Skip to content

Est. 2011·Microsoft Partner 7033487·Delivery under 3 min·Support 7 days a week

Your vault is empty.

License Error 0xC1900101 - 0x20004

0xC1900101 – 0x20004 and 0x8007042B: drivers and killed processes roll the upgrade back

11 min read Updated October 4, 2026 Windows Update & Setup

Fix it now

0xC1900101 – 0x20004 is a SAFE_OS failure during the INSTALL_RECOVERY_ENVIRONMENT operation, and Microsoft’s published cause is out-of-date drivers. 0x8007042B is Win32 error 1067, ERROR_PROCESS_ABORTED – a process terminated unexpectedly. Both point at software with a kernel driver rather than at a broken Windows installation.

Run these in an elevated Command Prompt after the rollback

SetupDiag.exe /Output:C:\SetupDiag\Results.log
fltmc filters
reagentc /info
  1. Work through Microsoft’s published mitigation for 0x20004 in order: uninstall antivirus applications, remove all unused SATA devices, remove all unused devices and drivers, and update drivers and BIOS.
  2. Uninstall rather than disable. Read the fltmc filters output and confirm any third-party file system filter driver has actually gone, using the vendor’s own removal tool if the ordinary uninstall leaves it behind.
  3. Read the reagentc /info output. Windows RE reported as Disabled, or an empty location line, explains why the operation that installs the recovery environment cannot complete.
  4. If it is disabled or unregistered, run reagentc /disable then reagentc /enable, and confirm with reagentc /info that it reports enabled with a location.
  5. Suspend BitLocker with manage-bde -protectors -disable C: -rebootcount 3, disconnect everything except mouse, keyboard and display, and restart.
  6. Run the upgrade from mounted media so you can control it and read the logs: setup.exe /auto upgrade /dynamicupdate disable.

Take the recovery key off the machine before you touch BitLocker, and do not resize or recreate partitions mid-upgrade.

If the upgrade completes, you are finished. If it rolls back again, the next section explains what SAFE_OS is doing at that point and what kills a setup process.

Why it happens

Before an upgrade can boot the new build it runs a phase in a temporary offline environment. Microsoft calls it SAFE_OS, and the extend code 0x20004 is phase 2 with operation 0x04, INSTALL_RECOVERY_ENVIRONMENT: setup is servicing the recovery environment for the new installation. Microsoft’s published cause for that failure is out-of-date drivers, and the published mitigation is a list – uninstall antivirus applications, remove all unused SATA devices, remove all unused devices and drivers, update drivers and BIOS.

That list is more interesting than it first looks. Every item on it removes something from the driver set that the offline phase has to load. An antivirus product with a filter driver, a SATA channel with nothing attached to it, an obsolete driver package still registered in the store: each of them is a thing setup has to deal with in an environment that has none of the recovery paths a running Windows has.

0x8007042B is a different statement. Its low word is 1067, and the published Win32 text is ‘The process terminated unexpectedly.’ Nothing checked and failed – something was killed. Microsoft documents the pairing 0x8007042B – 0x4000D as a failure during the second boot phase attempting MIGRATE_DATA, caused by file system, application or driver issues, and the published mitigation is to read the logs to find the file, application or driver that could not be migrated, then disconnect, update, remove or replace it. Note the phase: the second boot phase, not SAFE_OS. The two codes on this page do not describe the same moment.

0xC1900106 and 0xC1900104 fill in the rest of the picture and both have published names. 0xC1900106 is MOSETUP_E_TERMINATE_PROCESS, ‘The installation process was terminated.’ 0xC1900104 is MOSETUP_E_PROCESS_TIMEOUT, ‘The installation process did not complete within the required time limit.’ Between them they distinguish a run that was stopped from a run that ran out of time – which is a genuinely useful distinction when you are deciding whether to blame an agent or a slow disk.

An endpoint or encryption agent kills the setup worker

You have this one if 0x8007042B or 0xC1900106 accompanies the rollback, and the machine runs an endpoint agent, disk encryption product or backup client with a kernel driver.

