mirror of
https://github.com/dockur/windows.git
synced 2026-10-09 02:44:34 +01:00
Compare commits
32
Commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
c8ff794df9 | ||
|
|
013ea27498 | ||
|
|
8fa0dacad0 | ||
|
|
ddd1785881 | ||
|
|
4ad4d9b121 | ||
|
|
9937f3b7e4 | ||
|
|
f444ddecc4 | ||
|
|
1e99833c8f | ||
|
|
c504d7c144 | ||
|
|
792ff0d7ec | ||
|
|
e0026b432d | ||
|
|
3dfc86cb47 | ||
|
|
ef4094039a | ||
|
|
a448c81b97 | ||
|
|
d0a910707e | ||
|
|
220bdf5db1 | ||
|
|
aaa0cdffda | ||
|
|
4b64464292 | ||
|
|
f2f4d941a7 | ||
|
|
8ffeb98eb3 | ||
|
|
09ed611a7f | ||
|
|
66998948c3 | ||
|
|
27f5a75ec3 | ||
|
|
3ce2f2eace | ||
|
|
d66fa8714a | ||
|
|
262b2d4d7c | ||
|
|
cf3772768e | ||
|
|
874c5d5fa3 | ||
|
|
3c50cdd981 | ||
|
|
ed83980b1d | ||
|
|
91b7e8a9c1 | ||
|
|
4e57031200 |
@@ -6,6 +6,7 @@ services:
|
|||||||
RAM_SIZE: "half"
|
RAM_SIZE: "half"
|
||||||
DISK_SIZE: "max"
|
DISK_SIZE: "max"
|
||||||
CPU_CORES: "max"
|
CPU_CORES: "max"
|
||||||
|
DISK_MINIMUM: "1G"
|
||||||
devices:
|
devices:
|
||||||
- /dev/kvm
|
- /dev/kvm
|
||||||
- /dev/net/tun
|
- /dev/net/tun
|
||||||
|
|||||||
@@ -26,7 +26,7 @@ jobs:
|
|||||||
-e SC2317
|
-e SC2317
|
||||||
-
|
-
|
||||||
name: Lint Dockerfile
|
name: Lint Dockerfile
|
||||||
uses: hadolint/hadolint-action@v3.4.0
|
uses: hadolint/hadolint-action@v3.5.0
|
||||||
with:
|
with:
|
||||||
dockerfile: Dockerfile
|
dockerfile: Dockerfile
|
||||||
ignore: DL3006,DL3008,DL3067
|
ignore: DL3006,DL3008,DL3067
|
||||||
|
|||||||
@@ -832,6 +832,13 @@ jobs:
|
|||||||
|
|
||||||
echo "token=$token" >> "$GITHUB_OUTPUT"
|
echo "token=$token" >> "$GITHUB_OUTPUT"
|
||||||
|
|
||||||
|
- name: Set up Docker Buildx
|
||||||
|
id: buildx
|
||||||
|
uses: docker/setup-buildx-action@v4
|
||||||
|
with:
|
||||||
|
driver: docker-container
|
||||||
|
driver-opts: image=moby/buildkit:v0.25.2
|
||||||
|
|
||||||
- name: Build image
|
- name: Build image
|
||||||
shell: bash
|
shell: bash
|
||||||
run: |
|
run: |
|
||||||
@@ -841,9 +848,12 @@ jobs:
|
|||||||
echo "Commit: $(git rev-parse HEAD)"
|
echo "Commit: $(git rev-parse HEAD)"
|
||||||
|
|
||||||
for attempt in 1 2 3; do
|
for attempt in 1 2 3; do
|
||||||
if docker build \
|
if docker buildx build \
|
||||||
|
--builder "${{ steps.buildx.outputs.name }}" \
|
||||||
|
--load \
|
||||||
|
--progress=plain \
|
||||||
--tag "$IMAGE" \
|
--tag "$IMAGE" \
|
||||||
. >/dev/null 2>/dev/null; then
|
.; then
|
||||||
break
|
break
|
||||||
fi
|
fi
|
||||||
|
|
||||||
|
|||||||
+10
-7
@@ -1,15 +1,15 @@
|
|||||||
# syntax=docker/dockerfile:1
|
# syntax=docker/dockerfile:1.28
|
||||||
|
|
||||||
ARG VERSION_ARG="latest"
|
ARG VERSION_ARG="latest"
|
||||||
FROM scratch AS build-amd64
|
FROM scratch AS build-amd64
|
||||||
|
|
||||||
COPY --from=qemux/qemu:7.48 / /
|
COPY --from=qemux/qemu:7.50 --exclude=usr/bin/qemu-system-x86_64 / /
|
||||||
|
|
||||||
ARG TARGETARCH
|
ARG TARGETARCH
|
||||||
|
|
||||||
ARG VERSION_UDF="1.2.0"
|
|
||||||
ARG VERSION_WSDD="1.27"
|
ARG VERSION_WSDD="1.27"
|
||||||
ARG VERSION_VIRTIO="1.9.60"
|
ARG VERSION_DXVK="3.1.1"
|
||||||
|
ARG VERSION_VIRTIO="1.9.61"
|
||||||
ARG VERSION_BLINTER="1.0.112"
|
ARG VERSION_BLINTER="1.0.112"
|
||||||
|
|
||||||
ARG DEBCONF_NOWARNINGS="yes"
|
ARG DEBCONF_NOWARNINGS="yes"
|
||||||
@@ -39,9 +39,10 @@ RUN <<EOF
|
|||||||
wget "https://github.com/gershnik/wsdd-native/releases/download/v${VERSION_WSDD}/wsddn_${VERSION_WSDD}_${TARGETARCH}.deb" -O /tmp/wsddn.deb -q --timeout=10
|
wget "https://github.com/gershnik/wsdd-native/releases/download/v${VERSION_WSDD}/wsddn_${VERSION_WSDD}_${TARGETARCH}.deb" -O /tmp/wsddn.deb -q --timeout=10
|
||||||
dpkg -i /tmp/wsddn.deb
|
dpkg -i /tmp/wsddn.deb
|
||||||
|
|
||||||
# Install UDFread package
|
# Install dxvk-native
|
||||||
wget "https://github.com/qemus/udfread/releases/download/v${VERSION_UDF}/udfread_${VERSION_UDF}_${TARGETARCH}.deb" -O /tmp/udfread.deb -q --timeout=10
|
wget "https://github.com/doitsujin/dxvk/releases/download/v${VERSION_DXVK}/dxvk-native-${VERSION_DXVK}-steamrt-sniper.tar.gz" -O /tmp/dxvk-native.tar.gz -q --timeout=10
|
||||||
dpkg -i /tmp/udfread.deb
|
tar -xzf /tmp/dxvk-native.tar.gz -C /
|
||||||
|
ldconfig
|
||||||
|
|
||||||
apt-get clean
|
apt-get clean
|
||||||
rm -rf /var/lib/apt/lists/* /tmp/* /var/tmp/*
|
rm -rf /var/lib/apt/lists/* /tmp/* /var/tmp/*
|
||||||
@@ -49,6 +50,8 @@ EOF
|
|||||||
|
|
||||||
COPY --chmod=755 ./src /run/
|
COPY --chmod=755 ./src /run/
|
||||||
COPY --chmod=755 ./assets /run/assets
|
COPY --chmod=755 ./assets /run/assets
|
||||||
|
COPY --from=qemux/udfread:1.2.0 /udfread /usr/bin/
|
||||||
|
COPY --from=qemux/qemu-windows:11.2.23 /usr/bin/qemu-system-x86_64 /usr/bin/
|
||||||
|
|
||||||
ADD --chmod=664 https://github.com/qemus/virtiso-whql/releases/download/v${VERSION_VIRTIO}-0/virtio-win-${VERSION_VIRTIO}.tar.xz /var/drivers.txz
|
ADD --chmod=664 https://github.com/qemus/virtiso-whql/releases/download/v${VERSION_VIRTIO}-0/virtio-win-${VERSION_VIRTIO}.tar.xz /var/drivers.txz
|
||||||
|
|
||||||
|
|||||||
@@ -8,13 +8,63 @@ set "SETUP_COMPLETE=%SCRIPT_DIR%setup.complete"
|
|||||||
if "%~1"=="" goto setup
|
if "%~1"=="" goto setup
|
||||||
if /i "%~1"=="setup" goto setup
|
if /i "%~1"=="setup" goto setup
|
||||||
if /i "%~1"=="logon" goto logon
|
if /i "%~1"=="logon" goto logon
|
||||||
|
if /i "%~1"=="specialize" goto specialize
|
||||||
exit /b 2
|
exit /b 2
|
||||||
|
|
||||||
|
:specialize
|
||||||
|
|
||||||
|
reg.exe add "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\OOBE" /v BypassNRO /t REG_DWORD /d 1 /f
|
||||||
|
reg.exe load "HKU\mount" "C:\Users\Default\NTUSER.DAT"
|
||||||
|
reg.exe add "HKU\mount\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager" /v "ContentDeliveryAllowed" /t REG_DWORD /d 0 /f
|
||||||
|
reg.exe add "HKU\mount\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager" /v "FeatureManagementEnabled" /t REG_DWORD /d 0 /f
|
||||||
|
reg.exe add "HKU\mount\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager" /v "OEMPreInstalledAppsEnabled" /t REG_DWORD /d 0 /f
|
||||||
|
reg.exe add "HKU\mount\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager" /v "PreInstalledAppsEnabled" /t REG_DWORD /d 0 /f
|
||||||
|
reg.exe add "HKU\mount\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager" /v "PreInstalledAppsEverEnabled" /t REG_DWORD /d 0 /f
|
||||||
|
reg.exe add "HKU\mount\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager" /v "SilentInstalledAppsEnabled" /t REG_DWORD /d 0 /f
|
||||||
|
reg.exe add "HKU\mount\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager" /v "SoftLandingEnabled" /t REG_DWORD /d 0 /f
|
||||||
|
reg.exe add "HKU\mount\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager" /v "SubscribedContentEnabled" /t REG_DWORD /d 0 /f
|
||||||
|
reg.exe add "HKU\mount\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager" /v "SubscribedContent-310093Enabled" /t REG_DWORD /d 0 /f
|
||||||
|
reg.exe add "HKU\mount\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager" /v "SubscribedContent-338387Enabled" /t REG_DWORD /d 0 /f
|
||||||
|
reg.exe add "HKU\mount\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager" /v "SubscribedContent-338388Enabled" /t REG_DWORD /d 0 /f
|
||||||
|
reg.exe add "HKU\mount\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager" /v "SubscribedContent-338389Enabled" /t REG_DWORD /d 0 /f
|
||||||
|
reg.exe add "HKU\mount\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager" /v "SubscribedContent-338393Enabled" /t REG_DWORD /d 0 /f
|
||||||
|
reg.exe add "HKU\mount\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager" /v "SubscribedContent-353698Enabled" /t REG_DWORD /d 0 /f
|
||||||
|
reg.exe add "HKU\mount\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager" /v "SystemPaneSuggestionsEnabled" /t REG_DWORD /d 0 /f
|
||||||
|
reg.exe add "HKU\mount\Software\Policies\Microsoft\Windows\CloudContent" /v "DisableCloudOptimizedContent" /t REG_DWORD /d 1 /f
|
||||||
|
reg.exe add "HKU\mount\Software\Policies\Microsoft\Windows\CloudContent" /v "DisableWindowsConsumerFeatures" /t REG_DWORD /d 1 /f
|
||||||
|
reg.exe add "HKU\mount\Software\Policies\Microsoft\Windows\CloudContent" /v "DisableConsumerAccountStateContent" /t REG_DWORD /d 1 /f
|
||||||
|
reg.exe unload "HKU\mount"
|
||||||
|
reg.exe add "HKLM\Software\Policies\Microsoft\Windows\CloudContent" /v "DisableCloudOptimizedContent" /t REG_DWORD /d 1 /f
|
||||||
|
reg.exe add "HKLM\Software\Policies\Microsoft\Windows\CloudContent" /v "DisableWindowsConsumerFeatures" /t REG_DWORD /d 1 /f
|
||||||
|
reg.exe add "HKLM\Software\Policies\Microsoft\Windows\CloudContent" /v "DisableConsumerAccountStateContent" /t REG_DWORD /d 1 /f
|
||||||
|
|
||||||
|
rem Set Network Location to Home
|
||||||
|
reg.exe add "HKLM\SOFTWARE\Policies\Microsoft\Windows NT\CurrentVersion\NetworkList\Signatures\FirstNetwork" /v Category /t REG_DWORD /d 1 /f
|
||||||
|
|
||||||
|
rem Install the VMWare display driver before Windows Setup's final reboot.
|
||||||
|
certutil.exe -addstore -f Root "%SystemRoot%\Drivers\vmsvga\vm3d.cer" >nul 2>&1
|
||||||
|
certutil.exe -addstore -f TrustedPublisher "%SystemRoot%\Drivers\vmsvga\vm3d.cer" >nul 2>&1
|
||||||
|
start "" /wait /b pnputil.exe -i -a "%SystemRoot%\Drivers\vmsvga\vm3d.inf" >nul 2>&1
|
||||||
|
|
||||||
|
exit /b 0
|
||||||
|
|
||||||
:setup
|
:setup
|
||||||
if exist "%SETUP_COMPLETE%" exit /b 0
|
if exist "%SETUP_COMPLETE%" exit /b 0
|
||||||
|
|
||||||
type nul > "%SETUP_STARTED%"
|
type nul > "%SETUP_STARTED%"
|
||||||
|
|
||||||
|
rem Ignore unclean shutdowns when deciding whether to enter recovery.
|
||||||
|
bcdedit.exe /set {current} bootstatuspolicy IgnoreAllFailures
|
||||||
|
|
||||||
|
rem Keep the blue screen visible after a system crash.
|
||||||
|
bcdedit.exe /set {current} nocrashautoreboot on
|
||||||
|
|
||||||
|
rem Boot the default entry immediately without waiting at the boot menu.
|
||||||
|
bcdedit.exe /timeout 0
|
||||||
|
|
||||||
|
rem Disable automatic reboot after BSOD
|
||||||
|
reg.exe add "HKLM\SYSTEM\CurrentControlSet\Control\CrashControl" /v "AutoReboot" /t REG_DWORD /d 0 /f
|
||||||
|
|
||||||
rem Allow guest access to network shares.
|
rem Allow guest access to network shares.
|
||||||
reg.exe add "HKLM\SYSTEM\CurrentControlSet\Services\LanmanWorkstation\Parameters" /v "AllowInsecureGuestAuth" /t REG_DWORD /d 1 /f
|
reg.exe add "HKLM\SYSTEM\CurrentControlSet\Services\LanmanWorkstation\Parameters" /v "AllowInsecureGuestAuth" /t REG_DWORD /d 1 /f
|
||||||
|
|
||||||
@@ -51,7 +101,13 @@ rem Disable RemoteApp allowlist.
|
|||||||
reg.exe add "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Terminal Server\TSAppAllowList" /v "fDisabledAllowList" /t REG_DWORD /d 1 /f
|
reg.exe add "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Terminal Server\TSAppAllowList" /v "fDisabledAllowList" /t REG_DWORD /d 1 /f
|
||||||
|
|
||||||
rem Turn off automatic Windows Update downloads.
|
rem Turn off automatic Windows Update downloads.
