Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.
Windows NT 4.0’s Task Manager brought three views—Applications, Processes, and Performance—into one utility. It let users switch to or close a visible application, inspect the process behind it, and take a quick look at CPU and memory use. It was a useful first-response tool, not a replacement for Performance Monitor or a modern Windows Task Manager.
This is the subject of Jim Hoopes’s archival article, “Inside the NT 4.0 Task Manager,” published February 28, 1997. The interface and figures below refer to NT 4.0, not later Windows versions.
| # | Preview | Product | Price | |
|---|---|---|---|---|
| 1 |
|
Essential Windows Nt System Administration | $6.98 | Buy on Amazon |
| 2 |
|
Windows NT User Administration | $12.82 | Buy on Amazon |
| 3 |
|
Windows Nt Administration and Security | $25.00 | Buy on Amazon |
| 4 |
|
Windows NT System Administration | $22.24 | Buy on Amazon |
| 5 |
|
Microsoft Windows Nt Network Administration Training: Hands-On, Self-Paced Training for... | $6.98 | Buy on Amazon |
Why Task Manager mattered in NT 4.0
Earlier Windows NT releases had a Task List utility for desktop applications. NT 4.0’s Task Manager made it easier to connect those visible applications with their underlying processes and to see basic system performance in the same place. Administrators could get a quick snapshot without starting Performance Monitor, while retaining that more detailed tool for investigation.
Do these 3 things before closing this tab:
1Fix the driver behind crashes, sound loss and screen glitches2Clear out junk files and repair common Windows errors3Scan for outdated or missing drivers - takes under a minuteThe distinction between an application and a process is central to the interface. An application is the user-facing program or window; a process is a running instance of code. An application may involve one or more processes, and many processes have no visible application window at all.
#1 Best Overall
How to open it
The 1997 article documents these launch methods:
- Press Ctrl+Alt+Del to open the Windows NT Security dialog, then choose Task Manager.
- Right-click the taskbar and choose Task Manager.
- Choose Start → Run, enter
taskmgr.exe, and launch it. - Create a desktop shortcut to
taskmgr.exe.
The Ctrl+Alt+Del route fit a familiar troubleshooting habit: users often pressed the “three-finger salute” when an application stopped responding. The source documents these routes; it does not establish Ctrl+Shift+Esc as an NT 4.0 shortcut.
Applications: manage visible programs first
The Applications tab listed active user-facing applications. The source article’s example includes a communications program shown as Session A - [24 * 80]. Selecting an entry exposed actions such as switching to it, bringing it to the front, minimizing or maximizing it, and ending the task. Window-arrangement commands included cascading and tiling horizontally or vertically. Some commands could be unavailable depending on the state of open windows—for example, minimizing was not useful if all listed applications were already minimized.
If a visible program is hung, this is generally the sensible first view: End Task targets the application rather than inviting you to terminate an arbitrary process. It may still lose unsaved work, and it is not a guarantee that every associated process will disappear.
Go To Process links the high-level view to the lower-level one. Choose it for an application to identify its associated process on the Processes tab. A program such as Word might be represented by winword.exe; the process list also contains operating-system and background entries that have no corresponding desktop window.
Rank #2
- Used Book in Good Condition
Processes: inspect the running work
The Processes tab listed active processes and performance-related information, including CPU usage and total CPU time consumed. It also exposed process priority and selectable metrics. This view is useful when you need to find a process associated with a visible application or see which listed process is using resources, but it requires more care than the Applications tab.
CPU use is not CPU time
CPU usage describes current or recent processor activity. CPU Time is cumulative processor time attributed to a process since it started; a large total alone does not show that the process is busy now. The System Idle Process accounts for time when the system had no runnable work. In other words, the live performance display and a process’s accumulated CPU Time answer different questions.
Choose columns, sort, and adjust refresh
Use View → Select Columns to choose which process metrics appear. The available information depends on the selected columns; do not assume the list matches a later Windows version. Resize columns by dragging their boundaries. Click a column heading to sort by that field; clicking CPU sorts by CPU use, and clicking it again reverses the order.
View → Update Speed changes how often process data refreshes. Faster updates can make brief changes easier to catch, but produce more visual churn; slower updates give a less volatile view. The CPU-history display also depended partly on the update speed and the size of the Task Manager window.
