Quick fix (5 steps)
- Restart, disconnect any VPN, and make sure the C: drive has at least 15 GB free.
- Open Settings, System, Troubleshoot, Other troubleshooters, Windows Update, Run.
- Open Command Prompt as administrator and run
DISM /Online /Cleanup-Image /RestoreHealth, thensfc /scannow, then restart. - For 0x80070643 only: run
reagentc /info. If the recovery partition is small or Windows RE is disabled, jump to the WinRE section. - Retry the update. If it still fails, use the code-specific sections: 0x80070643, 0x80070005, 0x800f0922.
What these three Windows Update error codes actually mean
0x80070643, 0x80070005 and 0x800f0922 are three separate failures that happen to appear in the same place, Windows Update. The first is a generic installation failure, the second is "access denied", and the third is a servicing (CBS) failure. Treating them as one problem is why generic "fix Windows Update" videos often fail.
Each code is a Windows error number written in hexadecimal. The part after "0x8007" in the first two comes from the standard Win32 error table: 0x643 (1603 in decimal) is ERROR_INSTALL_FAILURE, and 0x5 is ERROR_ACCESS_DENIED. The third, 0x800f0922, belongs to the component-based servicing stack, the part of Windows that installs, stages and commits updates. Knowing which family the code belongs to tells you where to look: the installer, the permissions, or the servicing store.
| Code | Plain meaning | Most common real cause | First thing to try |
|---|---|---|---|
| 0x80070643 | Installation failed (generic) | Recovery (WinRE) partition too small, damaged .NET or Windows Installer, failed Defender platform update | reagentc /info, then DISM and SFC |
| 0x80070005 | Access denied | Wrong permissions, third-party security software, no admin rights, profile or disk problem | Reset update cache, check security software, run as administrator |
| 0x800f0922 | Servicing operation failed | Full System Reserved or EFI partition, VPN or proxy, corrupt component store, .NET 3.5 feature failure | Disconnect VPN, free space, DISM RestoreHealth |
The honest summary is that DISM and SFC help with all three, but only the right code-specific step actually ends the loop. If you want the deeper single-code pages, we also maintain focused guides for error 0x80070005, Windows 11 update failure 0x800f0922 and the related error 0x80073712. This article is the combined, decision-tree version: it helps you work out which family you are in and gives the commands in the right order.
Why people see these codes together
The same update often throws different codes on different tries, because a failure at one layer exposes a failure at the next. A permissions problem can leave a half-staged update, which then fails with a servicing error on the following attempt, and a servicing error can end with a generic install failure. That is why a user may report all three within a week.
A typical sequence looks like this. A cumulative update downloads, then fails at "Installing" with 0x80070005 because a security product locked a file. The retry runs on a partly staged update and fails with 0x800f0922 when the component store rejects the incomplete package. After a few more attempts the monthly update fails with 0x80070643 because the stale pending state blocks the installer. Each message is accurate for its moment, but the root cause is the first one. When you see several codes on one machine, fix the earliest failure in Update history first, not the latest.
How to read your own Update history
Open Settings, Windows Update, Update history. Under "Failed updates" Windows lists the update name, its KB number, the date and the error code. Sort mentally by date and look for the oldest failure. Also note the type of update: a cumulative update, a .NET Framework update, a Defender platform update, a driver, or a feature update. A failing .NET update points at .NET repair. A failing cumulative update after a recovery-environment warning points at the WinRE partition. A failing feature update points at disk space, drivers and the System Reserved partition.
What is not the cause
- A virus. These codes are almost never caused by malware, although malware can damage update components. Run Microsoft Defender once as a sanity check, but do not panic.
- A bad internet connection. Connection problems usually produce 0x8024xxxx download errors, not these three.
- A faulty SSD. Rare. If you also see freezes, file corruption or SMART warnings, see our SSD versus HDD guide and have the disk tested.
- The update being "bad" for everyone. Sometimes Microsoft does ship a defective update, but if only your machine fails, the cause is local.
Before you start: a safe routine that prevents most of the damage
Back up first, free disk space, and note your recovery key, because several of the fixes below touch system files or partitions. Ten minutes here protects you from the rare case where a repair step goes wrong or a power cut hits mid-operation.
