Microsoft Security Core Boot Driver (MsSecCore) Service Defaults in Windows 11

Microsoft Security Core Boot Driver.

The Microsoft Security Core Boot Driver service exists only in:

Default Settings

Startup type: Boot
Display name:Microsoft Security Core Boot Driver
Service name:MsSecCore
Service type:kernel
Error control:normal
Path:%SystemRoot%\system32\drivers\msseccore.sys
Registry key:HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\MsSecCore

Default Behavior

Microsoft Security Core Boot Driver is a kernel driver. In Windows 11 it starts by the operating system Boot Loader before the Kernel initialization, as a part of the driver stack. If Microsoft Security Core Boot Driver fails to start, the failure details will be recorded into Event Log. Then Windows 11 should boot up and notify the user about the MsSecCore service startup failure.

Restore Default Startup Configuration of Microsoft Security Core Boot Driver

1. Run the Command Prompt as an administrator.

2. Copy the commands below, paste them into the command window and press ENTER:

sc config MsSecCore start= boot
sc start MsSecCore

3. Close the command window and restart the computer.

The MsSecCore service is using the msseccore.sys file that is located in the C:\Windows\system32\drivers directory. If the file is removed or corrupted, read this article to restore its original version from Windows 11 installation media.