Table of Contents
When cumulative updates fail, Windows features refuse to install, or system binaries have been replaced, the underlying cause is usually a damaged component store (the WinSxS folder) or corrupted system files derived from it. Windows provides two complementary tools: DISM repairs the store, and SFC repairs the live system files from the store. Running them in the right order, with the right source, fixes most cases without a reinstall. The commands apply to Windows 10, Windows 11 (24H2, 25H2 and 26H1) and Windows Server 2019/2022/2025.
Applies to Windows 10, Windows 11 (24H2, 25H2, 26H1); Windows Server 2019, 2022 and 2025
Short answer: Open an elevated command prompt and run DISM /Online /Cleanup-Image /RestoreHealth first, then sfc /scannow; DISM pulls replacement files from Windows Update by default. If the machine cannot reach Windows Update or DISM reports “The source files could not be found”, mount installation media of the same build and repeat DISM with /Source:wim:D:\sources\install.wim:1 /LimitAccess, then run SFC again and reboot.
Order matters
SFC compares protected system files against the component store. If the store itself is damaged, SFC reports “Windows Resource Protection found corrupt files but was unable to fix some of them”. DISM RestoreHealth fixes the store, so it comes first. The full sequence:
DISM /Online /Cleanup-Image /CheckHealth
DISM /Online /Cleanup-Image /ScanHealth
DISM /Online /Cleanup-Image /RestoreHealth
sfc /scannow
CheckHealth only reads a flag and takes seconds; ScanHealth walks the store and takes several minutes; RestoreHealth repairs and can take 20 minutes or more, sitting at 62.3% for a long time, which is normal. Reboot after SFC if it repaired anything.
Use an offline source
RestoreHealth downloads missing payloads from Windows Update. On isolated servers, machines behind a WSUS that does not host the payloads, or when DISM returns error 0x800f081f, provide a local source. The source must be the same edition and a build at least as new as the machine, or DISM ignores it.
Download the current ISO for the branch, mount it (right-click » Mount, or Mount-DiskImage), and identify the index for your edition:
DISM /Get-WimInfo /WimFile:D:\sources\install.wim
Recent ISOs ship install.esd instead of install.wim; DISM accepts both. Then run:
DISM /Online /Cleanup-Image /RestoreHealth /Source:wim:D:\sources\install.wim:6 /LimitAccess
Replace 6 with the index number for your edition (Pro, Enterprise and so on). /LimitAccess stops DISM trying Windows Update as well. If the ISO is older than the installed cumulative update, DISM may still say source files were not found; in that case create an updated WIM by mounting the index and applying the latest cumulative update, or use a reference machine’s WinSxS folder as the source:
DISM /Online /Cleanup-Image /RestoreHealth /Source:\\FILESERVER\Refs\Win11-26H1\Windows\WinSxS /LimitAccess
Read the logs
DISM writes to C:\Windows\Logs\DISM\dism.log; SFC and the component servicing engine write to C:\Windows\Logs\CBS\CBS.log. Filter SFC results:
findstr /c:"[SR]" C:\Windows\Logs\CBS\CBS.log > C:\sfcdetails.txt
Lines containing “Cannot repair member file” name the file that could not be fixed; “Repairing corrupted file” lines confirm success. In dism.log, search for “Failed to” near the end of the run to see which payload was missing.
Repair from WinRE when Windows will not boot
Boot installation media or the recovery environment, open the command prompt, and target the offline installation:
DISM /Image:C:\ /Cleanup-Image /RestoreHealth /Source:wim:D:\sources\install.wim:6 /LimitAccess
sfc /scannow /offbootdir=C:\ /offwindir=C:\Windows
Drive letters differ in WinRE; run diskpart and list vol to find the Windows volume.
Verify it worked
Run sfc /verifyonly and DISM /Online /Cleanup-Image /CheckHealth after the reboot; both should report no integrity violations and “No component store corruption detected”. Then retry the failed update or feature install. If the trigger was a Windows Update error, see Fix Windows Update errors 0x80070002, 0x800f0922 and 0x80073712 for the follow-up steps once the store is clean.
Common pitfall
Using an install.wim from a different branch is the classic mistake: a 25H2 ISO cannot repair a 26H1 machine, and even the right branch fails if its image is older than the installed cumulative update. Check winver against the ISO’s build before mounting. Another trap is running DISM from a non-elevated PowerShell window, where the forward slash switches are interpreted as paths; use cmd.exe or prefix the command with dism.exe and quote the switches in PowerShell.
DISM RestoreHealth offline source at a glance

Official documentation: Windows client documentation, Windows Server documentation.
Related guides: Configure DHCP failover between two Windows Servers · Windows 11 25H2 and 26H1 upgrade blockers and compatibility holds explained · Disable RDP drive, clipboard and USB redirection with Group Policy.
Frequently asked questions
Does DISM RestoreHealth also apply to Windows Server 2025?
Yes. The same commands work on Windows Server 2019, 2022 and 2025, including Server Core, and the offline source method uses the Server ISO’s install.wim with the Standard or Datacenter index.
How long does DISM RestoreHealth take?
Typically 10–30 minutes online, longer on slow disks or when many payloads must be downloaded. Progress appears stuck at 62.3% or 100% for long stretches; wait rather than cancel.
Can I undo a DISM or SFC repair?
There is nothing to undo; both tools replace damaged files with signed copies of the same version. If a repaired file causes an issue with an application, reinstalling that application or the affected update is the correct follow-up.
Maintenance record
This guide changes servers, data or security settings, so we re-check it against current versions on a fixed schedule. Take a backup or snapshot before you start.
- Maintained by
- srvScripts editorial team
- Supported versions
- Windows 10, Windows 11 (24H2, 25H2, 26H1); Windows Server 2019, 2022 and 2025
- Last full review
- Next review