- Back up your files. Copy documents, photos and desktop files to an external drive, or confirm your cloud folder is truly synced by opening it on another device. Our short comparison of data recovery versus data backup explains why a tested backup beats hoping recovery works.
- Free 15 to 20 GB on C:. Use Settings, System, Storage, Temporary files. A nearly full system drive causes both 0x800f0922 and 0x80070643 more often than people expect.
- Plug in the laptop and disconnect docks, USB drives, printers and any VPN.
- Save your BitLocker key if the drive is encrypted. Find it at the Microsoft account recovery key page or in your work account. Partition and boot changes can trigger a recovery prompt.
- Create a restore point by searching "Create a restore point", selecting your system drive and choosing Create. It will not undo partition changes, but it protects against many driver and registry mistakes.
Pre-repair checklist
- ☐ Files backed up and verified on a second device or drive
- ☐ At least 15 GB free on C:
- ☐ Laptop plugged in, VPN off, extras unplugged
- ☐ BitLocker or device-encryption key saved if applicable
- ☐ Failed update name, KB number and code written down
- ☐ Restore point created
If you cannot complete the checklist, for example you have no backup and the machine holds client files, pause here. A remote technician can clone the drive or copy the data first. Stopping early is cheaper than data recovery, which we cover in data recovery after a Windows update or reinstall.
Fixes that work for all three codes (do these first)
Start with the five universal repairs in this order: restart and clean the environment, run the troubleshooter, repair with DISM, repair with SFC, then reset the update cache. They are safe, reversible and solve a large share of cases before you need any code-specific step.
Step 1: Restart and clean the environment
Restart the computer fully (not Sleep, not Fast Startup). Choose Restart from the Start menu, because shutting down with Fast Startup enabled can preserve a broken state. Disconnect any VPN client, close remote-access tools, and pause heavy sync clients for the duration. If the machine is a work PC, check that you are not blocked by a policy that pins updates.
Step 2: Run the Windows Update troubleshooter
Open Settings, System, Troubleshoot, Other troubleshooters and press Run next to Windows Update. It resets some services and clears a few flags. It rarely fixes the deepest causes, but it costs one minute and sometimes gets the job done.
Step 3: Repair the component store with DISM
Right-click the Start button, choose Terminal (Admin) or Command Prompt (Admin), and run these commands one at a time:
DISM /Online /Cleanup-Image /CheckHealth
DISM /Online /Cleanup-Image /ScanHealth
DISM /Online /Cleanup-Image /RestoreHealth
RestoreHealth downloads clean copies of damaged system components from Windows Update and can take 10 to 30 minutes. It may sit at 20 percent or 62 percent for a long time, which is normal. If it reports error 0x800f081f, the source files could not be found: mount the official Windows ISO and run DISM /Online /Cleanup-Image /RestoreHealth /Source:WIM:D:\sources\install.wim:1 /LimitAccess, replacing D: with the mounted drive letter and 1 with the image index that matches your edition. Microsoft documents the DISM options on its repair a Windows image page.
Step 4: Run System File Checker
After DISM finishes, run sfc /scannow in the same administrator window. SFC compares protected system files against the component store and replaces bad ones. Run it twice if the first run says it fixed files. If it reports that it found corrupt files it could not fix, check the CBS log at C:\Windows\Logs\CBS\CBS.log and go back to DISM with an ISO source. Restart afterwards.
Step 5: Reset the Windows Update cache
This clears the downloaded and staged update files so Windows starts fresh. In an administrator Command Prompt:
net stop wuauserv
net stop cryptSvc
net stop bits
net stop msiserver
ren C:\Windows\SoftwareDistribution SoftwareDistribution.old
ren C:\Windows\System32\catroot2 catroot2.old
net start wuauserv
net start cryptSvc
net start bits
net start msiserver
If a rename fails with "access denied", that is a clue for 0x80070005, which we cover below. Otherwise, restart and check for updates again. Windows rebuilds both folders automatically. You can delete the .old folders after a few successful updates; keep them until then in case you need to look at old logs.
Do not skip the order
Running the cache reset before DISM and SFC can look faster, but a damaged component store will simply poison the fresh cache. Repair first, reset second. The sequence above takes 30 to 50 minutes on a typical laptop and is the same sequence a technician follows.