|
||||||
reg.exe add "HKLM\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU" /v "NoAutoUpdate" /t REG_DWORD /d 1 /f
|
reg.exe add "HKLM\SOFTWARE\Microsoft\WindowsUpdate\UX\Settings" /v "FlightSettingsMaxPauseDays" /t REG_DWORD /d 3650 /f
|
||||||
|
reg.exe add "HKLM\SOFTWARE\Microsoft\WindowsUpdate\UX\Settings" /v "PauseFeatureUpdatesStartTime" /t REG_SZ /d "2026-01-01T00:00:00Z" /f
|
||||||
|
reg.exe add "HKLM\SOFTWARE\Microsoft\WindowsUpdate\UX\Settings" /v "PauseFeatureUpdatesEndTime" /t REG_SZ /d "2035-12-29T00:00:00Z" /f
|
||||||
|
reg.exe add "HKLM\SOFTWARE\Microsoft\WindowsUpdate\UX\Settings" /v "PauseQualityUpdatesStartTime" /t REG_SZ /d "2026-01-01T00:00:00Z" /f
|
||||||
|
reg.exe add "HKLM\SOFTWARE\Microsoft\WindowsUpdate\UX\Settings" /v "PauseQualityUpdatesEndTime" /t REG_SZ /d "2035-12-29T00:00:00Z" /f
|
||||||
|
reg.exe add "HKLM\SOFTWARE\Microsoft\WindowsUpdate\UX\Settings" /v "PauseUpdatesStartTime" /t REG_SZ /d "2026-01-01T00:00:00Z" /f
|
||||||
|
reg.exe add "HKLM\SOFTWARE\Microsoft\WindowsUpdate\UX\Settings" /v "PauseUpdatesExpiryTime" /t REG_SZ /d "2035-12-29T00:00:00Z" /f
|
||||||
|
|
||||||
rem Enable Network Discovery.
|
rem Enable Network Discovery.
|
||||||
netsh advfirewall firewall set rule group="@FirewallAPI.dll,-32752" new enable=Yes
|
netsh advfirewall firewall set rule group="@FirewallAPI.dll,-32752" new enable=Yes
|
||||||
@@ -78,7 +134,7 @@ type nul > "%SETUP_COMPLETE%"
|
|||||||
exit /b 0
|
exit /b 0
|
||||||
|
|
||||||
:logon
|
:logon
|
||||||
rem Run the machine setup here when SetupComplete.cmd was skipped.
|
rem Run the machine setup here when the SetupComplete hook was skipped.
|
||||||
if not exist "%SETUP_COMPLETE%" call "%~f0" setup
|
if not exist "%SETUP_COMPLETE%" call "%~f0" setup
|
||||||
|
|
||||||
rem Show file extensions in Explorer.
|
rem Show file extensions in Explorer.
|
||||||
|
|||||||
@@ -150,104 +150,8 @@
|
|||||||
<RunSynchronous>
|
<RunSynchronous>
|
||||||
<RunSynchronousCommand wcm:action="add">
|
<RunSynchronousCommand wcm:action="add">
|
||||||
<Order>1</Order>
|
<Order>1</Order>
|
||||||
<Path>reg.exe add "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\OOBE" /v BypassNRO /t REG_DWORD /d 1 /f</Path>
|
<Path>wscript.exe //B //NoLogo %WINDIR%\Setup\Scripts\Unattend.vbs specialize</Path>
|
||||||
</RunSynchronousCommand>
|
<Description>Run the specialize pass of the unattended setup script</Description>
|
||||||
<RunSynchronousCommand wcm:action="add">
|
|
||||||
<Order>2</Order>
|
|
||||||
<Path>reg.exe load "HKU\mount" "C:\Users\Default\NTUSER.DAT"</Path>
|
|
||||||
</RunSynchronousCommand>
|
|
||||||
<RunSynchronousCommand wcm:action="add">
|
|
||||||
<Order>3</Order>
|
|
||||||
<Path>reg.exe add "HKU\mount\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager" /v "ContentDeliveryAllowed" /t REG_DWORD /d 0 /f</Path>
|
|
||||||
</RunSynchronousCommand>
|
|
||||||
<RunSynchronousCommand wcm:action="add">
|
|
||||||
<Order>4</Order>
|
|
||||||
<Path>reg.exe add "HKU\mount\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager" /v "FeatureManagementEnabled" /t REG_DWORD /d 0 /f</Path>
|
|
||||||
</RunSynchronousCommand>
|
|
||||||
<RunSynchronousCommand wcm:action="add">
|
|
||||||
<Order>5</Order>
|
|
||||||
<Path>reg.exe add "HKU\mount\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager" /v "OEMPreInstalledAppsEnabled" /t REG_DWORD /d 0 /f</Path>
|
|
||||||
</RunSynchronousCommand>
|
|
||||||
<RunSynchronousCommand wcm:action="add">
|
|
||||||
<Order>6</Order>
|
|
||||||
<Path>reg.exe add "HKU\mount\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager" /v "PreInstalledAppsEnabled" /t REG_DWORD /d 0 /f</Path>
|
|
||||||
</RunSynchronousCommand>
|
|
||||||
<RunSynchronousCommand wcm:action="add">
|
|
||||||
<Order>7</Order>
|
|
||||||
<Path>reg.exe add "HKU\mount\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager" /v "PreInstalledAppsEverEnabled" /t REG_DWORD /d 0 /f</Path>
|
|
||||||
</RunSynchronousCommand>
|
|
||||||
<RunSynchronousCommand wcm:action="add">
|
|
||||||
<Order>8</Order>
|
|
||||||
<Path>reg.exe add "HKU\mount\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager" /v "SilentInstalledAppsEnabled" /t REG_DWORD /d 0 /f</Path>
|
|
||||||
</RunSynchronousCommand>
|
|
||||||
<RunSynchronousCommand wcm:action="add">
|
|
||||||
<Order>9</Order>
|
|
||||||
<Path>reg.exe add "HKU\mount\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager" /v "SoftLandingEnabled" /t REG_DWORD /d 0 /f</Path>
|
|
||||||
</RunSynchronousCommand>
|
|
||||||
<RunSynchronousCommand wcm:action="add">
|
|
||||||
<Order>10</Order>
|
|
||||||
<Path>reg.exe add "HKU\mount\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager" /v "SubscribedContentEnabled" /t REG_DWORD /d 0 /f</Path>
|
|
||||||
</RunSynchronousCommand>
|
|
||||||
<RunSynchronousCommand wcm:action="add">
|
|
||||||
<Order>11</Order>
|
|
||||||
<Path>reg.exe add "HKU\mount\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager" /v "SubscribedContent-310093Enabled" /t REG_DWORD /d 0 /f</Path>
|
|
||||||
</RunSynchronousCommand>
|
|
||||||
<RunSynchronousCommand wcm:action="add">
|
|
||||||
<Order>12</Order>
|
|
||||||
<Path>reg.exe add "HKU\mount\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager" /v "SubscribedContent-338387Enabled" /t REG_DWORD /d 0 /f</Path>
|
|
||||||
</RunSynchronousCommand>
|
|
||||||
<RunSynchronousCommand wcm:action="add">
|
|
||||||
<Order>13</Order>
|
|
||||||
<Path>reg.exe add "HKU\mount\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager" /v "SubscribedContent-338388Enabled" /t REG_DWORD /d 0 /f</Path>
|
|
||||||
</RunSynchronousCommand>
|
|
||||||
<RunSynchronousCommand wcm:action="add">
|
|
||||||
<Order>14</Order>
|
|
||||||
<Path>reg.exe add "HKU\mount\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager" /v "SubscribedContent-338389Enabled" /t REG_DWORD /d 0 /f</Path>
|
|
||||||
</RunSynchronousCommand>
|
|
||||||
<RunSynchronousCommand wcm:action="add">
|
|
||||||
<Order>15</Order>
|
|
||||||
<Path>reg.exe add "HKU\mount\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager" /v "SubscribedContent-338393Enabled" /t REG_DWORD /d 0 /f</Path>
|
|
||||||
</RunSynchronousCommand>
|
|
||||||
<RunSynchronousCommand wcm:action="add">
|
|
||||||
<Order>16</Order>
|
|
||||||
<Path>reg.exe add "HKU\mount\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager" /v "SubscribedContent-353698Enabled" /t REG_DWORD /d 0 /f</Path>
|
|
||||||
</RunSynchronousCommand>
|
|
||||||
<RunSynchronousCommand wcm:action="add">
|
|
||||||
<Order>17</Order>
|
|
||||||
<Path>reg.exe add "HKU\mount\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager" /v "SystemPaneSuggestionsEnabled" /t REG_DWORD /d 0 /f</Path>
|
|
||||||
</RunSynchronousCommand>
|
|
||||||
<RunSynchronousCommand wcm:action="add">
|
|
||||||
<Order>18</Order>
|
|
||||||
<Path>reg.exe add "HKU\mount\Software\Policies\Microsoft\Windows\CloudContent" /v "DisableCloudOptimizedContent" /t REG_DWORD /d 1 /f</Path>
|
|
||||||
</RunSynchronousCommand>
|
|
||||||
<RunSynchronousCommand wcm:action="add">
|
|
||||||
<Order>19</Order>
|
|
||||||
<Path>reg.exe add "HKU\mount\Software\Policies\Microsoft\Windows\CloudContent" /v "DisableWindowsConsumerFeatures" /t REG_DWORD /d 1 /f</Path>
|
|
||||||
</RunSynchronousCommand>
|
|
||||||
<RunSynchronousCommand wcm:action="add">
|
|
||||||
<Order>20</Order>
|
|
||||||
<Path>reg.exe add "HKU\mount\Software\Policies\Microsoft\Windows\CloudContent" /v "DisableConsumerAccountStateContent" /t REG_DWORD /d 1 /f</Path>
|
|
||||||
</RunSynchronousCommand>
|
|
||||||
<RunSynchronousCommand wcm:action="add">
|
|
||||||
<Order>21</Order>
|
|
||||||
<Path>reg.exe unload "HKU\mount"</Path>
|
|
||||||
</RunSynchronousCommand>
|
|
||||||
<RunSynchronousCommand wcm:action="add">
|
|
||||||
<Order>22</Order>
|
|
||||||
<Path>reg.exe add "HKLM\Software\Policies\Microsoft\Windows\CloudContent" /v "DisableCloudOptimizedContent" /t REG_DWORD /d 1 /f</Path>
|
|
||||||
</RunSynchronousCommand>
|
|
||||||
<RunSynchronousCommand wcm:action="add">
|
|
||||||
<Order>23</Order>
|
|
||||||
<Path>reg.exe add "HKLM\Software\Policies\Microsoft\Windows\CloudContent" /v "DisableWindowsConsumerFeatures" /t REG_DWORD /d 1 /f</Path>
|
|
||||||
</RunSynchronousCommand>
|
|
||||||
<RunSynchronousCommand wcm:action="add">
|
|
||||||
<Order>24</Order>
|
|
||||||
<Path>reg.exe add "HKLM\Software\Policies\Microsoft\Windows\CloudContent" /v "DisableConsumerAccountStateContent" /t REG_DWORD /d 1 /f</Path>
|
|
||||||
</RunSynchronousCommand>
|
|
||||||
<RunSynchronousCommand wcm:action="add">
|
|
||||||
<Order>25</Order>
|
|
||||||
<Path>reg.exe add "HKLM\SOFTWARE\Policies\Microsoft\Windows NT\CurrentVersion\NetworkList\Signatures\FirstNetwork" /v Category /t REG_DWORD /d 1 /f</Path>
|
|
||||||
<Description>Set Network Location to Home</Description>
|
|
||||||
</RunSynchronousCommand>
|
</RunSynchronousCommand>
|
||||||
</RunSynchronous>
|
</RunSynchronous>
|
||||||
</component>
|
</component>
|
||||||
@@ -323,7 +227,7 @@
|
|||||||
<FirstLogonCommands>
|
<FirstLogonCommands>
|
||||||
<SynchronousCommand wcm:action="add">
|
<SynchronousCommand wcm:action="add">
|
||||||
<Order>1</Order>
|
<Order>1</Order>
|
||||||
<CommandLine>cmd.exe /d /c call "%WINDIR%\Setup\Scripts\SetupComplete.cmd" logon</CommandLine>
|
<CommandLine>wscript.exe //B //NoLogo %WINDIR%\Setup\Scripts\Unattend.vbs logon</CommandLine>
|
||||||
<Description>Configure Windows after logon</Description>
|
<Description>Configure Windows after logon</Description>
|
||||||
</SynchronousCommand>
|
</SynchronousCommand>
|
||||||
</FirstLogonCommands>
|
</FirstLogonCommands>
|
||||||
|
|||||||
+58
-2
@@ -8,13 +8,63 @@ set "SETUP_COMPLETE=%SCRIPT_DIR%setup.complete"
|
|||||||
if "%~1"=="" goto setup
|
if "%~1"=="" goto setup
|
||||||
if /i "%~1"=="setup" goto setup
|
if /i "%~1"=="setup" goto setup
|
||||||
if /i "%~1"=="logon" goto logon
|
if /i "%~1"=="logon" goto logon
|
||||||
|
if /i "%~1"=="specialize" goto specialize
|
||||||
exit /b 2
|
exit /b 2
|
||||||
|
|
||||||
|
:specialize
|
||||||
|
|
||||||
|
reg.exe add "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\OOBE" /v BypassNRO /t REG_DWORD /d 1 /f
|
||||||
|
reg.exe load "HKU\mount" "C:\Users\Default\NTUSER.DAT"
|
||||||
|
reg.exe add "HKU\mount\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager" /v "ContentDeliveryAllowed" /t REG_DWORD /d 0 /f
|
||||||
|
reg.exe add "HKU\mount\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager" /v "FeatureManagementEnabled" /t REG_DWORD /d 0 /f
|
||||||
|
reg.exe add "HKU\mount\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager" /v "OEMPreInstalledAppsEnabled" /t REG_DWORD /d 0 /f
|
||||||
|
reg.exe add "HKU\mount\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager" /v "PreInstalledAppsEnabled" /t REG_DWORD /d 0 /f
|
||||||
|
reg.exe add "HKU\mount\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager" /v "PreInstalledAppsEverEnabled" /t REG_DWORD /d 0 /f
|
||||||
|
reg.exe add "HKU\mount\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager" /v "SilentInstalledAppsEnabled" /t REG_DWORD /d 0 /f
|
||||||
|
reg.exe add "HKU\mount\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager" /v "SoftLandingEnabled" /t REG_DWORD /d 0 /f
|
||||||
|
reg.exe add "HKU\mount\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager" /v "SubscribedContentEnabled" /t REG_DWORD /d 0 /f
|
||||||
|
reg.exe add "HKU\mount\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager" /v "SubscribedContent-310093Enabled" /t REG_DWORD /d 0 /f
|
||||||
|
reg.exe add "HKU\mount\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager" /v "SubscribedContent-338387Enabled" /t REG_DWORD /d 0 /f
|
||||||
|
reg.exe add "HKU\mount\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager" /v "SubscribedContent-338388Enabled" /t REG_DWORD /d 0 /f
|
||||||
|
reg.exe add "HKU\mount\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager" /v "SubscribedContent-338389Enabled" /t REG_DWORD /d 0 /f
|
||||||
|
reg.exe add "HKU\mount\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager" /v "SubscribedContent-338393Enabled" /t REG_DWORD /d 0 /f
|
||||||
|
reg.exe add "HKU\mount\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager" /v "SubscribedContent-353698Enabled" /t REG_DWORD /d 0 /f
|
||||||
|
reg.exe add "HKU\mount\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager" /v "SystemPaneSuggestionsEnabled" /t REG_DWORD /d 0 /f
|
||||||
|
reg.exe add "HKU\mount\Software\Policies\Microsoft\Windows\CloudContent" /v "DisableCloudOptimizedContent" /t REG_DWORD /d 1 /f
|
||||||
|
reg.exe add "HKU\mount\Software\Policies\Microsoft\Windows\CloudContent" /v "DisableWindowsConsumerFeatures" /t REG_DWORD /d 1 /f
|
||||||
|
reg.exe add "HKU\mount\Software\Policies\Microsoft\Windows\CloudContent" /v "DisableConsumerAccountStateContent" /t REG_DWORD /d 1 /f
|
||||||
|
reg.exe unload "HKU\mount"
|
||||||
|
reg.exe add "HKLM\Software\Policies\Microsoft\Windows\CloudContent" /v "DisableCloudOptimizedContent" /t REG_DWORD /d 1 /f
|
||||||
|
reg.exe add "HKLM\Software\Policies\Microsoft\Windows\CloudContent" /v "DisableWindowsConsumerFeatures" /t REG_DWORD /d 1 /f
|
||||||
|
reg.exe add "HKLM\Software\Policies\Microsoft\Windows\CloudContent" /v "DisableConsumerAccountStateContent" /t REG_DWORD /d 1 /f
|
||||||
|
|
||||||
|
rem Set Network Location to Home
|
||||||
|
reg.exe add "HKLM\SOFTWARE\Policies\Microsoft\Windows NT\CurrentVersion\NetworkList\Signatures\FirstNetwork" /v Category /t REG_DWORD /d 1 /f
|
||||||
|
|
||||||
|
rem Install the VMWare display driver before Windows Setup's final reboot.
