powercfg is the built-in tool that reads them. A new guide from TweakTown's Yasir Mahmood walks through the commands that show what woke a machine, what's allowed to wake it, what timers are set, what's keeping it awake, and what a Modern Standby laptop was doing while it looked asleep. His approach is to find the cause before changing any settings.Below is the full routine. Each step is checked against Microsoft's own documentation, with notes on what each result proves and what it doesn't.
Before you start: open an elevated terminal
Every command here needs admin rights. Press Win + X and choose Terminal (Admin). PowerShell and Command Prompt both work, but one later step uses a different syntax in each, and that's flagged when it comes up.
Microsoft describes powercfg as a tool for managing power plans and sleep states, controlling power for individual devices, and checking a system for common energy-efficiency and battery-life problems. Most people only ever use it to switch power plans.
Section summary: One admin terminal is all you need, and the whole diagnosis takes a few minutes.
Step 1: Ask what woke the PC last time
Run:
powercfg /lastwake
Microsoft's reference says this reports what woke the system from its last sleep transition. It only covers the most recent wake, so it's a starting point, not a full history.
The answer can be indirect. On Mahmood's desktop it named a PCI Express Root Port. A root port is a bridge between the chipset and whatever's plugged into it, so the real trigger sits behind it. On his machine that was most likely the Realtek network adapter. On your PC the same label could point to a different device in a different slot.
Sometimes there's no answer at all. His laptop reported a wake source count of zero. Microsoft Q&A has older threads where users hit the same wall: one user who had already disabled wake on every device said powercfg -lastwake showed no record of the wakes at all.
Fallback: Event Viewer
When /lastwake comes back empty, check the System log:
- Open Event Viewer.
- Go to Windows Logs > System and click Filter Current Log.
- Under Event sources, pick Power-Troubleshooter.
- Open an entry and read its Wake Source line.
A Microsoft Q&A answer confirms this event: Event ID 1 from Power-Troubleshooter is issued every time the system wakes up from sleep mode. In the examples posted on Microsoft's forum, the Wake Source line named specific devices, such as the ACPI Power Button or an HID-compliant mouse.
There's a limit to this. Mahmood reports that on a Modern Standby laptop the log usually says Unknown, so those owners should use the sleep study report in Step 5. "Unknown" means Windows couldn't attribute the wake. It doesn't mean nothing happened.
Section summary: /lastwake covers one wake event, and Event Viewer gives you more of the history. Treat a Root Port result as a hint, and treat "Unknown" as a gap in the record.
Step 2: See which devices are allowed to wake the PC
powercfg /devicequery wake_armed
Microsoft documents wake_armed as the list of devices currently configured to wake the system. That's different from wake_programmable, which lists every device whose wake setting you're allowed to change. Mahmood's desktop showed the usual three: keyboard, mouse and Realtek network adapter.
To revoke a device's wake permission, use its exact name in quotes:
powercfg /devicedisablewake "device name"
To restore it:
powercfg /deviceenablewake "device name"
Watch the spelling here. Microsoft's reference page lists the enable switch as /deviceenableawake, with an extra "a". TweakTown's guide and a Microsoft Q&A support answer both use /deviceenablewake. If one spelling fails on your build, run powercfg /? and use the switch it lists.
The point-and-click route
- Open Device Manager and right-click the device.
- Choose Properties and go to the Power Management tab.
- Clear Allow this device to wake the computer.
Some network adapters also offer Only allow a magic packet to wake the computer. That keeps remote Wake-on-LAN working while ignoring routine network traffic. Not every adapter has this option, so don't worry if yours doesn't.
Mahmood suggests leaving the keyboard armed, otherwise you'll be pressing the power button every morning. That's a convenience call, not a Windows requirement.
If disabling one device doesn't stop the wakes, a Microsoft support answer recommends disabling the listed devices one at a time until you find the culprit. It's slow, but it works.
Section summary: Check wake_armed, remove permission from the likely device, and test one change at a time.
Step 3: Hunt down wake timers
If the PC woke at a suspiciously regular time, suspect a timer rather than a device:
powercfg /waketimers
Microsoft says this lists the active wake timers, and that an enabled timer can wake the system from sleep or hibernation when it expires. You'll only see timers that are set when you run the command, not ones that have already fired.
