October DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsSlow PC?RecommendedPC slow today? Run a repair scan before it gets worseResolve common Windows issues and optimize system performance.Scan NowOctober DealsAmazon USDeal season is back - check today's better picksAmazon US: current deals, useful picks and tech finds.See Picks×
Skip to content
endpoint management

Devices Rebooting From SCCM? Find the Cause and Stop Unexpected Restarts

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Configuration Manager (often still called SCCM) can restart a device after a required software update, application, package, or task sequence—or an administrator can request a restart directly. But a reboot that follows SCCM activity is not proof that SCCM initiated it. Start by matching the Windows shutdown record to Configuration Manager client logs and the deployment timeline; then change the responsible deployment or restart policy rather than disabling restarts blindly.

Why Configuration Manager devices restart

A required deployment can install successfully while Windows still needs a restart to finish applying it. Configuration Manager may notify the user and, if its force-restart policy is enabled, enforce the restart after the deployment deadline. The documented default is enabled, but client settings and deployment configuration can change the behavior. Microsoft’s restart-notification guidance covers the current-branch controls.

Software updates

Windows updates can leave a restart pending after installation. The client coordinates the restart and then evaluates update detection again after Windows starts. Check UpdatesDeployment.log, UpdatesHandler.log, WUAHandler.log, and RebootCoordinator.log to trace that sequence. A pending restart is not itself proof that a restart has already occurred. See Microsoft’s software-update planning guidance.

Applications, packages, and programs

An application installer may report that a restart is required—for example, an MSI can return code 3010. Inspect the deployment type’s return-code mapping to see whether that result is treated as a soft or hard reboot. For legacy packages and programs, check the command line and scripts for direct calls such as shutdown.exe or Restart-Computer, as well as the program’s restart behavior. Use execmgr.log to correlate execution and return codes; do not assume the client made the restart decision independently of the installer.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Task sequences

A task sequence can intentionally restart Windows using its Restart Computer step, either into the installed operating system or an assigned boot image. The step supports a user notification and timeout; Microsoft documents a 60-second default for that notification. Task sequences can restart more than once, especially when installing updates. For update-related second restarts, review the SMSTSWaitForSecondReboot variable and the step sequence. Check smsts.log, and consult Microsoft’s documentation for the Restart Computer step and task-sequence variables.

Administrator-requested restart

An administrator can send a client notification using Client Notification → Restart. Microsoft documents a 90-minute default delay for this notification, subject to the applicable Computer Restart client settings. This is separate from a deployment deadline. Details are in Microsoft’s client-management documentation.

Confirm whether Configuration Manager initiated the reboot

  1. Establish the Windows timeline. Open Event Viewer → Windows Logs → System and inspect events around the reboot. Event 1074 can identify the process or user that initiated a shutdown or restart and include a reason. Events 6005 and 6006 help mark event-log service startup and shutdown; 6008 indicates an unexpected shutdown. Kernel-Power event 41 and Windows Error Reporting event 1001 can point toward a power loss, crash, or bugcheck. None of these event IDs alone proves SCCM was responsible.
  2. Check the device’s Pending Restart value. In the Configuration Manager console, open Assets and Compliance → Devices, then add or inspect the Pending Restart column. This reports a client restart condition, not necessarily a completed or imminent reboot.
  3. Read the client logs around the same time. On the device, the usual log directory is %WINDIR%CCMLogs. Start with RebootCoordinator.log for restart coordination and SCNotify.log for Software Center notifications and user actions.
  4. Find the deployment and deadline. For updates, correlate UpdatesDeployment.log with the deployment deadline and UpdatesHandler.log. For applications and packages, inspect execmgr.log; for task sequences, inspect smsts.log.
  5. Check the effective maintenance window and other restart authorities. Review ServiceWindowManager.log and MaintenanceCoordinator.log, then consider Intune, Windows Update for Business, Group Policy, third-party patching, BIOS-management utilities, security products, or scripts.

