• System Protection (Restore Points)

    From Brian Gregory@3:633/10 to All on Friday, July 31, 2026 01:08:29
    Windows 11 25H2 26200.8973.

    Something keeps setting the amount of my C: drive set aside for System Protection to 2%.

    I want it set to 10%.

    Has anyone any idea what might be doing this on two different PCs I own???

    --
    Brian Gregory (in England).


    --- PyGate Linux v1.5.19
    * Origin: Dragon's Lair, PyGate NNTP<>Fido Gate (3:633/10)
  • From sticks@3:633/10 to All on Thursday, July 30, 2026 19:18:19
    On 7/30/2026 7:08 PM, Brian Gregory wrote:
    Windows 11 25H2 26200.8973.

    Something keeps setting the amount of my C: drive set aside for System Protection to 2%.

    I want it set to 10%.

    Has anyone any idea what might be doing this on two different PCs I own

    googles answer:

    The culprit is a newly introduced feature in Windows 11 called
    "Point-in-time restore", which actively overrides and resets your
    classic System Protection slider.

    Why This Is Happening In your specific build of Windows 11 25H2,
    Microsoft bundles a modern Point-in-time restore mechanism into the
    Settings app. Even though it looks different from the legacy Control
    Panel interface, both features share the exact same underlying VSS
    (Volume Shadow Copy) storage pool on your C: drive.The new
    "Point-in-time restore" feature has its own maximum storage slider,
    which defaults to roughly 2% to 3%. Windows periodically runs a
    background maintenance task that forces the VSS pool to match the modern feature's configuration. Every time this task triggers, it silently
    overwrites your 10% setting back down to its own ~2% default,
    unfortunately purging your older restore points along with it.

    How to Fix It Permanentely. To keep your storage pool at 10%, you have
    to change the setting through the modern interface so Windows stops
    fighting itself.Open the Settings app (Win + I).Navigate to System > Recovery.Look for the Point-in-time restore section and select View or
    edit (or click into its configuration menu).Adjust the Disk usage slider inside this menu to your preferred capacity.Once you save the change
    here, the system will lock that value into the shared pool, and your
    classic System Protection slider will finally stay where you want it.


    --
    Science Doesn?t Support Darwin. Scientists Do


    --- PyGate Linux v1.5.19
    * Origin: Dragon's Lair, PyGate NNTP<>Fido Gate (3:633/10)
  • From VanguardLH@3:633/10 to All on Thursday, July 30, 2026 23:00:07
    Brian Gregory <void-invalid-dead-dontuse@email.invalid> wrote:

    Windows 11 25H2 26200.8973.

    Something keeps setting the amount of my C: drive set aside for System Protection to 2%.

    I want it set to 10%.

    Has anyone any idea what might be doing this on two different PCs I own???

    Unclear is if what you state is about the reserve space versus the used
    space reserved for SR points. When looking at SR configurations (a
    per-drive setting), are you looking at Current Usage, or at Max Usage?

    You also don't state how much free space there is on the drive where SR
    is enabled. SR is a per-drive setting. Some drives can have it
    enabled, so have it disabled, and the amount for Max Usage (and Current
    Usage) can be different for each drive. Windows requires a minimum free
    space on the system drive for its own use outside of SR points. You
    can't be trying to use all available free space on a drive to dedicate
    to SR points storage.

    SR points are automatically discarded when they reach 60 days of age.
    No matter how much you set for reserve space, SR points will expire
    based on age, not based on available free space within the SR storage
    quota. SR points always expired, but now they expire sooner.

    https://www.windowslatest.com/2025/06/21/windows-11-24h2-system-restore-points-now-expire-after-60-days-microsoft-confirms/

    The SR backups used to expire when there wasn't sufficient remaining
    capacity in the specified reserve storage for SR points. In Windows 11,
    that changed to 60 days for expiration. I'm not sure this Win11 change
    is reflected into earlier versions of Windows.

    I don't bother with SR points, and instead use a 3rd-party imaging
    backup program to let me restore the EXACT same prior state of a drive.
    SR does not restore back to a prior state of a drive. It restores only
    files, and only the system files. It will not eradicate malware in
    other (non-system/app) files. It will not undo any corruption of other
    files. It's to get Windows working again, but a restore does not
    guarantee the system fileset is in full sync at some update level.

