A Windows service is a background program that runs under the Service Control Manager, performs one specific job for the operating system, and can be set to start automatically, on demand, or never. So what are Windows services and which can be disabled? Only a small group of feature-specific ones, and each one has a condition attached to it.
This guide covers what are Windows services and which can be disabled on Windows 10 and Windows 11, including how the startup types work, why stopping a service is not the same as disabling it, and how to undo a change that goes wrong. It applies to a desktop or laptop you own, not to a managed work machine where Group Policy will overwrite your settings.
One thing worth saying up front: on a modern machine with an SSD and 16 GB of RAM, disabling services rarely makes Windows feel dramatically faster. The wins people actually report are idle CPU and battery behaviour, quieter fans, and getting a security-relevant service turned off on a shared machine.
Table of Contents
- What Are Windows Services?
- Where services actually live
- Services are not startup apps or drivers
- The four tabs in a service’s Properties dialog
- How Do Windows Services Start and Stop?
- Which Windows Services Can Be Disabled?
- What are Windows services and which can be disabled? Five checks per service
- Services That Are Usually Safe to Disable or Set to Manual
- Windows Services You Should Not Disable Without a Specific Reason
- How to Disable a Windows Service Safely
- Through the Services console
- Through PowerShell
- How to Test Whether Disabling a Service Caused a Problem
- Frequently Asked Questions
- Which Windows services can I safely disable?
- Does setting a service to Manual mean it is disabled?
- Can I delete a Windows service outright?
- What happens if I disable all services in msconfig?
- Will disabling services actually make my PC faster?
- Why does a service I disabled come back after Windows Update?
- Conclusion
What Are Windows Services?

A Windows service is a program that Windows runs in the background, under its own account, whether or not you have an application open. Each one does a defined job such as printing, Bluetooth pairing, update downloads or firewall filtering, and each can be started, stopped, paused and configured independently of the program you click on.
The Service Control Manager (SCM) is the component that owns all of them. It reads each service’s stored configuration, starts services in the correct order at boot, restarts them when configured to do so, and reports their state back to anything that asks, including the Services console, PowerShell and Task Manager.
Where services actually live
You open the console with Win + R, type services.msc and press Enter. The list you see comes straight from the SCM database, and it includes services Microsoft ships, services your hardware vendor added, and services installed with third-party software.
Many services do not have a process of their own. They are hosted inside svchost.exe, a single Windows process that can host a dozen or more services at once, which is exactly why a CPU spike attributed to svchost tells you almost nothing until you expand it in Task Manager.
Services are not startup apps or drivers
A startup app is a program Windows launches when you sign in, managed under Task Manager’s Startup tab or Settings. A driver is kernel-mode code that talks to hardware. A service runs under the SCM, typically as LocalSystem or LocalService, and keeps running after you close whatever window you started it from.
That distinction matters because turning off a service is a different operation from uninstalling a startup app, and neither one touches a driver.
The four tabs in a service’s Properties dialog
General holds the startup type and the Stop button. Log On shows the account the service runs under and whether it can interact with the desktop. Recovery sets what happens on failure, such as restart the service or run a program. Dependencies lists both the services this one needs and the ones that break if it goes away, and it is the tab most people skip and should not.
How Do Windows Services Start and Stop?
Startup type is the setting that decides when the SCM starts a service. Changing it writes a new configuration, and that is where most of the confusion lives, so here is the plain version.
| Startup type | When Windows starts it | Typical use |
|---|---|---|
| Automatic | During boot, before most users sign in | Core networking, storage and security services |
| Automatic (Delayed Start) | Shortly after boot, once the desktop is settling | Update and telemetry services that would otherwise slow startup |
| Manual (Trigger Start) | Only when an app or another service asks for it | Features you use occasionally, such as printing or fax |
| Disabled | Never, and Windows will not start it on demand either | Services you have confirmed you do not need |
Automatic (Delayed Start) exists because so many machines installed it without noticing. Windows waits for the desktop to be usable before starting those services, so they cost you almost nothing at boot.
