Fix it now
0xC0000001 is STATUS_UNSUCCESSFUL – the requested operation was unsuccessful. It is the most generic status Windows has and it names nothing. The useful information is the bug check the automatic restart is hiding. Stop the loop, read the real stop code, and start work from that.
bcdedit /set {default} recoveryenabled Off
bcdedit /set {default} bootstatuspolicy IgnoreAllFailures
bcdedit /enum
- Boot from Windows Server installation media and choose Repair your computer, Troubleshoot, Command Prompt.
- Run the commands above, restart, and write down the exact stop code and parameters now shown. That is the fault; 0xC0000001 was only the wrapper.
- If the code is 0x00000032 or 0x0000006F, read parameter 1. On both, it is an NT status code that says why initialisation failed, and it is the only thing on the screen that identifies anything.
- Confirm the boot entries are sane in the
bcdedit /enumoutput:deviceandosdevicemust name the partition that actually holds Windows. - Check the file system with
chkdsk X: /f, using the letter the recovery environment assigned rather than assuming C.
Put the recovery behaviour back when you are finished: bcdedit /set {default} recoveryenabled On and bcdedit /set {default} bootstatuspolicy DisplayAllFailures.
If the exposed stop code has a clear owner – a driver, a hive, a volume – you now have an article to read about that. If not, the next section maps each companion code to the point in startup it belongs to.
Why it happens
Windows starts in stages. The boot manager hands over to the boot loader, which loads the kernel and the boot-start drivers. The kernel then runs its initialisation phases, bringing up memory management, the object manager, the registry and the rest of the executive. Only then does the session manager start, create session 0 for services and session 1 for the console, and hand over to the logon process.
0xC0000001 is published as STATUS_UNSUCCESSFUL, with the text that the requested operation was unsuccessful. That is all it says. Two servers showing this code can have entirely unrelated faults, and searching for it produces advice for every one of them at once. The first job is therefore not to fix anything; it is to make the machine show you what actually failed.
The companion codes are more specific, but less specific than they are usually made out to be. 0x00000032, PHASE1_INITIALIZATION_FAILED, means system initialisation failed, and parameter 1 is the NT status code describing why. 0x0000006F, SESSION3_INITIALIZATION_FAILED, is published as the initialisation of the Windows operating system failing, again with an NT status in parameter 1 – not, as it is often described, the session manager failing to start a particular subsystem. 0x00000033, UNEXPECTED_INITIALIZATION_CALL, has a name and nothing else: Microsoft publishes no description, cause or resolution for it and notes that it appears very infrequently.
On servers the component that changed is rarely a consumer-style driver. It is a storage controller driver, a firmware update that changed the controller mode, an agent that installs a boot-start filter, a hive damaged by an unclean shutdown, or a guest moved to a host whose storage stack does not match. Work through what changed rather than through everything that could theoretically be wrong.
The boot configuration points at the wrong volume
You have this one if bcdedit /enum shows a device or osdevice of unknown, or a partition with no Windows folder. Common after a restore, a clone, a disk replacement or a firmware change.
- Identify the EFI system partition:
diskpart, thenlist disk,sel disk 0,list volume. It is the small FAT32 one. - Give it a letter:
sel volume <n>,assign letter=S,exit. - Rewrite the boot files:
bcdboot C:\Windows /s S: /f UEFI, using/f BIOSon a legacy installation or/f ALLif you are unsure. - Or correct the entries in place:
bcdedit /store <store> /set {<id>} device partition=X:and the same forosdevice.
On UEFI machines bootrec /fixboot often returns access denied. Use bcdboot rather than trying to force it.
A boot-start driver is failing initialisation
You have this one if The exposed code is 0x00000032 or 0x0000006F, the server starts in Safe Mode or Directory Services Restore Mode but not normally, and the first failure followed patching, an agent upgrade or a driver rollout.
- Use Uninstall Updates in the recovery environment to remove the most recent quality update.
- List what is present offline with
dism /Image:C:\ /Get-Drivers /Format:Tableand remove the third-party package withdism /Image:C:\ /Remove-Driver /Driver:oemNN.inf. - Where the driver belongs to a management agent, remove the whole agent from Safe Mode rather than pulling its driver out from under it.
- Translate parameter 1 of the bug check; it is an NT status and it usually names the class of failure precisely.
A registry hive is missing or damaged
You have this one if The failure happens before any sign-in prompt, and the exposed bug check or the boot screen refers to a file under the config folder.
- From the recovery command prompt, check the sizes and dates of SYSTEM, SOFTWARE, SAM, SECURITY and DEFAULT in
C:\Windows\System32\config. A zero-length or absent hive is your answer. - Do not count on
RegBack; from Windows 10 version 1803 onwards those files are 0 KB by default. - On a server, restore the system state from backup. It is nearly always faster and safer than hand-repairing hives.
- If you must copy a hive back by hand, copy the existing file to a new name first so the change can be undone.
Virtual hardware changed under the guest
You have this one if The server was migrated, restored to a different host, or had its virtual disk moved between controllers. Other guests on the same host start normally.
- Confirm the generation and firmware settings match what the guest was built on: a generation 2 machine expects a UEFI boot entry and a SCSI controller.
- Check whether Secure Boot or its template changed; a mismatched template stops a guest that previously started.
- If a checkpoint was applied or merged around the time of the failure, confirm the disk chain is intact and no differencing disk is orphaned.