    System Restore should NOT be viewed as a backup scheme. It is merely an [attempt at a] recovery scheme. It might work, but not fix other
    problems. It might not work (the typical result). It wastes disk
    space. If you want to completely heal your drive, save image backups.
    The image backups should be scheduled. Anytime user interventions is
    required means the image backups are often missing, or so long ago that
    a restore results in severe loss of data or apps. Don't do the backups yourself. Schedule them. The granularity of those backups depends on
    how much you can afford to lose, and how much storage space you have for
    the image files.

    --- PyGate Linux v1.5.19
    * Origin: Dragon's Lair, PyGate NNTP<>Fido Gate (3:633/10)
  • From Brian Gregory@3:633/10 to All on Friday, July 31, 2026 14:00:33
    On 31/07/2026 01:18, sticks wrote:
    On 7/30/2026 7:08 PM, Brian Gregory wrote:
    Windows 11 25H2 26200.8973.

    Something keeps setting the amount of my C: drive set aside for System
    Protection to 2%.

    I want it set to 10%.

    Has anyone any idea what might be doing this on two different PCs I own

    googles answer:

    The culprit is a newly introduced feature in Windows 11 called "Point- in-time restore", which actively overrides and resets your classic
    System Protection slider.

    Why This Is Happening In your specific build of Windows 11 25H2,
    Microsoft bundles a modern Point-in-time restore mechanism into the
    Settings app. Even though it looks different from the legacy Control
    Panel interface, both features share the exact same underlying VSS
    (Volume Shadow Copy) storage pool on your C: drive.The new "Point-in-
    time restore" feature has its own maximum storage slider, which defaults
    to roughly 2% to 3%. Windows periodically runs a background maintenance
    task that forces the VSS pool to match the modern feature's
    configuration. Every time this task triggers, it silently overwrites
    your 10% setting back down to its own ~2% default, unfortunately purging your older restore points along with it.

    How to Fix It Permanentely.ÿ To keep your storage pool at 10%, you have
    to change the setting through the modern interface so Windows stops
    fighting itself.Open the Settings app (Win + I).Navigate to System > Recovery.Look for the Point-in-time restore section and select View or
    edit (or click into its configuration menu).Adjust the Disk usage slider inside this menu to your preferred capacity.Once you save the change
    here, the system will lock that value into the shared pool, and your
    classic System Protection slider will finally stay where you want it.



    Thank you.

    --
    Brian Gregory (in England).

    --- PyGate Linux v1.5.19
    * Origin: Dragon's Lair, PyGate NNTP<>Fido Gate (3:633/10)
  • From sticks@3:633/10 to All on Friday, July 31, 2026 08:30:40
    On 7/31/2026 8:00 AM, Brian Gregory wrote:
    On 31/07/2026 01:18, sticks wrote:

    ---snip---

    How to Fix It Permanentely.ÿ To keep your storage pool at 10%, you
    have to change the setting through the modern interface so Windows
    stops fighting itself.Open the Settings app (Win + I).Navigate to
    System > Recovery.Look for the Point-in-time restore section and
    select View or edit (or click into its configuration menu).Adjust the
    Disk usage slider inside this menu to your preferred capacity.Once you
    save the change here, the system will lock that value into the shared
    pool, and your classic System Protection slider will finally stay
    where you want it.



    Thank you.

    Yep, Mine was down at 2% also. I raised mine up a bit too as disk space
    is available for me.


    --
    Science Doesn?t Support Darwin. Scientists Do


    --- PyGate Linux v1.5.19
    * Origin: Dragon's Lair, PyGate NNTP<>Fido Gate (3:633/10)
  • From s|b@3:633/10 to All on Friday, July 31, 2026 16:26:21
    On Fri, 31 Jul 2026 01:08:29 +0100, Brian Gregory wrote:

    Windows 11 25H2 26200.8973.

    Something keeps setting the amount of my C: drive set aside for System Protection to 2%.

    I want it set to 10%.

    Has anyone any idea what might be doing this on two different PCs I own???

