DISM is Deployment Image Servicing and Management, and on a running machine it is the tool that repairs the component store. SFC repairs protected system files by copying good versions out of that store, so a corrupt store leaves it nothing clean to copy from.
That is why DISM /Online /Cleanup-Image /RestoreHealth runs first and sfc /scannow second. Of the three health switches, only /RestoreHealth repairs anything: /CheckHealth reads a flag, and /ScanHealth is the one that actually scans.
- /CheckHealth only reports corruption already flagged, and it is fast
- /ScanHealth scans the store for corruption and takes several minutes
- /RestoreHealth scans and repairs, from Windows Update by default
- /Source supplies your own files, /LimitAccess blocks Windows Update
- /StartComponentCleanup /ResetBase makes installed updates unremovable
On this page
Three switchesThe three health switches, and what each one does
All three live under /Cleanup-Image, and they are not three strengths of the same scan. They do different work, and Microsoft's reference describes each one in a single sentence. Open an elevated command prompt for all of them, because none of these commands will run without administrator rights.
/CheckHealth checks a flag. It checks whether the image has been flagged as corrupted by a failed process, and whether that corruption can be repaired. It does not go looking. On a healthy machine it returns in seconds, and a clean result means nothing has been recorded, not that nothing is wrong.
DISM /Online /Cleanup-Image /CheckHealth
/ScanHealth does the looking. It scans the image for component store corruption, and Microsoft's own note is that the operation will take several minutes. This is the switch that finds corruption nothing has flagged yet.
DISM /Online /Cleanup-Image /ScanHealth
/RestoreHealth scans and then repairs. It scans for component store corruption and performs the repair operations automatically. On an online image the replacement files come from the configured repair source, which is Windows Update unless policy says otherwise.
DISM /Online /Cleanup-Image /RestoreHealth
Microsoft's repair guidance is to scan, then check, and only then restore: if /CheckHealth reports the image as non-repairable, the advice is to discard the image and start again rather than keep running commands at it.
Order with SFCWhy the DISM command comes before SFC
This is the ordering that matters on a real machine, and it follows from where each tool gets its replacement files.
sfc /scannow scans the integrity of all protected system files and repairs the ones with problems. Microsoft's description of how it does that is the important half: when SFC finds that a protected file has been overwritten, it retrieves the correct version of the file from the systemroot folder. Those correct versions live in the component store.
So the chain runs in one direction. Windows Update or a source you supply feeds the component store, and the component store feeds the protected system files. DISM repairs the first link and SFC repairs the second.
Running SFC on a machine whose store is corrupt either fails or reports that it could not fix some files, and running it a second time changes nothing, because the source it copies from is still bad.
The working order on a machine that is throwing servicing errors, update failures or a bug check that points at a system file:
1. DISM /Online /Cleanup-Image /ScanHealth to find out whether the store is the problem 2. DISM /Online /Cleanup-Image /RestoreHealth to repair the store 3. sfc /scannow to repair the system files from the now clean store 4. Reboot, then repeat step 3 once to confirm it comes back clean
Offline sourcesRepairing when Windows Update is not available
Plenty of machines cannot reach Windows Update, either because the network blocks it or because the repair source is set somewhere else by policy. DISM covers both cases, and this is where the DISM command starts looking like a deployment tool rather than a repair tool.
/Source names the files to repair from. Used with /RestoreHealth, it specifies the location of known good versions of files, such as the path to the Windows directory of a mounted image.
DISM /Online /Cleanup-Image /RestoreHealth /Source:c:\test\mount\windows /LimitAccess
/LimitAccess stops DISM from reaching out. It prevents DISM from contacting Windows Update for the repair of online images, which is what you want when the source you supplied is the source you intend to be used.
More than one /Source is allowed, and only one is used. If you specify more than one, the files are copied from the first location where they are found and the rest are ignored.
What counts as a source. Microsoft's repair source page lists a mounted Windows image, a running Windows installation shared over the network, a side by side folder such as z:\sources\SxS from installation media, and a WIM file on a share addressed with a Wim: prefix and an index, for example Wim:\\network\images\contoso.wim:3.
Two conditions come with it: use RTM media rather than refresh media, because refresh media has older file versions excluded, and make sure the source is patched to the latest cumulative update.
In practice that side by side folder arrives as an ISO mounted to a drive letter, or as a USB stick built from the same ISO, and the build of that ISO is the thing to check first when a repair from local sources fails.
Where the default comes from. Windows Update is the default repair source when policy allows it, and Group Policy can name one or more network locations instead. That policy is the same one Features on Demand uses, which is why a machine that cannot add an optional feature usually cannot repair itself either.
Will not bootRunning the DISM command when Windows will not boot
A system that fails to boot cannot be serviced in online mode, and DISM has switches for exactly that case.
/RevertPendingActions undoes the last servicing operation. Microsoft's description is that on a boot failure you can use it to try to recover the system, because it reverts all pending actions from previous servicing operations, and those pending actions might be the cause.
