Fix it now
0x80070424 is Win32 error 1060, ERROR_SERVICE_DOES_NOT_EXIST: the Service Control Manager looked in its database and found no such service. In Windows Security that means the firewall service or something it depends on has been removed, disabled or damaged. It is not a rule problem, so editing rules gets you nowhere – and the same code appears in Windows Update for exactly the same reason.
sc query mpssvc
sc query bfe
sc qc mpssvc
sc config bfe start= auto
sc config mpssvc start= auto
net start bfe
net start mpssvc
- Read the first two results. “The specified service does not exist” means the registration is gone and you are in the repair section below; a service that exists but is stopped or disabled is the easy case.
- Note the dependency list
sc qc mpssvcprints. Start what it depends on first, then the firewall service itself. - Once both are running, rebuild the rule set from defaults with
netsh advfirewall reset– but export or record your custom rules first, because the reset discards them. - Confirm the result with
Get-NetFirewallProfile | Select-Object Name, Enabledand by opening Firewall and network protection in Windows Security. - If a security suite was removed just before this started, run that vendor’s own removal tool, reboot, and repeat the checks.
If sc query wuauserv and sc query bits return the same complaint, you have one problem and not two. Error 1060 is about the service database, and the components that use it are incidental.
If both services run automatically after a reboot and Windows Security loads without a banner, stop here. If a service exists but still refuses to start, the next section covers what each refusal code means.
Why it happens
Windows Defender Firewall is not one component. The rules and profiles you see belong to the firewall service, MpsSvc, but the packet decisions are made by the Windows Filtering Platform, whose base component runs in the Base Filtering Engine service, BFE. Run sc qc mpssvc and the dependency is printed for you. If BFE will not start, MpsSvc cannot start, and the management interface has nothing to talk to.
Error 1060 is a specific statement, and it is worth taking literally. The Service Control Manager is not saying the service failed; it is saying there is no such service registered. That happens when a key under HKLM\SYSTEM\CurrentControlSet\Services has been deleted, or when its permissions have been changed so that the account the service runs as can no longer read it. Either way, nothing you do inside Windows Security will help, because there is no service behind the interface.
The companion codes describe the other two shapes this takes. 0x8007042C is error 1068, ERROR_SERVICE_DEPENDENCY_FAIL – the dependency service or group failed to start, which is BFE refusing while MpsSvc waits. 0x8007041D is error 1053, ERROR_SERVICE_REQUEST_TIMEOUT – the service did not respond to the start or control request in a timely fashion, meaning it exists, it launched, and it never reported ready. Microsoft documents that the Service Control Manager waits for the period set by ServicesPipeTimeout before logging events 7000 or 7011 in the System log.
A removed security suite took the service registration with it
You have this one if The problem began immediately after an antivirus product was uninstalled, or on a machine where two suites were installed at once.
- Run the vendor’s dedicated removal tool for the product that was uninstalled; ordinary uninstallers routinely leave service registrations broken.
- Reboot, then re-check
sc query mpssvcandsc query bfe. - If the services are back but stopped, set both to automatic and start BFE before MpsSvc.
- Run
netsh advfirewall resetto restore policy defaults once the services are running.
Never leave two real-time endpoint products installed. They register competing filters in the same platform, and a missing firewall service is one of the milder outcomes.
The service is disabled by policy
You have this one if The service exists, its start type reads disabled, and it goes back to disabled after every reboot no matter what you set.
- Produce a policy report:
gpresult /h %USERPROFILE%\Desktop\gp.html, and read the Computer Configuration section for System Services and firewall settings. - Where a domain policy is setting it, correct the policy rather than the machine, then run
gpupdate /force. - On a standalone machine, check
HKLM\SOFTWARE\Policies\Microsoft\WindowsFirewallfor a profile subkey turning the firewall off, and remove the value. - Set the start type back with
sc config mpssvc start= autoand restart.
The service starts but never reports ready
You have this one if 0x8007041D rather than 0x80070424, and the System log carries event 7000 or 7011 for the service at the moment it was started.
- Read the System log entry, which names the service and the underlying reason.
- Where the machine is genuinely slow to start services, Microsoft documents a workaround: create the DWORD
ServicesPipeTimeoutunderHKLM\SYSTEM\CurrentControlSet\Control, in milliseconds, and increase it in small steps. - Treat that as a workaround rather than a fix. Microsoft’s own advice is to research why the service is slow rather than simply waiting longer for it.
- Reboot and confirm the service reaches Running without help.
System files or the service database are damaged
You have this one if Several unrelated services misbehave, and the same code shows up in Windows Update as well as in Windows Security.
- Run
sfc /scannowfrom an elevated prompt and let it finish. - Follow with
DISM /Online /Cleanup-Image /RestoreHealth. - Reboot and re-check both services.
- If the component store cannot be repaired, an in-place upgrade from current Windows installation media rebuilds the service database while keeping applications and data.
You will find advice to add NT SERVICE\BFE to the permissions on the BFE service key. Microsoft publishes no such procedure, and a wrong permission change under Services can leave a machine that will not start cleanly. Repair the component store first; treat registry surgery as a last resort with a full backup behind it.
Full reference
The three codes, as Microsoft states them
| Code | Win32 | Constant | Message |
|---|---|---|---|
0x80070424 |
1060 | ERROR_SERVICE_DOES_NOT_EXIST | The specified service does not exist as an installed service |
0x8007042C |
1068 | ERROR_SERVICE_DEPENDENCY_FAIL | The dependency service or group failed to start |
0x8007041D |
1053 | ERROR_SERVICE_REQUEST_TIMEOUT | The service did not respond to the start or control request in a timely fashion |
The 0x8007 prefix is the Win32 facility: everything after it is the plain Win32 error number in hexadecimal. That is why the same three codes turn up under Windows Update, Windows Search and half a dozen other components. They are statements about services, not about firewalls.
