Windows Command #45 – sc qfailureflag (Windows OS)

Diverse technology operations team reviewing Windows service status in a nighttime airport operations center.

sc.exe qfailureflag reads whether a Windows service is configured to run its recovery actions for qualifying non-crash failures. It is the read-only companion to Windows Command #44 – sc failureflag, which changes that setting.

What qfailureflag tells you

Windows services can have recovery actions such as restarting the service, running a command, or rebooting the computer after a failure. The failureflag setting controls whether those actions can also run when a service reports SERVICE_STOPPED with a nonzero Win32 exit code instead of simply crashing. qfailureflag lets you inspect that flag without changing it.

Windows Services management console listing local services, status, startup type, and logon accounts.
Windows Services management console. Source: STRONTIC technical documentation.

Basic syntax

Use sc.exe qfailureflag SERVICE_NAME. Replace SERVICE_NAME with the actual service name, not the friendly display name shown to users. For example:

sc.exe qfailureflag DemoService

A successful query typically reports the service failure-actions flag as either TRUE or FALSE. A result of TRUE means qualifying non-crash failures are eligible to trigger the service’s configured recovery actions. FALSE means those recovery actions are limited to the normal crash-style failure condition.

Mossé Cyber Security Institute explains Windows services, Service Control Manager, service states, startup behavior, and management tools.

TRUE does not mean recovery actions exist

This distinction is essential. qfailureflag reads only the flag that expands which failures can trigger recovery. It does not prove that restart, command, or reboot actions have been configured. Use sc.exe qfailure SERVICE_NAME to inspect the actual recovery policy.

A service can therefore report TRUE for qfailureflag while still having no useful recovery action configured. Conversely, a service can have recovery actions but report FALSE, meaning those actions apply only to the narrower failure condition.

Read the recovery configuration beside the flag

sc.exe qfailure DemoService
sc.exe qfailureflag DemoService

Running both commands gives you the full picture. qfailure shows actions, delay values, reset period, command, and reboot message when configured. qfailureflag shows whether non-crash failures are also eligible to trigger those actions.

This overview explains the Windows Service Control Manager, the subsystem queried by sc.exe.

Example interpretation

[SC] QueryServiceConfig2 SUCCESS
FAILURE_ACTIONS_ON_NONCRASH_FAILURES: TRUE

This output means Windows will consider qualifying non-crash service failures for the recovery actions already configured on that service. It does not tell you what those actions are. Query them separately with sc.exe qfailure SERVICE_NAME.

Query a remote computer

sc.exe can target another Windows computer when your account has the required remote Service Control Manager permissions and network access:

sc.exe \\SERVER01 qfailureflag DemoService

Remote queries can fail because of firewall rules, RPC connectivity, service-control permissions, or administrative policy. An access-denied result is not evidence that the service lacks a failure flag; it means the query itself was not authorized.

Common mistakes

  • Using the display name: sc.exe normally expects the service name.
  • Assuming TRUE means restart: the flag does not define the recovery action.
  • Skipping qfailure: always inspect the actual configured recovery actions too.
  • Confusing query with configuration: qfailureflag is read-only; failureflag changes the setting.
  • Testing a critical service: learn with a disposable or noncritical service rather than production infrastructure.

Practice lab

  1. Choose a noncritical service that you are authorized to inspect.
  2. Find its service name in services.msc or with sc.exe query.
  3. Run sc.exe qfailure SERVICE_NAME and record the recovery actions.
  4. Run sc.exe qfailureflag SERVICE_NAME and record whether the flag is TRUE or FALSE.
  5. Explain in one sentence what the flag changes and what it does not change.
  6. If you previously completed Windows Command #44 on a disposable service, compare the before-and-after query output.

Knowledge check

  1. What does sc.exe qfailureflag read?
  2. Does a TRUE result prove that restart actions are configured?
  3. Which command reads the service’s actual recovery actions?
  4. Which command changes the failure-actions flag?
  5. Why can a remote query return Access Denied?
  6. Should you use the service name or display name?

Answer guide

  1. Whether configured recovery actions can also run for qualifying non-crash failures.
  2. No. It only reports the flag.
  3. sc.exe qfailure SERVICE_NAME.
  4. sc.exe failureflag SERVICE_NAME flag= 0 or flag= 1.
  5. The account may lack Service Control Manager permissions, or RPC/firewall policy may block remote access.
  6. The service name.

Key takeaway

sc.exe qfailureflag answers one focused question: are this service’s configured recovery actions eligible to run for qualifying non-crash failures? Pair it with sc.exe qfailure so you know both the trigger scope and the actual actions.

References

Primary references: Microsoft Learn — sc.exe qfailureflag, Microsoft Learn — Configuring a Service Using SC, and Microsoft Learn — SERVICE_FAILURE_ACTIONS_FLAG.


Advertisement

BitcoinVersus.Tech Editor’s Note:

We volunteer daily to ensure the credibility of the information on this platform is Verifiably True. If you would like to support our independent technical education work, please donate Bitcoin here: 3C9o19EH5HSiwEPyCTmEKzxhNCbo2X6TTb

BitcoinVersus.tech is not a financial advisor. This lesson is for informational and educational purposes.

One response to “Windows Command #45 – sc qfailureflag (Windows OS)”

  1. […] continues the Service Control Manager sequence after Windows Command #45 – sc qfailureflag. The command that changes this setting is sc.exe privs; this lesson focuses only on inspecting the […]

    Like

Leave a Reply