The scope note matters: it is not supported on a running operating system, or on a Windows PE or Windows Recovery Environment image. You boot into WinRE and run it against the offline Windows installation on disk.
DISM /Image:C:\offline /Cleanup-Image /RevertPendingActions
Microsoft's own guardrail is that this option should be used only in a system recovery scenario, on a Windows image that did not boot. It is not a maintenance command.
Everything else works offline too. The health and cleanup switches take /Image: in place of /Online, so the same repair you would run on a live machine runs against the volume from WinRE. The version rule still applies, and it is the one that bites here: the DISM build inside an old recovery image cannot service a newer Windows installation.
/Cleanup-Mountpoints fixes a broken mount. An image can be corrupted while you are modifying it with DISM, and this repairs that state. It will not unmount images that are already mounted, and it will not delete images that /Remount-Image can recover.
Disk spaceReclaiming disk space with /Cleanup-Image
The same /Cleanup-Image parameter carries the component store cleanup switches, and this is the half of the DISM command that MSPs run on purpose rather than in a panic. One of them has a consequence worth reading before you type it.
/AnalyzeComponentStore measures before you cut. It creates a report of the component store. The output separates the size Windows Explorer reports from the actual size, then breaks the actual size into what is shared with Windows through hard links, what is held for backups and disabled features, and what is cache and temporary data.
Microsoft's own arithmetic for the real overhead is the backups and disabled features figure plus the cache and temporary data figure. The report also ends with a count of reclaimable packages and a yes or no on whether cleanup is recommended.
DISM /Online /Cleanup-Image /AnalyzeComponentStore
/StartComponentCleanup removes superseded components. Run from the command line it gives results similar to the scheduled task of the same name, with two differences Microsoft spells out: previous versions of updated components are deleted immediately rather than after a 30 day grace period, and there is no one hour timeout.
DISM /Online /Cleanup-Image /StartComponentCleanup
/ResetBase goes further and does not come back. Added to /StartComponentCleanup it removes all superseded versions of every component in the store. Microsoft's warning is the whole story: after the command completes, all existing update packages cannot be uninstalled, though future update packages can still be removed.
If your rollback plan for a bad patch is to uninstall it, do not run this on the machines that plan covers.
DISM /Online /Cleanup-Image /StartComponentCleanup /ResetBase
From Windows 10, version 1607 onward a /Defer option can be added to /ResetBase, and Microsoft is specific that it belongs in the factory, where /ResetBase needs more than 30 minutes to finish, rather than in normal use.
To find out when /ResetBase last ran on a system, check the LastResetBase_UTC value under HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Component Based Servicing.
/SPSuperseded is the service pack equivalent. It removes the backup components kept for uninstalling a service pack, and the service pack cannot be uninstalled afterwards.
Never delete the folder by hand. Microsoft's warning on the WinSxS folder is blunt: deleting files from it, or deleting the folder, may severely damage the system so that the PC might not boot and make it impossible to update. The cleanup switches exist because the folder is full of hard links and cannot be cleaned by file size.
The logReading the log when a repair fails
A DISM run that ends in an error code tells you almost nothing on screen, and the log tells you most of it.
The default path. If /LogPath is not set, the log is written to %WINDIR%\Logs\Dism\dism.log. Each time it is archived, the previous file is saved with .bak appended and a new log begins, and that .bak file is overwritten on the next archive. Copy it before rerunning anything if the failure matters.
Turn the detail up. The default log level is 3. Raising it produces more of the servicing detail, and lowering it to 1 leaves errors only.
Windows PE is the exception. There the default directory is the RAMDISK scratch space, which can be as little as 32 MB, so a long servicing operation in WinPE should be given a real /LogPath.
Watch the version rule. DISM cannot be used with images newer than the installed version of DISM. A technician servicing a current image from an old WinPE build gets errors that look like corruption and are not, which is the most common wasted hour in this whole area.
PitfallsWhere people go wrong
Running SFC first and stopping there. If the store is corrupt, SFC reports problems it could not fix, and the technician concludes the machine needs a rebuild rather than trying the store first. The order in this article exists because of that one habit.
Treating /CheckHealth as a scan. It reads a flag. A clean /CheckHealth on a machine with symptoms means run /ScanHealth next, not that the image is healthy.
Running /ResetBase across a fleet to reclaim disk space. It works, and it removes the ability to uninstall every update already installed. Run /AnalyzeComponentStore first, see whether cleanup is even recommended, and keep /ResetBase for image preparation rather than for production endpoints.
Repairing from the wrong media. A source older than the target, or refresh media rather than RTM media, fails in ways that read as corruption. Match the source to the build and patch it to the current cumulative update.
Forgetting /LimitAccess on an isolated machine. Without it, DISM still tries Windows Update, and the run sits there until it times out. With a good /Source supplied, adding it saves the wait.