Rank #3
End Process and Set Priority: use restraint
The End Process button terminates the selected process. A process appearing in the list is not evidence that it is safe to stop. Hoopes specifically warns readers about services.exe, which is necessary for NT operation, and rpcss.exe, which supports networking functions. Those examples are not an exhaustive map of critical processes. Ending a system or networking component can disrupt the machine; terminating an ordinary application process can also discard unsaved work. A service-managed process may restart, and the process that looks busy may be a symptom rather than the cause.
For a visible, unresponsive application, try End Task from Applications before using End Process. Use process termination only when you understand the process’s role and the consequences.
Right-clicking a process offered Set Priority. The original article describes temporarily raising a communications process to High as a possible way to let a task complete if it is not receiving enough CPU time. This is an exceptional troubleshooting intervention, not a general speed setting: a higher-priority process can take time from other work, reduce responsiveness, and fail to address the real cause. The article does not provide a complete transcription of every priority choice in the menu.
Performance: a compact system snapshot
The Performance tab combined live readings and history with system totals. Its purpose was to help identify broad symptoms quickly, not to explain every cause.
Rank #4
CPU
A bar showed current CPU utilization, while a graph displayed utilization history. How much history was visible depended partly on the update interval and window size. A high reading tells you the processor is busy; it does not, by itself, identify why.
Memory and system counts
The tab showed memory utilization and history, physical-memory information, kernel-memory information, commit charge, and counts of handles, threads, and processes. These figures help describe the system at that moment, but their labels and accounting should not be treated as identical to those in modern Windows interfaces.
- Physical memory is the RAM available to the operating system.
- Kernel memory is used by the operating system and was divided into paged memory, which could be written to disk when necessary, and nonpaged memory, which had to remain resident.
- Commit charge represented memory allocated to application and system programs. The display included current use, the maximum available, and peak use since Task Manager started. The status-bar Memory Usage figures corresponded to current commit charge and its limit.
Hoopes’s example machine had 32 MB of physical memory, with roughly 10 MB available and about 8 MB used for file caching. Those are observations from the machine in the article, not NT 4.0 requirements or universal figures.
Free tools Windows power users keep installed
One-click scans. No signup required.
A practical troubleshooting sequence
- Open Performance and check whether CPU use or memory pressure looks unusual.
- If a visible program is involved, go to Applications and use Go To Process to find its associated process.
- On Processes, select relevant columns with View → Select Columns, then sort by CPU or another useful field. Distinguish current CPU use from accumulated CPU Time.
- If an application is unresponsive, try End Task before considering process termination.
- Do not end system or networking processes simply because they appear in the list. Identify their role first.
- If the snapshot does not explain the problem, move to Performance Monitor for detailed counters and subsystem-level investigation.
Where Task Manager stopped
NT 4.0 Task Manager was best for quick checks: spotting an obviously busy process, seeing broad CPU or memory conditions, listing processes, and closing a hung application. It was not a full diagnostic suite. When an issue involved a specific subsystem, needed historical logging or counter comparisons, or could not be explained by a live snapshot, Performance Monitor (often called Perfmon) was the more appropriate tool. The original article’s practical division is simple: use Task Manager to spot a problem, then Perfmon to investigate it in greater depth.
Best Value
Later Windows Task Manager versions gained capabilities that were not part of this three-tab NT 4.0 interface. Do not project features such as startup management, app history, GPU graphs, or modern service and user views backward onto it.
Historical notes and alternatives
The NT 4.0 administrative manual mirrored by ManualMachine describes a DisableTaskMgr policy, reportedly added in Service Pack 2, at HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionPoliciesSystem. It says a value of 1 disables Task Manager and that 0 or removing the value leaves it enabled. This information comes from a mirrored manual rather than a currently maintained Microsoft support page, so treat it as historical documentation, not a modern support procedure. Read the mirrored NT 4.0 manual.
For command-line process inspection, Sysinternals later offered PsList, including a task-manager mode with configurable refresh and a switch to indent parent-child process relationships. It was a separate tool, not a built-in part of NT 4.0 Task Manager. Microsoft’s Sysinternals archive describes it.
The Tool Desk
Outbyte PC Repair FREERepair Windows errors before they cause bigger problemsFix Now →Outbyte Driver Updater FREEScan for outdated or missing drivers - takes under a minuteDriver Scan →For historical context on NT 4.0’s predecessor Task List and the utility’s place in the release, see the Windows NT 4.0 overview.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

