In the Windows Service Control Manager, how do the Automatic, Automatic (Delayed Start), Manual and Disabled start types differ, and what problem does delayed start solve?
answer
- a number in the service's Start value
- boot, system, auto, demand, disabled
- stopped is not the same as off
- two minutes and lower priority
- let the logon screen breathe
basics
~20 sAutomatic starts a service during boot, Manual only when something requests it, and Disabled blocks starting at all. Automatic (Delayed Start) still starts unattended but after the automatic wave, at lowered priority, so it stops slow services from delaying logon.
solid answer
~50 sThe start type lives in the service's registry key as the `Start` value and tells the Service Control Manager *when* to launch it. `Automatic` means the SCM starts it as part of the boot sequence, before anyone logs on. `Manual` — demand start — means the SCM starts it only when something asks: an administrator, a dependent service, or a trigger. `Disabled` means the SCM refuses to start it at all, even on explicit request, which is the difference between disabling a service and merely stopping it. `Automatic (Delayed Start)` is an automatic service flagged with `DelayedAutostart`; the SCM launches it after the automatic wave has finished — about two minutes after boot by default — and initially runs its process at reduced CPU, I/O and memory priority. That exists so non-urgent background services stop competing with the boot path and slowing the logon screen. Modern Windows refines this further with trigger-start services, which stay stopped until a specific event occurs.
code
powershell · 8 linesGet-CimInstance Win32_Service |
Where-Object { $_.StartMode -eq 'Auto' } |
Select-Object Name, StartMode, DelayedAutoStart, StartName |
Sort-Object DelayedAutoStart, Name
# Move a non-critical service off the boot critical path
sc.exe config Spooler start= delayed-auto
sc.exe qc Spoolergo deeper
Be able to name the four start types you see in services.msc and say which ones run without anyone logging on. Know that Disabled, not Stopped, is what survives a reboot.
Explain that the start type is the Start DWORD in the service's registry key, that delayed start is auto-start plus a DelayedAutostart flag with a default two-minute delay and lowered process priority, and why boot/system values are driver-only.
Demonstrate the judgment: which services belong off the boot critical path, when trigger start beats delayed start, and how a disabled dependency produces a misleading boot failure in an unrelated service.
Own the startup profile of a standard image — what is allowed to be automatic at all, how boot-time-to-usable is measured and defended, and how hardening baselines and dependency chains are validated before the image ships.
## Where the setting actually lives Every service is a registry key under `HKLM\SYSTEM\CurrentControlSet\Services\<name>`, and the start type is a `REG_DWORD` value named `Start`: | Start | Constant | Meaning | |---|---|---| | 0 | SERVICE_BOOT_START | Loaded by the boot loader — drivers only | | 1 | SERVICE_SYSTEM_START | Loaded during kernel init — drivers only | | 2 | SERVICE_AUTO_START | Started by the SCM during boot | | 3 | SERVICE_DEMAND_START | Started on request ("Manual") | | 4 | SERVICE_DISABLED | Cannot be started | Values 0 and 1 are for kernel-mode drivers, which are also "services" as far as the SCM's database is concerned — that is why a driver and a user-mode service share a namespace. A delayed-start service is `Start = 2` **plus** a `DelayedAutostart` `REG_DWORD` of 1; it is not a fifth start value. ## What the SCM does at boot After the kernel and drivers are up, the SCM (`services.exe`) walks its database and starts every auto-start service, honouring the dependency graph in each service's `DependOnService` value and the load-ordering groups in `HKLM\SYSTEM\CurrentControlSet\Control\ServiceGroupOrder`. Only when that wave has settled does it turn to the delayed-start set, after an additional delay — 120 seconds by default, adjustable via the `AutoStartDelay` value under `HKLM\SYSTEM\CurrentControlSet\Control`. The delay is only half of the mechanism. Windows also starts a delayed-start service's process in a background processing mode: reduced thread priority, reduced memory priority and throttled I/O priority, lifted once initialisation finishes. So even after it launches, it yields to whatever the user is doing. ## Why delayed start exists The symptom it was invented to fix is a machine that reaches the logon screen and is then useless for a minute because a dozen updaters, telemetry agents and indexing services are all hammering the disk. Marking those delayed removes them from the critical path without giving up unattended startup — nobody has to log on for them to run. The rule of thumb: if nothing else depends on the service and a two-minute wait is harmless, delayed is the right default. If something depends on it, or it must be listening before the first client connects, it stays plain automatic. ## Manual is not "off" A manual service is fully installed and fully permitted to run; it simply waits. It starts when an administrator starts it, when a service that lists it in `DependOnService` starts, or when an application calls `StartService` on it — many COM and RPC-activated Windows services work exactly this way. Disabled is the real off switch, and it is the one that survives a reboot: stopping a service leaves it automatic and it comes back at next boot, while disabling it does not, and an explicit start attempt fails with "the service cannot be started because it is disabled". ## Trigger start Since Windows 7 / Server 2008 R2, a service can be *trigger-started*: left at demand start but registered to launch when a defined event occurs — a device of a given class arriving, the machine joining or leaving a domain, an IP address becoming available, a firewall port opening, a specific ETW event firing. `sc.exe qtriggerinfo <name>` shows a service's triggers. This is strictly better than automatic for anything that only matters in a particular condition, because a service that never starts consumes no memory and exposes no attack surface. ## Changing and inspecting it ``` sc.exe qc W32Time sc.exe config W32Time start= delayed-auto sc.exe config W32Time start= disabled ``` `sc.exe` requires the space after `start=` — the token before the space is the parameter name. From PowerShell, `Get-Service` shows `StartType`, and `Set-Service -StartupType` changes it; `AutomaticDelayedStart` is accepted by `Set-Service` in PowerShell 6 and later but not in Windows PowerShell 5.1, where you fall back to `sc.exe` or a direct registry write. `Get-CimInstance Win32_Service | Select-Object Name, StartMode, DelayedAutoStart, StartName` gives the whole picture including which account each runs as. ## The hardening angle Baselines like the CIS benchmarks express "turn this off" as *disabled*, not *stopped*, precisely because stopping is not durable. When you disable a service, check what depends on it: a dependent automatic service whose dependency is disabled fails to start at boot and reports a dependency error rather than anything that names the real cause.
- You stop a service to take it out of service for the weekend. What happens at the next reboot?If its start type is still Automatic, it starts again at boot — stopping only affects the current run. To keep it down across reboots you set the start type to Disabled, which also causes explicit start attempts to fail rather than silently succeeding. Disabled is the durable off switch; stopped is a transient state.
- Why would you choose trigger start over Automatic (Delayed Start)?Delayed start still runs the service on every boot, just later. A trigger-started service does not run at all until its condition occurs — a device arriving, an IP address becoming available, a domain join. That saves memory and removes attack surface on machines where the condition never happens, which is why several Windows services ship this way.
- An automatic service reports a dependency failure at boot. Where do you look first?At the services named in its `DependOnService` value. If one of them has been set to Disabled — often by a hardening baseline — the SCM refuses to start the dependent and reports the dependency error, which never names the real culprit clearly. Check the whole dependency chain's start types before assuming the service itself is broken.
saying these in an interview costs you the question
- Says stopping a service keeps it off after reboot
- Thinks Manual means the service is broken or unused
- Believes delayed start is just a fixed sleep with no priority change
- Treats Disabled and Stopped as the same state
- Claims Automatic guarantees the service is running now