  1. List the loaded filter drivers with fltmc filters; anything not from Microsoft is a candidate.
  2. Uninstall the agent with the vendor’s own removal tool. Removing it through Apps and Features often leaves the driver in place.
  3. Restart and confirm with fltmc filters that the driver is gone rather than stopped.
  4. Run the upgrade, then reinstall the agent on a build the vendor supports for the new Windows version.

Out-of-date drivers in the SAFE_OS phase

You have this one if 0xC1900101 – 0x20004 specifically, with no obvious agent involved.

  1. Work Microsoft’s list: uninstall antivirus applications, remove unused SATA devices, remove unused devices and drivers, update drivers and BIOS.
  2. Get storage and chipset drivers from the machine manufacturer rather than from a driver utility.
  3. Remove obsolete packages from the driver store: pnputil /enum-drivers, then pnputil /delete-driver oemNN.inf /uninstall for the ones that no longer belong to hardware you have.
  4. Retry with peripherals disconnected.

The recovery environment is unavailable to service

You have this one if reagentc /info reports Windows RE status Disabled, or the Windows RE location line is empty.

  1. Run reagentc /disable, then reagentc /enable, then reagentc /info to confirm the state changed.
  2. If enable fails, check whether Winre.wim exists under C:\Windows\System32\Recovery or in the recovery partition.
  3. Where the image exists but is not registered, point the service at it with reagentc /setreimage /path <path to the WindowsRE folder>.
  4. Retry once reagentc /info reports it enabled with a location.

Leaving Windows RE disabled during the upgrade is a legitimate tactic when a small or badly placed recovery partition cannot be serviced – setup creates its own. Re-enable it afterwards and confirm with reagentc /info.

An attached device drags its driver into the offline phase

You have this one if The upgrade rolls back reliably with a dock, external disk or card reader attached, and completes with them removed.

  1. Shut down, disconnect everything except mouse, keyboard and display, and start again.
  2. Run the upgrade with /dynamicupdate disable so Windows Update does not fetch a fresh copy of the same problem driver mid-run.
  3. Reconnect devices one at a time afterwards.

Setup’s own sources are damaged, or it simply runs out of time

You have this one if 0xC1900104, or DISM /ScanHealth reporting the store is repairable.

  1. Run DISM.exe /Online /Cleanup-image /Restorehealth, or point it at media with /Source:wim:D:\sources\install.wim:1 /LimitAccess where there is no update path.
  2. Run sfc /scannow afterwards and confirm it completes without unrepairable files.
  3. For a timeout, check whether the disk is healthy and whether an agent is scanning every file setup touches; both make an upgrade slow enough to exceed its own limits.

Full reference

What each code is, precisely

Code Published meaning
0xC1900101 - 0x20004 SAFE_OS / INSTALL_RECOVERY_ENVIRONMENT failure, caused by out-of-date drivers
0x8007042B Win32 1067, ERROR_PROCESS_ABORTED: the process terminated unexpectedly
0xC1900106 MOSETUP_E_TERMINATE_PROCESS: the installation process was terminated
0xC1900104 MOSETUP_E_PROCESS_TIMEOUT: the installation process did not complete within the required time limit

Commands worth having open

Command What it does
reagentc /info Reports whether Windows RE is enabled and where its image lives
reagentc /disable / reagentc /enable Unregisters and re-registers the recovery environment
reagentc /setreimage /path <folder> Points the service at a Windows RE boot image
fltmc filters Lists loaded file system filter drivers
pnputil /enum-drivers Lists third-party driver packages in the driver store
setup.exe /auto upgrade /dynamicupdate disable Runs the upgrade from media without fetching updates or drivers mid-run
SetupDiag.exe /Output:<file> Parses the setup logs and names a recognised failure

Where to read what actually happened

After a rollback the logs move to %windir%\Panther; during a run they are under %SystemDrive%\$Windows.~BT\Sources\Panther. setuperr.log holds the errors and setupact.log the full sequence. The rollback folder, $Windows.~BT\Sources\Rollback, is where a setupmem.dmp appears if setup crashed rather than stopping, and a dump names a module far more reliably than any of the setup logs do.

On the recovery partition

A recovery partition of a few hundred megabytes, or one that sits before the Windows partition rather than after it, cannot be extended to hold a new build’s recovery image. That is the same layout limitation that makes recovery environment patches fail on machines imaged years ago. Disabling Windows RE for the duration lets setup build its own rather than trying to service one it cannot grow. Repartitioning a system disk is a bigger job than an upgrade and deserves a full backup and its own maintenance window.

