Technical support

Installing Windows 10 Feature Updates on an Full Disk Encrypted (FDE) system
Article ID: KB379 email a link to this article
Please note: As of The Creators Update (1703), users can convert the boot mode of their system from MBR to UEFI in place.
This is not supported by ESET Endpoint Encryption.


When installing a Windows 10 Feature Update,

You see the following:

0xC1900101 - 0x20017

The installation failed in the SAFE_OS phase with an error during BOOT operation.


This error message is shown when Windows fails to install a Feature update on a Full Disk Encrypted (FDE) Workstation. Windows will fail to install a Feature Update if you do not specify the location of the encryption drivers as part of the installation process.

Solution 1:

ESET Endpoint Encryption (EEE) has a preset SetupConfig.ini file which specifies the necessary parameters to allow Windows to install Feature Updates seamlessly through the built-in Windows Update mechanism found in Settings. To update in this manner, first ensure you are running the latest version of EEE, then search for Check for updates in the Start Menu and follow the shortcut to the Windows Settings.

Solution 2:

If you have are attempting to upgrade Windows using a new Windows ISO file, then you must follow this article instead: 

KB462 - How to manually install Windows 10 Feature Updates on an Full Disk Encrypted (FDE) system

Related Information:

KB465 - Technical Details regarding DESlock+ and Windows Feature Updates (version 4.9.0+)

Keywords: redstone 1, 14385 1607 14393 1703 1709 reflect, drivers reflectdrivers reflectdrivers disable windows ten FDE feature update anniversary creator's update creators update fall 1809

We use cookies on our website to enhance your browsing experience. Read more