Windows Command #43 – sc failure (Windows OS)

IT technicians working together at a Windows terminal in a server room.

sc failure configures the recovery actions Windows can take when a service fails. This lesson follows Windows Command #42 – sc delete and continues the Service Control Manager command sequence.

What the command does

Windows services can stop unexpectedly because of application faults, dependencies, or system conditions. With sc.exe failure, an administrator can specify actions such as restarting a service, running a command, or rebooting the computer after particular failures. It changes recovery settings; it does not repair the underlying fault.

Read the existing recovery policy first

Open an elevated Command Prompt and run sc.exe qfailure "Spooler" to inspect the Print Spooler service recovery settings. Reading settings does not change them. For service configuration, review Windows Command #38 – sc qc.

Syntax

The basic pattern is sc.exe failure SERVICE_NAME reset= SECONDS actions= ACTIONS. Note that the space after each equals sign is required by the sc.exe option syntax. In PowerShell, use sc.exe, not sc, to avoid ambiguity with aliases in some environments.

Practical example

For a disposable test service you administer, an example recovery configuration is sc.exe failure DemoService reset= 86400 actions= restart/60000/restart/60000/none/0. It specifies a one-day failure-count reset interval, a restart after 60 seconds for each of the first two failures, and no action on the third. Do not run this against a production service without an approved change plan.

Confirm the settings with sc.exe qfailure DemoService. The service account, recovery configuration, and restart rights must permit the action. The reset interval controls the failure count; it is not the delay before a restart.

Important safety details

  • Do not configure repeated automatic restarts as a substitute for root-cause analysis.
  • Service failure actions normally concern service failures rather than every intentional administrative stop.
  • Recovery behavior can depend on whether failure actions on non-crash failures are enabled; inspect sc.exe qfailureflag SERVICE_NAME and consult the Windows documentation before changing that policy.
  • A restart action can interrupt users or dependent workloads. Review service dependencies and change windows first.
  • Record the original settings before modification so you can restore them.

Exercises

  1. Open Command Prompt as an administrator and identify a noncritical test service you are authorized to inspect.
  2. Run sc.exe qfailure SERVICE_NAME and record the existing recovery actions.
  3. Explain what reset= 86400 means.
  4. Write, but do not execute, a command to restart a test service once after 30 seconds and then take no action.
  5. Describe how you would verify the new settings and safely roll them back.

Knowledge check and answer guide

1. What does sc failure configure? Service failure recovery actions. 2. Which command reads the configuration? sc.exe qfailure SERVICE_NAME. 3. What does restart/30000 mean? Restart the service after a 30,000-millisecond (30-second) delay. 4. Why avoid testing on a critical service? Recovery changes can trigger disruptive restarts and hide underlying faults. 5. Why use sc.exe in PowerShell? It explicitly invokes the Windows Service Control executable.

Further reading

Consult the official Microsoft sc failure reference and Microsoft sc qfailure reference. For the broader context of service states, startup types, and dependencies, see Windows Services Fundamentals.

One response to “Windows Command #43 – sc failure (Windows OS)”

  1. […] configured recovery actions also run for non-crash failures. It follows directly from Windows Command #43 – sc failure, which defines the recovery actions […]

    Like

Leave a Reply