Windows device recovery framework

Windows recovery capabilities change over time. As new features and improvements become available, this framework reflects the latest guidance and deployment recommendations.

Note

For less technical guidance, please visit Recovery options in Windows.

Scenarios and solutions

The following framework summarizes how to choose the right recovery approach for your scenario. The scenarios appear in the order from more to less common, highlighting the newer tools alongside the other alternatives.

Note

Existing solutions remain available and continue to serve specific roles. They include Get Help troubleshooters, uninstall updates, Reset this PC, System Restore, and the command prompt in WinRE. Support staff can use Remote Help to offer live assistance to users on Microsoft Intune-managed devices that can boot. Quick Assist remains available for everyone who needs remote assistance. To learn more about these tools, please visit their respective documentation.

Scenario Solution Tools
Individual device issues after an update If the PC can boot, users can reinstall the current version of Windows. If needed, go back to the previous version of Windows. Uninstall the update if the PC cannot boot or issues persist 10 or more days after the update. For known issues in non-security updates, use Known Issue Rollback (KIR) via Group Policy.
  • Reinstall the current version of Windows
  • Go Back
  • Uninstall a Windows Update
  • Use Group Policy to deploy Known Issue Rollback
  • A single malfunctioning component
    (audio, networking, printing, etc.)
    Users run targeted diagnostics and remediation for the affected components. Get Help troubleshooters
    Recent, isolated issue or widespread device issue IT or users roll back the system to its exact state from a past point in time. Requires a recent restore point. New! Point-in-time restore for Windows
    Persistent device issues after targeted recovery attempts
    (unknown cause)
    Users reinstall Windows while removing apps and settings. Optionally, keep user files. Reset this PC
    Deep OS corruption
    (point-in-time restore and Reset this PC don’t work)
    IT or user initiates clean OS install that downloads a target Windows image and device drivers and applies it to the device for a fresh start.
  • New! Cloud rebuild (preview)
  • Create a recovery drive
  • Manufacturer-created recovery media
  • Hardware failure or device unavailability
    (lost, stolen, or isolated during a security investigation)
    IT provisions a temporary Cloud PC. Settings, documents, and managed apps are restored on new device. Recommended for immediate user productivity. New! Windows 365 Reserve
    A mass-scale outage affecting boot
    (rare)
    When a device repeatedly fails to boot and enters WinRE, it automatically checks for and applies a Microsoft-provided fix from Windows Update. No user action is required. New! Quick machine recovery

    Each recovery scenario has at least one tool that you can use to remediate the device. In practice, start with the least disruptive, fastest option and reach for a heavier tool only when the situation calls for it.

    Tooling considerations for your organization

    Device disruptions come in many shapes. A misconfigured policy can render thousands of PCs unbootable overnight. A user accidentally modifying critical system settings can disrupt a single laptop. An aging device can have a random hardware failure and simply stop cooperating. That’s why this tiered recovery framework includes a series of tools designed for a specific class of problem. New and pre-existing tools as well as supporting capabilities, work together to give your IT team a clear path to recovery.

    Here’s what you can do to start preparing your organization.

    Microsoft Intune

    Use Microsoft Intune as a centralized management platform for recovery and resiliency capabilities. Through Intune, you can configure and deploy the policy settings exposed through Windows CSPs, including settings for quick machine recovery, point-in-time restore, cloud rebuild, Windows Autopilot, and Windows settings backup and restore. Enable quick machine recovery on your managed devices via the Recovery CSP. Configure Wi-Fi credentials, scanning intervals, and test the experience using test mode before production deployment.

    Point-in-time restore

    Test point-in-time restore. Explore the settings locally and via the Recovery CSP, perform a test restore, and share your feedback through Feedback Hub.

    Windows settings backup and restore

    Enable Windows settings backup and restore to streamline device transitions. Use Intune to enable backup and restore policies to preserve user settings: accessibility preferences, personalization, language and regional settings, and the list of installed Microsoft Store apps. When a device is reset, rebuilt, or replaced, these settings are automatically restored during the out-of-box experience (OOBE) or first sign-in for Microsoft Entra hybrid joined devices and Cloud PCs.

    OneDrive for work or school

    Configure OneDrive for work or school for your organization. Cloud file storage helps ensure that user documents, photos, and other files are continuously synced and protected. Whether you roll back a device with point-in-time restore, rebuild it from scratch, or replace it entirely, cloud-synced files remain accessible and unaffected. This is especially important with point-in-time restore, where local files are reverted to the restore point state. To begin, enable Known Folder Move regardless of which recovery path you use. It syncs the latest file state with its versions down to your device when connected to the cloud.

    Microsoft 365 Backup

    Configure Microsoft 365 Backup for point-in-time recovery to protect all OneDrive accounts, mailboxes, and SharePoint sites. That way, you can roll back malicious or accidental data modifications and deletions. The combination of OneDrive with Microsoft 365 Backup provide file protection beyond the device itself and are a recommended resiliency plan.

    Windows Autopilot

    Set up Windows Autopilot profiles for zero-touch device provisioning. Autopilot automatically enrolls devices in your management environment, applies policies, and installs apps during OOBE. After a cloud rebuild or on a new replacement device, Autopilot helps get users back to productivity on a fully configured and compliant device without requiring manual IT intervention.