Microsoft Keyboard Filter (MsKeyboardFilter) Service Defaults in Windows 11

Controls keystroke filtering and mapping.

The Microsoft Keyboard Filter service does not exist in:

Default Settings

Startup type: Disabled
Display name:Microsoft Keyboard Filter
Service name:MsKeyboardFilter
Service type:share
Error control:normal
Object:LocalSystem
Path:%SystemRoot%\system32\svchost.exe -k netsvcs -p
File:%SystemRoot%\System32\KeyboardFilterSvc.dll
Registry key:HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\MsKeyboardFilter
Privileges:
  • SeTcbPrivilege
  • SeAssignPrimaryTokenPrivilege

Default Behavior

Microsoft Keyboard Filter is a Win32 service. In Windows 11 it is disabled. When the Microsoft Keyboard Filter service is started, it logs on as LocalSystem and running in a shared process of svchost.exe. If Microsoft Keyboard Filter fails to start, the failure details will be recorded into Event Log. Then Windows 11 should boot up and notify the user about the MsKeyboardFilter service startup failure.

Restore Default Startup Configuration of Microsoft Keyboard Filter

1. Run the Command Prompt as an administrator.

2. Copy the commands below, paste them into the command window and press ENTER:

sc stop MsKeyboardFilter
sc config MsKeyboardFilter start= disabled

3. Close the command window and restart the computer.

The MsKeyboardFilter service is using the KeyboardFilterSvc.dll file that is located in the C:\Windows\System32 directory. If the file is removed or corrupted, read this article to restore its original version from Windows 11 installation media.