|
||||||
|
certutil.exe -addstore -f Root "%SystemRoot%\Drivers\vmsvga\vm3d.cer" >nul 2>&1
|
||||||
|
certutil.exe -addstore -f TrustedPublisher "%SystemRoot%\Drivers\vmsvga\vm3d.cer" >nul 2>&1
|
||||||
|
start "" /wait /b pnputil.exe -i -a "%SystemRoot%\Drivers\vmsvga\vm3d.inf" >nul 2>&1
|
||||||
|
|
||||||
|
exit /b 0
|
||||||
|
|
||||||
:setup
|
:setup
|
||||||
if exist "%SETUP_COMPLETE%" exit /b 0
|
if exist "%SETUP_COMPLETE%" exit /b 0
|
||||||
|
|
||||||
type nul > "%SETUP_STARTED%"
|
type nul > "%SETUP_STARTED%"
|
||||||
|
|
||||||
|
rem Ignore unclean shutdowns when deciding whether to enter recovery.
|
||||||
|
bcdedit.exe /set {current} bootstatuspolicy IgnoreAllFailures
|
||||||
|
|
||||||
|
rem Keep the blue screen visible after a system crash.
|
||||||
|
bcdedit.exe /set {current} nocrashautoreboot on
|
||||||
|
|
||||||
|
rem Boot the default entry immediately without waiting at the boot menu.
|
||||||
|
bcdedit.exe /timeout 0
|
||||||
|
|
||||||
|
rem Disable automatic reboot after BSOD
|
||||||
|
reg.exe add "HKLM\SYSTEM\CurrentControlSet\Control\CrashControl" /v "AutoReboot" /t REG_DWORD /d 0 /f
|
||||||
|
|
||||||
rem Allow guest access to network shares.
|
rem Allow guest access to network shares.
|
||||||
reg.exe add "HKLM\SYSTEM\CurrentControlSet\Services\LanmanWorkstation\Parameters" /v "AllowInsecureGuestAuth" /t REG_DWORD /d 1 /f
|
reg.exe add "HKLM\SYSTEM\CurrentControlSet\Services\LanmanWorkstation\Parameters" /v "AllowInsecureGuestAuth" /t REG_DWORD /d 1 /f
|
||||||
|
|
||||||
@@ -51,7 +101,13 @@ rem Disable RemoteApp allowlist.
|
|||||||
reg.exe add "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Terminal Server\TSAppAllowList" /v "fDisabledAllowList" /t REG_DWORD /d 1 /f
|
reg.exe add "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Terminal Server\TSAppAllowList" /v "fDisabledAllowList" /t REG_DWORD /d 1 /f
|
||||||
|
|
||||||
rem Turn off automatic Windows Update downloads.
|
rem Turn off automatic Windows Update downloads.
|
||||||
reg.exe add "HKLM\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU" /v "NoAutoUpdate" /t REG_DWORD /d 1 /f
|
reg.exe add "HKLM\SOFTWARE\Microsoft\WindowsUpdate\UX\Settings" /v "FlightSettingsMaxPauseDays" /t REG_DWORD /d 3650 /f
|
||||||
|
reg.exe add "HKLM\SOFTWARE\Microsoft\WindowsUpdate\UX\Settings" /v "PauseFeatureUpdatesStartTime" /t REG_SZ /d "2026-01-01T00:00:00Z" /f
|
||||||
|
reg.exe add "HKLM\SOFTWARE\Microsoft\WindowsUpdate\UX\Settings" /v "PauseFeatureUpdatesEndTime" /t REG_SZ /d "2035-12-29T00:00:00Z" /f
|
||||||
|
reg.exe add "HKLM\SOFTWARE\Microsoft\WindowsUpdate\UX\Settings" /v "PauseQualityUpdatesStartTime" /t REG_SZ /d "2026-01-01T00:00:00Z" /f
|
||||||
|
reg.exe add "HKLM\SOFTWARE\Microsoft\WindowsUpdate\UX\Settings" /v "PauseQualityUpdatesEndTime" /t REG_SZ /d "2035-12-29T00:00:00Z" /f
|
||||||
|
reg.exe add "HKLM\SOFTWARE\Microsoft\WindowsUpdate\UX\Settings" /v "PauseUpdatesStartTime" /t REG_SZ /d "2026-01-01T00:00:00Z" /f
|
||||||
|
reg.exe add "HKLM\SOFTWARE\Microsoft\WindowsUpdate\UX\Settings" /v "PauseUpdatesExpiryTime" /t REG_SZ /d "2035-12-29T00:00:00Z" /f
|
||||||
|
|
||||||
rem Enable Network Discovery.
|
rem Enable Network Discovery.
|
||||||
netsh advfirewall firewall set rule group="@FirewallAPI.dll,-32752" new enable=Yes
|
netsh advfirewall firewall set rule group="@FirewallAPI.dll,-32752" new enable=Yes
|
||||||
@@ -78,7 +134,7 @@ type nul > "%SETUP_COMPLETE%"
|
|||||||
exit /b 0
|
exit /b 0
|
||||||
|
|
||||||
:logon
|
:logon
|
||||||
rem Run the machine setup here when SetupComplete.cmd was skipped.
|
rem Run the machine setup here when the SetupComplete hook was skipped.
|
||||||
if not exist "%SETUP_COMPLETE%" call "%~f0" setup
|
if not exist "%SETUP_COMPLETE%" call "%~f0" setup
|
||||||
|
|
||||||
rem Show file extensions in Explorer.
|
rem Show file extensions in Explorer.
|
||||||
|
|||||||
+3
-99
@@ -156,104 +156,8 @@
|
|||||||
<RunSynchronous>
|
<RunSynchronous>
|
||||||
<RunSynchronousCommand wcm:action="add">
|
<RunSynchronousCommand wcm:action="add">
|
||||||
<Order>1</Order>
|
<Order>1</Order>
|
||||||
<Path>reg.exe add "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\OOBE" /v BypassNRO /t REG_DWORD /d 1 /f</Path>
|
<Path>wscript.exe //B //NoLogo %WINDIR%\Setup\Scripts\Unattend.vbs specialize</Path>
|
||||||
</RunSynchronousCommand>
|
<Description>Run the specialize pass of the unattended setup script</Description>
|
||||||
<RunSynchronousCommand wcm:action="add">
|
|
||||||
<Order>2</Order>
|
|
||||||
<Path>reg.exe load "HKU\mount" "C:\Users\Default\NTUSER.DAT"</Path>
|
|
||||||
</RunSynchronousCommand>
|
|
||||||
<RunSynchronousCommand wcm:action="add">
|
|
||||||
<Order>3</Order>
|
|
||||||
<Path>reg.exe add "HKU\mount\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager" /v "ContentDeliveryAllowed" /t REG_DWORD /d 0 /f</Path>
|
|
||||||
</RunSynchronousCommand>
|
|
||||||
<RunSynchronousCommand wcm:action="add">
|
|
||||||
<Order>4</Order>
|
|
||||||
<Path>reg.exe add "HKU\mount\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager" /v "FeatureManagementEnabled" /t REG_DWORD /d 0 /f</Path>
|
|
||||||
</RunSynchronousCommand>
|
|
||||||
<RunSynchronousCommand wcm:action="add">
|
|
||||||
<Order>5</Order>
|
|
||||||
<Path>reg.exe add "HKU\mount\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager" /v "OEMPreInstalledAppsEnabled" /t REG_DWORD /d 0 /f</Path>
|
|
||||||
</RunSynchronousCommand>
|
|
||||||
<RunSynchronousCommand wcm:action="add">
|
|
||||||
<Order>6</Order>
|
|
||||||
<Path>reg.exe add "HKU\mount\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager" /v "PreInstalledAppsEnabled" /t REG_DWORD /d 0 /f</Path>
|
|
||||||
</RunSynchronousCommand>
|
|
||||||
<RunSynchronousCommand wcm:action="add">
|
|
||||||
<Order>7</Order>
|
|
||||||
<Path>reg.exe add "HKU\mount\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager" /v "PreInstalledAppsEverEnabled" /t REG_DWORD /d 0 /f</Path>
|
|
||||||
</RunSynchronousCommand>
|
|
||||||
<RunSynchronousCommand wcm:action="add">
|
|
||||||
<Order>8</Order>
|
|
||||||
<Path>reg.exe add "HKU\mount\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager" /v "SilentInstalledAppsEnabled" /t REG_DWORD /d 0 /f</Path>
|
|
||||||
</RunSynchronousCommand>
|
|
||||||
<RunSynchronousCommand wcm:action="add">
|
|
||||||
<Order>9</Order>
|
|
||||||
<Path>reg.exe add "HKU\mount\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager" /v "SoftLandingEnabled" /t REG_DWORD /d 0 /f</Path>
|
|
||||||
</RunSynchronousCommand>
|
|
||||||
<RunSynchronousCommand wcm:action="add">
|
|
||||||
<Order>10</Order>
|
|
||||||
<Path>reg.exe add "HKU\mount\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager" /v "SubscribedContentEnabled" /t REG_DWORD /d 0 /f</Path>
|
|
||||||
</RunSynchronousCommand>
|
|
||||||
<RunSynchronousCommand wcm:action="add">
|
|
||||||
<Order>11</Order>
|
|
||||||
<Path>reg.exe add "HKU\mount\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager" /v "SubscribedContent-310093Enabled" /t REG_DWORD /d 0 /f</Path>
|
|
||||||
</RunSynchronousCommand>
|
|
||||||
<RunSynchronousCommand wcm:action="add">
|
|
||||||
<Order>12</Order>
|
|
||||||
<Path>reg.exe add "HKU\mount\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager" /v "SubscribedContent-338387Enabled" /t REG_DWORD /d 0 /f</Path>
|
|
||||||
</RunSynchronousCommand>
|
|
||||||
<RunSynchronousCommand wcm:action="add">
|
|
||||||
<Order>13</Order>
|
|
||||||
<Path>reg.exe add "HKU\mount\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager" /v "SubscribedContent-338388Enabled" /t REG_DWORD /d 0 /f</Path>
|
|
||||||
</RunSynchronousCommand>
|
|
||||||
<RunSynchronousCommand wcm:action="add">
|
|
||||||
<Order>14</Order>
|
|
||||||
<Path>reg.exe add "HKU\mount\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager" /v "SubscribedContent-338389Enabled" /t REG_DWORD /d 0 /f</Path>
|
|
||||||
</RunSynchronousCommand>
|
|
||||||
<RunSynchronousCommand wcm:action="add">
|
|
||||||
<Order>15</Order>
|
|
||||||
<Path>reg.exe add "HKU\mount\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager" /v "SubscribedContent-338393Enabled" /t REG_DWORD /d 0 /f</Path>
|
|
||||||
</RunSynchronousCommand>
|
|
||||||
<RunSynchronousCommand wcm:action="add">
|
|
||||||
<Order>16</Order>
|
|
||||||
<Path>reg.exe add "HKU\mount\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager" /v "SubscribedContent-353698Enabled" /t REG_DWORD /d 0 /f</Path>
|
|
||||||
</RunSynchronousCommand>
|
|
||||||
<RunSynchronousCommand wcm:action="add">
|
|
||||||
<Order>17</Order>
|
|
||||||
<Path>reg.exe add "HKU\mount\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager" /v "SystemPaneSuggestionsEnabled" /t REG_DWORD /d 0 /f</Path>
|
|
||||||
</RunSynchronousCommand>
|
|
||||||
<RunSynchronousCommand wcm:action="add">
|
|
||||||
<Order>18</Order>
|
|
||||||
<Path>reg.exe add "HKU\mount\Software\Policies\Microsoft\Windows\CloudContent" /v "DisableCloudOptimizedContent" /t REG_DWORD /d 1 /f</Path>
|
|
||||||
</RunSynchronousCommand>
|
|
||||||
<RunSynchronousCommand wcm:action="add">
|
|
||||||
<Order>19</Order>
|
|
||||||
<Path>reg.exe add "HKU\mount\Software\Policies\Microsoft\Windows\CloudContent" /v "DisableWindowsConsumerFeatures" /t REG_DWORD /d 1 /f</Path>
|
|
||||||
</RunSynchronousCommand>
|
|
||||||
<RunSynchronousCommand wcm:action="add">
|
|
||||||
<Order>20</Order>
|
|
||||||
<Path>reg.exe add "HKU\mount\Software\Policies\Microsoft\Windows\CloudContent" /v "DisableConsumerAccountStateContent" /t REG_DWORD /d 1 /f</Path>
|
|
||||||
</RunSynchronousCommand>
|
|
||||||
<RunSynchronousCommand wcm:action="add">
|
|
||||||
<Order>21</Order>
|
|
||||||
<Path>reg.exe unload "HKU\mount"</Path>
|
|
||||||
</RunSynchronousCommand>
|
|