- Where the guest moved between hosts of different processor generations, check the processor compatibility setting.
Full reference
What each code marks
| Code | Name | Published meaning | Parameter 1 |
|---|---|---|---|
0xC0000001 |
STATUS_UNSUCCESSFUL | {Operation Failed} The requested operation was unsuccessful | – |
0x00000032 |
PHASE1_INITIALIZATION_FAILED | System initialization failed | The NT status code describing why |
0x0000006F |
SESSION3_INITIALIZATION_FAILED | The initialization of the Windows operating system failed | The NT status code that caused it |
0x00000033 |
UNEXPECTED_INITIALIZATION_CALL | Name only. No description, cause or resolution is published | – |
Two of the four carry an NT status in parameter 1, and that is where the real content is. A stop screen showing 0x00000032 with a parameter of 0xC0000034 is telling you an object name was not found; the same code with 0xC000009A is telling you an allocation failed. Those are different problems with different fixes, and the bug check number alone cannot distinguish them.
Boot repair command reference
| Command | Purpose |
|---|---|
bcdedit /enum |
Shows the current boot entries and the volumes they refer to |
bcdedit /set {default} recoveryenabled Off |
Stops Windows looping into automatic repair so you can read the stop screen |
bcdedit /set {default} bootstatuspolicy IgnoreAllFailures |
Stops the boot status policy intervening as well |
bcdboot C:\Windows /s S: /f UEFI |
Recreates the boot files on the EFI system partition |
bcdedit /set {default} safeboot minimal |
Forces the next start into Safe Mode |
bcdedit /set {default} safeboot dsrepair |
Forces a domain controller into Directory Services Restore Mode |
bcdedit /deletevalue {default} safeboot |
Removes either safeboot setting once you have finished |
Repair or restore
On a server with a current system state or full backup, restoring is often the better decision and it is certainly the more predictable one. Hand-repairing a boot failure can take hours with no guarantee at the end. Repair is the better choice when the backup is old, when the fault is clearly one update or one driver, or when the machine holds a role that is awkward to restore – a domain controller in particular, where a whole-image restore has consequences a system state restore does not.
Do not copy registry hives over existing ones without keeping the originals, and do not run repair operations against a volume on a disk you already suspect. Image the disk first if the data matters and there is no current backup.
Confirming the machine is genuinely healthy afterwards
- Put the recovery behaviour back. A server left with recoveryenabled Off will sit on a stop screen rather than restarting, which is often what you want on a machine with out-of-band management – but it should be a decision, not a leftover.
- Run
Get-Service | Where-Object {$_.StartType -eq 'Automatic' -and $_.Status -ne 'Running'}and account for anything that did not start. - Watch the System log for new BugCheck entries with ID 1001 over the following day.
- On a clustered node, weigh leaving automatic restart off against how quickly you want a failed node out of the way.
- Re-apply anything you removed, one item at a time, so the server ends up in a supported state rather than a working one.
Every code this article covers
| Code | What it points at | Source |
|---|---|---|
0xC0000001 |
STATUS_UNSUCCESSFUL: {Operation Failed} The requested operation was unsuccessful. The most generic status Windows has; it identifies nothing on its own | Microsoft Learn |
0x0000006F |
SESSION3_INITIALIZATION_FAILED: the initialization of the Windows operating system failed. Parameter 1 is the NT status code that caused it | Microsoft Learn |
0x00000032 |
PHASE1_INITIALIZATION_FAILED: system initialization failed. Parameter 1 is the NT status code describing why | Microsoft Learn |
0x00000033 |
Microsoft publishes the name UNEXPECTED_INITIALIZATION_CALL and nothing else – no description, cause or resolution – and notes the bug check appears very infrequently | Microsoft Learn |
Confirm the fix worked
- The server restarts twice and reaches the sign-in screen both times without intervention.
- The recovery behaviour has been restored, or left off deliberately and recorded.
bcdedit /enumshows device and osdevice naming the volume that actually holds Windows.- No automatic-start service is stopped without a reason you know.
- No new BugCheck entries with ID 1001 appear in the System log over the following day.
Questions people ask about this
Is 0xC0000001 always the same problem?
No, and that is the point. It is published as STATUS_UNSUCCESSFUL – the requested operation was unsuccessful – and nothing more. Two servers showing it can have entirely unrelated faults. The code that appears once automatic restart is disabled is the one worth searching for.
Can I leave automatic restart disabled permanently?
On a server, yes, and many administrators do. An unattended crash then leaves the machine on a stop screen rather than looping, which is usually preferable when you have out-of-band management. On a clustered node, weigh that against how quickly you want the node out of the way.
Will reinstalling Windows Server mean buying it again?
No. The entitlement attaches to the hardware or to your agreement, not to a particular installation. Reinstalling the same edition and activating against your existing key or KMS host costs nothing extra, and fixing this error costs nothing at all.
The screen shows 0x00000032 and four hex parameters. Which one matters?
The first. Microsoft documents parameter 1 of PHASE1_INITIALIZATION_FAILED as the NT status code describing why initialisation failed, and the same is true of 0x0000006F. Translate that value and you have a real error rather than a category.
Should I restore from backup instead of repairing?
On a server with a current system state or full backup, often yes. Hand-repairing a boot failure can take hours with no guarantee; a restore is predictable. Repair is better when the backup is old, or when the fault is clearly one update or one driver.