Manual does not mean switched off. The service stays stopped until something requests it, which is why a Manual printer service still prints the moment you open a document, and why a Manual service will happily start itself when an application looks for it.
Two startup concepts matter less day to day but explain odd behaviour. Boot-start drivers load before the operating system itself, and system-start services load in a defined order after it. Both are listed in services.msc but neither should be touched by anyone who has not read the specific Microsoft documentation for it.
| Action | Lasts until | Use it when |
|---|---|---|
| Stop | Reboot, or until something starts it again | You are testing, or a service is misbehaving right now |
| Set to Manual | Permanent, starts on demand | You use the feature occasionally |
| Set to Disabled | Permanent, will not start at all | You have confirmed the feature is not needed |
That middle row is the one most guides skip. Someone stops Print Spooler to fix a stuck print job, then a week later reboots and assumes the change was lost, or worse, they open the Properties dialog and disable it properly by accident.
Which Windows Services Can Be Disabled?
There is no universal list, because service behaviour changes between Windows editions, build versions and installation methods. The reliable answer is a framework you apply per service, and the framework takes about two minutes.
What are Windows services and which can be disabled? Five checks per service
Read the description. In services.msc, widen the Description column. If it names a feature you use, keep it. If it says the service runs only on a particular hardware type, check whether you have that hardware.
Check the publisher. The Path to executable column tells you who ships it. Microsoft services are the ones documented on Microsoft Learn; anything pointing into a vendor folder such as Intel, Realtek, ASUS or NVIDIA is a driver companion service, not a core Windows service.
Open the Dependencies tab. Anything listed under This service depends on must stay enabled, and anything listed under Services that depend on this service will break the moment you disable it. Disabling a parent in the chain takes its children down with it.
Look before you leap. If your reason is high CPU or memory, open Task Manager’s Processes tab, sort by CPU, and expand the svchost entry to find the offending service. Disable a service you have measured, not one you guessed at.
Match the service to the feature. Ask whether you use printing, Bluetooth, fax, a projector, a phone link, a pen, a maps app or a remote desktop connection. No printer means Print Spooler is dead weight. A laptop used on the train every day is a different machine from a desktop in a home lab.
If you cannot answer those five questions for a service, leave it on Automatic. An idle service costs almost nothing; a broken one costs you an afternoon.
Services That Are Usually Safe to Disable or Set to Manual
These are the services people ask about most, and each one is conditional. The verdict column assumes you genuinely do not use the feature.
| Service | What it does | Verdict | Condition |
|---|---|---|---|
| Print Spooler | Queues documents and holds the printing queue | Disable | No printer, no scanner, no PDF tool that prints |
| Fax | Legacy fax sending and receiving | Disable | Nothing sends or receives a physical fax |
| Remote Registry | Lets other tools edit the registry remotely | Disable | You never remote-registry-connect to this PC |
| Windows Search | Indexes files for fast search and Start menu results | Set to Manual | You accept slow search or rarely search files |
| Bluetooth Support Service | Bluetooth pairing and audio routing | Set to Manual | No Bluetooth mouse, keyboard, headphones or controller |
| Remote Desktop Services and Remote Desktop Configuration | Allows inbound remote connections | Disable | Nobody RDPs into the machine, or it is a kiosk |
| Connected User Experiences and Telemetry (DiagTrack) | Sends usage and diagnostic data to Microsoft | Disable, expect it to reset | Privacy priority outweighs diagnostics; Windows Update can restore it |
| Windows Insider Service | Opt-in to preview builds | Disable | You are not enrolled in Insider Program |
| OEM and driver vendor services | Intel, Realtek, NVIDIA, ASUS tuning and update helpers | Set to Manual | Not Disabled: vendor updaters and thermal behaviour often break. Intel Dynamic Tuning Technology telemetry is the one most often set to Manual for battery life |
Some names changed with the version. Phone Link replaced Your Phone, WalletService and DevicePicker no longer appear on every build, Windows 11 added WarpJITSvc for DirectX fallback rendering, and Widgets brings its own services. Check what your machine actually has rather than hunting for a name from a guide.
