{"id":36878,"date":"2025-01-16T23:15:28","date_gmt":"2025-01-16T22:15:28","guid":{"rendered":"http:\/\/159.69.82.204\/win\/?p=36878"},"modified":"2025-01-17T10:32:43","modified_gmt":"2025-01-17T09:32:43","slug":"windows-10-server-2022-sgrmbroker-service-no-longer-starts-after-jan-2025-update-kb5049981","status":"publish","type":"post","link":"https:\/\/borncity.com\/win\/2025\/01\/16\/windows-10-server-2022-sgrmbroker-service-no-longer-starts-after-jan-2025-update-kb5049981\/","title":{"rendered":"Windows 10\/Server 2022: SgrmBroker service no longer starts after Jan. 2025 update (KB5049981)"},"content":{"rendered":"<p><img decoding=\"async\" style=\"margin: 0px 10px 0px 0px; display: inline; float: left;\" title=\"Windows\" src=\"https:\/\/www.borncity.com\/blog\/wp-content\/uploads\/2021\/04\/Windows-klein.jpg\" alt=\"Windows\" width=\"200\" align=\"left\" \/>[<a href=\"https:\/\/www.borncity.com\/blog\/2025\/01\/15\/windows-10-server-2022-dienst-sgrmbroker-startet-nach-jan-2025-update-kb5049981-nicht-mehr\/\" target=\"_blank\" rel=\"noopener\">German<\/a>]Microsoft has distributed the security update KB5049981 for Windows 10 21H2-22H2 for the January 2025 Patchday (14.1.2025). After installing this update, administrators notice that the <em>SgrmBroker<\/em> service (broker for runtime monitoring of system monitoring) no longer starts. Administrators also notice the same behavior under Windows Server 2022. I will summarize the information I have in this regard.<\/p>\n<p><!--more--><\/p>\n<h2>Windows 10 Update KB5049981<\/h2>\n<p><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/vg05.met.vgwort.de\/na\/cba56de4ad044b8aa27a25caa457306a\" alt=\"\" width=\"1\" height=\"1\" \/>Cumulative Update <a href=\"https:\/\/support.microsoft.com\/help\/5049981\" target=\"_blank\" rel=\"noopener\">KB5049981<\/a> is available for Windows 10 version 21H2 (Enterprise and Education) and all Windows 10 22H2 variants. The update contains security fixes and updates the Windows Kernel Vulnerable Driver Blocklist file (DriverSiPolicy.p7b). I had reported in the blog post <a href=\"https:\/\/borncity.com\/win\/2025\/01\/15\/patchday-windows-10-11-updates-january-14-2025\/\">Patchday: Windows 10\/11 Updates (January 14, 2025)<\/a>.<\/p>\n<h2>SgrmBroker service no longer starts<\/h2>\n<p>German blog reader <em>armin<\/em> has responded promptly with <a href=\"https:\/\/www.borncity.com\/blog\/2025\/01\/15\/patchday-windows-10-11-updates-14-januar-2025\/#comment-205547\" target=\"_blank\" rel=\"noopener\">this comment<\/a> and writes that after installing the January 2025 security updates, the <em>SgrmBroker<\/em> service (broker for runtime monitoring of system monitoring) no longer starts.<\/p>\n<p>The name System <em>Guard Runtime Monitor<\/em> indicates that the service is part of System Guard and the exploit protection of Defender. You can find more information in <a href=\"https:\/\/medium.com\/@boutnaru\/the-windows-process-journey-sgrmbroker-exe-system-guard-runtime-monitor-broker-service-c4cc4628dd01\" target=\"_blank\" rel=\"noopener\">this article<\/a> and <a href=\"https:\/\/malwaretips.com\/blogs\/sgrmbroker-exe\/\" target=\"_blank\" rel=\"noopener\">here<\/a>. And <a href=\"http:\/\/blog.syscall.party\/2022\/08\/02\/inside-windows-defender-system-guard-runtime-monitor.html\" target=\"_blank\" rel=\"noopener\">here<\/a> is also an analysis of the feature, that hasn't been updated for y yars.The reader writes in his comment that in the folder:<\/p>\n<p>C:\\WINDOWS\\system32\\<\/p>\n<p>four files with the corresponding name have the date of the update installation from timestamps. After uninstalling the January 2025 update, the problem was resolved.<\/p>\n<p>The reader has previously observed this behavior with some Windows 10 clients (update <a href=\"https:\/\/support.microsoft.com\/help\/5049981\" target=\"_blank\" rel=\"noopener\">KB5049981<\/a>) and Windows Server 2022 (update \u00a0<a href=\"https:\/\/support.microsoft.com\/help\/5049983\" target=\"_blank\" rel=\"noopener\">KB5049983<\/a>) in virtual machines (VMs), where the VMs were running under Hyper-V.<\/p>\n<p>This observation by the blog reader was confirmed by other blog readers. Bolko writes that the error code 0x80070005 (access denied) is thrown. This means that the service can no longer monitor the integrity of Windows &#8211; Microsoft has shot itself down.<\/p>\n<h2>Post on Microsoft Answers<\/h2>\n<p>On Microsoft Answers there is the thread <a href=\"https:\/\/answers.microsoft.com\/en-us\/windows\/forum\/all\/error-7023-service-control-managersystem-guard\/38c44edb-d206-4506-9ed4-eb164acb739c\" target=\"_blank\" rel=\"noopener\">Error 7023 Service Control Manager&#8230;.System Guard Runtime Monitor Broker.exe terminated<\/a>, in which an affected person also confirms the problem as of January 15, 2025. Affected are a HP Omen Desktop and a HP Envy Laptop with Windows 10 22H2.