Fix it now
Enabling .NET Framework 3.5 is not an ordinary feature install: the payload is not on disk after a normal Windows installation, so Windows has to fetch it. Microsoft publishes 0x800F0906 as the computer being unable to download the required files from Windows Update. Supply the files yourself and the feature enables in under a minute.
winver
Dism /online /enable-feature /featurename:NetFx3 /All /Source:D:\sources\sxs /LimitAccess
DISM /Online /Get-FeatureInfo /FeatureName:NetFx3
- Run
winverfirst and note the version and build. The source must match the version, edition family and language of the running system, and this is where most second attempts fail. - Mount the ISO, note its drive letter, and point
/Sourceat thesources\sxsfolder on it. - Check the sxs folder is readable by the account running DISM. If the source was copied from elsewhere it may have arrived without Read access, which produces 0x800F081F.
- Confirm the result with the last command: the feature state should read Enabled.
The PowerShell equivalent is Enable-WindowsOptionalFeature -Online -FeatureName NetFx3 -All -LimitAccess -Source D:\sources\sxs, which takes the same source and the same restriction.
If the feature reports as enabled you are done. If it still fails, the next section explains which of the three codes you have and what each one is telling you.
Why it happens
Optional components such as .NET Framework 3.5 are delivered on demand. The manifests describing them are present on every installation but the payload is not, which keeps the installed footprint smaller. When you tick the box in Windows Features, Windows looks for the payload: first in any source you specified, then from Windows Update. If neither can supply it, the operation stops.
On a domain-joined machine, update traffic is usually pointed at an internal update server. Those servers distribute updates, not feature payload, so the request arrives somewhere that cannot answer it. Microsoft’s remedy is a policy setting written for exactly this case, and knowing its name saves an argument with whoever owns Group Policy: Specify settings for optional component installation and component repair.
The three codes are more specific than they are usually treated. 0x800F0906 is the computer being unable to download the required files from Windows Update. 0x800F0907 means an alternative source is missing or invalid AND that policy is set to Never attempt to download payload from Windows Update – so it names the setting that is blocking you. 0x800F081F means an alternative source was supplied but the location does not contain the required files, the user does not have Read access to it, or the files there are corrupted, incomplete or invalid.
That distinction is the whole article. 0x800F0907 is a policy problem and no amount of pointing at media fixes it if the source you gave is also wrong. 0x800F081F is a source problem and the READ ACCESS clause in Microsoft’s wording is the part people skip, because a copied sxs folder frequently arrives without it.
Update traffic is redirected to an internal server
You have this one if The machine is domain-joined, ordinary updates install normally, and only feature payload fails.
- Supply the payload locally with
/Sourceand/LimitAccess. This is the least disruptive option and needs no policy change. - Alternatively, enable Specify settings for optional component installation and component repair, and select Contact Windows Update directly to download repair content instead of Windows Server Update Services (WSUS).
- Apply the policy, run
gpupdate /force, then retry without/LimitAccess.
That policy is normally scoped to a group of machines rather than the whole estate. Ask whoever owns it rather than editing it locally on a managed device.
The policy is set to never download the payload
You have this one if 0x800F0907 specifically.
- Read the policy on the machine: Specify settings for optional component installation and component repair, under Computer Configuration, Administrative Templates, System.
- If it is set to Never attempt to download payload from Windows Update, an alternate source has to be supplied – either in the policy’s Alternate source file path or on the DISM command line.
- Supply a matching sxs folder and retry.
The source does not match, or cannot be read
You have this one if 0x800F081F: a local source is supplied and the operation still fails.
- Run
winverand obtain media for that same version, edition family and language. - Point
/Sourceat thesources\sxsfolder on that media, and check the path is exactly right. - Check the folder’s permissions. Microsoft names lack of Read access as one of the three causes of this code, and a copied folder often loses it.
- Retry the enable command.
The component store itself is damaged
You have this one if Other servicing operations also fail, or sfc /scannow reports violations it cannot repair.
- Check the store:
DISM /Online /Cleanup-Image /ScanHealth. - Repair it:
DISM /Online /Cleanup-Image /RestoreHealth, supplying a matching source if the machine cannot reach Windows Update. - Run
sfc /scannowafterwards. - Retry the feature installation once the store reports healthy.
