Windows device recovery is fundamentally stronger today than it was a year ago. Thanks to your feedback, you have a comprehensive set of tools available to help you restore user productivity quickly. From automated, cloud-based fixes to full device rebuilds, let's explore the newest recovery tools that keep you in control while helping you address a broad range of scenarios:
Existing solutions—such as Get Help troubleshooters, Uninstall updates, Reset this PC, System Restore, and the command prompt in WinRE—remain available and continue to serve specific roles. To learn more about these tools, please visit their respective documentation.
Windows device recovery: scenarios and solutions
The following framework summarizes how to choose the right recovery approach for your scenario. The scenarios appear roughly in order from more common to less common and we highlight the newer tools alongside the other alternatives.
|
Scenario |
Solution |
Tools |
|
Individual device issues after an update |
User reinstalls the current Windows version (or if needed, go back to previous version) if the PC can boot. User uninstalls the update if the PC cannot boot or issues persist beyond 10 days. For some known issues listed on the Microsoft 365 admin center, IT can use Known Issue Rollback. |
Reinstall the current version of Windows |
|
A single malfunctioning component (audio, networking, printing, etc.) |
User runs targeted diagnostics and remediation for the affected components. | |
|
Recent, isolated issue or widespread device issue |
User (sometimes under IT supervision) rolls back the system to its exact state from a past point in time. Requires a recent restore point. | |
|
Persistent device issues after targeted recovery attempts (unknown cause) |
User reinstalls Windows while removing apps and settings. Optionally, keep user files. | |
|
Deep OS corruption |
User (sometimes under IT supervision) initiates clean OS install that downloads a target Windows image and device drivers and applies it to the device for a fresh start. |
New! Cloud rebuild (preview) |
|
Hardware failure or device unavailability (lost, stolen, or isolated during a security investigation) |
IT provisions a temporary Cloud PC. Settings, documents, and managed apps are restored on a new device. Recommended for immediate user productivity. |
New! Windows 365 Reserve |
|
A mass-scale outage affecting boot (rare) |
When a device repeatedly fails to boot and enters WinRE, it automatically checks for and applies a Microsoft-provided fix from Windows Update. No user action is required. |
Each recovery scenario has at least one tool that can be used to remediate the device. In practice, start with the least disruptive, fastest option and reach for a heavier tool only when the situation calls for it.
Recovery scenarios: meet the newest solutions
Now let's do a more detailed walkthrough of the scenarios you can address using the newest recovery tools.
Mass scale outage: Quick machine recovery
When Microsoft identifies a mass scale outage that prevents devices from booting, we become your first line of defense. Microsoft develops, validates, and publishes a targeted fix that quick machine recovery delivers directly to affected devices.
How it works:
-
The device fails to boot and enters Windows Recovery Environment (WinRE).
-
Microsoft identifies, builds, and publishes a remediation package.
-
WinRE establishes a network connection.
-
The device scans Windows Update, downloads, and applies the remediation package automatically.
-
The device restarts safely to Windows.
Availability: Generally available on Windows 11, version 24H2 and later. Enabled by default on Windows Home. For managed Pro, Enterprise, and Education devices, you can enable quick machine recovery through policy.
Prerequisites: Enable the feature and ensure devices will be able to connect to a supported network. To learn more about WinRE requirements, see the WinRE documentation.
Impact to data: None
Alternative solutions: Startup Repair remains the first automatic response to boot failures. Quick machine recovery builds on Startup Repair by adding cloud-based remediation when local repair is not sufficient.
Additional capabilities for best results: Recovery CSP
Recent, isolated issue or widespread disruption: Point-in-time restore
Most disruptions aren't mass-scale outages. A single device or group of devices can break due to a bad application installation, an incompatible driver, or a misconfigured setting. If quick machine recovery doesn't have a fix yet, point-in-time restore lets you roll the entire device back to a previous state in minutes. Here's how it works.
Point-in-time restore automatically captures comprehensive restore points of the full system state (the OS, applications, settings, and local files) at a configurable frequency and retention[2]. The default is every 24 hours. Restore points use the Volume Shadow Copy Service (VSS) and are stored locally for up to 72 hours.
-
When a disruption occurs, initiate restoration from WinRE. (BitLocker recovery key is required)
-
Select a restore point. The device rolls back to that exact state.