Diagnose which code family you have in 5 minutes
The quickest diagnosis combines three checks: the exact error code in Update history, the output of reagentc /info, and the free space on your system and recovery partitions. Together they point to the right section instead of sending you through every fix.
| Symptom | Likely family | Go to |
|---|---|---|
| Cumulative update fails, "Windows RE" or recovery warnings, older PC with a small recovery partition | 0x80070643 (WinRE) | 0x80070643 section |
| .NET Framework or Defender platform update fails with 0x80070643 | 0x80070643 (installer or .NET) | 0x80070643 section |
| Renaming SoftwareDistribution is denied, or a manual installer says access denied | 0x80070005 | 0x80070005 section |
| Third-party antivirus, disk encryption or "security suite" installed recently | 0x80070005 | 0x80070005 section |
| Feature update fails near 85 to 100 percent and rolls back | 0x800f0922 | 0x800f0922 section |
| Enabling .NET Framework 3.5 fails | 0x800f0922 | 0x800f0922 section |
| Works on home Wi-Fi, fails on work VPN | 0x800f0922 | 0x800f0922 section |
Run the three diagnostic commands
In an administrator terminal, run:
reagentc /info
diskpart
list disk
list volume
exit
wmic logicaldisk get caption,freespace,size
If wmic is missing on your build, use Get-Volume in PowerShell instead. In the reagentc output, look at "Windows RE status" (Enabled or Disabled) and "Windows RE location" (for example \\?\GLOBALROOT\device\harddisk0\partition4\Recovery\WindowsRE). The number after "partition" tells you which partition holds it. Compare that with Disk Management (right-click Start, Disk Management) to see its size and free space. A recovery partition of 500 MB or less that is nearly full is the classic 0x80070643 culprit.
Read the logs when the code alone is not enough
For a servicing failure, open C:\Windows\Logs\CBS\CBS.log and search for the word "Error". For an install failure, Event Viewer, Windows Logs, Setup and Application often show the failing component. For Windows Update client details, run PowerShell Get-WindowsUpdateLog, which writes a readable file to your desktop. You do not need to read all of it. Search for the KB number and the HRESULT near it. The lines nearby usually name the file, service or partition that failed, which turns a vague code into a specific target.
Identify your disk layout
Two layouts matter. A GPT/UEFI disk has an EFI System Partition (usually 100 to 260 MB), a Microsoft Reserved partition, the C: partition, and a recovery partition. An MBR/BIOS disk has a System Reserved partition (100 to 500 MB) and C:, with the recovery partition sometimes at the end. Run msinfo32 and read "BIOS Mode": UEFI means GPT in nearly all modern installs, Legacy means MBR. The correct commands in the WinRE section differ for each, so do not skip this.

Fixing error 0x80070643
Error 0x80070643 is a generic "installation failed" result, and the cause you can actually act on is usually one of four: a small Windows Recovery Environment partition, a damaged .NET Framework, a broken Windows Installer service, or a failed Defender platform update. Work through them in that order of likelihood for cumulative updates, and in reverse order if the failing item is a .NET or Defender update.
Cause A: the WinRE partition is too small
Windows keeps a small recovery image (WinRE) on a hidden partition. In January 2024 Microsoft published KB5034441, a Windows Recovery Environment update for Windows 10 that failed with 0x80070643 on many PCs because the recovery partition did not have enough free space. Microsoft's guidance at the time described needing roughly 250 MB of free space in that partition. Similar recovery-image updates have been issued since, and the same pattern appears in recent Q&A threads for Windows 11, including a Microsoft Q&A thread about 24H2. Check the current Microsoft notice for your exact KB before acting, since requirements can change between releases.
First confirm the diagnosis with reagentc /info. If Windows RE status is Enabled and the location points to a partition that Disk Management shows as, say, 500 MB with under 250 MB free, you have the classic case. If Windows RE shows Disabled, or the location is blank, the recovery environment itself is not registered, which also blocks the update.
Do not run this if
Do not resize partitions if the drive is failing or reporting SMART warnings, if the disk is encrypted with BitLocker and you have not saved the key, if the machine is a managed work PC (ask your IT team, they may have a script), or if you cannot identify the recovery partition with certainty. In those cases skip to the manual install or call for help.