When everything above is clean

  • Run the upgrade with /CopyLogs \\server\share\ on an unattended machine so you get the logs even from a failed run.
  • Try /MigrateDrivers None so the new build does not inherit the current driver set.
  • Check the firmware version against the manufacturer’s current release; Microsoft names updating the BIOS in its own mitigation.
  • Confirm there is real free space on the system volume, because a slow, full disk is a common reason a run hits its time limit.
  • If the failure is reproducible on several identical machines, treat it as a fleet driver problem and take it to the hardware vendor rather than repeating it.

When a licence is the actual fix

Nothing on this page is fixed by buying software, and you should work the driver and agent causes first. Two commercial questions sit at the end of the road rather than at the start. The first is a security agent that has no supported build for the Windows version you are upgrading to: the fix is a current, supported build from that vendor, which is a licensing and support question for them rather than a Windows one, and removing the agent for the duration is free and supported in the meantime because Microsoft Defender takes over. The second is the point at which you decide the in-place upgrade is not going to work and a clean installation is quicker. That needs a valid Windows 11 entitlement for the edition you are installing – a device with an existing digital licence for that edition already has one, and only an edition change requires a Windows 11 Pro upgrade licence. Neither purchase makes the rollback stop; they are decisions you reach after it does.

Every code this article covers

Code What it points at Source
0xC1900101 - 0x20004 A SAFE_OS failure during the INSTALL_RECOVERY_ENVIRONMENT operation, published as caused by out-of-date drivers Microsoft Learn
0x8007042B Win32 1067, ERROR_PROCESS_ABORTED: the process terminated unexpectedly. Documented with extend code 0x4000D as a second boot phase migration failure from file system, application or driver issues Microsoft Learn
0xC1900106 MOSETUP_E_TERMINATE_PROCESS: the installation process was terminated Microsoft Learn
0xC1900104 MOSETUP_E_PROCESS_TIMEOUT: the installation process did not complete within the required time limit Microsoft Learn

Confirm the fix worked

  1. winver reports the build number you were upgrading to.
  2. reagentc /info reports Windows RE enabled with a valid location, whether or not you disabled it during the upgrade.
  3. fltmc filters shows only the filter drivers you expect after any agents are reinstalled.
  4. manage-bde -status C: shows protection on again if you suspended BitLocker.
  5. %windir%\Panther\setuperr.log from the successful run contains no errors from the phase that previously failed.

Questions people ask about this

Is it safe to leave Windows RE disabled?

During the upgrade, yes – setup creates its own. Afterwards, no: without it the machine loses its recovery options, including the automatic repair path after two failed starts. Run reagentc /enable and confirm with reagentc /info once the upgrade is done.

Do I need to buy a new licence to get past this?

No. These are driver and process failures. An activated machine keeps its digital licence across an in-place upgrade and reactivates on its own.

Does 0x8007042B mean the SAFE_OS phase failed?

No, and that is the correction this article needed. 0x8007042B is simply a process that terminated unexpectedly, and Microsoft documents it paired with extend code 0x4000D, which is the second boot phase. Only 0xC1900101 – 0x20004 is a SAFE_OS failure.

Will removing my antivirus leave the machine exposed during the upgrade?

Microsoft Defender takes over automatically when a third-party product is uninstalled, so the machine keeps real-time protection throughout. Reinstall the product afterwards on a build the vendor supports.

Where do I find the logs that name the real cause?

%windir%\Panther\setuperr.log and setupact.log after a rollback, and $Windows.~BT\Sources\Rollback for a memory dump if setup crashed. SetupDiag reads all of them and names the failure it recognises, which is a faster start than reading them yourself.

Related error codes

Was this article helpful?

Your feedback helps us improve our documentation.

Related articles

Free Fix 0x80240034 and 0x80240438: the download fails, or an update endpoint is unreachable Free Fix 0x80070652 and 0x80240016: another installation is already in progress License Error 0xC1900130 and 0x80190001: the feature update download never finishes License Error 0x8024500C and 0x8024402A: update policy is pointing clients nowhere
← Back to Knowledge Base