Working out which service is actually missing
| Component | Services to check |
|---|---|
| Windows Defender Firewall | mpssvc, and bfe beneath it |
| Windows Update | wuauserv, and bits |
| Windows Security interface | SecurityHealthService, wscsvc |
| Microsoft Defender Antivirus | WinDefend |
sc query <name>tells you whether the service exists and what state it is in.sc qc <name>prints its start type, the binary that hosts it, the account it runs as and what it depends on.sc queryex <name>adds the process id, which is how you tell a service that is running from one that reports Running and has no process.- The System log, filtered on Service Control Manager, records events 7000 and 7011 with the reason a start failed or timed out.
Resetting the firewall, and what it costs
netsh advfirewall reset is documented as restoring policy defaults, and it does exactly that: every custom inbound and outbound rule you have added goes, and all three profiles return to their default state. On a machine where line-of-business applications rely on rules somebody added years ago, that is a real outage. Capture the current state first – Get-NetFirewallRule | Where-Object Enabled -eq True gives you a readable inventory – and be ready to put the important ones back.
Back up the registry before editing anything under Services. Select the branch, choose File then Export, and keep the .reg copy. Service keys carry the account and permission settings the operating system uses to start itself, and a mistake there is not recoverable from the desktop.
Seeing what the firewall is doing once it runs again
When the services are back, the fastest way to prove the firewall is making decisions rather than merely running is to turn its own logging on. Microsoft documents the log at %windir%\system32\logfiles\firewall\pfirewall.log, and it is enabled per profile with netsh advfirewall set allprofiles logging droppedconnections enable and the matching allowedconnections switch. For a fuller picture, the Security log records event 5157 when the Windows Filtering Platform blocks a connection, once the Audit Filtering Platform Connection subcategory is enabled.
Rebuilding a service that has genuinely gone
- Repair the component store first with SFC and DISM. Most missing service registrations are a symptom of component store damage rather than an isolated deletion.
- An in-place upgrade from current installation media rebuilds the service database while keeping applications, settings and data, and is the supported route when DISM cannot repair the store.
- Importing a service key exported from another machine works only if that machine is the same Windows version, build and architecture, and it is fragile enough that it should be a last resort rather than a first move.
- If the machine is a member of a domain with a standard build, reimaging is often faster than any of the above, and leaves you with a machine whose state you understand.
When a licence is the actual fix
Nothing here needs a licence. Windows Defender Firewall and the Base Filtering Engine ship with Windows, and every repair above uses tools already on the machine. What a licence buys is the thing that stops the machine getting into this state again: one managed agent instead of two products fighting over the same filtering platform. Bitdefender GravityZone Business Security includes Modern Endpoint Protection, Network Attack Defense and Risk Management, managed from what Bitdefender describes as a single integrated management console giving one view of all security management components – so firewall and network policy is defined once rather than assembled per machine. Be clear about the boundary: the repair above is free, and central management is what you are paying for. Arco can work out which GravityZone tier matches your device count and tell you if the free route is enough.
Every code this article covers
| Code | What it points at | Source |
|---|---|---|
0x80070424 |
Win32 error 1060, ERROR_SERVICE_DOES_NOT_EXIST: the specified service does not exist as an installed service | Microsoft Learn |
0x8007042C |
Win32 error 1068, ERROR_SERVICE_DEPENDENCY_FAIL: the dependency service or group failed to start | Microsoft Learn |
0x8007041D |
Win32 error 1053, ERROR_SERVICE_REQUEST_TIMEOUT: the service did not respond to the start or control request in a timely fashion | Microsoft Learn |
Confirm the fix worked
Get-Service MpsSvc, BFEreports both Running, with Automatic start type.Get-NetFirewallProfile | Select-Object Name, Enabledshows all three profiles enabled.- Windows Security opens the Firewall and network protection page without an error banner.
sc query wuauservandsc query bitsno longer return the same complaint, which tells you the fault was the service database rather than the firewall alone.- Reboot and re-check, so you know the state survives a restart rather than having been started by hand.
Questions people ask about this
Do I need to buy antivirus to fix this?
No. Windows Defender Firewall and the Base Filtering Engine ship with Windows and are restored by the free steps above. A paid suite is worth considering for central management, or when you are cleaning up after a product that broke the machine, but not as a way of clearing this error.
Is netsh advfirewall reset safe?
It will not damage the machine, but it is documented as restoring policy defaults, which means every custom rule goes and all three profiles revert. Inventory your rules first with Get-NetFirewallRule and expect to re-add the ones applications depend on.
Why does Windows Update show the same code?
Because it is the same complaint about different services. Update needs wuauserv and bits. If either has been removed or disabled, the client reports that the service does not exist, which is error 1060 again.
Can I recreate the firewall service by hand?
You can import the service key from a healthy machine of the same build and architecture, and it is fragile enough that it should not be your first attempt. Repairing the component store with DISM, or an in-place upgrade from current media, is the supported route and is usually faster.
The service exists but times out on start. Is that the same problem?
No, that is 0x8007041D – error 1053 – and it means the service launched and never reported ready. Read the System log for events 7000 or 7011, which name the service and the reason. Microsoft documents ServicesPipeTimeout as a workaround for genuinely slow starts, while advising you to find out why it is slow.