||||||
<RunSynchronousCommand wcm:action="add">
|
|
||||||
<Order>22</Order>
|
|
||||||
<Path>reg.exe add "HKLM\Software\Policies\Microsoft\Windows\CloudContent" /v "DisableCloudOptimizedContent" /t REG_DWORD /d 1 /f</Path>
|
|
||||||
</RunSynchronousCommand>
|
|
||||||
<RunSynchronousCommand wcm:action="add">
|
|
||||||
<Order>23</Order>
|
|
||||||
<Path>reg.exe add "HKLM\Software\Policies\Microsoft\Windows\CloudContent" /v "DisableWindowsConsumerFeatures" /t REG_DWORD /d 1 /f</Path>
|
|
||||||
</RunSynchronousCommand>
|
|
||||||
<RunSynchronousCommand wcm:action="add">
|
|
||||||
<Order>24</Order>
|
|
||||||
<Path>reg.exe add "HKLM\Software\Policies\Microsoft\Windows\CloudContent" /v "DisableConsumerAccountStateContent" /t REG_DWORD /d 1 /f</Path>
|
|
||||||
</RunSynchronousCommand>
|
|
||||||
<RunSynchronousCommand wcm:action="add">
|
|
||||||
<Order>25</Order>
|
|
||||||
<Path>reg.exe add "HKLM\SOFTWARE\Policies\Microsoft\Windows NT\CurrentVersion\NetworkList\Signatures\FirstNetwork" /v Category /t REG_DWORD /d 1 /f</Path>
|
|
||||||
<Description>Set Network Location to Home</Description>
|
|
||||||
</RunSynchronousCommand>
|
</RunSynchronousCommand>
|
||||||
</RunSynchronous>
|
</RunSynchronous>
|
||||||
</component>
|
</component>
|
||||||
@@ -329,7 +233,7 @@
|
|||||||
<FirstLogonCommands>
|
<FirstLogonCommands>
|
||||||
<SynchronousCommand wcm:action="add">
|
<SynchronousCommand wcm:action="add">
|
||||||
<Order>1</Order>
|
<Order>1</Order>
|
||||||
<CommandLine>cmd.exe /d /c call "%WINDIR%\Setup\Scripts\SetupComplete.cmd" logon</CommandLine>
|
<CommandLine>wscript.exe //B //NoLogo %WINDIR%\Setup\Scripts\Unattend.vbs logon</CommandLine>
|
||||||
<Description>Configure Windows after logon</Description>
|
<Description>Configure Windows after logon</Description>
|
||||||
</SynchronousCommand>
|
</SynchronousCommand>
|
||||||
</FirstLogonCommands>
|
</FirstLogonCommands>
|
||||||
|
|||||||
@@ -8,13 +8,63 @@ set "SETUP_COMPLETE=%SCRIPT_DIR%setup.complete"
|
|||||||
if "%~1"=="" goto setup
|
if "%~1"=="" goto setup
|
||||||
if /i "%~1"=="setup" goto setup
|
if /i "%~1"=="setup" goto setup
|
||||||
if /i "%~1"=="logon" goto logon
|
if /i "%~1"=="logon" goto logon
|
||||||
|
if /i "%~1"=="specialize" goto specialize
|
||||||
exit /b 2
|
exit /b 2
|
||||||
|
|
||||||
|
:specialize
|
||||||
|
|
||||||
|
reg.exe add "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\OOBE" /v BypassNRO /t REG_DWORD /d 1 /f
|
||||||
|
reg.exe load "HKU\mount" "C:\Users\Default\NTUSER.DAT"
|
||||||
|
reg.exe add "HKU\mount\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager" /v "ContentDeliveryAllowed" /t REG_DWORD /d 0 /f
|
||||||
|
reg.exe add "HKU\mount\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager" /v "FeatureManagementEnabled" /t REG_DWORD /d 0 /f
|
||||||
|
reg.exe add "HKU\mount\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager" /v "OEMPreInstalledAppsEnabled" /t REG_DWORD /d 0 /f
|
||||||
|
reg.exe add "HKU\mount\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager" /v "PreInstalledAppsEnabled" /t REG_DWORD /d 0 /f
|
||||||
|
reg.exe add "HKU\mount\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager" /v "PreInstalledAppsEverEnabled" /t REG_DWORD /d 0 /f
|
||||||
|
reg.exe add "HKU\mount\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager" /v "SilentInstalledAppsEnabled" /t REG_DWORD /d 0 /f
|
||||||
|
reg.exe add "HKU\mount\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager" /v "SoftLandingEnabled" /t REG_DWORD /d 0 /f
|
||||||
|
reg.exe add "HKU\mount\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager" /v "SubscribedContentEnabled" /t REG_DWORD /d 0 /f
|
||||||
|
reg.exe add "HKU\mount\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager" /v "SubscribedContent-310093Enabled" /t REG_DWORD /d 0 /f
|
||||||
|
reg.exe add "HKU\mount\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager" /v "SubscribedContent-338387Enabled" /t REG_DWORD /d 0 /f
|
||||||
|
reg.exe add "HKU\mount\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager" /v "SubscribedContent-338388Enabled" /t REG_DWORD /d 0 /f
|
||||||
|
reg.exe add "HKU\mount\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager" /v "SubscribedContent-338389Enabled" /t REG_DWORD /d 0 /f
|
||||||
|
reg.exe add "HKU\mount\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager" /v "SubscribedContent-338393Enabled" /t REG_DWORD /d 0 /f
|
||||||
|
reg.exe add "HKU\mount\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager" /v "SubscribedContent-353698Enabled" /t REG_DWORD /d 0 /f
|
||||||
|
reg.exe add "HKU\mount\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager" /v "SystemPaneSuggestionsEnabled" /t REG_DWORD /d 0 /f
|
||||||
|
reg.exe add "HKU\mount\Software\Policies\Microsoft\Windows\CloudContent" /v "DisableCloudOptimizedContent" /t REG_DWORD /d 1 /f
|
||||||
|
reg.exe add "HKU\mount\Software\Policies\Microsoft\Windows\CloudContent" /v "DisableWindowsConsumerFeatures" /t REG_DWORD /d 1 /f
|
||||||
|
reg.exe add "HKU\mount\Software\Policies\Microsoft\Windows\CloudContent" /v "DisableConsumerAccountStateContent" /t REG_DWORD /d 1 /f
|
||||||
|
reg.exe unload "HKU\mount"
|
||||||
|
reg.exe add "HKLM\Software\Policies\Microsoft\Windows\CloudContent" /v "DisableCloudOptimizedContent" /t REG_DWORD /d 1 /f
|
||||||
|
reg.exe add "HKLM\Software\Policies\Microsoft\Windows\CloudContent" /v "DisableWindowsConsumerFeatures" /t REG_DWORD /d 1 /f
|
||||||
|
reg.exe add "HKLM\Software\Policies\Microsoft\Windows\CloudContent" /v "DisableConsumerAccountStateContent" /t REG_DWORD /d 1 /f
|
||||||
|
|
||||||
|
rem Set Network Location to Home
|
||||||
|
reg.exe add "HKLM\SOFTWARE\Policies\Microsoft\Windows NT\CurrentVersion\NetworkList\Signatures\FirstNetwork" /v Category /t REG_DWORD /d 1 /f
|
||||||
|
|
||||||
|
rem Install the VMWare display driver before Windows Setup's final reboot.
|
||||||
|
certutil.exe -addstore -f Root "%SystemRoot%\Drivers\vmsvga\vm3d.cer" >nul 2>&1
|
||||||
|
certutil.exe -addstore -f TrustedPublisher "%SystemRoot%\Drivers\vmsvga\vm3d.cer" >nul 2>&1
|
||||||
|
start "" /wait /b pnputil.exe -i -a "%SystemRoot%\Drivers\vmsvga\vm3d.inf" >nul 2>&1
|
||||||
|
|
||||||
|
exit /b 0
|
||||||
|
|
||||||
:setup
|
:setup
|
||||||
if exist "%SETUP_COMPLETE%" exit /b 0
|
if exist "%SETUP_COMPLETE%" exit /b 0
|
||||||
|
|
||||||
type nul > "%SETUP_STARTED%"
|
type nul > "%SETUP_STARTED%"
|
||||||
|
|
||||||
|
rem Ignore unclean shutdowns when deciding whether to enter recovery.
|
||||||
|
bcdedit.exe /set {current} bootstatuspolicy IgnoreAllFailures
|
||||||
|
|
||||||
|
rem Keep the blue screen visible after a system crash.
|
||||||
|
bcdedit.exe /set {current} nocrashautoreboot on
|
||||||
|
|
||||||
|
rem Boot the default entry immediately without waiting at the boot menu.
|
||||||
|
bcdedit.exe /timeout 0
|
||||||
|
|
||||||
|
rem Disable automatic reboot after BSOD
|
||||||
|
reg.exe add "HKLM\SYSTEM\CurrentControlSet\Control\CrashControl" /v "AutoReboot" /t REG_DWORD /d 0 /f
|
||||||
|
|
||||||
rem Allow guest access to network shares.
|
rem Allow guest access to network shares.
|
||||||
reg.exe add "HKLM\SYSTEM\CurrentControlSet\Services\LanmanWorkstation\Parameters" /v "AllowInsecureGuestAuth" /t REG_DWORD /d 1 /f
|
reg.exe add "HKLM\SYSTEM\CurrentControlSet\Services\LanmanWorkstation\Parameters" /v "AllowInsecureGuestAuth" /t REG_DWORD /d 1 /f
|
||||||
|
|
||||||
@@ -51,7 +101,13 @@ rem Disable RemoteApp allowlist.
|
|||||||
reg.exe add "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Terminal Server\TSAppAllowList" /v "fDisabledAllowList" /t REG_DWORD /d 1 /f
|
reg.exe add "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Terminal Server\TSAppAllowList" /v "fDisabledAllowList" /t REG_DWORD /d 1 /f
|
||||||
|
|
||||||
rem Turn off automatic Windows Update downloads.
|
rem Turn off automatic Windows Update downloads.
|
||||||
reg.exe add "HKLM\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU" /v "NoAutoUpdate" /t REG_DWORD /d 1 /f
|
reg.exe add "HKLM\SOFTWARE\Microsoft\WindowsUpdate\UX\Settings" /v "FlightSettingsMaxPauseDays" /t REG_DWORD /d 3650 /f
|
||||||
|
reg.exe add "HKLM\SOFTWARE\Microsoft\WindowsUpdate\UX\Settings" /v "PauseFeatureUpdatesStartTime" /t REG_SZ /d "2026-01-01T00:00:00Z" /f
|
||||||
|
reg.exe add "HKLM\SOFTWARE\Microsoft\WindowsUpdate\UX\Settings" /v "PauseFeatureUpdatesEndTime" /t REG_SZ /d "2035-12-29T00:00:00Z" /f
|
||||||
|
reg.exe add "HKLM\SOFTWARE\Microsoft\WindowsUpdate\UX\Settings" /v "PauseQualityUpdatesStartTime" /t REG_SZ /d "2026-01-01T00:00:00Z" /f
|
||||||
|
reg.exe add "HKLM\SOFTWARE\Microsoft\WindowsUpdate\UX\Settings" /v "PauseQualityUpdatesEndTime" /t REG_SZ /d "2035-12-29T00:00:00Z" /f
|
||||||
|
reg.exe add "HKLM\SOFTWARE\Microsoft\WindowsUpdate\UX\Settings" /v "PauseUpdatesStartTime" /t REG_SZ /d "2026-01-01T00:00:00Z" /f
|
||||||
|
reg.exe add "HKLM\SOFTWARE\Microsoft\WindowsUpdate\UX\Settings" /v "PauseUpdatesExpiryTime" /t REG_SZ /d "2035-12-29T00:00:00Z" /f
|
||||||
|
|
||||||
rem Enable Network Discovery.
|
rem Enable Network Discovery.
|
||||||
netsh advfirewall firewall set rule group="@FirewallAPI.dll,-32752" new enable=Yes
|
netsh advfirewall firewall set rule group="@FirewallAPI.dll,-32752" new enable=Yes
|
||||||
@@ -78,7 +134,7 @@ type nul > "%SETUP_COMPLETE%"
|
|||||||
exit /b 0
|
exit /b 0
|
||||||
|
|
||||||
:logon
|
:logon
|
||||||
rem Run the machine setup here when SetupComplete.cmd was skipped.
|
rem Run the machine setup here when the SetupComplete hook was skipped.
|
||||||
if not exist "%SETUP_COMPLETE%" call "%~f0" setup
|
if not exist "%SETUP_COMPLETE%" call "%~f0" setup
|
||||||
|
|
||||||
rem Show file extensions in Explorer.
|
rem Show file extensions in Explorer.
