RPC Endpoint Mapper (RpcEptMapper) Service Defaults in Windows 11

Resolves RPC interfaces identifiers to transport endpoints. If this service is stopped or disabled, programs using Remote Procedure Call (RPC) services will not function properly.

Default Settings

Startup type: Automatic
Display name:RPC Endpoint Mapper
Service name:RpcEptMapper
Service type:share
Error control:normal
Group:COM Infrastructure
Object:NT AUTHORITY\NetworkService
Path:%SystemRoot%\system32\svchost.exe -k RPCSS -p
File:%SystemRoot%\System32\RpcEpMap.dll
Registry key:HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RpcEptMapper
Privileges:
  • SeChangeNotifyPrivilege
  • SeImpersonatePrivilege
  • SeCreateGlobalPrivilege

Default Behavior

RPC Endpoint Mapper is a Win32 service. In Windows 11 it starts automatically during the operating system startup. Then the RPC Endpoint Mapper service logs on as NT AUTHORITY\NetworkService and running in a shared process of svchost.exe. If RPC Endpoint Mapper fails to start, the failure details will be recorded into Event Log. Then Windows 11 should boot up and notify the user about the RpcEptMapper service startup failure.

Dependencies

If RPC Endpoint Mapper doesn't work properly, the following services will not start:

Restore Default Startup Configuration of RPC Endpoint Mapper

1. Run the Command Prompt as an administrator.

2. Copy the commands below, paste them into the command window and press ENTER:

sc config RpcEptMapper start= auto
sc start RpcEptMapper

3. Close the command window and restart the computer.

The RpcEptMapper service is using the RpcEpMap.dll file that is located in the C:\Windows\System32 directory. If the file is removed or corrupted, read this article to restore its original version from Windows 11 installation media.