Windows Recovery Partition - 夜莺博客

Windows Recovery Partition

原文:Windows Recovery Partition — theDXT (Daniel Keer)

When you install Windows it always creates a Recovery Partition, which runs a very lite version of Windows with a few tools. There’s been a few times where I’ve used those tools to fix a system.

I wanted to know what would happen if I deleted the Recovery Partition. This is what I found down that rabbit hole.

Your Windows partitioning will look something like this.

Disk Management showing the Windows layout with a Recovery Partition

Disk Partitioning with Recovery Partition

Before getting to what changes when you delete it, it is worth being precise about what the partition is, what actually lives inside it, and why it keeps causing trouble on machines that are otherwise perfectly healthy.

What the Recovery Partition Really Is

The partition holds a single file — Winre.wim, the Windows Recovery Environment image — plus a small directory structure under \Recovery\WindowsRE. WinRE is a stripped Windows Preinstallation Environment build: a boot image with a handful of tools, a command prompt, and a small GUI. It boots from its own entry in the Boot Configuration Data store rather than from your installed copy of Windows, which is exactly why it works when Windows will not start.

On a UEFI system built by an OEM or a clean install, the order of partitions on the disk is normally:

  • EFI System Partition — 100 MB (260 MB on some OEM builds), FAT32, holds the boot manager and BCD store.
  • Microsoft Reserved (MSR) — 16 MB of unformatted reserved space.
  • Windows (C:) — the OS volume.
  • Recovery — typically 500 MB–1 GB, no drive letter, hidden.

Two details are worth remembering, because they explain almost every problem described later in this post. First, the recovery partition has a specific GPT type, de94bba4-06d1-4d40-a16a-bfd50179d6ac, and carries the attribute 0x8000000000000001 — “platform required, no drive letter”. Windows treats a partition carrying that attribute as unmovable plumbing, not as free space. Second, WinRE is registered with the OS through a small service, reagentc.exe, which keeps a BCD entry and a pointer to the image location in C:\Windows\System32\Recovery\ReAgent.xml.

Check the current state of all of that with:

reagentc /info

A healthy machine reports something like this:

Windows Recovery Environment (Windows RE) and system reset configuration
Information:

    Windows RE status:         Enabled
    Windows RE location:       \\?\GLOBALROOT\device\harddisk0\partition4\Recovery\WindowsRE
    Boot Configuration Data (BCD) identifier: 8b2c1f4a-...
    Recovery image location:
    Recovery image index:      0
    Custom image location:
    Custom image index:        0

REAGENTC.EXE: Operation Successful.

If the status says Disabled and the location is blank, Windows cannot find its recovery environment, and every troubleshooting feature that depends on it disappears from the menu — which is the whole subject of this post.

What WinRE Actually Gives You

With the Recovery Partition in place you have access to troubleshooting options like:

  • Reset this PC

Windows troubleshooting options available with the Recovery Partition present

Troubleshooting options with the Recovery Partition

You also have access to advanced troubleshooting options like:

  • Startup Repair
  • Uninstall Updates
  • Startup Settings
  • UEFI Firmware Settings
  • Command Prompt
  • System Restore
  • System Image Recovery

Advanced Troubleshooting options with the Recovery Partition

Advanced Troubleshooting options with the Recovery Partition

More Advanced Troubleshooting options with the Recovery Partition

More Advanced Troubleshooting options with the Recovery Partition

These are not cosmetic. Startup Repair is the one that fixes a corrupt boot configuration without you having to rebuild the BCD by hand. Uninstall Updates is the fastest recovery from a bad cumulative update that leaves the machine in a boot loop — and it is a GUI front end for what would otherwise be a DISM and a package-removal dance from a command prompt. Command Prompt is the escape hatch for everything else: bootrec, chkdsk, diskpart, sfc, dism, and bcdedit all work from it. System Image Recovery restores a full disk image, and Reset this PC is the standard “wipe and reload while keeping files” path for handing a machine to a new user.

Note that UEFI Firmware Settings is the odd one out on that list: it is just a reboot into the firmware setup screens, supplied by the firmware and the Windows Boot Manager rather than by WinRE. That is why it survives when the partition is gone.

What Happens When You Delete the Partition

Once I deleted my Recovery Partition I had a lot less troubleshooting options.

The only options you get are:

  • Startup Settings
  • UEFI Firmware Settings

Troubleshooting options without the Recovery Partition

Troubleshooting options without the Recovery Partition

It’s interesting to see how many options rely directly on the Windows Recovery Partition. I didn’t see any impact to the system after deleting the Recovery Partition other than significantly fewer recovery options.

