercfg /setacvalueindex and /setdcvalueindex take a scheme GUID, a subgroup GUID, a setting GUID and an index. Index 0 is Disabled, index 1 is Enabled. Finish with powercfg /setactive on the same scheme so the change applies, and read it back with /query before closing the ticket.

powershell
# Read the active scheme GUID
$scheme = (powercfg /getactivescheme) -replace '.*GUID:\s*([0-9a-f-]+).*','$1'

# USB settings subgroup and the USB selective suspend setting GUIDs: confirm both against powercfg /query on your build
$usb  = '2a737441-1930-4402-8d77-b2bebba308a3'
$ss   = '48e6b7a6-50f5-4782-a5d4-53bb8f07e226'

powercfg /setacvalueindex $scheme $usb $ss 0   # plugged in: disabled
powercfg /setdcvalueindex $scheme $usb $ss 1   # on battery: leave enabled
powercfg /setactive $scheme
powercfg /query $scheme $usb

Two cautions. The change is per power plan, so a user who switches from Balanced to High performance loses it. And some devices have their own idle timer in firmware that ignores the Windows setting entirely, which is why a dock firmware update sometimes fixes what the power plan could not.

The r/UsbCHardware thread above is the user side of this: external SSDs and USB Ethernet adapters that keep dropping to USB 2.0 speeds after an idle period, and the argument that unplugging a device saves more power than letting it idle at a lower link rate.

The Other Switches That Cut Peripherals Off

Selective suspend gets the blame, but three other power settings produce the same ticket.

Allow the computer to turn off this device to save power. Each USB Root Hub, Generic USB Hub and network adapter has this box on the Power Management tab of its Device Manager properties. It is a per-device switch, so a fleet with mixed docks can turn it off on the dock's hub and NIC without touching anything else. Microsoft's NDIS documentation lists the matching driver keywords: *DeviceSleepOnDisconnect puts a network adapter to sleep when the cable is unplugged, and the wake-on-LAN keywords (*WakeOnMagicPacket, *WakeOnPattern) decide whether it can bring the machine back. If you rely on Wake-on-LAN for patch windows, a NIC that is allowed to power down with wake disabled is a machine you cannot reach at night.

PCI Express link state power management. This one governs the PCIe link itself, which matters for Thunderbolt docks and add-in cards. Microsoft Learn documents three values: Off, Moderate power savings (the link tries the L0s state when idle) and Maximum power savings (it tries L1). The setting is hidden from the GUI on many builds and reachable through powercfg under the PCI Express subgroup; the setting GUID is ee12f906-d277-404b-b6da-e5fa1a576df5. A Thunderbolt dock that flickers both displays after a quiet spell, with selective suspend already off, is often this.

Energy-Efficient Ethernet. IEEE 802.3az lets a NIC drop into a low-power idle between packets. The Windows driver keyword is *EEE, exposed in the adapter's Advanced tab as Energy-Efficient Ethernet. Older switches negotiate it badly, and the symptom is a link that renegotiates or stalls for a second when traffic resumes. Turning it off on the adapter is a per-device change and costs almost nothing on a desktop.

Then there is Modern Standby, which is not a switch at all. Microsoft describes it as the system staying in S0 with the screen off, waking in short bursts for background work, with network devices dropping to a low-power mode when nothing needs them. You cannot move a machine between Modern Standby and the older S3 sleep by changing a setting; Microsoft's documentation says that requires a full reinstall. What you can do is read powercfg /sleepstudy and powercfg /lastwake on a laptop that keeps waking in a bag, and set the dock expectations accordingly: a Modern Standby laptop treats a docked overnight session as a series of short wakes, each one re-running the suspend handshake.

Fleet: Script It, Do Not Click It

There is no native Intune, Group Policy or Configuration Manager setting for USB selective suspend. Microsoft's Power policy CSP covers sleep, hibernate, display and energy saver timeouts and nothing USB-related, and a Microsoft moderator confirmed in January 2023 that Configuration Manager's power management settings do not include it. The fleet route is powercfg in a script, pushed from whatever runs scripts on your endpoints.