    I haven't, I'm sorry. But just a suggestion since my experience with
    System Restore is overall negative; it leaves stuff behind when it
    "restores".

    Why don't you turn it off and create your own images? I'm using Macrium
    Reflect Free (the last free version 8.*), but there's also Hasleo Backup
    Suite Free:

    <https://www.easyuefi.com/backup-software/backup-suite-free.html>

    It lets you create backup images and when you restore an image
    everything will be as it was when you made the image. No crap left
    behind.

    --
    s|b

    --- PyGate Linux v1.5.19
    * Origin: Dragon's Lair, PyGate NNTP<>Fido Gate (3:633/10)
  • From Mark Lloyd@3:633/10 to All on Friday, July 31, 2026 16:55:19
    On Thu, 30 Jul 2026 23:00:07 -0500, VanguardLH wrote:

    [snip[

    System Restore should NOT be viewed as a backup scheme. It is merely an [attempt at a] recovery scheme. It might work, but not fix other
    problems. It might not work (the typical result). It wastes disk
    space. If you want to completely heal your drive, save image backups.
    The image backups should be scheduled. Anytime user interventions is required means the image backups are often missing, or so long ago that
    a restore results in severe loss of data or apps. Don't do the backups yourself. Schedule them. The granularity of those backups depends on
    how much you can afford to lose, and how much storage space you have for
    the image files.

    Scheduled backup may be a good idea, but it requires the backup device to
    be always connected to the PC. Removing the device except during backup
    would be better. For one thing, a virus can't infect a file on a
    disconnected device.

    --
    Mark Lloyd
    http://notstupid.us/

    Obey Psalms 137:9!

    --- PyGate Linux v1.5.19
    * Origin: Dragon's Lair, PyGate NNTP<>Fido Gate (3:633/10)
  • From Paul@3:633/10 to All on Friday, July 31, 2026 16:23:19
    On Fri, 7/31/2026 12:55 PM, Mark Lloyd wrote:
    On Thu, 30 Jul 2026 23:00:07 -0500, VanguardLH wrote:

    [snip[

    System Restore should NOT be viewed as a backup scheme. It is merely an
    [attempt at a] recovery scheme. It might work, but not fix other
    problems. It might not work (the typical result). It wastes disk
    space. If you want to completely heal your drive, save image backups.
    The image backups should be scheduled. Anytime user interventions is
    required means the image backups are often missing, or so long ago that
    a restore results in severe loss of data or apps. Don't do the backups
    yourself. Schedule them. The granularity of those backups depends on
    how much you can afford to lose, and how much storage space you have for
    the image files.

    Scheduled backup may be a good idea, but it requires the backup device to
    be always connected to the PC. Removing the device except during backup would be better. For one thing, a virus can't infect a file on a disconnected device.


    You could have a NAS that wakes up ten minutes before the backup,
    and do the backup over the network.

    Paul

    --- PyGate Linux v1.5.19
    * Origin: Dragon's Lair, PyGate NNTP<>Fido Gate (3:633/10)
  • From VanguardLH@3:633/10 to All on Friday, July 31, 2026 16:04:41
    Mark Lloyd <not.email@all.invalid> wrote:

    On Thu, 30 Jul 2026 23:00:07 -0500, VanguardLH wrote:

    [snip[

    System Restore should NOT be viewed as a backup scheme. It is merely an
    [attempt at a] recovery scheme. It might work, but not fix other
    problems. It might not work (the typical result). It wastes disk
    space. If you want to completely heal your drive, save image backups.
    The image backups should be scheduled. Anytime user interventions is
    required means the image backups are often missing, or so long ago that
    a restore results in severe loss of data or apps. Don't do the backups
    yourself. Schedule them. The granularity of those backups depends on
    how much you can afford to lose, and how much storage space you have for
    the image files.

    Scheduled backup may be a good idea, but it requires the backup device to
    be always connected to the PC. Removing the device except during backup would be better. For one thing, a virus can't infect a file on a disconnected device.

    I have 2 copies of backups: one on an always-attached USB HDD, and
    another on a USB HDD that is attached only when I run Syncback to sync
    the backups on the other USB drive to this one.