|
||||||
|
|||||||
@@ -153,104 +153,8 @@
|
|||||||
<RunSynchronous>
|
<RunSynchronous>
|
||||||
<RunSynchronousCommand wcm:action="add">
|
<RunSynchronousCommand wcm:action="add">
|
||||||
<Order>1</Order>
|
<Order>1</Order>
|
||||||
<Path>reg.exe add "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\OOBE" /v BypassNRO /t REG_DWORD /d 1 /f</Path>
|
<Path>wscript.exe //B //NoLogo %WINDIR%\Setup\Scripts\Unattend.vbs specialize</Path>
|
||||||
</RunSynchronousCommand>
|
<Description>Run the specialize pass of the unattended setup script</Description>
|
||||||
<RunSynchronousCommand wcm:action="add">
|
|
||||||
<Order>2</Order>
|
|
||||||
<Path>reg.exe load "HKU\mount" "C:\Users\Default\NTUSER.DAT"</Path>
|
|
||||||
</RunSynchronousCommand>
|
|
||||||
<RunSynchronousCommand wcm:action="add">
|
|
||||||
<Order>3</Order>
|
|
||||||
<Path>reg.exe add "HKU\mount\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager" /v "ContentDeliveryAllowed" /t REG_DWORD /d 0 /f</Path>
|
|
||||||
</RunSynchronousCommand>
|
|
||||||
<RunSynchronousCommand wcm:action="add">
|
|
||||||
<Order>4</Order>
|
|
||||||
<Path>reg.exe add "HKU\mount\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager" /v "FeatureManagementEnabled" /t REG_DWORD /d 0 /f</Path>
|
|
||||||
</RunSynchronousCommand>
|
|
||||||
<RunSynchronousCommand wcm:action="add">
|
|
||||||
<Order>5</Order>
|
|
||||||
<Path>reg.exe add "HKU\mount\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager" /v "OEMPreInstalledAppsEnabled" /t REG_DWORD /d 0 /f</Path>
|
|
||||||
</RunSynchronousCommand>
|
|
||||||
<RunSynchronousCommand wcm:action="add">
|
|
||||||
<Order>6</Order>
|
|
||||||
<Path>reg.exe add "HKU\mount\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager" /v "PreInstalledAppsEnabled" /t REG_DWORD /d 0 /f</Path>
|
|
||||||
</RunSynchronousCommand>
|
|
||||||
<RunSynchronousCommand wcm:action="add">
|
|
||||||
<Order>7</Order>
|
|
||||||
<Path>reg.exe add "HKU\mount\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager" /v "PreInstalledAppsEverEnabled" /t REG_DWORD /d 0 /f</Path>
|
|
||||||
</RunSynchronousCommand>
|
|
||||||
<RunSynchronousCommand wcm:action="add">
|
|
||||||
<Order>8</Order>
|
|
||||||
<Path>reg.exe add "HKU\mount\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager" /v "SilentInstalledAppsEnabled" /t REG_DWORD /d 0 /f</Path>
|
|
||||||
</RunSynchronousCommand>
|
|
||||||
<RunSynchronousCommand wcm:action="add">
|
|
||||||
<Order>9</Order>
|
|
||||||
<Path>reg.exe add "HKU\mount\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager" /v "SoftLandingEnabled" /t REG_DWORD /d 0 /f</Path>
|
|
||||||
</RunSynchronousCommand>
|
|
||||||
<RunSynchronousCommand wcm:action="add">
|
|
||||||
<Order>10</Order>
|
|
||||||
<Path>reg.exe add "HKU\mount\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager" /v "SubscribedContentEnabled" /t REG_DWORD /d 0 /f</Path>
|
|
||||||
</RunSynchronousCommand>
|
|
||||||
<RunSynchronousCommand wcm:action="add">
|
|
||||||
<Order>11</Order>
|
|
||||||
<Path>reg.exe add "HKU\mount\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager" /v "SubscribedContent-310093Enabled" /t REG_DWORD /d 0 /f</Path>
|
|
||||||
</RunSynchronousCommand>
|
|
||||||
<RunSynchronousCommand wcm:action="add">
|
|
||||||
<Order>12</Order>
|
|
||||||
<Path>reg.exe add "HKU\mount\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager" /v "SubscribedContent-338387Enabled" /t REG_DWORD /d 0 /f</Path>
|
|
||||||
</RunSynchronousCommand>
|
|
||||||
<RunSynchronousCommand wcm:action="add">
|
|
||||||
<Order>13</Order>
|
|
||||||
<Path>reg.exe add "HKU\mount\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager" /v "SubscribedContent-338388Enabled" /t REG_DWORD /d 0 /f</Path>
|
|
||||||
</RunSynchronousCommand>
|
|
||||||
<RunSynchronousCommand wcm:action="add">
|
|
||||||
<Order>14</Order>
|
|
||||||
<Path>reg.exe add "HKU\mount\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager" /v "SubscribedContent-338389Enabled" /t REG_DWORD /d 0 /f</Path>
|
|
||||||
</RunSynchronousCommand>
|
|
||||||
<RunSynchronousCommand wcm:action="add">
|
|
||||||
<Order>15</Order>
|
|
||||||
<Path>reg.exe add "HKU\mount\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager" /v "SubscribedContent-338393Enabled" /t REG_DWORD /d 0 /f</Path>
|
|
||||||
</RunSynchronousCommand>
|
|
||||||
<RunSynchronousCommand wcm:action="add">
|
|
||||||
<Order>16</Order>
|
|
||||||
<Path>reg.exe add "HKU\mount\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager" /v "SubscribedContent-353698Enabled" /t REG_DWORD /d 0 /f</Path>
|
|
||||||
</RunSynchronousCommand>
|
|
||||||
<RunSynchronousCommand wcm:action="add">
|
|
||||||
<Order>17</Order>
|
|
||||||
<Path>reg.exe add "HKU\mount\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager" /v "SystemPaneSuggestionsEnabled" /t REG_DWORD /d 0 /f</Path>
|
|
||||||
</RunSynchronousCommand>
|
|
||||||
<RunSynchronousCommand wcm:action="add">
|
|
||||||
<Order>18</Order>
|
|
||||||
<Path>reg.exe add "HKU\mount\Software\Policies\Microsoft\Windows\CloudContent" /v "DisableCloudOptimizedContent" /t REG_DWORD /d 1 /f</Path>
|
|
||||||
</RunSynchronousCommand>
|
|
||||||
<RunSynchronousCommand wcm:action="add">
|
|
||||||
<Order>19</Order>
|
|
||||||
<Path>reg.exe add "HKU\mount\Software\Policies\Microsoft\Windows\CloudContent" /v "DisableWindowsConsumerFeatures" /t REG_DWORD /d 1 /f</Path>
|
|
||||||
</RunSynchronousCommand>
|
|
||||||
<RunSynchronousCommand wcm:action="add">
|
|
||||||
<Order>20</Order>
|
|
||||||
<Path>reg.exe add "HKU\mount\Software\Policies\Microsoft\Windows\CloudContent" /v "DisableConsumerAccountStateContent" /t REG_DWORD /d 1 /f</Path>
|
|
||||||
</RunSynchronousCommand>
|
|
||||||
<RunSynchronousCommand wcm:action="add">
|
|
||||||
<Order>21</Order>
|
|
||||||
<Path>reg.exe unload "HKU\mount"</Path>
|
|
||||||
</RunSynchronousCommand>
|
|
||||||
<RunSynchronousCommand wcm:action="add">
|
|
||||||
<Order>22</Order>
|
|
||||||
<Path>reg.exe add "HKLM\Software\Policies\Microsoft\Windows\CloudContent" /v "DisableCloudOptimizedContent" /t REG_DWORD /d 1 /f</Path>
|
|
||||||
</RunSynchronousCommand>
|
|
||||||
<RunSynchronousCommand wcm:action="add">
|
|
||||||
<Order>23</Order>
|
|
||||||
<Path>reg.exe add "HKLM\Software\Policies\Microsoft\Windows\CloudContent" /v "DisableWindowsConsumerFeatures" /t REG_DWORD /d 1 /f</Path>
|
|
||||||
</RunSynchronousCommand>
|
|
||||||
<RunSynchronousCommand wcm:action="add">
|
|
||||||
<Order>24</Order>
|
|
||||||
<Path>reg.exe add "HKLM\Software\Policies\Microsoft\Windows\CloudContent" /v "DisableConsumerAccountStateContent" /t REG_DWORD /d 1 /f</Path>
|
|
||||||
</RunSynchronousCommand>
|
|
||||||
<RunSynchronousCommand wcm:action="add">
|
|
||||||
<Order>25</Order>
|
|
||||||
<Path>reg.exe add "HKLM\SOFTWARE\Policies\Microsoft\Windows NT\CurrentVersion\NetworkList\Signatures\FirstNetwork" /v Category /t REG_DWORD /d 1 /f</Path>
|
|
||||||
<Description>Set Network Location to Home</Description>
|
|
||||||
</RunSynchronousCommand>
|
</RunSynchronousCommand>
|
||||||
</RunSynchronous>
|
</RunSynchronous>
|
||||||
</component>
|
</component>
|
||||||
@@ -326,7 +230,7 @@
|
|||||||
<FirstLogonCommands>
|
<FirstLogonCommands>
|
||||||
<SynchronousCommand wcm:action="add">
|
<SynchronousCommand wcm:action="add">
|
||||||
<Order>1</Order>
|
<Order>1</Order>
|
||||||
<CommandLine>cmd.exe /d /c call "%WINDIR%\Setup\Scripts\SetupComplete.cmd" logon</CommandLine>
|
<CommandLine>wscript.exe //B //NoLogo %WINDIR%\Setup\Scripts\Unattend.vbs logon</CommandLine>
|
||||||
<Description>Configure Windows after logon</Description>
|
<Description>Configure Windows after logon</Description>
|
||||||
</SynchronousCommand>
|
</SynchronousCommand>
|
||||||
</FirstLogonCommands>
|
</FirstLogonCommands>
|
||||||
|
|||||||
+57
-2
@@ -8,13 +8,62 @@ set "SETUP_COMPLETE=%SCRIPT_DIR%setup.complete"
|
|||||||
if "%~1"=="" goto setup
|
if "%~1"=="" goto setup
|
||||||
if /i "%~1"=="setup" goto setup
|
if /i "%~1"=="setup" goto setup
|
||||||
if /i "%~1"=="logon" goto logon
|
if /i "%~1"=="logon" goto logon
|
||||||
|
if /i "%~1"=="specialize" goto specialize
|
||||||
exit /b 2
|
exit /b 2
|
||||||
|
|
||||||
|
:specialize
|
||||||
|
|
||||||
|
reg.exe add "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\OOBE" /v BypassNRO /t REG_DWORD /d 1 /f
|
||||||
|
reg.exe load "HKU\mount" "C:\Users\Default\NTUSER.DAT"
|
||||||
|
reg.exe add "HKU\mount\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager" /v "ContentDeliveryAllowed" /t REG_DWORD /d 0 /f
|
||||||
|
reg.exe add "HKU\mount\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager" /v "FeatureManagementEnabled" /t REG_DWORD /d 0 /f
|
||||||
|
reg.exe add "HKU\mount\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager" /v "OEMPreInstalledAppsEnabled" /t REG_DWORD /d 0 /f
|
||||||
|
reg.exe add "HKU\mount\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager" /v "PreInstalledAppsEnabled" /t REG_DWORD /d 0 /f
|
||||||
|
reg.exe add "HKU\mount\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager" /v "PreInstalledAppsEverEnabled" /t REG_DWORD /d 0 /f
|
||||||
|
reg.exe add "HKU\mount\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager" /v "SilentInstalledAppsEnabled" /t REG_DWORD /d 0 /f
|
||||||
|
reg.exe add "HKU\mount\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager" /v "SoftLandingEnabled" /t REG_DWORD /d 0 /f
|
||||||
|
reg.exe add "HKU\mount\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager" /v "SubscribedContentEnabled" /t REG_DWORD /d 0 /f
|
||||||
|
reg.exe add "HKU\mount\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager" /v "SubscribedContent-310093Enabled" /t REG_DWORD /d 0 /f
|
||||||
|
reg.exe add "HKU\mount\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager" /v "SubscribedContent-338387Enabled" /t REG_DWORD /d 0 /f
|
||||||
|
reg.exe add "HKU\mount\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager" /v "SubscribedContent-338388Enabled" /t REG_DWORD /d 0 /f
|
||||||
|
reg.exe add "HKU\mount\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager" /v "SubscribedContent-338389Enabled" /t REG_DWORD /d 0 /f
|
||||||
|
reg.exe add "HKU\mount\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager" /v "SubscribedContent-338393Enabled" /t REG_DWORD /d 0 /f
|
||||||
|
reg.exe add "HKU\mount\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager" /v "SubscribedContent-353698Enabled" /t REG_DWORD /d 0 /f
|
||||||
|
reg.exe add "HKU\mount\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager" /v "SystemPaneSuggestionsEnabled" /t REG_DWORD /d 0 /f
|
||||||
|
reg.exe add "HKU\mount\Software\Policies\Microsoft\Windows\CloudContent" /v "DisableCloudOptimizedContent" /t REG_DWORD /d 1 /f
|
||||||
|
reg.exe add "HKU\mount\Software\Policies\Microsoft\Windows\CloudContent" /v "DisableWindowsConsumerFeatures" /t REG_DWORD /d 1 /f
|
||||||
|
reg.exe add "HKU\mount\Software\Policies\Microsoft\Windows\CloudContent" /v "DisableConsumerAccountStateContent" /t REG_DWORD /d 1 /f
|
||||||
|
reg.exe unload "HKU\mount"
|
||||||
|
reg.exe add "HKLM\Software\Policies\Microsoft\Windows\CloudContent" /v "DisableCloudOptimizedContent" /t REG_DWORD /d 1 /f
|
||||||
|
reg.exe add "HKLM\Software\Policies\Microsoft\Windows\CloudContent" /v "DisableWindowsConsumerFeatures" /t REG_DWORD /d 1 /f
|
||||||
|
reg.exe add "HKLM\Software\Policies\Microsoft\Windows\CloudContent" /v "DisableConsumerAccountStateContent" /t REG_DWORD /d 1 /f
|
||||||
|
|
||||||
|
rem Set Network Location to Home
|
||||||
|
reg.exe add "HKLM\SOFTWARE\Policies\Microsoft\Windows NT\CurrentVersion\NetworkList\Signatures\FirstNetwork" /v Category /t REG_DWORD /d 1 /f
|
||||||
|
|
||||||
|
rem Install the VMWare display driver before Windows Setup's final reboot.
|
||||||
|
certutil.exe -addstore -f Root "%SystemRoot%\Drivers\vmsvga\vm3d.cer" >nul 2>&1
|
||||||
|
certutil.exe -addstore -f TrustedPublisher "%SystemRoot%\Drivers\vmsvga\vm3d.cer" >nul 2>&1
|
||||||
|
start "" /wait /b pnputil.exe -i -a "%SystemRoot%\Drivers\vmsvga\vm3d.inf" >nul 2>&1
|
||||||
|
|
||||||
|
exit /b 0
|
||||||
:setup
|
:setup
|
||||||
if exist "%SETUP_COMPLETE%" exit /b 0
|
if exist "%SETUP_COMPLETE%" exit /b 0
|
||||||
|
|
||||||
type nul > "%SETUP_STARTED%"
|
type nul > "%SETUP_STARTED%"
|
||||||
|
|
||||||
|
rem Ignore unclean shutdowns when deciding whether to enter recovery.
|
||||||
|
bcdedit.exe /set {current} bootstatuspolicy IgnoreAllFailures
|
||||||
|
|
||||||
|
rem Keep the blue screen visible after a system crash.
|
||||||
|
bcdedit.exe /set {current} nocrashautoreboot on
|
||||||
|
|
||||||
|
rem Boot the default entry immediately without waiting at the boot menu.
|
||||||
|
bcdedit.exe /timeout 0
|
||||||
|
|
||||||
|
rem Disable automatic reboot after BSOD
|
||||||
|
reg.exe add "HKLM\SYSTEM\CurrentControlSet\Control\CrashControl" /v "AutoReboot" /t REG_DWORD /d 0 /f
|
||||||
|
|
||||||
rem Allow guest access to network shares.
|
rem Allow guest access to network shares.
|
||||||
reg.exe add "HKLM\SYSTEM\CurrentControlSet\Services\LanmanWorkstation\Parameters" /v "AllowInsecureGuestAuth" /t REG_DWORD /d 1 /f
|
reg.exe add "HKLM\SYSTEM\CurrentControlSet\Services\LanmanWorkstation\Parameters" /v "AllowInsecureGuestAuth" /t REG_DWORD /d 1 /f
|
||||||
|
|
||||||
@@ -51,7 +100,13 @@ rem Disable RemoteApp allowlist.
|
|||||||
reg.exe add "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Terminal Server\TSAppAllowList" /v "fDisabledAllowList" /t REG_DWORD /d 1 /f
|
reg.exe add "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Terminal Server\TSAppAllowList" /v "fDisabledAllowList" /t REG_DWORD /d 1 /f
|
||||||
|
|
||||||
rem Turn off automatic Windows Update downloads.
|
rem Turn off automatic Windows Update downloads.
|
||||||
reg.exe add "HKLM\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU" /v "NoAutoUpdate" /t REG_DWORD /d 1 /f
|
reg.exe add "HKLM\SOFTWARE\Microsoft\WindowsUpdate\UX\Settings" /v "FlightSettingsMaxPauseDays" /t REG_DWORD /d 3650 /f
|
||||||
|
reg.exe add "HKLM\SOFTWARE\Microsoft\WindowsUpdate\UX\Settings" /v "PauseFeatureUpdatesStartTime" /t REG_SZ /d "2026-01-01T00:00:00Z" /f
|
||||||
|
reg.exe add "HKLM\SOFTWARE\Microsoft\WindowsUpdate\UX\Settings" /v "PauseFeatureUpdatesEndTime" /t REG_SZ /d "2035-12-29T00:00:00Z" /f
|
||||||
|
reg.exe add "HKLM\SOFTWARE\Microsoft\WindowsUpdate\UX\Settings" /v "PauseQualityUpdatesStartTime" /t REG_SZ /d "2026-01-01T00:00:00Z" /f
|
||||||
|
reg.exe add "HKLM\SOFTWARE\Microsoft\WindowsUpdate\UX\Settings" /v "PauseQualityUpdatesEndTime" /t REG_SZ /d "2035-12-29T00:00:00Z" /f
|
||||||
|
reg.exe add "HKLM\SOFTWARE\Microsoft\WindowsUpdate\UX\Settings" /v "PauseUpdatesStartTime" /t REG_SZ /d "2026-01-01T00:00:00Z" /f
|
||||||
|
reg.exe add "HKLM\SOFTWARE\Microsoft\WindowsUpdate\UX\Settings" /v "PauseUpdatesExpiryTime" /t REG_SZ /d "2035-12-29T00:00:00Z" /f
|
||||||
|
|
||||||
rem Enable Network Discovery.