Cause B: Windows RE is simply disabled
Try the cheap fix before touching partitions. In an administrator terminal run:
reagentc /disable
reagentc /enable
reagentc /info
If /enable succeeds and the status becomes Enabled, retry the update. If it fails with an error about a missing Winre.wim, the recovery image is absent and needs to be restored from an ISO, which a technician can do in a few minutes by copying winre.wim out of the install image. Microsoft documents the tool on its REAgentC page.
Cause C: a damaged .NET Framework or Windows Installer
If the failing update is a ".NET Framework cumulative update" or a Defender platform update, the partition is not the culprit. Do this instead:
- Open Control Panel, Programs and Features, Turn Windows features on or off. Untick .NET Framework 3.5 and 4.8 Advanced Services, restart, then tick them again and let Windows reinstall them.
- Download Microsoft's .NET Framework Repair Tool from the official Microsoft site, run it and accept the recommended repairs.
- In an administrator terminal run
sc query msiserver. If the service is missing or stuck, runmsiexec /unregisterfollowed bymsiexec /regserver, and restart. - For a failing Defender platform update, open Windows Security, Virus and threat protection, Protection updates, and select Check for updates. If it fails, remove leftover third-party antivirus and retry.
Cause D: pending reboot or stale pending.xml
An interrupted earlier install can leave a pending operation that blocks the next one. Restart twice. If it persists, check whether C:\Windows\WinSxS\pending.xml exists. Do not delete it blindly. A technician can safely move it or run DISM /Online /Cleanup-Image /RevertPendingActions, but be aware that command is meant for Windows that is not fully installed and should not be a first choice.
Resizing or recreating the WinRE partition step by step
The permanent fix for the small-recovery-partition cause is to disable WinRE, shrink the C: partition, delete the old recovery partition, create a larger one with the correct type, and re-enable WinRE. The steps below follow the approach in Microsoft's published guidance, but verify the GUID and attribute values against the current Microsoft page before running them, since a wrong partition type can make the recovery environment unusable.
Stop before you touch diskpart
Back up your files first. Deleting or resizing the wrong partition can make a PC unbootable and its data hard to recover. If you are not 100% sure which partition is which, or the partitions do not look like the layout described below, do not continue. Call a technician: a remote or on-site session costs far less than a data recovery job.
Step 1: Record your starting state
Run reagentc /info and note the partition number. In Disk Management, confirm that the recovery partition sits directly after C: (to the right of it). If other partitions sit between them, the standard shrink approach will not work without third-party tools, and you should stop and get help.
Step 2: Disable WinRE and open diskpart
reagentc /disable
diskpart
list disk
select disk 0
list partition
Identify the C: partition (largest) and the recovery partition (type Recovery, often 450 to 600 MB). Select the C: partition with select partition X (where X is the number you identified) and make sure it is the right one with detail partition.
Step 3: Shrink C: by 250 MB or more
shrink desired=250 minimum=250
If you want headroom for future updates, use 500 instead. A larger recovery partition costs you a small slice of disk and prevents repeat failures. If shrink fails because of unmovable files, run Disk Cleanup, disable hibernation temporarily with powercfg /h off, restart, and try again.
Step 4: Delete the old recovery partition
select partition Y
delete partition override
Replace Y with the recovery partition number you confirmed. Triple-check it. Deleting the wrong partition can make Windows unbootable. This is the step where most disasters happen.
Step 5: Create the new partition
For a GPT/UEFI disk:
create partition primary
format quick fs=ntfs label="Windows RE tools"
set id="de94bba4-06d1-4d40-a16a-bfd50179d6ac"
gpt attributes=0x8000000000000001
exit
For an MBR/BIOS disk the id differs:
create partition primary
format quick fs=ntfs label="Windows RE tools"
set id=27
exit
The new partition takes the space you freed from C: when it is created right after the shrink. If you shrank by 250 MB and need it all, the new partition will use all unallocated space.
Step 6: Re-enable WinRE and verify
reagentc /enable
reagentc /info
Status should be Enabled and the location should point to the new partition. Retry Windows Update. If the update still fails, check reagentc /info again, and consider a manual install from the Microsoft Update Catalog in the final section.
| Approach | Risk | Time | Best for |
|---|---|---|---|
| Wait for Microsoft to ship a fix or script | Very low | None | Non-critical PCs, no urgency |
| reagentc /disable then /enable | Very low | 2 minutes | Disabled WinRE |
| Manual diskpart resize (above) | Medium (typo or wrong partition) | 20 to 40 minutes | Technical users with a backup |
| Partition manager tool | Medium | 15 to 30 minutes | Layouts with partitions in between |
| Remote technician | Low | One 60-minute session | Business PCs or no backup |
Fixing error 0x80070005 (access denied)
Error 0x80070005 means Windows or an installer tried to read, write or start something and was refused. The refusal comes from file or registry permissions, a security product that blocked the action, a missing administrator token, or a damaged user profile. Fixing it is mostly about finding who said no.