In a Windows event, a process such as svchost.exe or shutdown.exe is a clue, not a complete attribution. Match its timestamp and context to the ConfigMgr logs and deployment. The client-log descriptions are listed in Microsoft’s log-files reference.

What the Pending Restart value means

Configuration Manager’s status can identify several different restart sources. These labels distinguish a pending condition; none alone names the process that will ultimately restart the computer. Microsoft lists these categories in its device-management guidance.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Pending Restart value What it indicates
No No pending restart is reported by this ConfigMgr status check. It is not a guarantee that every deployment completed successfully.
Configuration Manager The ConfigMgr client’s reboot coordinator reports a pending restart condition. Inspect the deployment and restart logs to determine why.
Windows Update Windows Update reports a pending restart condition.
File rename A pending file-rename operation is reported as requiring a restart.
Add or remove feature Windows component servicing reports a restart condition.

A local registry check can help identify common indicators, but it does not establish which process initiated a reboot or whether a condition remains actionable:

Rank #2
Sale
StarTech Crash Cart Adapter, Server Management, USB VGA, TAA (NOTECONS01)
  • LAPTOP TO SERVER: USB crash cart adapter connects your laptop to a headless system, turning your laptop into a portable console for rack servers in your server room, PCs, ATMs, kiosks, etc
  • EFFICIENT TROUBLESHOOTING: Easily log server activity using the crash cart adapter software; For optimal performance, be sure to install the latest drivers; Note: Please make sure to download the drivers specifically for the NOTECONS01
  • BIOS-LEVEL CONTROL: Connect the laptop crash cart adapter to your computer using the included USB cable, then connect the integrated USB and VGA cables to your server for instant BIOS-level control
  • SELF-POWERED: The KVM adapter is powered by the server-side USB connection, reducing strain on the laptop's battery and eliminating the need for an AC outlet, allowing you to connect to any PC or device with a VGA output port and USB connection
  • COMPACT DESIGN: This TAA Compliant pocket-sized data center crash cart adapter requires no additional accessories, eliminating the need to carry around a traditional crash cart/trolley when troubleshooting and servicing your systems
$rebootPending = [ordered]@{
    ConfigMgrRebootCoordinator = Test-Path 'HKLM:SOFTWAREMicrosoftSMSMobile ClientReboot ManagementRebootData'
    WindowsUpdateRebootRequired = Test-Path 'HKLM:SOFTWAREMicrosoftWindowsCurrentVersionWindowsUpdateAuto UpdateRebootRequired'
    ComponentBasedServicing = Test-Path 'HKLM:SOFTWAREMicrosoftWindowsCurrentVersionComponent Based ServicingRebootPending'
    PendingFileRename = $false
}

$pendingRename = Get-ItemProperty `
    'HKLM:SYSTEMCurrentControlSetControlSession Manager' `
    -Name PendingFileRenameOperations `
    -ErrorAction SilentlyContinue

$rebootPending.PendingFileRename = $null -ne $pendingRename.PendingFileRenameOperations
[pscustomobject]$rebootPending

Use the console classification and client logs as the stronger evidence when attributing a restart.

Which logs answer which question?

Log Use it to investigate
RebootCoordinator.log Whether ConfigMgr recorded a restart requirement, coordinated it, or scheduled a restart after update installation.
SCNotify.log Whether Software Center presented a notification and whether a user chose to restart or defer. Entries such as “User chose to restart/logoff” are useful evidence; an absent notification alone does not prove what happened.
UpdatesDeployment.log Update deployment activation, deadline, enforcement, pending-reboot state, and post-reboot evaluation. A pending-reboot enforcement state can appear as ASSIGNMENT_ENFORCE_PENDING_REBOOT.
UpdatesHandler.log and WUAHandler.log Update installation handling and Windows Update Agent activity.
ServiceWindowManager.log Available and evaluated maintenance windows.
MaintenanceCoordinator.log Whether maintenance-window rules were considered or an operation was allowed to bypass them.
execmgr.log Application, package, and program execution, installer return codes, and commands that may call a restart.
smsts.log Task-sequence steps and restarts during operating-system deployment or other task-sequence work.

