Fix it now
The optional feature, RSAT tool or language pack could not get its payload. 0x800F0954 is the servicing stack saying the update servers it was told to use hold no optional content. Start by establishing which build you are on, because the correct answer changed with Windows 11 version 22H2.
winver
Get-WindowsCapability -Online -Name "<capability-name>"
DISM /Online /Get-Capabilities /Format:Table
- On Windows 11 version 22H2 or later with a managed update server, the content should already be available from that server through on-premises UUP. Check the server is synchronising it before changing any policy.
- On Windows 10 version 2004 through Windows 11 version 21H2, the usual cause is a policy conflict. Set Computer Configuration, Administrative Templates, System, Specify settings for optional component installation and component repair to Windows Update, and then either point feature and quality updates at Windows Update too, or stop specifying update sources by class at all.
- Run
gpupdate /force, then retry from Settings, System, Optional features, using View features. - Where the machine has no route out, install from media that matches its version:
DISM /Online /Add-Capability /CapabilityName:<name> /Source:<path> /LimitAccess. - For .NET Framework 3.5 the payload is on ordinary installation media:
Dism /online /enable-feature /featurename:NetFx3 /All /Source:D:\sources\sxs /LimitAccess.
Two options were removed from that policy in Windows 11 version 24H2, including the one that used to bypass a managed server. If you cannot find it, that is why, and on those builds you do not need it.
If the feature installs you can stop here. If not, the next section explains where the payload is supposed to come from and how the rules changed.
Why it happens
Features on Demand are packages Windows deliberately does not ship inside the image. RSAT, language and handwriting resources, .NET Framework 3.5 and a long list of smaller capabilities sit outside the component store until somebody asks for one, at which point servicing must fetch the payload before it can enable anything. Every code here is that fetch failing.
Microsoft documents where servicing looks, in order: the location given by /Source, then the locations set by Group Policy, then Windows Update for an online image unless access has been limited. When all three fail, Add-WindowsCapability fails silently and throws no exception, which is why the command often just stops rather than telling you anything.
The rule for managed machines has changed, and most guidance has not caught up. It used to be true that a managed update server could not serve this content, and a policy option existed to send optional content to Windows Update while patching stayed on the server. From Windows 11 version 22H2, on-premises Unified Update Platform updates made Features on Demand and language packs available from the update server again, so those clients do not need the policy. In version 24H2 the two options that configured it were removed.
On the builds in between, Windows 10 version 2004 through Windows 11 version 21H2, there is a specific documented conflict worth knowing. Clients cannot download this content when the optional component policy is set to Windows Update while the policy that specifies a source service for particular classes of update points feature or quality updates at the managed server. The two settings disagree, and optional content is what loses.
A policy conflict on an older build
You have this one if 0x800F0950 or 0x800F0954 on Windows 10 version 2004 through Windows 11 version 21H2, with a managed update server and ordinary patching working normally.
- Set Specify settings for optional component installation and component repair to Windows Update.
- Then either change the source selection for feature and quality updates to Windows Update as well, or stop configuring source selections by class so every class comes from the managed server.
- Run
gpupdate /forceand confirm the setting arrived withgpresult /h report.html. - Retry the capability install.
Those are Microsoft’s own two resolutions for this conflict. Setting the optional component policy on its own is what fails, and it is what most older guidance tells you to do.
The build is current and the server is not synchronising the content
You have this one if Windows 11 version 22H2 or later, pointed at a managed server, with the policy irrelevant.
- Confirm the update server is set up for on-premises UUP and is synchronising optional content.
- Check the server’s disk space, since content synchronisation stops long before metadata does.
- If the server genuinely cannot serve it, use matching media with an explicit source rather than hunting for a removed policy option.
Policy forbids reaching Windows Update and no source is given
You have this one if 0x800F0907, which Microsoft attributes to exactly this combination.
- Check the optional component policy. If it is set never to attempt a download from Windows Update, and no alternate source path is configured, this code is the expected outcome.
- Either supply an alternate source path in that policy, or give the command an explicit
/Source. - Confirm the account running the install can read the source location and the files in it.
The media does not match the build
You have this one if The command is correct, the path is right, and it still fails. winver shows a newer version than the media.
- Run
winverand note the version and build. - Use the media published for that version: the Windows 11 Languages and Optional Features ISO, or the Features on Demand ISO for Windows 10 version 2004 and later.
- Keep one copy per Windows version on an internal share, named by version, so nobody has to guess.
- Retry with the matching source.
Microsoft states the requirement plainly: use the ISO that matches your Windows image version. Media from an earlier feature update does not carry the current packages.
Full reference
Where servicing looks, in order
- The location given by
/Source, if one was given. - The locations configured by the optional component and component repair policy.
- Windows Update, for an online image, unless
/LimitAccesswas specified. - Nothing.
Add-WindowsCapabilityfails silently at this point and throws no exception.
That last step explains a great deal of the confusion around these codes. A command can appear to do nothing at all, and the absence of an error is not evidence that anything worked.