|
rem Enable Network Discovery.
|
||||||
netsh advfirewall firewall set rule group="@FirewallAPI.dll,-32752" new enable=Yes
|
netsh advfirewall firewall set rule group="@FirewallAPI.dll,-32752" new enable=Yes
|
||||||
@@ -78,7 +133,7 @@ type nul > "%SETUP_COMPLETE%"
|
|||||||
exit /b 0
|
exit /b 0
|
||||||
|
|
||||||
:logon
|
:logon
|
||||||
rem Run the machine setup here when SetupComplete.cmd was skipped.
|
rem Run the machine setup here when the SetupComplete hook was skipped.
|
||||||
if not exist "%SETUP_COMPLETE%" call "%~f0" setup
|
if not exist "%SETUP_COMPLETE%" call "%~f0" setup
|
||||||
|
|
||||||
rem Show file extensions in Explorer.
|
rem Show file extensions in Explorer.
|
||||||
|
|||||||
+3
-99
@@ -150,104 +150,8 @@
|
|||||||
<RunSynchronous>
|
<RunSynchronous>
|
||||||
<RunSynchronousCommand wcm:action="add">
|
<RunSynchronousCommand wcm:action="add">
|
||||||
<Order>1</Order>
|
<Order>1</Order>
|
||||||
<Path>reg.exe add "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\OOBE" /v BypassNRO /t REG_DWORD /d 1 /f</Path>
|
<Path>wscript.exe //B //NoLogo %WINDIR%\Setup\Scripts\Unattend.vbs specialize</Path>
|
||||||
</RunSynchronousCommand>
|
<Description>Run the specialize pass of the unattended setup script</Description>
|
||||||
<RunSynchronousCommand wcm:action="add">
|
|
||||||
<Order>2</Order>
|
|
||||||
<Path>reg.exe load "HKU\mount" "C:\Users\Default\NTUSER.DAT"</Path>
|
|
||||||
</RunSynchronousCommand>
|
|
||||||
<RunSynchronousCommand wcm:action="add">
|
|
||||||
<Order>3</Order>
|
|
||||||
<Path>reg.exe add "HKU\mount\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager" /v "ContentDeliveryAllowed" /t REG_DWORD /d 0 /f</Path>
|
|
||||||
</RunSynchronousCommand>
|
|
||||||
<RunSynchronousCommand wcm:action="add">
|
|
||||||
<Order>4</Order>
|
|
||||||
<Path>reg.exe add "HKU\mount\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager" /v "FeatureManagementEnabled" /t REG_DWORD /d 0 /f</Path>
|
|
||||||
</RunSynchronousCommand>
|
|
||||||
<RunSynchronousCommand wcm:action="add">
|
|
||||||
<Order>5</Order>
|
|
||||||
<Path>reg.exe add "HKU\mount\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager" /v "OEMPreInstalledAppsEnabled" /t REG_DWORD /d 0 /f</Path>
|
|
||||||
</RunSynchronousCommand>
|
|
||||||
<RunSynchronousCommand wcm:action="add">
|
|
||||||
<Order>6</Order>
|
|
||||||
<Path>reg.exe add "HKU\mount\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager" /v "PreInstalledAppsEnabled" /t REG_DWORD /d 0 /f</Path>
|
|
||||||
</RunSynchronousCommand>
|
|
||||||
<RunSynchronousCommand wcm:action="add">
|
|
||||||
<Order>7</Order>
|
|
||||||
<Path>reg.exe add "HKU\mount\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager" /v "PreInstalledAppsEverEnabled" /t REG_DWORD /d 0 /f</Path>
|
|
||||||
</RunSynchronousCommand>
|
|
||||||
<RunSynchronousCommand wcm:action="add">
|
|
||||||
<Order>8</Order>
|
|
||||||
<Path>reg.exe add "HKU\mount\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager" /v "SilentInstalledAppsEnabled" /t REG_DWORD /d 0 /f</Path>
|
|
||||||
</RunSynchronousCommand>
|
|
||||||
<RunSynchronousCommand wcm:action="add">
|
|
||||||
<Order>9</Order>
|
|
||||||
<Path>reg.exe add "HKU\mount\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager" /v "SoftLandingEnabled" /t REG_DWORD /d 0 /f</Path>
|
|
||||||
</RunSynchronousCommand>
|
|
||||||
<RunSynchronousCommand wcm:action="add">
|
|
||||||
<Order>10</Order>
|
|
||||||
<Path>reg.exe add "HKU\mount\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager" /v "SubscribedContentEnabled" /t REG_DWORD /d 0 /f</Path>
|
|
||||||
</RunSynchronousCommand>
|
|
||||||
<RunSynchronousCommand wcm:action="add">
|
|
||||||
<Order>11</Order>
|
|
||||||
<Path>reg.exe add "HKU\mount\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager" /v "SubscribedContent-310093Enabled" /t REG_DWORD /d 0 /f</Path>
|
|
||||||
</RunSynchronousCommand>
|
|
||||||
<RunSynchronousCommand wcm:action="add">
|
|
||||||
<Order>12</Order>
|
|
||||||
<Path>reg.exe add "HKU\mount\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager" /v "SubscribedContent-338387Enabled" /t REG_DWORD /d 0 /f</Path>
|
|
||||||
</RunSynchronousCommand>
|
|
||||||
<RunSynchronousCommand wcm:action="add">
|
|
||||||
<Order>13</Order>
|
|
||||||
<Path>reg.exe add "HKU\mount\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager" /v "SubscribedContent-338388Enabled" /t REG_DWORD /d 0 /f</Path>
|
|
||||||
</RunSynchronousCommand>
|
|
||||||
<RunSynchronousCommand wcm:action="add">
|
|
||||||
<Order>14</Order>
|
|
||||||
<Path>reg.exe add "HKU\mount\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager" /v "SubscribedContent-338389Enabled" /t REG_DWORD /d 0 /f</Path>
|
|
||||||
</RunSynchronousCommand>
|
|
||||||
<RunSynchronousCommand wcm:action="add">
|
|
||||||
<Order>15</Order>
|
|
||||||
<Path>reg.exe add "HKU\mount\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager" /v "SubscribedContent-338393Enabled" /t REG_DWORD /d 0 /f</Path>
|
|
||||||
</RunSynchronousCommand>
|
|
||||||
<RunSynchronousCommand wcm:action="add">
|
|
||||||
<Order>16</Order>
|
|
||||||
<Path>reg.exe add "HKU\mount\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager" /v "SubscribedContent-353698Enabled" /t REG_DWORD /d 0 /f</Path>
|
|
||||||
</RunSynchronousCommand>
|
|
||||||
<RunSynchronousCommand wcm:action="add">
|
|
||||||
<Order>17</Order>
|
|
||||||
<Path>reg.exe add "HKU\mount\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager" /v "SystemPaneSuggestionsEnabled" /t REG_DWORD /d 0 /f</Path>
|
|
||||||
</RunSynchronousCommand>
|
|
||||||
<RunSynchronousCommand wcm:action="add">
|
|
||||||
<Order>18</Order>
|
|
||||||
<Path>reg.exe add "HKU\mount\Software\Policies\Microsoft\Windows\CloudContent" /v "DisableCloudOptimizedContent" /t REG_DWORD /d 1 /f</Path>
|
|
||||||
</RunSynchronousCommand>
|
|
||||||
<RunSynchronousCommand wcm:action="add">
|
|
||||||
<Order>19</Order>
|
|
||||||
<Path>reg.exe add "HKU\mount\Software\Policies\Microsoft\Windows\CloudContent" /v "DisableWindowsConsumerFeatures" /t REG_DWORD /d 1 /f</Path>
|
|
||||||
</RunSynchronousCommand>
|
|
||||||
<RunSynchronousCommand wcm:action="add">
|
|
||||||
<Order>20</Order>
|
|
||||||
<Path>reg.exe add "HKU\mount\Software\Policies\Microsoft\Windows\CloudContent" /v "DisableConsumerAccountStateContent" /t REG_DWORD /d 1 /f</Path>
|
|
||||||
</RunSynchronousCommand>
|
|
||||||
<RunSynchronousCommand wcm:action="add">
|
|
||||||
<Order>21</Order>
|
|
||||||
<Path>reg.exe unload "HKU\mount"</Path>
|
|
||||||
</RunSynchronousCommand>
|
|
||||||
<RunSynchronousCommand wcm:action="add">
|
|
||||||
<Order>22</Order>
|
|
||||||
<Path>reg.exe add "HKLM\Software\Policies\Microsoft\Windows\CloudContent" /v "DisableCloudOptimizedContent" /t REG_DWORD /d 1 /f</Path>
|
|
||||||
</RunSynchronousCommand>
|
|
||||||
<RunSynchronousCommand wcm:action="add">
|
|
||||||
<Order>23</Order>
|
|
||||||
<Path>reg.exe add "HKLM\Software\Policies\Microsoft\Windows\CloudContent" /v "DisableWindowsConsumerFeatures" /t REG_DWORD /d 1 /f</Path>
|
|
||||||
</RunSynchronousCommand>
|
|
||||||
<RunSynchronousCommand wcm:action="add">
|
|
||||||
<Order>24</Order>
|
|
||||||
<Path>reg.exe add "HKLM\Software\Policies\Microsoft\Windows\CloudContent" /v "DisableConsumerAccountStateContent" /t REG_DWORD /d 1 /f</Path>
|
|
||||||
</RunSynchronousCommand>
|
|
||||||
<RunSynchronousCommand wcm:action="add">
|
|
||||||
<Order>25</Order>
|
|
||||||
<Path>reg.exe add "HKLM\SOFTWARE\Policies\Microsoft\Windows NT\CurrentVersion\NetworkList\Signatures\FirstNetwork" /v Category /t REG_DWORD /d 1 /f</Path>
|
|
||||||
<Description>Set Network Location to Home</Description>
|
|
||||||
</RunSynchronousCommand>
|
</RunSynchronousCommand>
|
||||||
</RunSynchronous>
|
</RunSynchronous>
|
||||||
</component>
|
</component>
|
||||||
@@ -323,7 +227,7 @@
|
|||||||
<FirstLogonCommands>
|
<FirstLogonCommands>
|
||||||
<SynchronousCommand wcm:action="add">
|
<SynchronousCommand wcm:action="add">
|
||||||
<Order>1</Order>
|
<Order>1</Order>
|
||||||
<CommandLine>cmd.exe /d /c call "%WINDIR%\Setup\Scripts\SetupComplete.cmd" logon</CommandLine>
|
<CommandLine>wscript.exe //B //NoLogo %WINDIR%\Setup\Scripts\Unattend.vbs logon</CommandLine>
|
||||||
<Description>Configure Windows after logon</Description>
|
<Description>Configure Windows after logon</Description>
|
||||||
</SynchronousCommand>
|
</SynchronousCommand>
|
||||||
</FirstLogonCommands>
|
</FirstLogonCommands>
|
||||||
|
|||||||
@@ -6,15 +6,75 @@ set "SETUP_STARTED=%SCRIPT_DIR%setup.started"
|
|||||||
set "SETUP_COMPLETE=%SCRIPT_DIR%setup.complete"
|
set "SETUP_COMPLETE=%SCRIPT_DIR%setup.complete"
|
||||||
|
|
||||||
if "%~1"=="" goto setup
|
if "%~1"=="" goto setup
|
||||||
|
if /i "%~1"=="pe" goto pe
|
||||||
if /i "%~1"=="setup" goto setup
|
if /i "%~1"=="setup" goto setup
|
||||||
if /i "%~1"=="logon" goto logon
|
if /i "%~1"=="logon" goto logon
|
||||||
|
if /i "%~1"=="specialize" goto specialize
|
||||||
exit /b 2
|
exit /b 2
|
||||||
|
|
||||||
|
:pe
|
||||||
|
|
||||||
|
reg.exe add "HKLM\SYSTEM\Setup\LabConfig" /v BypassTPMCheck /t REG_DWORD /d 1 /f
|
||||||
|
reg.exe add "HKLM\SYSTEM\Setup\LabConfig" /v BypassSecureBootCheck /t REG_DWORD /d 1 /f
|
||||||
|
reg.exe add "HKLM\SYSTEM\Setup\LabConfig" /v BypassRAMCheck /t REG_DWORD /d 1 /f
|
||||||
|
reg.exe add "HKLM\SYSTEM\Setup\MoSetup" /v AllowUpgradesWithUnsupportedTPMOrCPU /t REG_DWORD /d 1 /f
|
||||||
|
|
||||||
|
exit /b 0
|
||||||
|
|
||||||
|
:specialize
|
||||||
|
|
||||||
|
reg.exe add "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\OOBE" /v BypassNRO /t REG_DWORD /d 1 /f
|
||||||
|
reg.exe load "HKU\mount" "C:\Users\Default\NTUSER.DAT"
|
||||||
|
reg.exe add "HKU\mount\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager" /v "ContentDeliveryAllowed" /t REG_DWORD /d 0 /f
|
||||||
|
reg.exe add "HKU\mount\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager" /v "FeatureManagementEnabled" /t REG_DWORD /d 0 /f
|
||||||
|
reg.exe add "HKU\mount\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager" /v "OEMPreInstalledAppsEnabled" /t REG_DWORD /d 0 /f
|
||||||
|
reg.exe add "HKU\mount\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager" /v "PreInstalledAppsEnabled" /t REG_DWORD /d 0 /f
|
||||||
|
reg.exe add "HKU\mount\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager" /v "PreInstalledAppsEverEnabled" /t REG_DWORD /d 0 /f
|
||||||
|
reg.exe add "HKU\mount\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager" /v "SilentInstalledAppsEnabled" /t REG_DWORD /d 0 /f
|
||||||
|
reg.exe add "HKU\mount\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager" /v "SoftLandingEnabled" /t REG_DWORD /d 0 /f
|
||||||
|
reg.exe add "HKU\mount\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager" /v "SubscribedContentEnabled" /t REG_DWORD /d 0 /f
|
||||||
|
reg.exe add "HKU\mount\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager" /v "SubscribedContent-310093Enabled" /t REG_DWORD /d 0 /f
|
||||||
|
reg.exe add "HKU\mount\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager" /v "SubscribedContent-338387Enabled" /t REG_DWORD /d 0 /f
|
||||||
|
reg.exe add "HKU\mount\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager" /v "SubscribedContent-338388Enabled" /t REG_DWORD /d 0 /f
|
||||||
|
reg.exe add "HKU\mount\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager" /v "SubscribedContent-338389Enabled" /t REG_DWORD /d 0 /f
|
||||||
|
reg.exe add "HKU\mount\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager" /v "SubscribedContent-338393Enabled" /t REG_DWORD /d 0 /f
|
||||||
|
reg.exe add "HKU\mount\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager" /v "SubscribedContent-353698Enabled" /t REG_DWORD /d 0 /f
|
||||||
|
reg.exe add "HKU\mount\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager" /v "SystemPaneSuggestionsEnabled" /t REG_DWORD /d 0 /f
|
||||||
|
reg.exe add "HKU\mount\Software\Policies\Microsoft\Windows\CloudContent" /v "DisableCloudOptimizedContent" /t REG_DWORD /d 1 /f
|
||||||
|
reg.exe add "HKU\mount\Software\Policies\Microsoft\Windows\CloudContent" /v "DisableWindowsConsumerFeatures" /t REG_DWORD /d 1 /f
|
||||||
|
reg.exe add "HKU\mount\Software\Policies\Microsoft\Windows\CloudContent" /v "DisableConsumerAccountStateContent" /t REG_DWORD /d 1 /f
|
||||||
|
reg.exe unload "HKU\mount"
|
||||||
|
reg.exe add "HKLM\Software\Policies\Microsoft\Windows\CloudContent" /v "DisableCloudOptimizedContent" /t REG_DWORD /d 1 /f
|
||||||
|
reg.exe add "HKLM\Software\Policies\Microsoft\Windows\CloudContent" /v "DisableWindowsConsumerFeatures" /t REG_DWORD /d 1 /f
|
||||||
|
reg.exe add "HKLM\Software\Policies\Microsoft\Windows\CloudContent" /v "DisableConsumerAccountStateContent" /t REG_DWORD /d 1 /f
|
||||||
|
|
||||||
|
rem Set Network Location to Home
|
||||||
|
reg.exe add "HKLM\SOFTWARE\Policies\Microsoft\Windows NT\CurrentVersion\NetworkList\Signatures\FirstNetwork" /v Category /t REG_DWORD /d 1 /f
|
||||||
|
|
||||||
|
rem Install the VMWare display driver before Windows Setup's final reboot.