On Mahmood's desktop the timer was the Maintenance Activator, with Automatic Maintenance scheduled for 2:00 AM. How-To Geek reports a similar default: Windows runs automatic maintenance tasks at 2:00 am every night if you're not using your computer. It's also set to wake your PC from sleep to run those tasks. The hour isn't fixed, though. Microsoft's older Windows 8 troubleshooting article describes a "Regular Maintenance" task set for 3:00 AM. In that case, /waketimers showed the timer was set by services.exe for a Task Scheduler maintenance job, and Windows Update had requested the wake.
Stop Automatic Maintenance from waking the PC
This switch isn't in Task Scheduler:
- Open Control Panel > System and Security > Security and Maintenance.
- Expand Maintenance and click Change maintenance settings.
- Clear Allow scheduled maintenance to wake up my computer at the scheduled time and click OK.
Microsoft's Windows 8 article gives the same fix, back when the setting lived under Action Center. The label hasn't changed, even though the menus around it have moved.
Ordinary scheduled tasks
Open Task Scheduler, find the task, and clear Wake the computer to run this task on its Conditions tab. A Microsoft Q&A answer confirms in Task Scheduler, go to the Conditions tab of the task and make sure "Wake the computer to run this task" is checked when you want a wake. To stop one, clear the same box.
Restrict wake timers for the whole power plan
- Press Win + R, type
powercfg.cpl, and press Enter. - Click Change plan settings, then Change advanced power settings.
- Expand Sleep > Allow wake timers.
- Set it to Important Wake Timers Only.
According to How-To Geek, this setting wakes your PC only for major Windows system events like a scheduled restart of your PC outside active hours following a Windows update. Don't expect separate battery and plugged-in options on a desktop. ElevenForum notes that desktop computers will not have separate On battery and Plugged in options available unless it has a data connection to a UPS.
You can also do this from the command line. A powercfg /query output posted on Microsoft Q&A shows the setting's alias is RTCWAKE, with Possible Setting Index: 000 Possible Setting Friendly Name: Disable Possible Setting Index: 001 Possible Setting Friendly Name: Enable Possible Setting Index: 002 Possible Setting Friendly Name: Important Wake Timers Only. For plugged-in power:
powercfg /setacvalueindex SCHEME_CURRENT SUB_SLEEP RTCWAKE 2
Use /setdcvalueindex for battery. Run powercfg /query afterward to confirm the change took.
Choosing "Important Wake Timers Only" instead of "Disable" is a tradeoff. It still allows update restarts, but it will also block a backup job you deliberately set to run at night. If you need that backup, XDA Developers suggests keeping wake timers on and making sure only that task has "Wake the computer to run this task" enabled in the Task Scheduler.
Section summary: /waketimers tells you whether a timer is responsible. Turn off the maintenance wake in Control Panel, turn off task wakes in Task Scheduler, and use the power-plan setting to restrict everything else.
Step 4: When the PC won't go to sleep
This is the opposite problem: the sleep timer passes and the PC stays on. Usually an app or driver has filed a power request. Microsoft's reference says power requests stop the computer from automatically turning off the display or entering low-power sleep. Run this while the problem is happening, because it only shows requests active at that moment:
powercfg /requests
Mahmood explains the output this way:
| Category | What it does |
|---|---|
| DISPLAY | Keeps the screen on |
| SYSTEM | Blocks sleep |
| EXECUTION | Lets a process keep running when Windows would otherwise pause it |
Each entry also has a tag: [PROCESS] for an app, [SERVICE] for a background service, [DRIVER] for a device driver.
Often the fix is closing a forgotten browser tab that's playing media. Mahmood's desktop was harder. Under SYSTEM it showed a [DRIVER] entry called Legacy Kernel Caller, a generic label that doesn't say where the request came from. Quitting iCUE and Armoury Crate didn't clear it, but closing Chrome did. On a later run, SYSTEM named the Realtek audio driver reporting an active audio stream, and closing Chrome cleared that too. His conclusion was that Chrome's audio was the cause.
This is one machine's result, not proof that Chrome or Realtek is usually to blame. It does show that the driver listed may only be passing along a request that started in an app.
Overrides
If an app should keep running but shouldn't hold the PC awake, set an override:
powercfg /requestsoverride process chrome.exe display
Microsoft's syntax is powercfg /requestsoverride [caller_type name request]. Caller types are process, service or driver. Request types are Display, System or Awaymode, and the one you use has to match the category the entry appeared under. Run /requestsoverride with no parameters to list your current overrides. To delete one, repeat the caller type and name and leave out the request type.