Microsoft’s deployment-tracking guide describes the update enforcement and post-reboot detection flow. Its software-update troubleshooting guide includes examples of restart evidence in client logs.

How Computer Restart client settings control behavior

To inspect or change the policy, open the Configuration Manager console and follow Administration → Client Settings. Open the client-setting policy that applies to the target devices, select Computer Restart, review the values, and deploy the policy to the intended device collection. Check for overlapping or higher-priority client settings that may determine the effective policy.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The important controls include:

  • Configuration Manager can force a device to restart — when enabled, the client can enforce a restart required by an application, software-update, or package deployment.
  • Specify the amount of time after the deadline before a device gets restarted (minutes) — the post-deadline delay.
  • Specify the amount of time that a user is presented a final countdown notification before a device gets restarted (minutes) — the final countdown period.
  • Specify the frequency of reminder notifications presented to the user, after the deadline, before a device gets restarted (minutes) — how often reminders appear before the final countdown.
  • When a deployment requires a restart, show a dialog window to the user instead of a toast notification — makes the notification more prominent, though it may be more disruptive.
  • When a deployment requires a restart, allow low-rights users to restart a device running Windows Server — consider the effect on other users and services before enabling this on servers.

Microsoft documents defaults of 90 minutes for the post-deadline delay, 15 minutes for the final countdown, and 240 minutes for reminders. These are documented defaults, not a promise that every environment uses them. The maximum post-deadline delay is 20,160 minutes (14 days). The restart delay and final-countdown duration must be shorter than the shortest applicable maintenance window; the reminder interval must be less than the restart delay minus the final-countdown duration. A final countdown cannot be snoozed, and sleep does not pause it. Windows 11 Focus Assist may suppress Software Center notifications during the first hour after a user signs in for the first time. See Microsoft’s restart-notification documentation for the details and version requirements.

Starting with Configuration Manager version 2309, administrators can use a Windows native reboot experience, including a deadline expressed in days and an organization name. The complete scenario depends on compatible, updated site and clients; updating the site alone is insufficient when clients have not been updated.

Rank #3
HP 14" HD Laptop, Windows 11, Intel Celeron Dual-Core Processor Up to 2.60GHz, 4GB RAM, 64GB SSD, Webcam(Renewed)
  • 14” Diagonal HD BrightView WLED-Backlit (1366 x 768), Intel Graphics
  • Intel Celeron Dual-Core Processor Up to 2.60GHz, 4GB RAM, 64GB SSD
  • 1x USB Type C, 2x USB Type A, 1x SD Card Reader, 1x Headphone/Microphone
  • 802.11a/b/g/n/ac (2x2) Wi-Fi and Bluetooth, HP Webcam with Integrated Digital Microphone
  • Windows 11 OS

How maintenance windows affect installation and restart timing

Keep three questions separate: when the deployment may install, when its restart may occur, and whether the deployment is allowed to override the maintenance window. Windows govern when Configuration Manager can perform impacting work for application, package, software-update, compliance-settings, operating-system, and custom task-sequence deployments. By default, deployment-caused restarts are not allowed outside a maintenance window, but deployment settings can override that behavior. Consult Microsoft’s maintenance-window guidance.

For a suspected update restart, compare the device’s collection memberships and effective windows with the deployment deadline. Check ServiceWindowManager.log, UpdatesDeployment.log, and MaintenanceCoordinator.log. In the update deployment settings, check whether restart behavior or maintenance-window handling allows an override. Microsoft’s troubleshooting example identifies entries such as Ignore reboot Window = True and swoverride=1 as signs that the reboot can ignore or override a window. Multiple collection windows, the device’s local time and time zone, and an override can all explain why the observed restart did not match an expected schedule. Content may download outside a window even when installation is scheduled for within it.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

How to stop or defer an unwanted restart safely

Correct the deployment first

Verify the deadline, user-experience settings, restart options, and maintenance-window override on the deployment that generated the restart. For an application, correct an inaccurate installer return-code mapping or a wrapper that restarts directly. For packages and programs, remove or control an embedded restart command. For task sequences, adjust the explicit restart step and its notification. Software-update deployment and automatic-deployment-rule controls are documented in Microsoft’s software-update deployment cmdlet reference and automatic deployment rule cmdlet reference.

