AWS Security ChangesHomeSearch

AWS AWSEC2: Serial console SAC troubleshooting content moved to dedicated page

Service: AWSEC2 · 2026-09-27 · Documentation low

File: AWSEC2/latest/UserGuide/troubleshoot-using-serial-console.md

Summary

Removed the inline Special Admin Console (SAC) and boot menu troubleshooting sections (commands, screenshots, bcdedit disable steps) and replaced them with a short summary that cross-links to the new 'Troubleshoot your Windows instance using SAC' page. Pure documentation restructuring with no policy or behavior change.

Security assessment

The change only relocates/condenses troubleshooting instructions about SAC and the boot menu into a linked page; it does not describe a vulnerability, credential handling, or exposure change, so it is a low-severity editorial edit even though serial console access is a sensitive capability.

Evidence

+The Special Administration Console (SAC) capability of Windows provides a way to troubleshoot a Windows instance. By connecting to the instance's serial console and using SAC, you can interrupt the boot process and boot Windows in safe mode. For information about enabling, using, and disabling SAC and the boot menu, see [Troubleshoot your Windows instance using SAC](./troubleshoot-windows-sac.html).

Diff

diff --git a/AWSEC2/latest/UserGuide/troubleshoot-using-serial-console.md b/AWSEC2/latest/UserGuide/troubleshoot-using-serial-console.md
index e71516800..af8bf2b92 100644
--- a//AWSEC2/latest/UserGuide/troubleshoot-using-serial-console.md
+++ b//AWSEC2/latest/UserGuide/troubleshoot-using-serial-console.md
@@ -136,146 +136 @@ The command that you use for sending a break request might be different dependin
-The Special Admin Console (SAC) capability of Windows provides a way to troubleshoot a Windows instance. By connecting to the instance's serial console and using SAC, you can interrupt the boot process and boot Windows in safe mode.
-
-###### Note
-
-If you enable SAC on an instance, the EC2 services that rely on password retrieval will not work from the Amazon EC2 console. Windows on Amazon EC2 launch agents (EC2Config, EC2Launch v1, and EC2Launch v2) rely on the serial console to execute various tasks. These tasks do not perform successfully when you enable SAC on an instance. For more information about Windows on Amazon EC2 launch agents, see [Configure your Amazon EC2 Windows instance](./ec2-windows-instances.html). If you enable SAC, you can disable it later. For more information, see Disable SAC and the boot menu.
-
-###### Tasks
-
-  * Use SAC
-
-  * Use the boot menu
-
-  * Disable SAC and the boot menu
-
-
-
-
-### Use SAC
-
-###### To use SAC
-
-  1. [Connect to the serial console.](./connect-to-serial-console.html)
-
-If SAC is enabled on the instance, the serial console displays the `SAC>` prompt.
-
-![SAC prompt displayed in the serial console.](/images/AWSEC2/latest/UserGuide/images/win-boot-3.png)
-
-  2. To display the SAC commands, enter ?, and then press **Enter**.
-
-Expected output
-
-![SAC command prompt displaying available commands.](/images/AWSEC2/latest/UserGuide/images/win-boot-4.png)
-
-  3. To create a command prompt channel (such as `cmd0001` or `cmd0002`), enter cmd, and then press **Enter**.
-
-  4. To view the command prompt channel, press **ESC** , and then press **TAB**.
-
-Expected output
-
-![The command prompt channel.](/images/AWSEC2/latest/UserGuide/images/win-boot-5.png)
-
-  5. To switch channels, press **ESC+TAB+channel number** together. For example, to switch to the `cmd0002` channel (if it has been created), press **ESC+TAB+2**.
-
-  6. Enter the credentials required by the command prompt channel.
-
-![The command prompt requiring credentials.](/images/AWSEC2/latest/UserGuide/images/win-boot-6.png)
-
-The command prompt is the same full-featured command shell that you get on a desktop, but with the exception that it does not allow the reading of characters that were already output.
-
-![A full-featured command shell.](/images/AWSEC2/latest/UserGuide/images/win-boot-7.png)
-
-
-
-
-**PowerShell can also be used from the command prompt.**
-
-Note that you might need to set the progress preference to silent mode.
-
-![PowerShell within the command prompt.](/images/AWSEC2/latest/UserGuide/images/win-boot-8.png)
-
-### Use the boot menu
-
-If the instance has the boot menu enabled and is restarted after connecting through SSH, you should see the boot menu, as follows.
-
-![Boot menu in the command prompt.](/images/AWSEC2/latest/UserGuide/images/win-boot-1.png)
-
-**Boot menu commands**
-
-ENTER
-    
-
-Starts the selected entry of the operating system.
-
-TAB
-    
-
-Switches to the Tools menu.
-
-ESC
-    
-
-Cancels and restarts the instance.
-
-ESC followed by 8
-    
-
-Equivalent to pressing **F8**. Shows advanced options for the selected item.
-
-ESC key + left arrow
-    
-
-Goes back to the initial boot menu.
-
-The ESC key alone does not take you back to the main menu because Windows is waiting to see if an escape sequence is in progress.
-
-![Advanced boot options.](/images/AWSEC2/latest/UserGuide/images/win-boot-2.png)
-
-### Disable SAC and the boot menu
-
-If you enable SAC and the boot menu, you can disable these features later.
-
-Use one of the following methods to disable SAC and the boot menu on an instance.
-
-PowerShell
-    
-
-###### To disable SAC and the boot menu on a Windows instance
-
-  1. [Connect](./connecting_to_windows_instance.html) to your instance and perform the following steps from an elevated PowerShell command line.
-
-  2. First disable the boot menu by changing the value to `no`.
-    
-        bcdedit /set '{bootmgr}' displaybootmenu no
-
-  3. Then disable SAC by changing the value to `off`.
-    
-        bcdedit /ems '{current}' off
-
-  4. Apply the updated configuration by rebooting the instance.
-    
-        shutdown -r -t 0
-
-
-
-
-Command prompt
-    
-
-###### To disable SAC and the boot menu on a Windows instance
-
-  1. [Connect](./connecting_to_windows_instance.html) to your instance and perform the following steps from the command prompt.
-
-  2. First disable the boot menu by changing the value to `no`.
-    
-        bcdedit /set {bootmgr} displaybootmenu no
-
-  3. Then disable SAC by changing the value to `off`.
-    
-        bcdedit /ems {current} off
-
-  4. Apply the updated configuration by rebooting the instance.
-    
-        shutdown -r -t 0
-
-
-
+The Special Administration Console (SAC) capability of Windows provides a way to troubleshoot a Windows instance. By connecting to the instance's serial console and using SAC, you can interrupt the boot process and boot Windows in safe mode. For information about enabling, using, and disabling SAC and the boot menu, see [Troubleshoot your Windows instance using SAC](./troubleshoot-windows-sac.html).