The entire process typically completes in a matter of minutes. The goal is to return the device to a stable state without requiring advanced troubleshooting.
Availability: Available on Windows 11 Home, Pro, and Enterprise, version 25H2 and later. Remote management capabilities are planned for a future release.
Prerequisites: Enable the feature and configure it for your environment using the Recovery CSP and back up local files to the cloud.
Impact to data: Point-in-time restore is a comprehensive rollback. Any local changes made after the selected restore point, including files, settings, passwords, certificates, and keys, will be lost. Data stored in cloud services like OneDrive is not affected.
Alternative solutions: System Restore provides event-triggered or manual restore points for system files and settings. Point-in-time restore modernizes this concept with automatic, comprehensive restore points (including local user files), strict retention policies, and a path toward remote management.
Additional capabilities for best results: OneDrive for work or school (for cloud storage to minimize data loss).
Deep OS corruption: Cloud rebuild
There are two main reasons to “start from scratch.” Sometimes a device is too deeply corrupted for a targeted fix or rollback to resolve the issue. Whether the OS is corrupted or drivers are in conflict, the system might be beyond restoration. If you've already tried quick machine recovery and point-in-time restore, start fresh with a clean operating system. Another reason to start fresh is for planned resets. You might want to reset devices for purposes of compliance, hygiene, or reuse by new users.
Cloud rebuild (preview) restores a Windows 11 PC to a clean, last known good state by performing a full operating system reinstallation from the cloud. Unlike Reset your PC, Cloud rebuild downloads both the target Windows image and the device drivers from Windows Update. This way, the device can come back fully functional without custom images, USB media, or physical access to the device. Here's how it works.
-
Start a Cloud rebuild from the “Troubleshoot” menu in WinRE. Do this directly on the device.
-
The device downloads a clean Windows OS, matching the device's current Windows release, edition, and language. It also downloads and applies the latest monthly security update.
-
The device downloads all required system drivers directly from Windows Update.
-
The system disk is formatted and Windows is installed fresh, landing the device in the out-of-box experience (OOBE).
-
If enrolled in Windows Autopilot, the device is automatically provisioned during OOBE. It also re-enrolls in your management environment with the right policies, apps, and configurations provisioned on the device.
-
If configured, Windows settings backup and restore (formerly Windows Backup for Organizations) restores the user's Windows settings and Microsoft Store app list. OneDrive for work or school then restores their files. This way, the user returns to a device that feels familiar, not factory fresh.
Availability: Available to Windows Insiders enrolled in the Experimental channel. Designed for cloud-managed, Intune-enrolled devices. Coming soon is the ability for IT Admins to customize the rebuild and initiate it remotely from their MDM.
Prerequisites: Before initiating Cloud rebuild, confirm that the target device meets the prerequisites listed in the Cloud rebuild documentation.
Impact to data: High. As the system disk is formatted during this process, all apps and data are lost.
Alternative solutions: Create a recovery drive or use manufacturer-created recovery media.
Additional capabilities for best results: Windows settings backup and restore, Windows Autopilot, Microsoft Intune, OneDrive for work or school (for cloud storage to prevent file loss)
Hardware failure or device unavailability: Windows 365 Reserve
If the hardware itself is the problem, no software recovery tool can help. This scenario occurs with a failed storage drive, damaged motherboard, or a device that simply won't power on. Other scenarios include devices that are lost, stolen, isolated during a security investigation, or otherwise unavailable during a broader incident. In these cases, the priority shifts from fixing the device to unblocking the user.
While you resolve the hardware issue, consider investing in Windows 365 Reserve for a fast, temporary solution. While point-in-time restore and cloud rebuild (preview) focus on restoring the affected physical device, Windows 365 Reserve helps maintain secure user productivity. Here's how it works.
-
Provision a Cloud PC to give the user immediate, temporary access to a full Windows desktop from any device. You can use existing Microsoft Intune policies or create a new provisioning setup beforehand.
-
(Optional but recommended) Enforce OneDrive cloud storage to help ensure that users' files are available. Additionally, Windows settings backup and restore can re-apply their personalized settings (desktop layout, accessibility preferences, language settings, and more) so they can pick up right where they left off.
-
Users sign in with work credentials to the Windows App or web portal on any device and connect to their Cloud PC. They immediately access a clean, cloud-isolated Windows environment with corporate apps, settings, and security policies already applied to stay productive.
