Skip to content

Est. 2011ยทMicrosoft Partner 7033487ยทDelivery under 3 minยทSupport 7 days a week

Your vault is empty.

License Error Event ID 1177

Event ID 1177 and 1564: quorum is lost and the cluster service shuts down

12 min read Updated October 5, 2026 Windows Server: RDS, Hyper-V & Clustering

Fix it now

Event ID 1177 is the cluster service shutting itself down because quorum was lost, and Event ID 1564 says the file share witness could not be arbitrated. Get the witness reachable again, or get the missing nodes back, and the cluster re-forms on its own.

Run these on a surviving node, in an elevated PowerShell session

Get-ClusterNode | Format-Table Name, State, NodeWeight, DynamicWeight
Get-ClusterQuorum
Test-NetConnection fs01 -Port 445
Test-Path '\\fs01\clusterwitness'
  1. Read the two outputs together. Get-ClusterQuorum tells you what the witness is meant to be; the node table tells you how many votes are actually left.
  2. If the witness is a file share, fix its access rather than its existence. Microsoft’s documented grant is Change and Read on the share, plus Modify, Read & execute, List folder contents and Read on the NTFS permissions, given to the cluster name object.
  3. If the share has gone for good, repoint the witness: Set-ClusterQuorum -FileShareWitness \\fileserver\fsw
  4. Start the cluster service on every node that is down, including ones you think are irrelevant, and let the cluster form normally once a majority exists.
  5. Only if service must be restored and no majority can form, force quorum on the node with the most current data: Start-ClusterNode -ForceQuorum, then start the remaining nodes normally.

-ForceQuorum is the documented parameter name. -fq and -FixQuorum are aliases for the same switch, so older runbooks that use them are not wrong, just older.

If the cluster is up and the witness resource is online, you can stop here. The next section covers how the vote arithmetic actually works, so the same failure does not repeat.

Why it happens

A cluster keeps running while a majority of votes survives. Nodes hold votes, a witness may hold one more so the total stays odd, and the moment the majority is gone the remaining nodes stop the cluster service deliberately. Event ID 1177 is that decision being recorded: the cluster service is shutting down because quorum was lost, which Microsoft attributes to lost network connectivity between some or all nodes, or a failover of the witness.

The alternative is worse than downtime: two isolated groups of nodes, each convinced it owns the storage, both writing to it. A 1177 is the safety mechanism working, not the fault.

The witness is where most of these incidents start, and the events around 1177 tell you which part of it failed. Event ID 1564 is the file share witness failing to arbitrate for its share. Event ID 1562 is the same resource failing a periodic health check. Event ID 1558 is different in kind: the cluster detected a problem with the witness resource and is failing the witness over to another node to re-establish access to cluster configuration data, which is why a witness can look healthy on a node you were not looking at.

The witness share is reachable but the cluster is not allowed in

You have this one if 1564 alongside 1177, and the share opens fine from your workstation but the resource will not come online.

  1. Confirm TCP 445 is open from every node to the file server: Test-NetConnection fs01 -Port 445
  2. On the share, grant the cluster name object Change and Read.
  3. On the NTFS security of the folder behind it, grant the same account Modify, Read & execute, List folder contents and Read.
  4. Take the witness resource offline and online again, and confirm it stays online.

The cluster authenticates as its own computer object, not as you. That is why a share you can open by hand can still be closed to the cluster.

The witness is hosted somewhere unsupported

You have this one if The witness works for months, then fails during exactly the incident it existed to survive.

  1. Confirm the share is not on a node of the cluster it arbitrates for.
  2. Confirm it is not published through DFS. Microsoft does not support DFS or replicated storage for a witness.
  3. Confirm the host supports SMB 2 or later and has at least 5 MB free.
  4. Give the share to one cluster only. A file server can host several witness shares, each dedicated to one cluster.

The witness points at something that no longer exists

You have this one if The witness path names a decommissioned file server, or a cloud witness whose access key was rotated.

  1. Choose a location that does not depend on the cluster itself.
  2. Repoint it: Set-ClusterQuorum -FileShareWitness \\newfs\clusterwitness, which also sets the quorum type to Node and File Share Majority.
  3. For a cloud witness, reconfigure it with the current account name and access key using Set-ClusterQuorum -CloudWitness -AccountName <name> -AccessKey <key>.
  4. Confirm the witness resource reports online before you call it done.

Enough votes went away at once that no witness could have helped

You have this one if No witness fault at all: several nodes went down together, or a site link failed in a stretched cluster.

  1. Restore the failed nodes and let the cluster form on its own. This is the designed outcome, not a fault to work around.
  2. Where service must come back sooner, force quorum on one node only, choosing the one with the most current data.
  3. Afterwards, look at the shape of the cluster rather than the incident: an even node count with no tie-breaker will do this again.

Full reference

The events that surround a 1177, and what each one is telling you

Event Published meaning
1177 The cluster service is shutting down because quorum was lost, through loss of connectivity between nodes or a failover of the witness
1564 A file share witness resource failed to arbitrate for its file share; the share must exist and be accessible by the cluster
1562 A file share witness resource failed a periodic health check on its file share
1558 The cluster detected a problem with the witness resource and is failing it over to another node to re-establish access to cluster configuration data
1809 No published meaning. Read it alongside the events above rather than treating it as a diagnosis

What a witness has to be

Microsoft publishes a specific set of requirements for a file share witness, and most of the witnesses that fail at the worst moment break one of them. The share must be dedicated to a single cluster and must not carry user or application data. It must support SMB 2 or later and have at least 5 MB free. It must not be a DFS path, and it must not sit on replicated storage, because either can leave two halves of the cluster looking at different copies. It should be physically separate from the cluster nodes or cluster sites it arbitrates for.