Change force-restart enforcement only with a completion plan

Disabling Configuration Manager can force a device to restart prevents automatic enforcement by ConfigMgr when a deployment requires a restart. It does not finish the deployment: updates, application revisions, and later software installations may remain incomplete until a user or administrator restarts the device. For kiosks, point-of-sale systems, lab machines, or unattended servers, pair any suppression with an explicit restart schedule, monitoring, and an owner responsible for completion.

Use a longer window or clearer notification

Where the deployment should proceed but users need more notice, increase the post-deadline delay within the documented limits, adjust reminder and countdown values so they satisfy the maintenance-window constraints, or replace a toast with a dialog. Do not apply sample timing values across an estate without checking the shortest effective maintenance window and the operational needs of each device group.

Rank #4
BENFEI USB 3.0 to Ethernet Adapter, USB C to RJ45 Gigabit LAN (1000Mbps) Network Adapter, Compatible with MacBook/Pro/Air, Surface Pro, Windows 11/10/8/7, Mac OS [Aluminium Shell&Nylon Cable]
  • COMPACT DESIGN - The compact-designed portable BENFEI USB A/C to Ethernet adapter connects your computer or tablet to a router,modem or network switch for network connection. It adds a standard RJ45 port to your Ultrabook, notebook or Macbook Air for file transferring, video conferencing, gaming, and HD video streaming.
  • SUPERIOR STABILITY - Built-in advanced IC chip works as the bridge between RJ45 Ethernet cable and your USB A/C devices. The driver-free installation with native driver support in Chrome, Mac, and Windows OS; The USB A/C Ethernet adapter dongle supports important performance features including Wake-on-Lan (WoL), Full-Duplex (FDX) and Half-Duplex (HDX) Ethernet, Crossover Detection, Backpressure Routing, Auto-Correction (Auto MDIX).
  • INCREDIBLE PERFORMANCE - Supports full 10/100/1000Mbps gigabit ethernet performance over USB A/C's 5Gbps bus, faster and more reliable than most wireless connections. Link and Activity LEDs. USB powered, no external power required. Backward compatible with USB 2.0/1.1.✅ To reach 1Gbps, make sure to use CAT6 & up Ethernet cables.
  • BROAD COMPATIBILITY - The USB A/C-Ethernet adapter is compatible with Windows 11/10/8.1/8/7/Vista/XP, Mac OSX 10.6/10.7/10.8/10.9/10.10/10.11/10.12, Linux kernel 3.x/2.6, Android and Chrome OS.Compatible with IEEE 802.3, IEEE 802.3u and IEEE 802.3ab. Supports IEEE 802.3az (Energy Efficient Ethernet).❌Do Not Support Windows RT. (NOT compatible with Nintendo Switch.)
  • 18 MONTH WARRANTY - Exclusive BENFEI Unconditional 18-month Warranty ensures long-time satisfaction of your purchase; Friendly and easy-to-reach customer service to solve your problems timely.

Example PowerShell configuration

From the Configuration Manager site drive, the following example changes a named client-setting policy. It is illustrative, not a universal recommendation; a 12-hour delay combined with disabled enforcement can leave updates or applications pending until a later restart. Confirm the installed cmdlet version and policy scope before deployment.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Set-CMClientSettingComputerRestart `
    -Name "Production Workstations" `
    -CountdownMins 720 `
    -FinalWindowMins 60 `
    -ReplaceToastNotificationWithDialog $true `
    -NoRebootEnforcement $true

The cmdlet supports parameters including -CountdownMins, -FinalWindowMins, -ReplaceToastNotificationWithDialog, and -NoRebootEnforcement. Microsoft documents -NoRebootEnforcement for Configuration Manager versions 2006 and later in the Set-CMClientSettingComputerRestart reference.