The policy, and what happened to it
| Build | What applies |
|---|---|
| Windows 11 version 22H2 and later | Optional content is available from the managed server through on-premises UUP. The policy is not needed for this |
| Windows 11 version 24H2 and later | Two options were removed from the policy, including the one that bypassed the managed server |
| Windows 10 version 2004 to Windows 11 version 21H2 | The policy is needed, and it conflicts with per-class update source selection. Resolve the conflict rather than setting it alone |
The policy itself is at Computer Configuration, Administrative Templates, System, Specify settings for optional component installation and component repair, and it is delivered by Servicing.admx. Its settings are written under HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Servicing. When it is enabled you supply one or more fully qualified alternate source paths, separated by semicolons; a path may be a folder, or a WIM file written as wim:\\server\share\install.wim:3 with the image index on the end. Disabled or not configured means the files come from Windows Update where policy allows it.
UseWUServer is read only from HKLM\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU. There is no AU subkey under the non-policy CurrentVersion\WindowsUpdate branch, so creating the value there writes something the update agent never reads. If you use the single-machine workaround of setting it to 0, installing the feature and setting it back to 1, use the policy path, export the key first, and put it back.
Commands for checking and installing capabilities
| Command | What it does |
|---|---|
Get-WindowsCapability -Online |
Lists every capability and its state |
Get-WindowsCapability -Online -Name "<name>" |
The state of one capability, which is how you confirm success |
Add-WindowsCapability -Online -Name "<name>" |
Installs using whatever source resolution finds |
Add-WindowsCapability -Online -Name "<name>" -Source <path> -LimitAccess |
Installs from your own source without falling back to Windows Update |
DISM /Online /Get-Capabilities /Format:Table |
The same listing from DISM, easier to read |
DISM /Online /Add-Capability /CapabilityName:<name> /Source:<path> /LimitAccess |
The DISM equivalent of the install |
winver |
The exact version and build the media has to match |
Which media carries what
| What you are installing | Where the payload lives |
|---|---|
| RSAT administration tools | Features on Demand, from Windows Update, the managed server on current builds, or the FoD media |
| A display language or language resource | The Languages and Optional Features media, or Windows Update |
.NET Framework 3.5 |
The sources\sxs folder on ordinary Windows installation media |
The Features on Demand and Languages and Optional Features images are not on the public download page. Microsoft lists three channels for them: the Volume Licensing Service Center, which needs volume licensing access; the OEM Portal, which needs OEM access; and MSDN Download, which needs a subscription. That is the only part of this article where a commercial arrangement is genuinely the gate.
When it still fails
- Confirm the capability name exactly. They carry version suffixes and a near-miss produces a silent failure rather than a complaint.
- Check the account has read access to the source path and to the files inside it, not just to the share.
- Check whether the connection is metered, which suppresses optional downloads.
- Compare a working machine with a failing one. The difference is nearly always which organisational unit they sit in and therefore which update policy applies.
- Remember that configuring a Features on Demand installation source does not involve the managed update server at all. They are separate mechanisms and treating them as one is what produces most of the confusion here.
When a licence is the actual fix
On Windows 11 version 22H2 and later this costs nothing: the content is available from a managed update server through on-premises UUP, and the fix is a synchronisation check rather than a purchase. On older builds it is a policy conflict, which is also free to resolve. The only case where a licence is genuinely the gate is an isolated network that cannot reach Windows Update at all, where the answer is the Features on Demand or Languages and Optional Features media, and Microsoft distributes that through volume licensing, OEM or subscription channels rather than publicly. Arco supplies Windows 11 Enterprise licences and will check which of your existing agreements already grants that download access before quoting for anything.
Every code this article covers
| Code | What it points at | Source |
|---|---|---|
0x800F0950 |
Seen when a capability install fails while acquiring its payload. Microsoft names the code only in its Add-Capability failure list, annotated as a COM exception, and publishes no meaning for it | not published by the vendor |
0x800F0954 |
CBS_E_NO_OPTIONAL_CONTENT_FOUND_ON_UPDATE_SERVERS: the update servers the client was told to use hold no optional content | Microsoft Learn |
0x800F0907 |
An alternative installation source was not specified or is invalid, and the optional component policy is set never to attempt to download payload from Windows Update | Microsoft Learn |
Confirm the fix worked
Get-WindowsCapability -Online -Name "<name>"reports the state as Installed.- Settings, System, Optional features lists the feature as installed rather than pending.
- For a language resource, it can be selected as the display language.
- An ordinary update scan still succeeds against the update server you intended, so nothing about patching was disturbed.
Questions people ask about this
I cannot find the option to download optional features directly from Windows Update.
On Windows 11 version 24H2 and later it is not there. That option and the one that never attempts a download were removed from the policy, because from version 22H2 onwards the content is available from a managed update server through on-premises UUP. If you are on a current build, you do not need the option you are looking for.
Do I need Windows 11 Enterprise just to install RSAT?
No. RSAT installs on Pro, and on a machine that can reach Windows Update or a properly synchronising update server it installs with no licensing change at all. Enterprise only enters the picture because volume licensing is one of the channels through which the offline media is distributed, and that matters only on networks with no route out.
Why did my command fail without an error?
Because that is documented behaviour. When the specified source, the policy locations and Windows Update all fail to provide the files, Add-WindowsCapability fails silently and throws no exception. Check the capability’s state afterwards rather than trusting the absence of a complaint.
Can I use last year’s Features on Demand media?
No. Microsoft’s requirement is that the ISO matches the Windows image version, and media from an earlier feature update does not contain the current packages. Keep one copy per version on an internal share and name the folders by version, because this is the single most common reason a correct-looking command fails.