|
||||||
|
certutil.exe -addstore -f Root "%SystemRoot%\Drivers\vmsvga\vm3d.cer" >nul 2>&1
|
||||||
|
certutil.exe -addstore -f TrustedPublisher "%SystemRoot%\Drivers\vmsvga\vm3d.cer" >nul 2>&1
|
||||||
|
start "" /wait /b pnputil.exe -i -a "%SystemRoot%\Drivers\vmsvga\vm3d.inf" >nul 2>&1
|
||||||
|
|
||||||
|
exit /b 0
|
||||||
|
|
||||||
:setup
|
:setup
|
||||||
if exist "%SETUP_COMPLETE%" exit /b 0
|
if exist "%SETUP_COMPLETE%" exit /b 0
|
||||||
|
|
||||||
type nul > "%SETUP_STARTED%"
|
type nul > "%SETUP_STARTED%"
|
||||||
|
|
||||||
|
rem Ignore unclean shutdowns when deciding whether to enter recovery.
|
||||||
|
bcdedit.exe /set {current} bootstatuspolicy IgnoreAllFailures
|
||||||
|
|
||||||
|
rem Keep the blue screen visible after a system crash.
|
||||||
|
bcdedit.exe /set {current} nocrashautoreboot on
|
||||||
|
|
||||||
|
rem Boot the default entry immediately without waiting at the boot menu.
|
||||||
|
bcdedit.exe /timeout 0
|
||||||
|
|
||||||
|
rem Disable automatic reboot after BSOD
|
||||||
|
reg.exe add "HKLM\SYSTEM\CurrentControlSet\Control\CrashControl" /v "AutoReboot" /t REG_DWORD /d 0 /f
|
||||||
|
|
||||||
rem Allow guest access to network shares.
|
rem Allow guest access to network shares.
|
||||||
reg.exe add "HKLM\SYSTEM\CurrentControlSet\Services\LanmanWorkstation\Parameters" /v "AllowInsecureGuestAuth" /t REG_DWORD /d 1 /f
|
reg.exe add "HKLM\SYSTEM\CurrentControlSet\Services\LanmanWorkstation\Parameters" /v "AllowInsecureGuestAuth" /t REG_DWORD /d 1 /f
|
||||||
|
|
||||||
@@ -29,6 +89,9 @@ rem Prevent the local user password from expiring.
|
|||||||
powershell.exe -ExecutionPolicy Unrestricted -NoLogo -NoProfile -NonInteractive set-localuser -name "Docker" -passwordneverexpires 1
|
powershell.exe -ExecutionPolicy Unrestricted -NoLogo -NoProfile -NonInteractive set-localuser -name "Docker" -passwordneverexpires 1
|
||||||
rem END LOCAL_ACCOUNT
|
rem END LOCAL_ACCOUNT
|
||||||
|
|
||||||
|
rem Disable per-CPU clock tick scheduling.
|
||||||
|
reg.exe add "HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\kernel" /v "EnablePerCpuClockTickScheduling" /t REG_DWORD /d 2 /f
|
||||||
|
|
||||||
rem Disable hibernation.
|
rem Disable hibernation.
|
||||||
POWERCFG -H OFF
|
POWERCFG -H OFF
|
||||||
|
|
||||||
@@ -54,7 +117,13 @@ rem Disable RemoteApp allowlist.
|
|||||||
reg.exe add "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Terminal Server\TSAppAllowList" /v "fDisabledAllowList" /t REG_DWORD /d 1 /f
|
reg.exe add "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Terminal Server\TSAppAllowList" /v "fDisabledAllowList" /t REG_DWORD /d 1 /f
|
||||||
|
|
||||||
rem Turn off automatic Windows Update downloads.
|
rem Turn off automatic Windows Update downloads.
|
||||||
reg.exe add "HKLM\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU" /v "NoAutoUpdate" /t REG_DWORD /d 1 /f
|
reg.exe add "HKLM\SOFTWARE\Microsoft\WindowsUpdate\UX\Settings" /v "FlightSettingsMaxPauseDays" /t REG_DWORD /d 3650 /f
|
||||||
|
reg.exe add "HKLM\SOFTWARE\Microsoft\WindowsUpdate\UX\Settings" /v "PauseFeatureUpdatesStartTime" /t REG_SZ /d "2026-01-01T00:00:00Z" /f
|
||||||
|
reg.exe add "HKLM\SOFTWARE\Microsoft\WindowsUpdate\UX\Settings" /v "PauseFeatureUpdatesEndTime" /t REG_SZ /d "2035-12-29T00:00:00Z" /f
|
||||||
|
reg.exe add "HKLM\SOFTWARE\Microsoft\WindowsUpdate\UX\Settings" /v "PauseQualityUpdatesStartTime" /t REG_SZ /d "2026-01-01T00:00:00Z" /f
|
||||||
|
reg.exe add "HKLM\SOFTWARE\Microsoft\WindowsUpdate\UX\Settings" /v "PauseQualityUpdatesEndTime" /t REG_SZ /d "2035-12-29T00:00:00Z" /f
|
||||||
|
reg.exe add "HKLM\SOFTWARE\Microsoft\WindowsUpdate\UX\Settings" /v "PauseUpdatesStartTime" /t REG_SZ /d "2026-01-01T00:00:00Z" /f
|
||||||
|
reg.exe add "HKLM\SOFTWARE\Microsoft\WindowsUpdate\UX\Settings" /v "PauseUpdatesExpiryTime" /t REG_SZ /d "2035-12-29T00:00:00Z" /f
|
||||||
|
|
||||||
rem Enable Network Discovery.
|
rem Enable Network Discovery.
|
||||||
netsh advfirewall firewall set rule group="@FirewallAPI.dll,-32752" new enable=Yes
|
netsh advfirewall firewall set rule group="@FirewallAPI.dll,-32752" new enable=Yes
|
||||||
@@ -81,7 +150,7 @@ type nul > "%SETUP_COMPLETE%"
|
|||||||
exit /b 0
|
exit /b 0
|
||||||
|
|
||||||
:logon
|
:logon
|
||||||
rem Run the machine setup here when SetupComplete.cmd was skipped.
|
rem Run the machine setup here when the SetupComplete hook was skipped.
|
||||||
if not exist "%SETUP_COMPLETE%" call "%~f0" setup
|
if not exist "%SETUP_COMPLETE%" call "%~f0" setup
|
||||||
|
|
||||||
rem Hide Copilot button.
|
rem Hide Copilot button.
|
||||||
|
|||||||
@@ -168,104 +168,8 @@
|
|||||||
<RunSynchronous>
|
<RunSynchronous>
|
||||||
<RunSynchronousCommand wcm:action="add">
|
<RunSynchronousCommand wcm:action="add">
|
||||||
<Order>1</Order>
|
<Order>1</Order>
|
||||||
<Path>reg.exe add "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\OOBE" /v BypassNRO /t REG_DWORD /d 1 /f</Path>
|
<Path>wscript.exe //B //NoLogo %WINDIR%\Setup\Scripts\Unattend.vbs specialize</Path>
|
||||||
</RunSynchronousCommand>
|
<Description>Run the specialize pass of the unattended setup script</Description>
|
||||||
<RunSynchronousCommand wcm:action="add">
|
|
||||||
<Order>2</Order>
|
|
||||||
<Path>reg.exe load "HKU\mount" "C:\Users\Default\NTUSER.DAT"</Path>
|
|
||||||
</RunSynchronousCommand>
|
|
||||||
<RunSynchronousCommand wcm:action="add">
|
|
||||||
<Order>3</Order>
|
|
||||||
<Path>reg.exe add "HKU\mount\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager" /v "ContentDeliveryAllowed" /t REG_DWORD /d 0 /f</Path>
|
|
||||||
</RunSynchronousCommand>
|
|
||||||
<RunSynchronousCommand wcm:action="add">
|
|
||||||
<Order>4</Order>
|
|
||||||
<Path>reg.exe add "HKU\mount\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager" /v "FeatureManagementEnabled" /t REG_DWORD /d 0 /f</Path>
|
|
||||||
</RunSynchronousCommand>
|
|
||||||
<RunSynchronousCommand wcm:action="add">
|
|
||||||
<Order>5</Order>
|
|
||||||
<Path>reg.exe add "HKU\mount\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager" /v "OEMPreInstalledAppsEnabled" /t REG_DWORD /d 0 /f</Path>
|
|
||||||
</RunSynchronousCommand>
|
|
||||||
<RunSynchronousCommand wcm:action="add">
|
|
||||||
<Order>6</Order>
|
|
||||||
<Path>reg.exe add "HKU\mount\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager" /v "PreInstalledAppsEnabled" /t REG_DWORD /d 0 /f</Path>
|
|
||||||
</RunSynchronousCommand>
|
|
||||||
<RunSynchronousCommand wcm:action="add">
|
|
||||||
<Order>7</Order>
|
|
||||||
<Path>reg.exe add "HKU\mount\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager" /v "PreInstalledAppsEverEnabled" /t REG_DWORD /d 0 /f</Path>
|
|
||||||
</RunSynchronousCommand>
|
|
||||||
<RunSynchronousCommand wcm:action="add">
|
|
||||||
<Order>8</Order>
|
|
||||||
<Path>reg.exe add "HKU\mount\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager" /v "SilentInstalledAppsEnabled" /t REG_DWORD /d 0 /f</Path>
|
|
||||||
</RunSynchronousCommand>
|
|
||||||
<RunSynchronousCommand wcm:action="add">
|
|
||||||
<Order>9</Order>
|
|
||||||
<Path>reg.exe add "HKU\mount\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager" /v "SoftLandingEnabled" /t REG_DWORD /d 0 /f</Path>
|
|
||||||
</RunSynchronousCommand>
|
|
||||||
<RunSynchronousCommand wcm:action="add">
|
|
||||||
<Order>10</Order>
|
|
||||||
<Path>reg.exe add "HKU\mount\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager" /v "SubscribedContentEnabled" /t REG_DWORD /d 0 /f</Path>
|
|
||||||
</RunSynchronousCommand>
|
|
||||||
<RunSynchronousCommand wcm:action="add">
|
|
||||||
<Order>11</Order>
|
|
||||||
<Path>reg.exe add "HKU\mount\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager" /v "SubscribedContent-310093Enabled" /t REG_DWORD /d 0 /f</Path>
|
|
||||||
</RunSynchronousCommand>
|
|
||||||
<RunSynchronousCommand wcm:action="add">
|
|
||||||
<Order>12</Order>
|
|
||||||
<Path>reg.exe add "HKU\mount\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager" /v "SubscribedContent-338387Enabled" /t REG_DWORD /d 0 /f</Path>
|
|
||||||
</RunSynchronousCommand>
|
|
||||||
<RunSynchronousCommand wcm:action="add">
|
|
||||||
<Order>13</Order>
|
|
||||||
<Path>reg.exe add "HKU\mount\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager" /v "SubscribedContent-338388Enabled" /t REG_DWORD /d 0 /f</Path>
|
|
||||||
</RunSynchronousCommand>
|
|
||||||
<RunSynchronousCommand wcm:action="add">
|
|
||||||
<Order>14</Order>
|
|
||||||
<Path>reg.exe add "HKU\mount\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager" /v "SubscribedContent-338389Enabled" /t REG_DWORD /d 0 /f</Path>
|
|
||||||
</RunSynchronousCommand>
|
|
||||||
<RunSynchronousCommand wcm:action="add">
|
|
||||||
<Order>15</Order>
|
|
||||||
<Path>reg.exe add "HKU\mount\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager" /v "SubscribedContent-338393Enabled" /t REG_DWORD /d 0 /f</Path>
|
|
||||||
</RunSynchronousCommand>
|
|
||||||
<RunSynchronousCommand wcm:action="add">
|
|
||||||
<Order>16</Order>
|
|
||||||
<Path>reg.exe add "HKU\mount\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager" /v "SubscribedContent-353698Enabled" /t REG_DWORD /d 0 /f</Path>
|
|
||||||
</RunSynchronousCommand>
|
|
||||||
<RunSynchronousCommand wcm:action="add">
|
|
||||||
<Order>17</Order>
|
|
||||||
<Path>reg.exe add "HKU\mount\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager" /v "SystemPaneSuggestionsEnabled" /t REG_DWORD /d 0 /f</Path>
|
|
||||||
</RunSynchronousCommand>
|
|
||||||
<RunSynchronousCommand wcm:action="add">
|
|
||||||
<Order>18</Order>
|
|
||||||
<Path>reg.exe add "HKU\mount\Software\Policies\Microsoft\Windows\CloudContent" /v "DisableCloudOptimizedContent" /t REG_DWORD /d 1 /f</Path>
|
|
||||||
</RunSynchronousCommand>
|
|
||||||
<RunSynchronousCommand wcm:action="add">
|
|
||||||
<Order>19</Order>
|
|
||||||
<Path>reg.exe add "HKU\mount\Software\Policies\Microsoft\Windows\CloudContent" /v "DisableWindowsConsumerFeatures" /t REG_DWORD /d 1 /f</Path>
|
|
||||||
</RunSynchronousCommand>
|
|
||||||
<RunSynchronousCommand wcm:action="add">
|
|
||||||
<Order>20</Order>
|
|
||||||
<Path>reg.exe add "HKU\mount\Software\Policies\Microsoft\Windows\CloudContent" /v "DisableConsumerAccountStateContent" /t REG_DWORD /d 1 /f</Path>
|
|
||||||
</RunSynchronousCommand>
|
|
||||||
<RunSynchronousCommand wcm:action="add">
|
|
||||||
<Order>21</Order>
|
|
||||||
<Path>reg.exe unload "HKU\mount"</Path>
|
|
||||||
</RunSynchronousCommand>
|
|
||||||
<RunSynchronousCommand wcm:action="add">
|
|
||||||
<Order>22</Order>
|
|
||||||
<Path>reg.exe add "HKLM\Software\Policies\Microsoft\Windows\CloudContent" /v "DisableCloudOptimizedContent" /t REG_DWORD /d 1 /f</Path>
|
|
||||||
</RunSynchronousCommand>
|
|
||||||
<RunSynchronousCommand wcm:action="add">
|
|
||||||
<Order>23</Order>
|
|
||||||
<Path>reg.exe add "HKLM\Software\Policies\Microsoft\Windows\CloudContent" /v "DisableWindowsConsumerFeatures" /t REG_DWORD /d 1 /f</Path>
|
|
||||||
</RunSynchronousCommand>
|
|
||||||
<RunSynchronousCommand wcm:action="add">
|
|
||||||
<Order>24</Order>
|
|
||||||
<Path>reg.exe add "HKLM\Software\Policies\Microsoft\Windows\CloudContent" /v "DisableConsumerAccountStateContent" /t REG_DWORD /d 1 /f</Path>