Check 1: Are you really running with admin rights?
If the error appears when you run a manual installer or a script, right-click it and choose Run as administrator. If your account is a standard user on a family or work computer, sign in with an administrator account. On a managed PC, a policy may block the installer on purpose, and the right fix is a request to your IT team, not a workaround.
Check 2: Security software
Third-party antivirus, endpoint protection, "tune-up" software and some disk encryption tools can lock system files or block the update service. Temporarily disable real-time protection of the third-party product (not Microsoft Defender) for the update, install, then re-enable it. If that works, check the vendor's exclusion list and add the Windows Update folders as documented. Never leave protection off. If you have two security products installed, remove one: running two real-time scanners is a common source of access-denied errors. Our free antivirus comparison helps you pick a single product to keep.
Check 3: Permissions on the update folders
The SoftwareDistribution and catroot2 folders must be accessible to SYSTEM and Administrators. Open an administrator terminal and run:
icacls C:\Windows\SoftwareDistribution /grant "NT SERVICE\TrustedInstaller":(OI)(CI)F
icacls C:\Windows\SoftwareDistribution /grant SYSTEM:(OI)(CI)F
icacls C:\Windows\SoftwareDistribution /grant Administrators:(OI)(CI)F
This restores the standard access that the update service expects. If a rename in the cache reset earlier was refused, this often unblocks it. Do not run icacls with /T across the whole Windows folder; broad permission changes cause more damage than they cure.
Check 4: Services and their accounts
Press Windows + R, type services.msc and check that Windows Update, Background Intelligent Transfer Service, Cryptographic Services and Windows Installer are not Disabled. Windows Update should be Manual (Trigger Start) or Automatic, and the Log On account should be Local System. A service set to run as a specific user, which some "optimizers" do, will cause access denied. Reset it to Local System and restart the service.
Check 5: Disk errors and a damaged profile
Run chkdsk C: /scan in an administrator terminal. A read-only scan catches file system errors without scheduling an offline repair. If errors are found, run chkdsk C: /f and restart. For a profile problem, create a new local administrator account, sign in, and try the update from there. If it works, the old profile was the issue and you can migrate your data to the new one.
Check 6: The registry key and the Microsoft Store variant
If 0x80070005 appears in the Microsoft Store or when installing a specific app, rather than Windows Update, reset the Store cache with wsreset.exe and re-register the app packages from PowerShell. The permission cause is the same family, but the folders (WindowsApps, the Store cache) are different. Our dedicated 0x80070005 page covers those variants in more detail.
Safety note on permissions
Be careful with any guide that tells you to take ownership of C:\Windows or give Everyone full control. That fixes the error by removing protections, and it leaves your PC less secure and sometimes unbootable. Restore standard permissions only on the specific folder named in the log.
| Check | Effort | Fixes it when |
|---|---|---|
| Run as administrator | 1 minute | Manual installers fail, standard user account |
| Disable third-party security briefly | 5 minutes | Antivirus is locking files |
| icacls on SoftwareDistribution | 5 minutes | Cache folder cannot be renamed or written |
| Reset service accounts | 5 minutes | "Optimizer" changed service logon |
| chkdsk and new profile | 20 to 40 minutes | File system or profile corruption |
Fixing error 0x800f0922
Error 0x800f0922 usually appears when an update reaches the final stage and cannot be committed, most often because the System Reserved or EFI partition is full, a VPN or proxy interrupts the connection to Microsoft, or the component store is damaged. Fix the cheap network and space causes first, then repair the store, then deal with the partition.
Cause A: VPN, proxy or firewall
Some updates must contact Microsoft servers during installation. A full-tunnel VPN, a corporate proxy or an aggressive firewall can drop that connection and produce 0x800f0922. Disconnect the VPN, turn off any manual proxy under Settings, Network and Internet, Proxy, and retry on a home network. If it works there, the cause is your work network and the remedy belongs to your IT team: ask them to allow Windows Update endpoints or let the machine update off-VPN.
