A laptop that won't boot, a blue screen on every start, a user who can't reach the desktop to fix anything. Before you reach for a USB stick or a reimage, there's a repair toolkit already sitting on the disk. WinRE, the Windows Recovery Environment, is that toolkit, and this guide covers what it is, how to check it with reagentc, and why its partition keeps breaking updates.
What WinRE Is and Where It Lives
WinRE is a small, separate copy of Windows built for repair work. Microsoft builds it on Windows PE, the same minimal environment used for deployment, and ships it with Windows 10, Windows 11 and Windows Server 2016 and later.
The whole environment lives in one image file, winre.wim. Windows Setup first drops it in C:\Windows\System32\Recovery, then copies it into a dedicated recovery partition during setup. That partition is the small NTFS slice you see in Disk Management labelled "Recovery".
The separate partition is the point. If the Windows partition is damaged or locked by BitLocker, WinRE still boots from its own space. It also keeps users from deleting it by accident.
Safe Mode is a different thing: Windows itself with only basic drivers loaded, reached through WinRE's Startup Settings. Our Safe Mode on Windows 11 guide covers that route step by step.
When WinRE Starts on Its Own
WinRE isn't only something you open on purpose. Per Microsoft's WinRE reference, Windows boots into it automatically after any of these:
- Two failed attempts to start Windows in a row.
- Two unexpected shutdowns in a row, each within two minutes of boot finishing.
- Two reboots in a row within two minutes of boot finishing.
- A Secure Boot error (except issues with Bootmgr.efi).
- A BitLocker error on touch-only devices.
That automatic failover is why a broken driver update often ends with the blue "Choose an option" screen instead of an endless crash loop.
You can also get there by hand. Hold Shift while you click Restart, use Settings > System > Recovery > Advanced startup > Restart now, boot from recovery media, or press the OEM's recovery key. From an admin prompt, reagentc /boottore sets the next restart to land in WinRE, which is handy when you're remote and the user just needs to reboot.
What's Inside the Troubleshoot Menu
Once WinRE loads, Troubleshoot > Advanced options holds the tools. Each one fixes a different kind of failure, so pick by symptom rather than working down the list.
Startup Repair scans for boot problems like missing or damaged boot files and tries to fix them automatically. It's the first thing to run when Windows won't start at all.
Uninstall Updates removes the latest quality or feature update. Use it when the trouble started right after Patch Tuesday.
System Restore rolls system files and settings back to a restore point, without touching personal files. It only works if restore points exist, and on a lot of managed fleets they're switched off.
Command Prompt is the power tool. From here you can run bcdedit, chkdsk, sfc /scannow /offbootdir=C:\ /offwindir=C:\Windows, and an offline DISM RestoreHealth against the installed image.
Startup Settings is how you reach Safe Mode, boot logging and "disable driver signature enforcement". UEFI Firmware Settings takes you into the firmware without hunting for the right key at power-on.
Reset this PC lives one level up, under Troubleshoot. It reinstalls Windows, with or without your files, and our Windows 11 factory reset guide walks through both options.
On Windows 11, Microsoft notes you can run nearly all of these tools without picking an admin account and typing its password. Encrypted files stay unreadable without the BitLocker key, so keep the BitLocker recovery key somewhere you can reach from another device.
This walkthrough from CNATT shows the menus on screen:
How to Check WinRE With reagentc
WinRE can be disabled, missing or pointing at a partition that no longer exists. The only way to know is to ask. Open an elevated Command Prompt or PowerShell and run:
codereagentc /info
The line that matters is Windows RE status. "Enabled" means WinRE is registered and will start on failure. "Disabled" means it won't, and the next unbootable PC goes straight to a USB stick. Windows RE location shows which disk and partition hold it, for example \\?\GLOBALROOT\device\harddisk0\partition4\Recovery\WindowsRE.
The other switches are short, per Microsoft's reagentc reference:
reagentc /enableturns WinRE on, usingwinre.wimfromC:\Windows\System32\Recoveryif no other image is set.reagentc /disableturns off the active WinRE image.reagentc /boottoremakes the next boot land in WinRE.reagentc /setreimage /path <folder>points Windows at a different WinRE image.
If /enable fails with "The Windows RE image was not found", winre.wim is missing from both places. Extract it from install media that matches the installed Windows build, put it in C:\Windows\System32\Recovery, and run /enable again.