Full reference
What each code is published as
| Code | Published cause |
|---|---|
| 0x800F0906 | The computer cannot download the required files from Windows Update. |
| 0x800F0907 | An alternative installation source is not specified or is invalid, and the Specify settings for optional component installation and component repair policy is set to Never attempt to download payload from Windows Update. |
| 0x800F081F | An alternative source is specified and one of the following is true: the location does not contain the required files, the user does not have Read access to it, or the installation files are corrupted, incomplete or invalid. |
The policy, by its real name
The setting is Specify settings for optional component installation and component repair, under Computer Configuration, Administrative Templates, System. It offers the three things that matter here: an Alternate source file path, an option to contact Windows Update directly for repair content instead of Windows Server Update Services, and the Never attempt to download payload from Windows Update option that 0x800F0907 is reporting. Naming it precisely is worth doing, because a request to “let the machine reach Windows Update” is usually refused and a request to enable this specific setting for a specific group usually is not.
Enabling the feature from a source
winver
Dism /online /enable-feature /featurename:NetFx3 /All /Source:D:\sources\sxs /LimitAccess
Enable-WindowsOptionalFeature -Online -FeatureName NetFx3 -All -LimitAccess -Source D:\sources\sxs
DISM /Online /Get-FeatureInfo /FeatureName:NetFx3
/LimitAccess stops Windows contacting Windows Update at all, which is what you want when a source is supplied and when the machine is isolated. Leave it off if you want Windows Update used as a fallback. On Windows Server, the Add Roles and Features wizard offers an alternate source path on its confirmation page, pointing at the same sxs folder.
Why the source has to match
| Must match | Why |
|---|---|
| Windows version and build | The manifests on the machine describe files that only exist in matching media |
| Edition family | Client media does not satisfy a server installation, or the reverse |
| Language | A localised payload is not interchangeable with another language |
| Read access on the folder | Microsoft names it explicitly as a cause of 0x800F081F |
Where to look when it still fails
| Log or command | What it gives you |
|---|---|
C:\Windows\Logs\DISM\dism.log |
The DISM operation’s own record, including the source it tried |
C:\Windows\Logs\CBS\CBS.log |
The servicing stack’s detailed log, where the real failure is recorded |
winver |
The exact Windows version and build the source must match |
DISM /Online /Get-Features |
Every optional feature and its current state |
gpresult /h report.html |
Whether an update or optional-component policy is applying |
One more code is worth recognising here. 0x800F0922 is documented alongside these three and Microsoft attributes it to processing advanced installers and generic commands failing, with Read and Execute permissions on the sxs folder as the first thing to check. If that is what you have, the permissions on the source really are the answer rather than a guess.
Every code this article covers
| Code | What it points at | Source |
|---|---|---|
0x800F0906 |
The computer cannot download the required files from Windows Update | Microsoft Learn |
0x800F0907 |
No valid alternative source is specified and policy is set to never download the payload from Windows Update | Microsoft Learn |
0x800F081F |
An alternative source was specified but it lacks the files, cannot be read by the account, or contains corrupted or incomplete files | Microsoft Learn |
Confirm the fix worked
- Run
DISM /Online /Get-FeatureInfo /FeatureName:NetFx3and confirm the state is Enabled. - Open Windows Features and confirm the .NET Framework 3.5 entry is ticked.
- Launch the application that required it and confirm it starts.
- Reboot and confirm the feature is still reported as enabled.
- If you changed a policy, run
gpupdate /forceon a second machine in the same scope and confirm the feature enables there without a local source.
Questions people ask about this
Does enabling .NET 3.5 cost anything?
No. It is an optional component of the Windows licence you already hold, and enabling it changes nothing about your activation state or entitlement. All you need is a source for the files.
What is the difference between 0x800F0907 and 0x800F081F?
0x800F0907 means no valid alternative source was given and policy forbids downloading the payload – so the policy is what is blocking you. 0x800F081F means a source was given but it does not contain the files, cannot be read by the account, or is damaged. One is a policy problem and the other is a source problem.
Can I use media from a different Windows build?
No, and this is the most common wasted hour. The payload must match the installed version, edition family and language. Media from another feature update is rejected.
Is it safe to use an sxs folder someone published online?
Take payload only from Microsoft media or your own licensing source. These files are written into the component store of the operating system, which is not a place to accept unknown binaries.
Do I need .NET 3.5 at all?
Only if an application requires it. Many older line-of-business applications do and will not start without it. If nothing on the machine asks for it, leave it disabled.