    However, the moment you connect an otherwise detached USB drive is the
    moment any malware can attack those "offsite" backup files, like
    ransomware renaming the backup files, encrypting them (even if already encrypted by the backup software), deleting them, etc. You think you're
    safe until the moment you plug in the otherwise disconnect drive.

    I use Macrium Reflect. I has a Guardian feature that blocks all access
    to the backup files. Only Reflect can access the backup files. Malware
    cannot rename, delete, or encrypt those files. In fact, I've got caught
    by Guardian when I tried to copy some backup files elsewhere. I had to
    disable Guardian, copy, and reenable Guardian.

    I did find a very small window of opportunity for malware to get around Guardian, like the UEFI code that Windows will run on startup.
    Microsoft added the UEFI rootkit mostly for software inventorying
    program where employers can monitor what its employees are putting on
    the company's workstations. I can supply my canned response on how the
    UEFI rootkit works. I've never been afflicated with it on any of my
    personal hosts, because no company IT admin touches my home computers,
    and I don't use sysprep images from any company (I do fresh installs).

    --- PyGate Linux v1.5.19
    * Origin: Dragon's Lair, PyGate NNTP<>Fido Gate (3:633/10)
  • From Mark Lloyd@3:633/10 to All on Saturday, August 01, 2026 16:33:20
    On Fri, 31 Jul 2026 16:23:19 -0400, Paul wrote:

    [snap]

    You could have a NAS that wakes up ten minutes before the backup,
    and do the backup over the network.

    Paul

    Yes. That could work. However, I can think of a few of problems:

    1. This means setting two timers. Some people will have trouble getting
    this right.

    2. The drive would need to be set up so your backup software can find it.

    3. There's a possibility of backing up an infected system. There's less
    chance of destroying a good backup with a bad one if you use TWO backup devices and alternate between then.

    4. What shuts down the NAS after doing backup?

    --
    Mark Lloyd
    http://notstupid.us/

    "Never build a dungeon you wouldn't be happy to spend the night in
    yourself. The world would be a happier place if more people remembered
    that." - Terry Pratchett

    --- PyGate Linux v1.5.19
    * Origin: Dragon's Lair, PyGate NNTP<>Fido Gate (3:633/10)
  • From Frank Slootweg@3:633/10 to All on Saturday, August 01, 2026 19:59:26
    Mark Lloyd <not.email@all.invalid> wrote:
    On Fri, 31 Jul 2026 16:23:19 -0400, Paul wrote:

    [snap]

    You could have a NAS that wakes up ten minutes before the backup,
    and do the backup over the network.

    Paul

    Yes. That could work. However, I can think of a few of problems:

    1. This means setting two timers. Some people will have trouble getting
    this right.

    The NAS, at least mine (Synology), doesn't need to be woken up before
    use. Just the first write (or read or whatever) will wake it up.

    2. The drive would need to be set up so your backup software can find it.

    A NAS is always set up (it's on your LAN) and accessible by its share
    name, \\<whatever>\<rest_of_path>.

    3. There's a possibility of backing up an infected system. There's less chance of destroying a good backup with a bad one if you use TWO backup devices and alternate between then.

    With image backup, you can have multiple copies on a single device/
    NAS. Of course that's no protection against device failure, but it is protection against the scenario you mention. The image backups are just
    big files. That one of the images contains an infected system doesn't
    make the image/file dangerous, just when you *restore* such an image,
    the excrements hit the rotating device.

    4. What shuts down the NAS after doing backup?

    On my just not accessing it makes it go to sleep after a settable
    timeout. Sleep not shutdown.I guess one could make it shutdown, but why?
    See VanguardLH's comments on Macrium's Guardian feature, with prevents
    any access - i.e. also by a virus - to Macrium images.

    Having said all that, *I* make *image* backup to alternating (on-site/ off-site) removable USB HDDs and different levels of *file level* backup
    to USB memory-stick, NAS, 'the cloud' (Google Drive) and these removable
    USB HDDs at different intervals (twice-daily, daily, weekly,
    three-monthly). This way, I always have a disaster recovery backup
    offsite and a differential backup of the most important stuff in the
    cloud, so I'm protected against things like fire, theft, etc..