The script has three jobs. Set the value on every scheme the fleet might use, not only the active one, so a plan switch does not undo it. Scope it by model, because a desktop fleet with no battery can take a blanket disable while laptops should keep selective suspend on battery. And write the result somewhere you can read back: powercfg /query output, or a single registry marker your inventory already collects.

powershell
# Apply on every power scheme, plugged-in only
$usb = '2a737441-1930-4402-8d77-b2bebba308a3'
$ss  = '48e6b7a6-50f5-4782-a5d4-53bb8f07e226'
$schemes = (powercfg /list) | Select-String '([0-9a-f-]{36})' | ForEach-Object { $_.Matches[0].Value }
foreach ($g in $schemes) { powercfg /setacvalueindex $g $usb $ss 0 }
powercfg /setactive ((powercfg /getactivescheme) -replace '.*GUID:\s*([0-9a-f-]+).*','$1')

Two more fleet notes. The Ultimate Performance plan is not a fix: it is a High performance variant that powercfg /duplicatescheme can expose, and it changes CPU and disk behaviour across the board. Fixing one dock by moving a laptop fleet to a plan that never idles is the wrong trade. And whatever you change, change the Device Manager boxes with care: a script that unticks "Allow the computer to turn off this device" on every USB hub also unticks it on the one that lets the keyboard wake the machine.

If you want the inventory first, run powercfg /query and powercfg /devicequery wake_armed across the estate and collect the output; OpenFrame can run that script across a client's devices and bring the results back in one place. Our guide to screen timeout policy covers the display side of the same power plan.

What to Change, in Order

Start with the symptom, not the setting. If the failures follow idle periods and a replug fixes them, you are in power management territory. Try the dock or device firmware first, because a firmware fix keeps the battery savings. Then disable selective suspend on the plugged-in side only, on the affected models, by script. Add the per-device Power Management box for the dock's hub and NIC if that is not enough, and look at PCIe link state power management last, only for Thunderbolt and add-in hardware.

What you should not do is turn every power setting off everywhere because one dock is flaky. The battery cost lands on every laptop, and the next ticket will be about runtime.

The r/techsupport thread is a useful counter-example: every USB port dropping at once right after a graphics card swap, with USB power management already disabled, is a power delivery or firmware problem, not a suspend problem. The timing rule above would have ruled selective suspend out in the first minute.

Plugable's walkthrough above shows the GUI route to the setting and the random-disconnect symptom it fixes, which is the version to send a user who wants to try it themselves before you push the script.

Short Version

USB selective suspend lets Windows put one idle USB port to sleep, and Microsoft wants it on because the alternative costs battery on every laptop. It breaks peripherals when a device or dock mishandles the wake, and the tell is failures after idle that a replug fixes. Turn it off on the plugged-in side, by script, on the models that need it, and reach for the per-device Power Management box, PCIe link state power management and Energy-Efficient Ethernet only when the symptom points there. For the broader picture on what a flaky dock does to the ticket queue, our guide on how to lower CPU usage covers the power throttling side of the same plan.

FAQ

Should USB selective suspend be enabled or disabled?

Enabled, unless a specific device breaks. Microsoft's documentation recommends leaving it on because a device that never suspends can keep the host controller active and stop the CPU from reaching deeper idle states, which costs battery. Disable it on the plugged-in side only, for the models and docks that misbehave, and keep the battery side enabled on laptops.

Does disabling USB selective suspend affect battery life?

Yes, on laptops. Idle USB devices that stay powered keep the host controller's transfer schedule in memory, and that activity can stop the processor from entering its deeper low-power states. The size of the cost depends on what is plugged in; a dock at a desk on mains power is the case where it does not matter.

Why does my dock disconnect when the laptop is idle?