<\/p>\n<p>Since installing the January 2025 update KB5049981, the System Guard Runtime Monitor Broker service (SgrmBroker.exe) no longer starts. Event 7023 is displayed in the Event Viewer with the following data:<\/p>\n<pre>Log Name:      System\r\nSource:        Service Control Manager\r\nDate:          1\/14\/2025 3:48:16 PM\r\nEvent ID:      7023\r\nTask Category: None\r\nLevel:         Error\r\nKeywords:      Classic\r\nUser:          N\/A\r\nComputer:      DESKTOP-\r\nDescription:\r\n\r\nThe System Guard Runtime Monitor Broker service terminated with the following error:\r\n\r\n%%3489660935\r\n\r\nEvent Xml:\r\n&lt;Event xmlns=\"http:\/\/schemas.microsoft.com\/win\/2004\/08\/events\/event\"&gt;\r\n &lt;System&gt;\r\n\u00a0 &lt;Provider Name=\"Service Control Manager\" Guid=\"{555908d1-a6d7-4695-8e1e-26931d2012f4}\" EventSourceName=\"Service Control Manager\" \/&gt;\r\n&lt;EventID Qualifiers=\"49152\"&gt;7023&lt;\/EventID&gt;\r\n\u00a0\u00a0 &lt;Version&gt;0&lt;\/Version&gt;\r\n\u00a0\u00a0\u00a0 &lt;Level&gt;2&lt;\/Level&gt;\r\n\u00a0\u00a0\u00a0 &lt;Task&gt;0&lt;\/Task&gt;\r\n\u00a0 &lt;Opcode&gt;0&lt;\/Opcode&gt;\r\n[...}<\/pre>\n<p>Another affected person confirms this problem for Windows 10 and an administrator has posted the following screenshot from Windows Server 2022 online.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" title=\"System Guard Monitor Broker service can't start\" src=\"https:\/\/i.postimg.cc\/g0qLY1s0\/image.png\" alt=\"System Guard Monitor Broker service can't start\" width=\"640\" height=\"427\" \/><\/p>\n<p>On reddit.com, the problem with the broken service is also confirmed in <a href=\"https:\/\/www.reddit.com\/r\/Windows10\/comments\/1i1cl7o\/cumulative_updates_january_14th_2025\/\" target=\"_blank\" rel=\"noopener\">this thread<\/a> and in <a href=\"https:\/\/www.reddit.com\/r\/sysadmin\/comments\/1i0ym1n\/patch_tuesday_megathread_20250114\/\" target=\"_blank\" rel=\"noopener\">this thread<\/a>. It doesn't have such a direct impact if the service is no longer running &#8211; Windows can simply no longer determine its own integrity. Let's see when Microsoft will comment on this.<\/p>\n<p><strong>Similar articles<\/strong><br \/>\n<a href=\"https:\/\/borncity.com\/win\/2025\/01\/14\/microsoft-security-update-summary-january-14-2025\/\">Microsoft Security Update Summary (January 14, 2025)<\/a><br \/>\n<a href=\"https:\/\/borncity.com\/win\/2025\/01\/15\/patchday-windows-10-11-updates-january-14-2025\/\">Patchday: Windows 10\/11 Updates (January 14, 2025)<\/a><br \/>\n<a href=\"https:\/\/borncity.com\/win\/2025\/01\/15\/patchday-windows-server-updates-january-14-2025\/\">Patchday: Windows Server Updates (January 14, 2025)<\/a><br \/>\n<a href=\"https:\/\/borncity.com\/win\/2025\/01\/16\/patchday-microsoft-office-updates-january-2025\/\">Patchday: Microsoft Office Updates (January 2025)<\/a><\/p>\n<p><a href=\"https:\/\/borncity.com\/win\/2025\/01\/17\/review-windows-patchday-issues-january-2025\/\">Review: Windows Patchday issues January 2025<\/a><br \/>\n<a href=\"https:\/\/borncity.com\/win\/2025\/01\/16\/windows-10-server-2022-sgrmbroker-service-no-longer-starts-after-jan-2025-update-kb5049981\/\" rel=\"bookmark\">Windows 10\/Server 2022: SgrmBroker service no longer starts after Jan. 2025 update (KB5049981)<\/a><br \/>\n<a href=\"https:\/\/borncity.com\/win\/2025\/01\/17\/attention-problems-with-windows-january-2025-updates-and-citrix-environments-session-recordings\/\">Attention: Problems with Windows January 2025 updates and Citrix environments (session recordings)<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>[German]Microsoft has distributed the security update KB5049981 for Windows 10 21H2-22H2 for the January 2025 Patchday (14.1.2025). After installing this update, administrators notice that the SgrmBroker service (broker for runtime monitoring of system monitoring) no longer starts. Administrators also notice &hellip; <a href=\"https:\/\/borncity.com\/win\/2025\/01\/16\/windows-10-server-2022-sgrmbroker-service-no-longer-starts-after-jan-2025-update-kb5049981\/\">Continue reading <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[463,22,2],"tags":[166,2890,195,194],"class_list":["post-36878","post","type-post","status-publish","format-standard","hentry","category-issue","category-update","category-windows","tag-issues","tag-patchday-1-2025","tag-update","tag-windows"],"_links":{"self":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/posts\/36878","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/comments?post=36878"}],"version-history":[{"count":6,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/posts\/36878\/revisions"}],"predecessor-version":[{"id":36897,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/posts\/36878\/revisions\/36897"}],"wp:attachment":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/media?parent=36878"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/categories?post=36878"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/tags?post=36878"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}