Cause B: the System Reserved or EFI partition is full
Feature updates write boot files to the System Reserved partition (MBR) or the EFI System Partition (GPT). If it is nearly full, often because old font files or third-party boot tools filled it, the update rolls back around 90 percent. Check it by opening Disk Management, or run mountvol S: /S to mount the EFI partition as S: and then dir S: /s to see what is in it. Do not delete anything in the EFI folder unless you know what it is. Common safe candidates are leftover font files in EFI\Microsoft\Boot\Fonts that are not required for boot. If this feels risky, it is: a technician can free space safely, or resize the partition with a proper tool after a backup.
When you finish, unmount the partition with mountvol S: /D. On a PC where the EFI partition is only 100 MB, a feature update is the most likely time to hit the limit, and it is why 0x800f0922 appears so often during version upgrades such as the one described in our Windows 11 0x800f0922 page.
Cause C: .NET Framework 3.5 or an optional feature
If the error shows up when enabling .NET Framework 3.5 from Windows Features, the usual causes are blocked access to Windows Update, a policy that redirects source files, or corrupt store files. Run DISM with the ISO as the source: DISM /Online /Enable-Feature /FeatureName:NetFx3 /All /LimitAccess /Source:D:\sources\sxs, replacing D: with your mounted ISO drive. This installs the feature from the local files and skips the network.
Cause D: a damaged component store
Repeat the DISM RestoreHealth and SFC sequence from earlier. If DISM cannot repair, use the ISO as the repair source. As a last resort before an in-place upgrade, run DISM /Online /Cleanup-Image /StartComponentCleanup to remove superseded components, then retry. Avoid /ResetBase unless you understand that it removes the ability to uninstall installed updates.
Manual install and in-place repair when the fixes do not stick
If the update still fails after the code-specific repairs, install it manually from the Microsoft Update Catalog, and if that fails too, run an in-place repair upgrade from the official ISO. Both methods bypass the parts of Windows Update that are failing and keep your files and apps.
Option 1: Install the standalone package
- Note the KB number from Update history, for example the KB listed next to the failed entry.
- Open the Microsoft Update Catalog and search for that KB number.
- Pick the entry that matches your Windows version (23H2, 24H2, 25H2) and architecture (x64 for most PCs, ARM64 for Copilot+ Arm devices). Check your build with
winverandsysteminfo. - Download the .msu file and double-click it, or install it from an administrator terminal with
wusa.exe C:\path\to\update.msu /quiet /norestart. Restart afterwards.
A standalone install fails differently from a Windows Update install, and the message is often more specific. If wusa reports a missing prerequisite, install the previous servicing stack update or the latest cumulative update it names. Some updates are delivered as .cab files rather than .msu. For those, use DISM /Online /Add-Package /PackagePath:C:\path\update.cab.
Option 2: In-place repair upgrade
This reinstalls Windows over itself while keeping your files, apps and settings, and replaces damaged system files and the component store. It is the most reliable fix for stubborn servicing and permission corruption.
- Download the Windows 11 ISO or Installation Assistant from Microsoft's download page. Use the same language and a version that is the same or newer than your current build.
- Right-click the ISO, choose Mount, and open it in File Explorer.
- Run setup.exe from the mounted drive. Choose "Keep personal files and apps" when prompted. Pick "Not right now" for the dynamic updates step if the earlier ones were failing.
- Allow 45 to 90 minutes and several restarts. Do not power off, even if the progress bar looks stuck.
- After it finishes, run Windows Update again and the earlier failure should be gone.
On a PC with a very small EFI or System Reserved partition, setup may still fail with 0x800f0922. In that case free space in the EFI partition or resize it first, as described above, then retry. If you are mid-way through the Windows 11 feature-update cycle, our Windows 11 25H2 update guide covers version-specific traps.
Option 3: Last resort, reset or clean install
If the in-place repair fails, the system has deeper corruption or a hardware cause (failing SSD, bad RAM). Test the disk and memory first. Then use Settings, System, Recovery, Reset this PC, or clean install from USB after backing up. A reset that keeps files is faster, but a clean install is the cleaner baseline. A clean install also gives Windows a chance to create a modern, correctly sized recovery partition. That is one genuine advantage on old machines, whose partitions were laid out years ago. See our Windows 11 speed guide for what to do after a fresh install.
