Device force restart explanation

cyber punk 20 Reputation points
2026-01-12T17:37:20.4533333+00:00

Hello Microsoft team,

We recently experienced unexpected forced reboots on our Intune-managed Windows 11 devices. The devices showed a message that Windows would shut down in 10 minutes, and Event Viewer recorded the following:

  • Event ID 1074 (User32) Process: omadmclient.exe Reason: Operating System: Reconfiguration (Planned)

MDM Event (DeviceManagement-Enterprise-Diagnostics-Provider)

Message1: QuickMachineRecoveryEnrolled  
Message2: Update  

After the reboot, we checked the device and confirmed:

reagentc /info shows Windows RE enabled

Quick Machine Recovery is OFF in Windows Settings (System → Recovery → Quick machine recovery)

So QMR itself was not enabled, but the OS recovery and resiliency components were clearly updated.

From our investigation, it appears that Microsoft rolled out the Windows Resiliency Platform (Quick Machine Recovery infrastructure) to the tenant, which updated WinRE and boot configuration, and that this required a planned reboot.

My questions:

Is “QuickMachineRecoveryEnrolled → Update” the event that indicates the Windows Resiliency Platform / QMR infrastructure was deployed or updated on the device?

Is it expected that Windows performs forced reboots when this resiliency platform is rolled out, even if Quick Machine Recovery is turned OFF in device settings?

Is this rollout controlled by Microsoft backend enablement, or is it triggered by Intune or security baselines?

Will similar reboots occur again when this platform is updated in the future?

We want to understand whether this behavior is expected and how to communicate it to users and administrators.

Thank you for your clarification.Hello Microsoft team,

We recently experienced unexpected forced reboots on our Intune-managed Windows 11 devices. The devices showed a message that Windows would shut down in 10 minutes, and Event Viewer recorded the following:

Event ID 1074 (User32)
Process: omadmclient.exe
Reason: Operating System: Reconfiguration (Planned)

MDM Event (DeviceManagement-Enterprise-Diagnostics-Provider)

Message1: QuickMachineRecoveryEnrolled  

After the reboot, we checked the device and confirmed:

reagentc /info shows Windows RE enabled

Quick Machine Recovery is OFF in Windows Settings (System → Recovery → Quick machine recovery)

So QMR itself was not enabled, but the OS recovery and resiliency components were clearly updated.

From our investigation, it appears that Microsoft rolled out the Windows Resiliency Platform (Quick Machine Recovery infrastructure) to the tenant, which updated WinRE and boot configuration, and that this required a planned reboot.

My questions:

Is “QuickMachineRecoveryEnrolled → Update” the event that indicates the Windows Resiliency Platform / QMR infrastructure was deployed or updated on the device?

Is it expected that Windows performs forced reboots when this resiliency platform is rolled out, even if Quick Machine Recovery is turned OFF in device settings?

Is this rollout controlled by Microsoft backend enablement, or is it triggered by Intune or security baselines?

Will similar reboots occur again when this platform is updated in the future?

We want to understand whether this behavior is expected and how to communicate it to users and administrators.

Thank you for your clarification.

Microsoft Security | Intune | Updates
0 comments No comments

1 answer

Sort by: Oldest
  1. AI answer

    2026-01-12T17:37:36.04+00:00

    The event message QuickMachineRecoveryEnrolled → Update indicates that the Windows Resiliency Platform (Quick Machine Recovery infrastructure) was indeed deployed or updated on the device. This is part of the process where the operating system's recovery and resiliency components are updated, which can necessitate a planned reboot.

    It is expected that Windows may perform forced reboots when this resiliency platform is rolled out, even if Quick Machine Recovery is turned off in device settings. The updates to the OS recovery components can require a restart to apply the changes effectively.

    The rollout of this infrastructure is typically controlled by Microsoft’s backend enablement rather than being directly triggered by Intune or security baselines. However, Intune can manage and enforce policies related to updates and reboots.

    Regarding future occurrences, similar reboots may happen again when updates to the Windows Resiliency Platform are rolled out. It's essential to communicate to users and administrators that these reboots are part of the update process for maintaining system recovery capabilities and that they may occur even when certain features are disabled in settings.


    References:

    AI-generated content may be incorrect. Read our transparency notes for more information.

    Was this answer helpful?

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.