The permissions are narrower than they are usually granted. The cluster name object needs Change and Read on the SMB share, and Modify, Read & execute, List folder contents and Read on the NTFS security settings. Full Control is the habit, not the requirement.

Reading the vote arithmetic instead of counting servers

Get-ClusterNode with NodeWeight and DynamicWeight is the only honest answer to “how many nodes can I lose”. Dynamic quorum adjusts weights as nodes leave cleanly, and the witness vote is added or removed to keep the total odd, so the survivable loss changes as the cluster changes. The clearest published illustration of this is Event ID 5398, which prints votes required to start the cluster, votes available, and the number of nodes with votes when a cluster refuses to form.

Forcing quorum, and what it costs

Forcing quorum starts the cluster with a minority and tells it to treat that node’s copy of the cluster database as authoritative. Do it on one node only, choose the node with the most current data, and never do it on two nodes in separate network partitions – that is how you get two clusters writing to the same storage.

Command What it does
Start-ClusterNode -ForceQuorum Forces the start of a cluster node regardless of whether quorum is formed. Aliases: -fq, -FixQuorum
Start-ClusterNode -PreventQuorum Starts the node but prevents it forming the cluster, to avoid two competing instances
Set-ClusterQuorum -NoWitness Node Majority; no witness vote
Set-ClusterQuorum -DiskWitness "Cluster Disk 7" Node and Disk Majority using the named disk resource
Set-ClusterQuorum -FileShareWitness \\fileserver\fsw Node and File Share Majority using the named share
Set-ClusterQuorum -DiskOnly Disk only. Microsoft advises against it: it creates a single point of failure for the cluster

Once the cluster is up after a forced start, review the quorum configuration and the resource list before anything else. Anything changed after the copy you forced was current is gone, and the quickest way to lose a second afternoon is to assume the configuration you are looking at is the one you left.

When the witness looks fine and the cluster still stops

  • Check name resolution from every node to the witness host, not just from the node you are logged on to.
  • Check that the cluster name object still exists and is enabled in Active Directory. Stale-account cleanup tools disable cluster identities because they do not authenticate the way workstations do.
  • Check whether the witness resource has moved. Event 1558 says the cluster will fail the witness over to another node, so the resource you are inspecting may not be the one that failed.
  • On a stretched cluster, count votes per site. A site with more votes than the other decides every partition, which is usually not what the design intended.

When a licence is the actual fix

Nothing on this page needs a purchase. A witness share on an existing file server costs nothing, and a cloud witness costs nothing to configure. The purchase question only appears when the honest answer is that the cluster is the wrong shape – an even number of nodes with no tie-breaker, or two nodes where three would survive a single failure. A third node needs its own Windows Server licence, and on a Hyper-V cluster the edition decides how many virtual machines that host may run: Standard covers two virtual machines plus one Hyper-V host per licence, Datacenter covers unlimited virtual machines plus one Hyper-V host per licence. Arco supplies Windows Server 2025 Datacenter and can work out the core count per node before you order anything.

Every code this article covers

Code What it points at Source
Event ID 1177 The cluster service is shutting down because quorum was lost, through loss of connectivity between nodes or a failover of the witness Microsoft Learn
Event ID 1564 A file share witness resource failed to arbitrate for its file share; the share must exist and be accessible by the cluster Microsoft Learn
Event ID 1809 Seen in the cluster log around vote and witness changes. Microsoft’s failover clustering event reference does not publish a meaning for it, so read it as context rather than as a cause not published by the vendor
Event ID 1558 The cluster detected a problem with the witness resource and is failing the witness over to another node to re-establish access to cluster configuration data Microsoft Learn
Event ID 1562 A file share witness resource failed a periodic health check on its file share Microsoft Learn

Confirm the fix worked

  1. Get-ClusterNode reports every node as Up, with the weights you expect.
  2. Get-ClusterQuorum shows the witness type and location you intended.
  3. The witness resource is online in Failover Cluster Manager, and stays online through a working day.
  4. Test-NetConnection <witness-host> -Port 445 succeeds from every node, not just from one.
  5. Drain and restart one node, and confirm the cluster survives that single loss without dropping below quorum.

Questions people ask about this

Can the witness share live on one of the cluster nodes?

No. Microsoft’s guidance is that the share should be physically separate from the cluster nodes or cluster sites. A witness hosted inside the cluster disappears at exactly the moment it is needed, which is the failure this article exists to describe.

Is it safe to force quorum?

It is a recovery action with real cost. It tells the cluster to accept one node’s copy of the cluster database, so configuration changes recorded elsewhere can be lost, and forcing it in two partitions at once can corrupt shared data. Use it when the alternative is staying down, on one node, chosen deliberately.

Why did the witness pass every test I ran and still fail?

Because you tested as yourself. The cluster reaches the share as its own computer object, so the share and NTFS permissions have to name that account. Check the grant rather than the reachability.

How many nodes can this cluster lose?

Read the weights rather than reasoning from the node count. Dynamic quorum changes the totals as nodes leave, and the witness vote is added or removed to keep the total odd, so the answer is different on different days.

Does a different Windows Server edition make quorum harder to lose?

No. Failover Clustering and every quorum option behave identically in Standard and Datacenter. Edition affects virtualisation rights and whether Storage Spaces Direct is available, not how votes are counted.

Related error codes

Was this article helpful?

Your feedback helps us improve our documentation.

Related articles

License Error Event ID 1511 and 1515: RDS users land in a temporary profile every logon Free Fix Event ID 16010 and 20148: Hyper-V storage operations fail and VMs go missing Free Fix 0x807800C5 and Event ID 521: Windows Server Backup dies at the snapshot Free Fix Event ID 304 and 305: RD Gateway blocks users on CAP and RAP policy checks
โ† Back to Knowledge Base