Bootrec /fixboot Access Is Denied: How to Fix It on UEFI PCs
If you’re trying to repair a PC that won’t boot, you’ve probably been told to run bootrec /fixboot, only to get “Access is denied.” The bootrec /fixboot access is denied error is common on Windows 10 and Windows 11 PCs that use UEFI firmware and GPT disks, which is almost every PC sold in recent years. The good news is there’s a better tool for UEFI: bcdboot. Here’s how to use it carefully, without putting your files at risk.
Why bootrec /fixboot says access is denied
Bootrec’s /fixboot option writes a new boot sector to the system partition, a repair designed around the older BIOS and MBR way of booting. On UEFI PCs, the boot files live on a small FAT32 partition called the EFI System Partition, and /fixboot frequently fails against it with “Access is denied.” Microsoft doesn’t document a single cause, but the practical answer is the same: on UEFI, rebuild the boot files with bcdboot instead of fighting bootrec.
Before you start: protect your data
The commands in this guide rebuild boot files. Typed correctly, they don’t touch your documents, photos, or other personal files. But you’ll be using diskpart, which can also erase disks, so:
- Never run
clean,delete partition, orformatin diskpart while following this guide. - Don’t format the EFI System Partition, even though some guides suggest it. It isn’t needed for this fix.
- If the files matter and aren’t backed up, consider copying them off first. Booting another computer and connecting the drive to it, or booting from a Linux USB stick, both let you copy files before any repair.
Step 1: Open Command Prompt in Windows Recovery
You need a Command Prompt outside of normal Windows:
- If Windows reaches the recovery screen: choose Advanced options → Troubleshoot → Advanced options → Command Prompt.
- If it doesn’t: boot from a Windows installation USB, choose your language, click Repair your computer, then Troubleshoot → Advanced options → Command Prompt.
Step 2: Confirm the disk is GPT (UEFI)
Run:
diskpart
list disk
If there’s an asterisk (*) in the Gpt column for your system disk, it’s a GPT disk booting in UEFI mode, and the steps below apply. If there’s no asterisk, the disk is MBR. See the section on MBR systems further down, and our MBR vs GPT guide for background.
Step 3: Find the Windows volume and the EFI System Partition
Still in diskpart, run:
list vol
Look for two volumes:
- The Windows volume: NTFS, the largest partition, usually labeled with your Windows drive. In the recovery environment it’s often not C:, so note the letter it shows.
- The EFI System Partition: a small FAT32 volume, typically around 100 to 300 MB, often shown as Hidden or System in the Info column, with no letter.
If you can’t find an NTFS volume of the right size, or the Windows volume shows as RAW, stop here. That’s a drive or file-system problem, not a boot-file problem.
Step 4: Give the EFI partition a temporary letter
Replace 3 with the volume number of the FAT32 EFI partition from your own list. Use a letter that isn’t already taken. S is used here as an example:
select vol 3
assign letter=S
exit
Double-check that you selected the small FAT32 volume, not the Windows volume.
Step 5: Rebuild the boot files with bcdboot
First, confirm where Windows lives. If C: isn’t the Windows volume in your list, use the correct letter:
dir C:\Windows
If that lists Windows’ folders, run:
bcdboot C:\Windows /s S: /f UEFI
What each part means:
C:\Windowsis the Windows installation to copy boot files from./s S:is the EFI System Partition you just lettered./f UEFItells bcdboot to create UEFI boot files.
You should see “Boot files successfully created.” Close the Command Prompt, remove any USB drive, and restart. The temporary letter generally doesn’t carry over into normal Windows, but you can remove it first in diskpart with select vol 3 and remove letter=S if you prefer.
If the Windows volume is locked by BitLocker
If dir C:\Windows returns an access error and the drive is encrypted, unlock it before running bcdboot:
manage-bde -status
manage-bde -unlock C: -RecoveryPassword YOUR-48-DIGIT-KEY
Our guide on how to find your BitLocker recovery key explains where the key is likely stored.
What about bootsect /nt60 sys?
Some guides recommend running bootsect /nt60 sys and then bootrec /fixboot again. That command updates the boot code on the system partition, and it’s mainly relevant to older BIOS and MBR systems. On a UEFI PC, bcdboot is the more direct fix. Results with bootsect vary between Windows versions, so treat it as something to try on MBR systems rather than a guaranteed fix.
For an MBR disk, the usual sequence from the recovery Command Prompt is:
bootsect /nt60 sys
bootrec /fixmbr
bootrec /fixboot
bootrec /rebuildbcd
When the boot repair isn’t the real problem
Rebuilding boot files fixes a damaged boot setup. It won’t fix a failing drive. Look more closely at the hardware if:
- The disk doesn’t appear in
list disk, or appears with the wrong size. - The Windows volume shows as RAW or can’t be read.
- bcdboot fails with a read or write error.
- The PC was showing errors like INACCESSIBLE_BOOT_DEVICE or boot device not found before it stopped booting.
In those cases, check the drive’s health (see how to check hard drive health) before running more repair commands, and copy your files off first if the drive is still readable.
The bottom line
“Bootrec /fixboot access is denied” is common on UEFI PCs and doesn’t mean your files are gone. Instead of fighting bootrec, give the EFI System Partition a temporary letter in diskpart and rebuild the boot files with bcdboot C:\Windows /s S: /f UEFI, using the correct letters for your system. Never run clean or format in diskpart, and unlock BitLocker first if the drive is encrypted. If the disk itself looks unhealthy, protect the data before any more repairs.
If the drive behind the boot problem has failed, our desktop and PC data recovery service recovers the files for one flat $1,200 price per single device, with free prepaid shipping, and you pay nothing unless the recovery succeeds.