That last sentence is the important one, and it is worth spelling out why the system kept working. Deleting the partition does not touch the OS volume, the boot manager on the EFI System Partition, or the BCD entries for the installed operating system. Windows boots exactly as it did before. What you have actually removed is the toolbox you reach for on the day the machine does not boot, and Windows is honest about it: reagentc /info now reports Disabled, and the WinRE boot entry is gone. Features that quietly depend on it — Reset this PC, Startup Repair, System Image Recovery, and automatic startup repair after a failed boot — now either grey out, fail with “Could not find the recovery environment”, or simply do not appear.

Two consequences are easy to miss:

  • BitLocker. If the OS volume is encrypted, avoid repartitioning a protected machine without suspending protection first. manage-bde -protectors -disable C: -rebootcount 1 suspends it for one reboot; without that, a partition table change is a classic trigger for the BitLocker recovery key prompt.
  • Windows Update servicing. Recent cumulative updates include a “Safe OS” update that patches Winre.wim itself. If the recovery environment is missing or unreachable, that part of servicing fails, and the failure can surface later as an update that never quite finishes.

The Other Reason the Partition Causes Trouble: It Is Too Small

There is a second failure mode that has nothing to do with deleting anything. Windows 10, version 2004 changed the minimum requirement for the recovery partition, and machines installed before that change — or OEM images with a 450–500 MB partition — started failing cumulative updates with a message about the Windows RE partition being too small. The update needs room to stage a replacement Winre.wim, and a partition that is nearly full cannot hold both.

Check the free space before you are surprised by it:

diskpart
  list disk
  select disk 0
  list partition
  select partition 4
  detail partition
  exit

detail partition prints the type GUID and attributes, so you can confirm which partition is the recovery one rather than guessing from the size. To see it from PowerShell instead:

Get-Partition -DiskNumber 0 | Select-Object PartitionNumber, DriveLetter, Size, GptType
Get-Volume

Microsoft’s guidance for current builds is a partition of at least 250 MB free, and most administrators now simply allocate 500 MB to 1 GB so the problem does not come back in eighteen months. If yours is 100 MB, that is the “Windows RE partition too small” error waiting to happen.

How to Get It Back

Deleting the partition is reversible without reinstalling Windows, but the steps depend on what state you are in. The clean path, in order of preference:

  1. If Winre.wim still exists in C:\Windows\System32\Recovery, you can point Windows at it directly:
    reagentc /disable
    reagentc /setreimage /path C:\Windows\System32\Recovery\Winre.wim
    reagentc /enable
    reagentc /info
  2. If the file is gone, extract Winre.wim from a matching Windows installation media image. Mount the install.wim or install.esd from the ISO and copy \Windows\System32\Recovery\Winre.wim out of the index for the edition you are running, then run the commands above.
  3. Create a replacement partition if you want the environment stored off the OS volume the way Microsoft intends, which is the arrangement that survives a wipe of C:. Copying the image to a new partition and re-enabling only works smoothly when that partition sits at the end of the disk; Windows will not automatically resize a recovery partition that is not the last one on the disk. The full walk-through of moving and rebuilding it is in Moving Windows Recovery Partition Correctly.
  4. Do nothing and use installation media instead. A Windows installation USB boots the same WinRE toolset — Startup Repair, Command Prompt, System Restore — via Repair your computer. It is a perfectly valid strategy for a lab bench, and it is what I would do on a machine whose recovery partition I deliberately removed. In production, though, it means needing a USB stick on hand at the worst possible moment.

The reagentc Commands Worth Memorising

reagentc /info                        # status, location and BCD identifier
reagentc /disable                     # move Winre.wim off the recovery partition into C:\Windows\System32\Recovery
reagentc /enable                      # register the image and create the recovery boot entry
reagentc /setreimage /path    # point Windows RE at a specific Winre.wim
reagentc /boottore                    # reboot straight into Windows RE on the next start

reagentc /disable is not destructive — it copies the image back onto the OS volume so you can work on the partition, which is why it is the first step in every repartitioning procedure. reagentc /boottore is the one to remember when a machine is in a boot loop and you cannot wait for the “failed to start” automatic repair to appear on its own.

So Should You Delete It?

No, and the case for keeping it is stronger now than when the original experiment was done. The modern recovery partition is roughly 500 MB on a disk that starts at 512 GB, it costs no performance, and it is the only thing standing between you and a boot loop fixed from the console instead of from a factory reset. If you are short of space, shrink the OS volume and extend the recovery partition rather than removing it. If you have just inherited a fleet of machines where somebody deleted it, the fix is reagentc /setreimage plus a copied Winre.wim, not a reinstall.

You can read Microsoft's own technical reference for the Windows Recovery Environment here: https://docs.microsoft.com/en-us/windows-hardware/manufacture/desktop/windows-recovery-environment–windows-re–technical-reference

If you are rebuilding machines anyway, two related posts are worth reading next: dealing with end-of-support builds in Enable Windows 10 Extended Security Updates, and checking activation when a machine is restored from an image in slmgr.vbs.