Realistic scenarios (illustrative, not real client cases)
The same code can have very different causes, so the quickest route is to match your situation to a pattern. The three realistic scenarios below show how the fixes combine in practice. They are illustrative composites and are not records of real clients.
Scenario 1: The home laptop that fails every Patch Tuesday
A five-year-old laptop with a 512 GB SSD has failed the monthly cumulative update for three months with 0x80070643. reagentc /info shows Windows RE enabled on partition 4. Disk Management shows a 523 MB recovery partition with about 120 MB free, below the roughly 250 MB that was cited for the KB5034441-style update. C: has 61 GB free. The owner backs up photos to an external drive, saves the BitLocker key, disables WinRE, shrinks C: by 500 MB, recreates the partition with the correct GPT type and re-enables WinRE. The next Patch Tuesday update installs. Total time: about 35 minutes, cost: nothing but a USB drive the owner already had.
Scenario 2: The office PC with 0x80070005 after a security suite change
A small accounting office replaces its antivirus with a new endpoint product, and the next Windows Update on one workstation fails with 0x80070005. Renaming SoftwareDistribution is denied. The old antivirus was only partly uninstalled, so two real-time scanners are fighting over the same files. The fix: use the old vendor's removal tool, restart, reset the update cache, and confirm only the new product is active. The workstation updates normally and the other PCs, which had a clean uninstall, were never affected. Time: about 40 minutes remote, within a single 60-minute session.
Scenario 3: The remote employee on a VPN with 0x800f0922
A remote employee's work laptop tries to install a feature update, reaches about 90 percent, rolls back and reports 0x800f0922. The always-on VPN forces all traffic through the head office, and the update needs to contact Microsoft during the final stage. On the employee's home network with the VPN paused (with IT approval), the same update installs. Because the EFI partition was also only 100 MB with 4 MB free, the support team frees space in the EFI font folder at the same time. Result: a one-off VPN exception policy and a documented procedure for the other twenty laptops, instead of twenty separate failures.
| Scenario | Code | Root cause | Fix that worked |
|---|---|---|---|
| Home laptop, monthly failures | 0x80070643 | Full recovery partition | Recreate larger WinRE partition |
| Office PC after antivirus change | 0x80070005 | Two real-time scanners | Clean removal, cache reset |
| Remote employee | 0x800f0922 | VPN plus full EFI partition | Update off-VPN, free EFI space |
What this costs in Canadian dollars: DIY versus paying a technician
Most of these fixes cost nothing but time, and a paid session only makes sense when your data is at risk, the PC is for business, or you have already spent a few hours without progress. The figures below are realistic ranges in CAD, not quotes, and prices at other providers vary.
| Route | Typical cost (CAD) | Your time | Risk |
|---|---|---|---|
| DIY with DISM, SFC and cache reset | 0 $ | 1 to 2 hours | Low |
| DIY partition resize with diskpart | 0 $ to 20 $ (USB backup drive) | 1 to 3 hours | Medium |
| Walk-in repair shop (varies by shop) | Often 60 $ to 150 $, plus drop-off time | Half a day without your PC | Low |
| IT Cares remote Expert Consultation | 119.99 $ for 60 minutes | About an hour at your screen | Low |
| New computer to dodge the problem | 800 $ to 1,500 $+ | Days to migrate | Unnecessary in nearly every case |
Think about what the hour is worth. If you run a clinic, a shop or a bookkeeping practice, a PC that cannot install security updates is also a compliance concern, and your own hour is worth more than the consultation. If you are a student or a retiree with a time-rich afternoon, the DIY route is a good way to learn. The mistake to avoid is the middle path: paying for a "PC cleaner" subscription of 40 $ to 90 $ a year that promises to fix update errors. Those products rarely address the real causes in this article.
The hidden cost of waiting
An update that fails every month is also a security delay. Each missed cumulative update leaves known vulnerabilities in place. For a business, one compromised workstation costs far more than a consultation. Even if you choose to defer the repair, keep the machine away from risky downloads and email attachments until it is patched.