Automating the repair without recording the result. A script that runs /RestoreHealth on every machine that logs a servicing error, and never captures the exit code or the log, produces no evidence of anything.
Corruption that keeps coming back is a hardware or storage problem, and you only see the pattern if the runs are recorded. This belongs with the rest of patch management, not beside it.
ComparisonWhat each health switch actually does
| Criterion | /CheckHealth | /ScanHealth | /RestoreHealth |
|---|---|---|---|
| Reads the corruption flag | Yes | Yes | Yes |
| Scans the store | No | Yes | Yes |
| Repairs anything | No | No | Yes |
| Takes several minutes | No | Yes | Yes |
| Needs a repair source | No | No | Yes |
| Accepts /Source | No | No | Yes |
| Safe to run on a healthy machine | Yes | Yes | Yes |
| Changes the system | No | No | Yes |
The middle column is the one people skip, and it is the one that answers whether the store is the problem.
FAQFrequently asked questions
What does the DISM command do?
DISM is Deployment Image Servicing and Management, a command line tool built into Windows for servicing and preparing Windows images, including Windows PE, Windows Recovery Environment and Windows Setup.
Microsoft documents a set of PowerShell cmdlets that do the same work, so the tool is reachable from either shell. It can service an offline image in a WIM, FFU, VHD or VHDX file, or the running operating system with /Online.
Should I run DISM or SFC first?
DISM first. SFC replaces protected system files with correct copies taken from the component store, so the store has to be intact before SFC can do anything useful. Microsoft's guidance is to use sfc /scannow for a quick check and DISM /Cleanup-Image for a more extensive check that can repair issues with the store.
What is the difference between ScanHealth and CheckHealth?
/CheckHealth checks whether the image has already been flagged as corrupted by a failed process and whether that corruption is repairable. /ScanHealth performs an actual scan of the component store for corruption, and it takes several minutes.
How long does DISM /RestoreHealth take?
Microsoft says the operation will take several minutes. In practice the scan is the predictable part and the download is not, because the replacement files come from Windows Update unless you supply a /Source.
Does DISM need an internet connection?
Only when the repair source is Windows Update, which is the default. Supply /Source pointing at a mounted image, a share or installation media, add /LimitAccess, and the repair runs with no internet access at all.
What does /LimitAccess do?
It prevents DISM from contacting Windows Update for the repair of online images, as either the primary or the backup source. Use it whenever you have deliberately supplied your own repair files.
Is DISM /StartComponentCleanup /ResetBase safe?
It is supported and it is not reversible. After it completes, all existing update packages cannot be uninstalled, although future ones can still be removed. Keep it for image preparation, and run /AnalyzeComponentStore on production machines to see whether cleanup is even recommended.
How much space will component cleanup free?
Run /AnalyzeComponentStore and add the backups and disabled features figure to the cache and temporary data figure. That sum is the component store overhead. Everything reported as shared with Windows is hard linked into normal Windows operation and is not yours to reclaim.
Can I just delete the WinSxS folder?
No. Microsoft's warning is that deleting files from the WinSxS folder, or the folder itself, may severely damage the system so that the PC might not boot and updating becomes impossible. The folder is full of hard links, so its apparent size is not the space it occupies.
Where does DISM write its log?
To %WINDIR%\Logs\Dism\dism.log unless /LogPath says otherwise. The default log level is 3, and each archive of the log leaves a .bak copy that the next archive overwrites.
What is the component store?
The WinSxS folder, where Windows keeps the components it installs from and the previous versions it may need to roll back to. It is the source SFC copies from and the thing DISM /Cleanup-Image repairs and cleans.
Can DISM repair an offline image?
Yes. Point it at the mounted image with /Image: instead of /Online, for example DISM /Image:C:\offline /Cleanup-Image /RestoreHealth /Source:c:\test\mount\windows. The one hard limit is version: DISM cannot service an image newer than the DISM build you are running.
What if DISM says the image is not repairable?
Microsoft's advice is to discard the image and start again. On a production machine that means an in place upgrade or a clean install, and continuing to try repair commands against it is time spent for nothing.
Keep readingRelated concepts
Read next · Operations The Blue Screen Is a Decision, and It Leaves Evidence The other end of the same problem: a system file that fails at load rather than at repair. Open this next13 min- Directory and identity · 13 min Group Policy Explained How the repair source DISM uses is set, and where to look when it is wrong.
- Operations · 13 min Patch Management, and Why the Hard Part Is Not the Patching Where the servicing errors that send you to DISM usually come from.
- Windows administration · 10 min CMD Commands Grouped by Job, With the Ones That Can Destroy Data Files, network, system, disk and account commands for Command Prompt, and which need admin.
- Windows administration · 11 min How to Reset a Graphics Driver, and What Windows Already Does for You A display driver problem that is sometimes a damaged Windows image underneath.