Plan predictable restarts for workstations and servers

  • Assign maintenance windows to the collections that reflect the actual service schedule, and verify the effective windows on devices with multiple collection memberships.
  • Use staged collections for broad updates, with a monitored pilot before wider deployment.
  • For servers, coordinate update and restart order with application dependencies, failover, and service owners. Consider server groups or orchestration groups and a separately approved restart schedule.
  • Where the update deployment suppresses its own restart, define how and when a later restart will occur; otherwise the deployment can remain pending.
  • Use a task sequence with explicit restart steps and clear user messaging when a controlled sequence is more appropriate.
  • Assign clear ownership if another platform also manages restarts. Multiple authorities can create conflicting schedules and make attribution harder.

Enabling low-rights users to restart a Windows Server device may affect other users or services on that machine, so treat that permission as an operational decision rather than a convenience setting.

How to request a controlled restart

Configuration Manager console

  1. Open Assets and Compliance, then select Device Collections or the collection containing the target device.
  2. Select the intended device and choose Client Notification → Restart.
  3. Confirm the action, and verify the target scope before using a collection containing multiple devices.

The client notification is delivered through the Configuration Manager client and Software Center. Its documented default delay is 90 minutes, subject to Computer Restart client settings.

PowerShell

Run the cmdlet from the Configuration Manager site drive. Target one device first and verify the cmdlet behavior in the installed module before using a collection-wide action.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Invoke-CMClientAction `
    -DeviceName "Computer073" `
    -NotificationType ClientNotificationRebootMachine

For a collection, the documented example is:

Invoke-CMClientAction `
    -NotificationType ClientNotificationRebootMachine `
    -CollectionId "ABC00012"

Check the installed cmdlet’s parameter sets and collection-action behavior before broad use. See Microsoft’s Invoke-CMClientAction reference.

Troubleshoot a reboot with no visible warning

  1. Determine whether Windows logged a planned restart. Inspect System event 1074 and identify the process, user, and timestamp if present. If there is no matching planned-shutdown record, examine events 41, 6008, and 1001 for evidence of a crash, power loss, or bugcheck.
  2. Check ConfigMgr restart and notification records. Review RebootCoordinator.log and SCNotify.log around the event. A user may have selected Restart; do not infer that from the incident report or from missing notification evidence.
  3. Trace updates and maintenance windows. Check UpdatesDeployment.log, UpdatesHandler.log, WUAHandler.log, ServiceWindowManager.log, and MaintenanceCoordinator.log, then compare the deadline and override settings.
  4. Trace application, package, or task-sequence activity. Inspect execmgr.log, installer command lines and return codes, and smsts.log where applicable.
  5. Check other restart authorities. Review Intune, Windows Update for Business, Group Policy, third-party patching, scripts or remediation packages, BIOS utilities, and security tools.
  6. If the management logs do not explain it, investigate Windows and hardware. Look for a crash, power interruption, watchdog reset, or device fault rather than attributing the reboot to ConfigMgr by timing alone.

When to treat servers and kiosks differently

Unattended servers and fixed-purpose devices often cannot tolerate a user-facing countdown or unscheduled restart. Disabling enforcement can protect availability in the short term, but it also leaves required updates and application changes unfinished. Use a separately owned patch and restart plan with maintenance windows, staged rollout, service dependencies, and a way to confirm completion. On servers, enabling low-rights-user restart permission can disrupt other users or services; grant it only where that impact is acceptable.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Leave a Reply

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Read next

Recommended PC Tool
Recommended PC Tool
Windows Errors? Fix Them Before They SpreadFree repair scan
Outdated Drivers Are Slowing You DownFree scan - exact matches

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.