- Local time
- 1:28 PM
- Posts
- 9
- OS
- Windows 11
Hi all,
I've been reading the recovery partition threads here for a while and wanted to share something I built. It's a PowerShell script that manages the Windows Recovery Environment — it repairs broken WinRE registrations, rebuilds winre.wim with the correct drivers, and resizes recovery partitions that have been outgrown by Windows Updates. MIT-licensed, single file.
I built it because three Windows 11-specific failure modes kept breaking machines:
1. 0x80070643 after KB updates. Windows pushes a WinRE update that requires more space than the OEM's recovery partition has. The update fails, and the partition is technically present but undersized by 50–200 MiB. This is the one that generates the most "Windows Update broke my recovery" threads here.
2. Device Encryption on 24H2+. The encryption service claims a newly created partition before the recovery type GUID can be applied. reagentc /enable then refuses with "Windows RE cannot be enabled on a volume with BitLocker Drive Encryption enabled." The machine has a recovery partition, but WinRE cannot use it.
3. VMD storage drivers missing from WinRE. On 12th-gen Intel and later, the recovery image needs the Intel VMD driver to see the OS disk. Without it, Startup Repair and Reset this PC fail with INACCESSIBLE_BOOT_DEVICE.
The script runs idempotently. On a healthy machine it takes a fast path — no WIM mount, no partition touch, no reagentc call. On a broken machine it does a full rebuild: strips the image to zero third-party drivers, injects the correct OEM/VMD recipe, resizes the recovery partition, and re-registers WinRE.
What took the longest to get right:
I've been reading the recovery partition threads here for a while and wanted to share something I built. It's a PowerShell script that manages the Windows Recovery Environment — it repairs broken WinRE registrations, rebuilds winre.wim with the correct drivers, and resizes recovery partitions that have been outgrown by Windows Updates. MIT-licensed, single file.
I built it because three Windows 11-specific failure modes kept breaking machines:
1. 0x80070643 after KB updates. Windows pushes a WinRE update that requires more space than the OEM's recovery partition has. The update fails, and the partition is technically present but undersized by 50–200 MiB. This is the one that generates the most "Windows Update broke my recovery" threads here.
2. Device Encryption on 24H2+. The encryption service claims a newly created partition before the recovery type GUID can be applied. reagentc /enable then refuses with "Windows RE cannot be enabled on a volume with BitLocker Drive Encryption enabled." The machine has a recovery partition, but WinRE cannot use it.
3. VMD storage drivers missing from WinRE. On 12th-gen Intel and later, the recovery image needs the Intel VMD driver to see the OS disk. Without it, Startup Repair and Reset this PC fail with INACCESSIBLE_BOOT_DEVICE.
The script runs idempotently. On a healthy machine it takes a fast path — no WIM mount, no partition touch, no reagentc call. On a broken machine it does a full rebuild: strips the image to zero third-party drivers, injects the correct OEM/VMD recipe, resizes the recovery partition, and re-registers WinRE.
What took the longest to get right:
- The reagentc /disable → /enable window. Everything that doesn't require a disabled WinRE runs before the disable. A race detector re-reads the registered image immediately before /disable and aborts if Windows Update serviced it during preparation.
- Target-volume BitLocker policy. reagentc checks the target volume, not C:. The dedicated-partition and enable-only paths don't care about C:'s encryption state. Only the OS-fallback route does.
- Driver strip normalization. Every rebuild strips the mounted image to zero third-party drivers, proven by re-enumeration, before injecting the current recipe. Otherwise drivers accumulate across rebuild cycles.
- Dell Pro Max 16 (Core Ultra 7) — full rebuild, 64 drivers injected, 1,000 MiB partition rejected as undersized, new 1,100 MiB partition created, reagentc /enable exit 0
- Two ASUS Vivobooks (both mid-encryption at 91%) — dedicated-partition path completed, new partition not re-claimed by Device Encryption
- ASUS PRIME H510M-D — fast path, DEDICATED, exit 0
- The strip stage hasn't been exercised against a source image with third-party drivers in production
- The destructive partition paths are VM-tested but not physical-hardware-tested under the current code
- A known residual corner: a post-deletion failure on an encrypted C: can leave the machine without a dedicated recovery partition or OS-fallback
My Computer
At a glance
Windows 11Intel® Core™ i5-11400Samsung 16GB DDR4 3200MHzNvidia GeForce GTX 1660 SUPER
- OS
- Windows 11
- Computer type
- PC/Desktop
- Manufacturer/Model
- Custom Built
- CPU
- Intel® Core™ i5-11400
- Motherboard
- ASUS PRIME H510M-D
- Memory
- Samsung 16GB DDR4 3200MHz
- Graphics Card(s)
- Nvidia GeForce GTX 1660 SUPER
- Sound Card
- Onboard
- Monitor(s) Displays
- Samsung 24"
- Screen Resolution
- 1920 * 1080