A dock is a hub with several devices behind it, and each one has to handle the suspend-and-wake handshake. One device that does not wake cleanly takes the dock with it. Check dock firmware first, then disable selective suspend on the plugged-in side, then untick "Allow the computer to turn off this device to save power" on the dock's hub and network adapter in Device Manager.

Can I set USB selective suspend with Group Policy or Intune?

Not natively. The Power policy CSP that Intune uses covers sleep, hibernate, display and energy saver settings, and Configuration Manager's power management settings do not include it either. Push a powercfg /setacvalueindex script from Intune, your RMM or whatever runs scripts on your endpoints, apply it to every power scheme, and read it back with powercfg /query.

Dmytro Koval

Dmytro Koval

Head of Product Engineering

Hi! My name is Dmytro, but everyone calls me Dima. I’m a Software Developer and together with the development team, I help bring Flamingo to life — putting it on its feet from a technical perspective. Originally from Lviv, Ukraine 🇺🇦, but currently based in Spain, where I’ve been enjoying the blend of great weather, culture, and nature. I’m passionate about the mountains and love traveling — exploring new places and cultures really inspires me. These experiences constantly recharge me and give me a fresh perspective, both personally and professionally.

Related Content

Blog Posts

Product Releases

Podcasts

Webinars

Case Studies

Events

Onboarding Guides

Frequently Asked Questions

USB Selective Suspend

Enabled, unless a specific device breaks. Microsoft's documentation recommends leaving it on because a device that never suspends can keep the host controller active and stop the CPU from reaching deeper idle states, which costs battery. Disable it on the plugged-in side only, for the models and docks that misbehave, and keep the battery side enabled on laptops.
Yes, on laptops. Idle USB devices that stay powered keep the host controller's transfer schedule in memory, and that activity can stop the processor from entering its deeper low-power states. The size of the cost depends on what is plugged in; a dock at a desk on mains power is the case where it does not matter.
A dock is a hub with several devices behind it, and each one has to handle the suspend-and-wake handshake. One device that does not wake cleanly takes the dock with it. Check dock firmware first, then disable selective suspend on the plugged-in side, then untick "Allow the computer to turn off this device to save power" on the dock's hub and network adapter in Device Manager.
Not natively. The Power policy CSP that Intune uses covers sleep, hibernate, display and energy saver settings, and Configuration Manager's power management settings do not include it either. Push a `powercfg /setacvalueindex` script from Intune, your RMM or whatever runs scripts on your endpoints, apply it to every power scheme, and read it back with `powercfg /query`.

MSP AI Agents

On a five-person desk, reported deployments show $78,000 to $130,000 in annual direct labor savings, roughly 30% fewer escalations, and 15% to 20% better SLA compliance. Broader MSP adoption data adds ticket handling time cut by 45% and five to 12 points of margin, all from reclaimed capacity rather than headcount cuts.
Yes. In production MSP shops today, 10% to 25% of tickets close before a human opens them. Thread alone has processed 173 million tickets across 750-plus MSP partners at 96% triage accuracy, handing back 490,000-plus technician hours. Agents own the low-risk, high-volume work (password resets, MFA enrollment, known installs, onboarding and offboarding) and flag anything that touches production data or needs judgment for a human to take.

About OpenFrame

OpenFrame isn't built to plug into your stack. It replaces it. Instead of duct-taping a dozen tools together (RMM, MDM, SIEM, patching, remote access, each its own login and bill), we bundle it into one unified platform: RMM, MDM, monitoring, automation, remote access, patch management, security monitoring, and ticketing, plus built-in AI copilots. So "does it integrate with X?" usually means: you won't need X anymore.
Most platforms give you one piece and expect you to bolt the rest on. OpenFrame unifies the whole stack in one place, with AI copilots built in. Fewer logins, fewer bills, less duct tape.
In the cloud, on US soil. Your data stays stateside.
Both. It's built for MSPs and MSSPs alike.