For third-party services, System Configuration is faster than services.msc. Run msconfig, go to the Services tab, tick Hide all Microsoft services, and you are left with only vendor software. Those are the ones safe to set to Disabled when you have removed the software they belong to.
Windows Services You Should Not Disable Without a Specific Reason
This is the list that matters most, because these services do not fail politely. Disabling one leaves you with a machine that cannot boot, cannot print, cannot patch, or cannot defend itself.
| Service | What breaks if you disable it |
|---|---|
| Remote Procedure Call (RPC) | A huge amount of Windows talks to everything else over RPC. Services that refuse to stop are usually protecting a dependency you did not read |
| DCOM Launcher Protocol Processor | Components that cannot start at all; error dialogs describing missing activation |
| Plug and Play | Hardware detection fails. No keyboard, no mouse, no display, no network adapter |
| Windows Update and BITS | The machine silently stops receiving security patches. BITS is also how Store apps download |
| Microsoft Defender Antivirus and Security Center | Real-time protection and the health dashboard go away |
| Windows Defender Firewall | Inbound connections are no longer filtered while the machine is on a network you do not control |
| Cryptographic Services | Certificate validation and many sign-in flows fail; HTTPS in some apps breaks |
| Windows Time | Clock drift breaks TLS, token authentication and anything that checks a date |
| Task Scheduler | Anything scheduled stops running, including some update and maintenance tasks |
| Audio Endpoint Builder and Windows Audio | No sound devices, no output, recording apps fail to start |
| Windows Event Log | No diagnostic history when you need it most, including during recovery |
| Windows Management Instrumentation (WMI) | Most admin and monitoring tools lose access to the machine |
You will see guides online telling you to disable Security Center and Windows Defender Firewall for performance. Do not. Those are not performance costs worth paying, a third-party antivirus does not restore the firewall unless it installs its own filter driver, and you cannot undo the damage quickly on a machine that has already been compromised.
Tech support communities repeat the same warning in different words: an unpatched machine with its firewall switched off is how people end up dealing with ransomware.
How to Disable a Windows Service Safely

Before changing anything, create a restore point. On Windows 10 press Win + R, type createa restorepoint and run it, then follow the wizard. It costs a couple of minutes and it is your only way back if you disable something the boot sequence depends on.
Through the Services console
Step 1. Press Win + R, type services.msc and press Enter. On Windows 11 you can also search for Services in the Start menu.
Step 2. Scroll to the service, right-click it and choose Properties.
Step 3. Read the Description and open the Dependencies tab before you change anything. This is the step that prevents the bad day.
Step 4. Set Startup type to Disabled, or Manual if you still need the feature occasionally. Click Apply.
Step 5. If the service is running and you want it stopped now, click Stop the service. Setting Disabled does not stop a running service by itself; it only applies at the next start.
Step 6. To undo it, set Startup type back to its original value and click Start the service if it was running when you started.
Through PowerShell
PowerShell gives you the same settings in a scriptable form, which is what you want on more than one machine. Run PowerShell as administrator.
Get-Service -Name Spooler
Get-Service | Where-Object {$_.StartType -eq 'Automatic'} | Select-Object Name, DisplayName
Stop-Service -Name Spooler
Set-Service -Name Spooler -StartupType Manual
Set-Service -Name Spooler -StartupType Automatic
For a fleet, the same commands run remotely against a list of machines, or the older sc.exe works too:
sc.exe query Spooler
sc.exe config Spooler start= demand
sc.exe config Spooler start= disabled
The space after start= in sc.exe is required. Leave it out and the command fails in a way that looks like a permissions problem but is not.
How to Test Whether Disabling a Service Caused a Problem
Treat every change as an experiment with a rollback, one service at a time. Changing four things at once means the reboot tells you nothing about which one mattered.