-
Users can track their access using the Windows App or web portal. You can use Intune to monitor licensing and usage as well as to deprovision Cloud PCs.
Availability: Available on supported Windows 11 Enterprise devices. Designed for cloud-managed, Intune-enrolled devices.
Prerequisites: Requires an active Windows 365 Reserve license managed through Microsoft Intune. Preconfigure Windows 365 Reserve Cloud PC.
Impact to data: None
Alternative solution: New or replacement device is always an option to unblock the user. Provide a new device and use Windows Autopilot for zero-touch provisioning. The device enrolls in your management environment, receives policies and apps, and is ready for the user without manual IT setup.
Additional capabilities for best results: Microsoft Intune, OneDrive for work or school (for cloud storage to prevent file loss), Windows settings backup and restore, Windows Autopilot
Get started today
Device disruptions come in many shapes. A misconfigured policy can render thousands of PCs unbootable overnight. A user accidentally modifying critical system settings can disrupt a single laptop. An aging device can have a random hardware failure and simply stop cooperating. That's why this tiered recovery framework includes a series of tools designed for a specific class of problem. New and pre-existing tools as well as supporting capabilities, work together to give your IT team a clear path to recovery.
Here's what you can do right now to prepare your organization:
-
Use Microsoft Intune as a centralized management platform for recovery and resiliency capabilities. Through Intune, you can configure and deploy the policy settings exposed through Windows CSPs, including settings for quick machine recovery, point-in-time restore, cloud rebuild, Windows Autopilot, and Windows settings backup and restore. Enable quick machine recovery on your managed devices via the Recovery CSP. Configure Wi-Fi credentials, scanning intervals, and test the experience using test mode before production deployment.
-
Test point-in-time restore. Explore the settings locally and via the Recovery CSP, perform a test restore, and share your feedback through Feedback Hub.
-
Enable Windows settings backup and restore to streamline device transitions. Use Intune to enable backup and restore policies to preserve user settings: accessibility preferences, personalization, language and regional settings, and the list of installed Microsoft Store apps. When a device is reset, rebuilt, or replaced, these settings are automatically restored during the out-of-box experience (OOBE) or first sign-in for Microsoft Entra hybrid joined devices and Cloud PCs.
-
Configure OneDrive for work or school for your organization. Cloud file storage helps ensure that user documents, photos, and other files are continuously synced and protected. Whether you roll back a device with point-in-time restore, rebuild it from scratch, or replace it entirely, cloud-synced files remain accessible and unaffected. This is especially important with point-in-time restore, where local files are reverted to the restore point state. To begin, enable Known Folder Move regardless of which recovery path you use. It syncs the latest file state with its versions down to your device when connected to the cloud.
-
Configure Microsoft 365 Backup for point-in-time recovery to protect all OneDrive accounts, mailboxes, and SharePoint sites. That way, you can roll back malicious or accidental data modifications and deletions. The combination of OneDrive with Microsoft 365 Backup provide file protection beyond the device itself and are a recommended resiliency plan.
-
Set up Windows Autopilot profiles for zero-touch device provisioning. Autopilot automatically enrolls devices in your management environment, applies policies, and installs apps during OOBE. After a cloud rebuild or on a new replacement device, Autopilot helps get users back to productivity on a fully configured and compliant device without requiring manual IT intervention.
Solutions to device recovery challenges
Windows recovery is no longer a single tool or a last resort– it's a comprehensive framework designed to match the right solution to every scenario. Whether you're defending against the next widespread outage or helping a single user get back to work, these capabilities work together to reduce downtime, minimize data loss, and keep your organization productive.
This blog reflects the current state of Windows recovery capabilities at the time of publication. As new features and improvements become available, the accompanying Windows device recovery framework documentation will be updated to provide the latest guidance, feature availability, and deployment recommendations. If you are a consumer, please visit Recovery options in Windows on Microsoft Support.
For additional strategies to prevent, respond to, and recover from endpoint disruptions, see the Windows Resiliency e-book.
[1] When live assistance is needed and the device can boot, Intune customers can use Remote Help so support staff can securely troubleshoot a managed device with the user. Quick Assist remains available for everyone who needs remote assistance.
[2] You can configure restore point frequency and retention on systems running Enterprise editions of Windows.
Continue the conversation. Find best practices. Bookmark the Windows Tech Community. Looking for support? Visit Windows on Microsoft Q&A.