Admins disable WinRE on purpose too, usually to stop users reaching a reset on kiosk or shared machines. This r/MDT thread covers doing it during deployment:
If you do that, write it down. A PC with WinRE off looks exactly like a healthy one until the day it won't boot.
The Recovery Partition and Why WinRE Updates Fail
Microsoft updates WinRE through monthly rollups, but not by patching the file in place. The update swaps in a whole new winre.wim, adds boot-critical drivers from the running OS, and carries over customizations. If the new image doesn't fit the old partition, Windows has to find room.
The WinRE reference spells out what happens next. If the recovery partition sits directly after the Windows partition, Windows shrinks C: and grows the recovery partition. If it sits anywhere else, Windows shrinks C:, creates a brand-new recovery partition and leaves the old one orphaned. If it can't shrink C: at all, WinRE ends up on the Windows partition itself.
That's why machines upgraded over the years end up with two or three "Recovery" partitions. It's also why Microsoft recommends putting the recovery partition right after Windows when you build images.
The partition size became everyone's problem in January 2024. KB5034441 shipped a WinRE fix for CVE-2024-20666, a BitLocker bypass through the recovery environment rated CVSS 6.6. On PCs with a small recovery partition, the update failed with 0x80070643 - ERROR_INSTALL_FAILURE, an error code Microsoft's KB page put down to a bug in its own error handling (the real cause was not enough space). The fix Microsoft published, KB5028997, has you disable WinRE, shrink C: by 250 MB with diskpart, rebuild the recovery partition and re-enable WinRE.
This r/SCCM thread from the week it shipped shows how fast that spread:
The lesson for image builders holds beyond that one KB. Put the recovery partition after Windows, leave it room, and check reagentc /info after big updates instead of assuming.
Why Attackers Switch WinRE Off
WinRE is a recovery path, which makes it a target. MITRE ATT&CK files this under T1490, Inhibit System Recovery: take away the ways a victim can roll back, and ransomware or a destructive payload sticks.
Elastic Security Labs documented this in July 2025 in NOVABLIGHT, an infostealer sold as a service. When its "antireset" option is on, it runs reagentc /disable and deletes every Volume Shadow Copy with vssadmin delete shadows /all. That combination is a strong signal that something on the machine is malware, not an admin.
The SigmaHQ community added a detection rule for it the same month. It flags any reagentc.exe process with /disable on the command line, at medium severity, with "legitimate administrative activity" as the known false positive. If your fleet disables WinRE on purpose, allowlist that deployment and alert on everything else.
Treat an unexpected "Windows RE status: Disabled" as an incident signal and pull it into your incident response process. Pair it with shadow copy deletions and new admin accounts on the same host, and the picture gets clear fast.
Checking WinRE Across a Fleet
One reagentc /info is easy. Knowing the status on 400 endpoints before one of them fails is the harder part. A short PowerShell script turns the check into data:
powershell$info = reagentc /info | Out-String [pscustomobject]@{ Computer = $env:COMPUTERNAME Status = if ($info -match 'Windows RE status:\s+(\w+)') { $Matches[1] } else { 'Unknown' } Location = if ($info -match 'Windows RE location:\s+(\S+)') { $Matches[1] } else { '' } }
Run it on a schedule and sort the output. Anything showing Disabled or an empty location goes on a fix list, along with a check of how many recovery partitions each disk carries. Our PowerShell commands guide covers the basics if scripting isn't routine yet.
OpenFrame can run a script like this across a client's devices and collect the output in one place, so the list builds itself.
WinRE: The Short Version
WinRE is the repair environment on its own partition that Windows falls back to after two failed boots. Check it with reagentc /info, fix a missing image with reagentc /enable, and keep the recovery partition after C: so updates can grow it. Treat an unexpected Disabled status as a warning sign, and read our blue screen of death guide for what to do when the crash comes first.
Dmytro Koval
Head of Product Engineering
Hi! My name is Dmytro, but everyone calls me Dima. I’m a Software Developer and together with the development team, I help bring Flamingo to life — putting it on its feet from a technical perspective. Originally from Lviv, Ukraine 🇺🇦, but currently based in Spain, where I’ve been enjoying the blend of great weather, culture, and nature. I’m passionate about the mountains and love traveling — exploring new places and cultures really inspires me. These experiences constantly recharge me and give me a fresh perspective, both personally and professionally.