Record the current state. Note the service name, its startup type and whether it is running. That is your rollback value, and writing it down beats trying to remember it three reboots later.
Change one service, then test. Restart only when the change genuinely needs it, and then exercise the feature: print a test page, pair a Bluetooth mouse, open a shared folder, join a call.
Watch the right logs. Event Viewer under Windows Logs, System and Application will show a service failing to start, usually with an error code and the service name attached. In Task Manager, use the Services tab to confirm the service is actually stopped rather than merely set to start on demand.
Check the features that lean on services. Windows Update failing to install is a common symptom of a dependency you disabled. Same story for printing, audio, networking and Windows Hello.
If the machine will not boot after a mass change, boot into Safe Mode or the Recovery Environment. Windows 11 lets you open Command Prompt from Advanced Options; from there you can set the startup type back:
sc.exe config Spooler start= auto
sc.exe config PlugPlay start= auto
If you hit the msconfig trap, where every third-party service is disabled and nothing runs properly, boot into Safe Mode, open msconfig, go to the Services tab, untick Hide all Microsoft services, and set everything you disabled back to Automatic or Manual.
And if you would rather skip the whole exercise, Windows 10 and Windows 11 LTSC ship with far less installed from the start, which is why experienced admins pick them over trimming a retail build.
Frequently Asked Questions
Which Windows services can I safely disable?
Print Spooler, Fax, Remote Registry and Remote Desktop Services are the safest candidates, provided you have no printer, no fax line and nobody connects to the machine remotely. Windows Search and Bluetooth Support Service are better set to Manual than Disabled, because Windows will start them on demand when an app needs them. Windows Defender Firewall and Security Center should not be disabled.
Does setting a service to Manual mean it is disabled?
No. A Manual service stays stopped until another program or service asks Windows to start it, which is why a Manual Print Spooler still prints the moment you open a document. Disabled is the only startup type that stops Windows from starting the service at all. That difference is why Manual is the right choice for a feature you use occasionally and Disabled is right for one you never use.
Can I delete a Windows service outright?
Technically yes, but you should not. Removing a service entry from the SCM database leaves its files and registry keys behind and gives you no Properties dialog to change it back. If a service must go permanently, disable it, confirm nothing breaks, then look for the feature in Settings, Apps, or Turn Windows features on or off. Delete only third-party remnants, and never a Microsoft service.
What happens if I disable all services in msconfig?
Most third-party and some vendor services come back; Microsoft ones stay if you hid them first, so the machine usually still boots but loses audio, printing, Bluetooth and your security tooling. Boot into Safe Mode, run msconfig, go to the Services tab, untick Hide all Microsoft services, and set the ones you changed back to Automatic or Manual. This is why you change one service at a time and record the original value.
Will disabling services actually make my PC faster?
On a machine with an SSD and 16 GB of RAM, usually not much. Disabling services costs little CPU and memory, because many sit idle until triggered. The measurable wins are usually idle CPU, fan noise and battery life on a laptop, plus removing a network-facing service such as Remote Desktop on a shared machine. Check Task Manager before and after so you are not changing things for nothing.
Why does a service I disabled come back after Windows Update?
Feature updates and Microsoft components can rewrite service configuration, and a disabled Windows Update service gets restored as part of the repair itself. The same happens when an OEM updater reinstalls its own telemetry helper. If you need the setting to stick, apply it through Group Policy in gpedit.msc rather than only in services.msc, and expect to re-check the startup type after each large update.
Conclusion
Start with the service you have actually measured, read its description and its Dependencies tab, write down the current startup type, and create a restore point before you touch anything. Then change one optional service at a time, set it to Manual where you still use the feature, and keep the original value written down so the rollback takes ten seconds.
Windows Update, the firewall, Defender, RPC, Plug and Play and the security services stay on Automatic. Anything you cannot explain in a sentence is not ready to be disabled.