Be careful with overrides. They can block legitimate requests too, and an override on a video app could let the screen turn off halfway through a film. Mahmood advises against overriding a generic driver entry like Legacy Kernel Caller, because one label can cover more than one source.
Section summary: Run /requests while the PC is refusing to sleep. Close the obvious culprits first, and only use overrides for specific, identified callers.
Step 5: Sleep study for Modern Standby laptops
First check what kind of sleep your laptop uses:
powercfg /a
If the top of the list shows Standby (S0 Low Power Idle), you have Modern Standby. The laptop keeps doing small background jobs while it looks asleep. If it only lists Standby (S3), the sleep study report has much less to show you, so stick with Steps 1 through 3.
On Modern Standby machines, generate the report from PowerShell:
powercfg /sleepstudy /output "$env:USERPROFILE\Desktop\sleepstudy.html"
In Command Prompt, use %USERPROFILE% in place of $env:USERPROFILE. Microsoft says the report covers the last three days by default. Add /duration 7 for a full week.
How to read it
- Session table: each standby period, with its battery drain and a % LOW POWER STATE TIME column. Microsoft defines this as the share of time the chip spent in its deepest idle state, which it calls DRIPS.
- Top Offenders: the components that kept a session busy.
- Exit reason: what ended each session, such as a key press or the power button. It doesn't always name a specific device.
What counts as good? Microsoft's optimization guidance says a session should stay in the low-power state more than 90 percent of the time. That target comes from a controlled four-hour test on Wi-Fi, so treat it as a benchmark, not a pass/fail line for every real-world nap.
Mahmood's laptop had one 31-minute session at 0%, with the USB host controller listed as active 99% of the time. Microsoft's training material shows nearly the same pattern: an 11-minute session at 0% DRIPS with the USB 3.0 host controller active 99% of the time. Microsoft's explanation is that a host controller can only power down after every device attached to it enters a low-power state. If the controller stays active for minutes at a time, it usually means one attached USB device isn't entering selective suspend. The report names the controller, not the device behind it. To find the actual device, Microsoft uses a performance trace analyzed in its Windows Performance Analyzer tool. For home users, unplugging USB peripherals one at a time and re-running the sleep study is the practical way to narrow it down.
Section summary: powercfg /a tells you whether sleep study applies. On Modern Standby, look for sessions with low low-power percentages and check their Top Offenders. If the USB controller shows up, the cause is usually a device plugged into it.
The bigger picture
Two things stand out from this guide.
First, sleep has become much harder to troubleshoot. Wake permissions now come from several places at once: devices, network adapters, maintenance timers, scheduled tasks, apps and drivers filing requests, and on Modern Standby a laptop that never fully sleeps. Randomly changing power settings rarely fixes it. Diagnosing first usually does.
Second, these tools are old, which is a strength. The same commands show up in Microsoft support threads going back to Windows 7 and in Windows 8-era KB articles. For IT admins, that means the steps above work across a mixed fleet, and the sleep study HTML file is easy to attach to a help-desk ticket.
The data has gaps, and you should allow for them. /lastwake can come back empty, Event Viewer can say "Unknown," generic driver labels hide where requests come from, and sleep study can name a controller without naming the device. These tools narrow the search. They won't always give you a definite answer.
Quick checklist
powercfg /lastwake: what caused the most recent wake?- Event Viewer, Power-Troubleshooter source: the wake history.
powercfg /devicequery wake_armed: which devices are allowed to wake the PC? Disable them one at a time.powercfg /waketimers: is a timer responsible? Fix it in Maintenance settings, Task Scheduler, or the power plan's Allow wake timers setting.powercfg /requests, run while the PC won't sleep: who's keeping it awake?powercfg /a, then/sleepstudyon Modern Standby laptops: what happened while it looked asleep?
Once the PC is sleeping through the night, Mahmood suggests checking the wake_armed list every few months, especially after adding a new mouse or backup software, since either can quietly add a wake permission or timer. If a laptop drains battery too fast while it's awake, run powercfg /energy with your apps closed. Microsoft recommends running it when the system is idle, and it covers power use while awake, which sleep study doesn't.
References
- These powercfg commands explain why your PC wakes at night or won't sleep - TweakTown TweakTown · 2026-10-01T21:47:13+00:00
- Enable or Disable to Allow Wake Timers in Windows 11 elevenforum.com
- Powercfg command-line options | Microsoft Learn learn.microsoft.com