    --- PyGate Linux v1.5.19
    * Origin: Dragon's Lair, PyGate NNTP<>Fido Gate (3:633/10)
  • From Paul@3:633/10 to All on Saturday, August 01, 2026 16:33:08
    On Sat, 8/1/2026 12:33 PM, Mark Lloyd wrote:
    On Fri, 31 Jul 2026 16:23:19 -0400, Paul wrote:

    [snap]

    You could have a NAS that wakes up ten minutes before the backup,
    and do the backup over the network.

    Paul

    Yes. That could work. However, I can think of a few of problems:

    1. This means setting two timers. Some people will have trouble getting
    this right.

    2. The drive would need to be set up so your backup software can find it.

    3. There's a possibility of backing up an infected system. There's less chance of destroying a good backup with a bad one if you use TWO backup devices and alternate between then.

    4. What shuts down the NAS after doing backup?


    There are obviously details to be worked there.

    The NAS needs an RTC (Real Time Clock), which is NTP
    synced to something.

    You would check the backup software, to see if it has
    a "Post-backup Script" you can code up. This would
    include a command to the NAS, to go back to sleep.
    The NAS should, at a minimum, spin down the drive when
    it is not in usage.

    You would not use Wake On LAN for the wakeup process,
    because some malware could sniff around for equipment
    to wake up.

    Such a scheme still has lots of exploit possibilities,
    and all we've done so far, is avoid leaving the drive
    running all the time. You might still need the
    Image Guardian feature or some other sort of Rube Goldberg
    scheme, to improve the protection against ransomware
    alteration.

    Macrium has the ability, to boot into its own WinRE.wim ,
    but since that is stored on the C: drive, I expect something
    can still get into that file and alter it.

    And a lot of these ideas, assume you're not using the
    computer at the time the backup is scheduled to run.

    All I can tell you, is things like Ransomware are extremely
    well designed, and when they hit their trip point (they
    can lay in wait for as long as a month), they wipe out
    your entire room. Then can worm into the other machines,
    if they haven't done that already. Altering or damaging
    your backup collection, is all part of their checklist.

    The people in the most danger, are those who own their
    own domain and chose to include their real email address
    in the GoDaddy registration. If you buy a domain, the
    registration should be "cloaked", so you will not
    start receiving phishing email to that address.

    Paul

    --- PyGate Linux v1.5.19
    * Origin: Dragon's Lair, PyGate NNTP<>Fido Gate (3:633/10)
  • From Paul@3:633/10 to All on Saturday, August 01, 2026 16:56:01
    On Sat, 8/1/2026 3:59 PM, Frank Slootweg wrote:

    Having said all that, *I* make *image* backup to alternating (on-site/ off-site) removable USB HDDs and different levels of *file level* backup
    to USB memory-stick, NAS, 'the cloud' (Google Drive) and these removable
    USB HDDs at different intervals (twice-daily, daily, weekly,
    three-monthly). This way, I always have a disaster recovery backup
    offsite and a differential backup of the most important stuff in the
    cloud, so I'm protected against things like fire, theft, etc..


    I might boot a Macrium CD and start my backup. The
    hard drive used for the backup, is added to the setup
    just before the offline backup. This makes the
    scheme purely manual.

    Doing it that way, doesn't solve all problems. It's
    just a basic way of trying to avoid the easy problems.

    The ransomware people are very good at what they do.
    Any theoretical attack you can think of, their "kit"
    already has code for that. There is a cottage industry
    in those kits, so not all the Black Hats have to be
    geniuses. They can buy the necessary materials from others.

    If you have your own web domain, like a registration
    with GoDaddy, don't forget to "cloak" your email address
    so the email address is not listed. This will reduce the
    amount of phishing email you might receive. The only case
    of Ransomware I've run into, is one USENETTER had a
    GoDaddy domain, a phishing email was sent to him
    (and likely thousands of others) and... he double
    clicked the attachment. And after that, his computer
    room was wiped out.

    Backups aren't as attractive as they once were, as
    the price of HDD has gone up since January. You would
    really want to pay for the backup software that features
    Incremental backups, just to reduce your storage costs.

    Paul

    --- PyGate Linux v1.5.19
    * Origin: Dragon's Lair, PyGate NNTP<>Fido Gate (3:633/10)