Printable troubleshooting checklist
Use this checklist in order and tick each box before moving on, so you never repeat a step or skip the one that matters. Keep it next to the PC, or paste it into a note.
Windows Update error checklist
- ☐ Code and KB noted from Update history (oldest failure first)
- ☐ Backup done, BitLocker key saved
- ☐ 15 GB or more free on C:, VPN off, restart done
- ☐ Windows Update troubleshooter run
- ☐ DISM RestoreHealth finished, SFC clean
- ☐ Update cache reset (SoftwareDistribution and catroot2)
- ☐ 0x80070643: reagentc /info checked, recovery partition size confirmed
- ☐ 0x80070005: security software checked, permissions on update folders reviewed
- ☐ 0x800f0922: VPN and proxy off, EFI or System Reserved space checked
- ☐ Standalone package from the Update Catalog tried
- ☐ In-place repair upgrade tried
- ☐ Disk and memory tested if everything else failed
How to stop these errors from coming back
Prevention comes down to four habits: keep free space, keep one security product, avoid "optimizer" tools, and update regularly instead of in big batches. Small monthly updates fail less often than a pile of six months of updates installed at once.
- Keep at least 15 percent of the system drive free. A drive at 95 percent full is the root of many update failures, and it also slows the PC, as covered in our speed-up guide.
- Use one real-time antivirus. Microsoft Defender is enough for most people. If you add a third-party product, uninstall the old one completely with the vendor's removal tool.
- Do not use registry cleaners or service "tweakers". Changing service accounts, permissions or startup types is a direct path to 0x80070005.
- Check your recovery partition once a year. A quick
reagentc /infoand a look at Disk Management takes two minutes. When you buy a refurbished PC, check it right away. - Keep a tested backup. Repair steps and updates are safer when a backup exists. A working automated plan, such as the one described in our automated backups guide for small businesses, turns every repair into a routine task.
- Avoid interrupting updates. Do not hold the power button during "Working on updates". Wait at least an hour with disk activity.
Official resources worth bookmarking
The most reliable references are Microsoft Learn pages for DISM, REAgentC and Windows Update troubleshooting, plus the Microsoft Update Catalog for manual downloads. They change over time, so check the date of any guide, including this one.
- Microsoft Learn: Troubleshoot Windows Update errors
- Microsoft Learn: REAgentC command-line options
- Microsoft Learn: Repair a Windows image with DISM
- Microsoft Update Catalog
- IT Cares: Windows Update stuck or failing, how to fix it
- IT Cares: error 0x80073712 (corrupt component store)
When to call a professional
Call a technician if the PC holds business data, you have no backup, DISM cannot repair the store, the disk shows errors, or you are about to delete a partition you cannot identify. Those are the moments where a small mistake becomes data loss, and where a one-hour session is cheaper than recovery.
- You see freezes, clicking sounds, slow file copies or SMART warnings along with the update error.
- The computer is a managed work device or part of a small-business network with several PCs failing at once.
- The partition layout has other partitions between C: and the recovery partition.
- You have tried DISM, SFC, cache reset and an in-place repair and the error remains.
- You are not comfortable running diskpart.
IT Cares has provided remote support from Quebec and across Canada since 2014. We connect to your device, you watch, we fix it and explain what we changed. A single Expert Consultation is 119.99 $ CAD for 60 minutes. Call 1 (888) 711-9428 and a technician can tell you in a minute whether your case fits a single session.
Still stuck? Get a technician on it now
Remote support from IT Cares: we connect to your device, fix it with you watching, and explain what happened.
Frequently asked questions
Related guides
- Fix Windows 11 update error 0x800f0922
- Fix error 0x80070005 (access denied)
- Fix error 0x80073712
- Windows Update stuck or failing: how to fix it
- Data recovery versus data backup
- Data recovery after a Windows update or reinstall
- How to speed up Windows 11
- SSD vs HDD upgrade and repair cost guide
Sources and official references
Last verified: October 1, 2026
- Microsoft Q&A: How to fix Windows Update error 0x80070643 (Windows 11 24H2)
- Microsoft Learn: Windows Recovery Environment (Windows RE) technical reference
- Microsoft Learn: REAgentC command-line options
- Microsoft Learn: Repair a Windows image with DISM
- Microsoft Learn: Troubleshoot Windows Update errors
- Microsoft Update Catalog