|
|
||||||
</RunSynchronousCommand>
|
|
||||||
<RunSynchronousCommand wcm:action="add">
|
|
||||||
<Order>25</Order>
|
|
||||||
<Path>reg.exe add "HKLM\SOFTWARE\Policies\Microsoft\Windows NT\CurrentVersion\NetworkList\Signatures\FirstNetwork" /v Category /t REG_DWORD /d 1 /f</Path>
|
|
||||||
<Description>Set Network Location to Home</Description>
|
|
||||||
</RunSynchronousCommand>
|
</RunSynchronousCommand>
|
||||||
</RunSynchronous>
|
</RunSynchronous>
|
||||||
</component>
|
</component>
|
||||||
@@ -341,7 +245,7 @@
|
|||||||
<FirstLogonCommands>
|
<FirstLogonCommands>
|
||||||
<SynchronousCommand wcm:action="add">
|
<SynchronousCommand wcm:action="add">
|
||||||
<Order>1</Order>
|
<Order>1</Order>
|
||||||
<CommandLine>cmd.exe /d /c call "%WINDIR%\Setup\Scripts\SetupComplete.cmd" logon</CommandLine>
|
<CommandLine>wscript.exe //B //NoLogo %WINDIR%\Setup\Scripts\Unattend.vbs logon</CommandLine>
|
||||||
<Description>Configure Windows after logon</Description>
|
<Description>Configure Windows after logon</Description>
|
||||||
</SynchronousCommand>
|
</SynchronousCommand>
|
||||||
</FirstLogonCommands>
|
</FirstLogonCommands>
|
||||||
|
|||||||
+71
-2
@@ -6,15 +6,75 @@ set "SETUP_STARTED=%SCRIPT_DIR%setup.started"
|
|||||||
set "SETUP_COMPLETE=%SCRIPT_DIR%setup.complete"
|
set "SETUP_COMPLETE=%SCRIPT_DIR%setup.complete"
|
||||||
|
|
||||||
if "%~1"=="" goto setup
|
if "%~1"=="" goto setup
|
||||||
|
if /i "%~1"=="pe" goto pe
|
||||||
if /i "%~1"=="setup" goto setup
|
if /i "%~1"=="setup" goto setup
|
||||||
if /i "%~1"=="logon" goto logon
|
if /i "%~1"=="logon" goto logon
|
||||||
|
if /i "%~1"=="specialize" goto specialize
|
||||||
exit /b 2
|
exit /b 2
|
||||||
|
|
||||||
|
:pe
|
||||||
|
|
||||||
|
reg.exe add "HKLM\SYSTEM\Setup\LabConfig" /v BypassTPMCheck /t REG_DWORD /d 1 /f
|
||||||
|
reg.exe add "HKLM\SYSTEM\Setup\LabConfig" /v BypassSecureBootCheck /t REG_DWORD /d 1 /f
|
||||||
|
reg.exe add "HKLM\SYSTEM\Setup\LabConfig" /v BypassRAMCheck /t REG_DWORD /d 1 /f
|
||||||
|
reg.exe add "HKLM\SYSTEM\Setup\MoSetup" /v AllowUpgradesWithUnsupportedTPMOrCPU /t REG_DWORD /d 1 /f
|
||||||
|
|
||||||
|
exit /b 0
|
||||||
|
|
||||||
|
:specialize
|
||||||
|
|
||||||
|
reg.exe add "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\OOBE" /v BypassNRO /t REG_DWORD /d 1 /f
|
||||||
|
reg.exe load "HKU\mount" "C:\Users\Default\NTUSER.DAT"
|
||||||
|
reg.exe add "HKU\mount\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager" /v "ContentDeliveryAllowed" /t REG_DWORD /d 0 /f
|
||||||
|
reg.exe add "HKU\mount\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager" /v "FeatureManagementEnabled" /t REG_DWORD /d 0 /f
|
||||||
|
reg.exe add "HKU\mount\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager" /v "OEMPreInstalledAppsEnabled" /t REG_DWORD /d 0 /f
|
||||||
|
reg.exe add "HKU\mount\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager" /v "PreInstalledAppsEnabled" /t REG_DWORD /d 0 /f
|
||||||
|
reg.exe add "HKU\mount\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager" /v "PreInstalledAppsEverEnabled" /t REG_DWORD /d 0 /f
|
||||||
|
reg.exe add "HKU\mount\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager" /v "SilentInstalledAppsEnabled" /t REG_DWORD /d 0 /f
|
||||||
|
reg.exe add "HKU\mount\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager" /v "SoftLandingEnabled" /t REG_DWORD /d 0 /f
|
||||||
|
reg.exe add "HKU\mount\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager" /v "SubscribedContentEnabled" /t REG_DWORD /d 0 /f
|
||||||
|
reg.exe add "HKU\mount\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager" /v "SubscribedContent-310093Enabled" /t REG_DWORD /d 0 /f
|
||||||
|
reg.exe add "HKU\mount\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager" /v "SubscribedContent-338387Enabled" /t REG_DWORD /d 0 /f
|
||||||
|
reg.exe add "HKU\mount\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager" /v "SubscribedContent-338388Enabled" /t REG_DWORD /d 0 /f
|
||||||
|
reg.exe add "HKU\mount\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager" /v "SubscribedContent-338389Enabled" /t REG_DWORD /d 0 /f
|
||||||
|
reg.exe add "HKU\mount\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager" /v "SubscribedContent-338393Enabled" /t REG_DWORD /d 0 /f
|
||||||
|
reg.exe add "HKU\mount\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager" /v "SubscribedContent-353698Enabled" /t REG_DWORD /d 0 /f
|
||||||
|
reg.exe add "HKU\mount\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager" /v "SystemPaneSuggestionsEnabled" /t REG_DWORD /d 0 /f
|
||||||
|
reg.exe add "HKU\mount\Software\Policies\Microsoft\Windows\CloudContent" /v "DisableCloudOptimizedContent" /t REG_DWORD /d 1 /f
|
||||||
|
reg.exe add "HKU\mount\Software\Policies\Microsoft\Windows\CloudContent" /v "DisableWindowsConsumerFeatures" /t REG_DWORD /d 1 /f
|
||||||
|
reg.exe add "HKU\mount\Software\Policies\Microsoft\Windows\CloudContent" /v "DisableConsumerAccountStateContent" /t REG_DWORD /d 1 /f
|
||||||
|
reg.exe unload "HKU\mount"
|
||||||
|
reg.exe add "HKLM\Software\Policies\Microsoft\Windows\CloudContent" /v "DisableCloudOptimizedContent" /t REG_DWORD /d 1 /f
|
||||||
|
reg.exe add "HKLM\Software\Policies\Microsoft\Windows\CloudContent" /v "DisableWindowsConsumerFeatures" /t REG_DWORD /d 1 /f
|
||||||
|
reg.exe add "HKLM\Software\Policies\Microsoft\Windows\CloudContent" /v "DisableConsumerAccountStateContent" /t REG_DWORD /d 1 /f
|
||||||
|
|
||||||
|
rem Set Network Location to Home
|
||||||
|
reg.exe add "HKLM\SOFTWARE\Policies\Microsoft\Windows NT\CurrentVersion\NetworkList\Signatures\FirstNetwork" /v Category /t REG_DWORD /d 1 /f
|
||||||
|
|
||||||
|
rem Install the VMWare display driver before Windows Setup's final reboot.
|
||||||
|
certutil.exe -addstore -f Root "%SystemRoot%\Drivers\vmsvga\vm3d.cer" >nul 2>&1
|
||||||
|
certutil.exe -addstore -f TrustedPublisher "%SystemRoot%\Drivers\vmsvga\vm3d.cer" >nul 2>&1
|
||||||
|
start "" /wait /b pnputil.exe -i -a "%SystemRoot%\Drivers\vmsvga\vm3d.inf" >nul 2>&1
|
||||||
|
|
||||||
|
exit /b 0
|
||||||
|
|
||||||
:setup
|
:setup
|
||||||
if exist "%SETUP_COMPLETE%" exit /b 0
|
if exist "%SETUP_COMPLETE%" exit /b 0
|
||||||
|
|
||||||
type nul > "%SETUP_STARTED%"
|
type nul > "%SETUP_STARTED%"
|
||||||
|
|
||||||
|
rem Ignore unclean shutdowns when deciding whether to enter recovery.
|
||||||
|
bcdedit.exe /set {current} bootstatuspolicy IgnoreAllFailures
|
||||||
|
|
||||||
|
rem Keep the blue screen visible after a system crash.
|
||||||
|
bcdedit.exe /set {current} nocrashautoreboot on
|
||||||
|
|
||||||
|
rem Boot the default entry immediately without waiting at the boot menu.
|
||||||
|
bcdedit.exe /timeout 0
|
||||||
|
|
||||||
|
rem Disable automatic reboot after BSOD
|
||||||
|
reg.exe add "HKLM\SYSTEM\CurrentControlSet\Control\CrashControl" /v "AutoReboot" /t REG_DWORD /d 0 /f
|
||||||
|
|
||||||
rem Allow guest access to network shares.
|
rem Allow guest access to network shares.
|
||||||
reg.exe add "HKLM\SYSTEM\CurrentControlSet\Services\LanmanWorkstation\Parameters" /v "AllowInsecureGuestAuth" /t REG_DWORD /d 1 /f
|
reg.exe add "HKLM\SYSTEM\CurrentControlSet\Services\LanmanWorkstation\Parameters" /v "AllowInsecureGuestAuth" /t REG_DWORD /d 1 /f
|
||||||
|
|
||||||
@@ -29,6 +89,9 @@ rem Prevent the local user password from expiring.
|
|||||||
powershell.exe -ExecutionPolicy Unrestricted -NoLogo -NoProfile -NonInteractive set-localuser -name "Docker" -passwordneverexpires 1
|
powershell.exe -ExecutionPolicy Unrestricted -NoLogo -NoProfile -NonInteractive set-localuser -name "Docker" -passwordneverexpires 1
|
||||||
rem END LOCAL_ACCOUNT
|
rem END LOCAL_ACCOUNT
|
||||||
|
|
||||||
|
rem Disable per-CPU clock tick scheduling.
|
||||||
|
reg.exe add "HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\kernel" /v "EnablePerCpuClockTickScheduling" /t REG_DWORD /d 2 /f
|
||||||
|
|
||||||
rem Disable hibernation.
|
rem Disable hibernation.
|
||||||
POWERCFG -H OFF
|
POWERCFG -H OFF
|
||||||
|
|
||||||
@@ -54,7 +117,13 @@ rem Disable RemoteApp allowlist.
|
|||||||
reg.exe add "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Terminal Server\TSAppAllowList" /v "fDisabledAllowList" /t REG_DWORD /d 1 /f
|
reg.exe add "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Terminal Server\TSAppAllowList" /v "fDisabledAllowList" /t REG_DWORD /d 1 /f
|
||||||
|
|
||||||
rem Turn off automatic Windows Update downloads.
|
rem Turn off automatic Windows Update downloads.
|
||||||
reg.exe add "HKLM\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU" /v "NoAutoUpdate" /t REG_DWORD /d 1 /f
|
reg.exe add "HKLM\SOFTWARE\Microsoft\WindowsUpdate\UX\Settings" /v "FlightSettingsMaxPauseDays" /t REG_DWORD /d 3650 /f
|
||||||
|
reg.exe add "HKLM\SOFTWARE\Microsoft\WindowsUpdate\UX\Settings" /v "PauseFeatureUpdatesStartTime" /t REG_SZ /d "2026-01-01T00:00:00Z" /f
|
||||||
|
reg.exe add "HKLM\SOFTWARE\Microsoft\WindowsUpdate\UX\Settings" /v "PauseFeatureUpdatesEndTime" /t REG_SZ /d "2035-12-29T00:00:00Z" /f
|
||||||
|
reg.exe add "HKLM\SOFTWARE\Microsoft\WindowsUpdate\UX\Settings" /v "PauseQualityUpdatesStartTime" /t REG_SZ /d "2026-01-01T00:00:00Z" /f
|
||||||
|
reg.exe add "HKLM\SOFTWARE\Microsoft\WindowsUpdate\UX\Settings" /v "PauseQualityUpdatesEndTime" /t REG_SZ /d "2035-12-29T00:00:00Z" /f
|
||||||
|
reg.exe add "HKLM\SOFTWARE\Microsoft\WindowsUpdate\UX\Settings" /v "PauseUpdatesStartTime" /t REG_SZ /d "2026-01-01T00:00:00Z" /f
|
||||||
|
reg.exe add "HKLM\SOFTWARE\Microsoft\WindowsUpdate\UX\Settings" /v "PauseUpdatesExpiryTime" /t REG_SZ /d "2035-12-29T00:00:00Z" /f
|
||||||
|
|
||||||
rem Enable Network Discovery.
|
rem Enable Network Discovery.
|
||||||
netsh advfirewall firewall set rule group="@FirewallAPI.dll,-32752" new enable=Yes
|
netsh advfirewall firewall set rule group="@FirewallAPI.dll,-32752" new enable=Yes
|
||||||
@@ -81,7 +150,7 @@ type nul > "%SETUP_COMPLETE%"
|
|||||||
exit /b 0
|
exit /b 0
|
||||||
|
|
||||||
:logon
|
:logon
|
||||||
rem Run the machine setup here when SetupComplete.cmd was skipped.
|
rem Run the machine setup here when the SetupComplete hook was skipped.
|
||||||
if not exist "%SETUP_COMPLETE%" call "%~f0" setup
|
if not exist "%SETUP_COMPLETE%" call "%~f0" setup
|
||||||
|
|
||||||
rem Hide Copilot button.
|
rem Hide Copilot button.
|
||||||
|
|||||||
+3
-99
@@ -168,104 +168,8 @@
|
|||||||
<RunSynchronous>
|
<RunSynchronous>
|
||||||
<RunSynchronousCommand wcm:action="add">
|
<RunSynchronousCommand wcm:action="add">
|
||||||
<Order>1</Order>
|
<Order>1</Order>
|
||||||
<Path>reg.exe add "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\OOBE" /v BypassNRO /t REG_DWORD /d 1 /f</Path>
|
<Path>wscript.exe //B //NoLogo %WINDIR%\Setup\Scripts\Unattend.vbs specialize</Path>
|
||||||
</RunSynchronousCommand>
|
<Description>Run the specialize pass of the unattended setup script</Description>
|
||||||
<RunSynchronousCommand wcm:action="add">
|
|
||||||
<Order>2</Order>
|
|
||||||
<Path>reg.exe load "HKU\mount" "C:\Users\Default\NTUSER.DAT"</Path>
|
|
||||||
</RunSynchronousCommand>
|
|
||||||
<RunSynchronousCommand wcm:action="add">
|
|
||||||
<Order>3</Order>
|
|
||||||
<Path>reg.exe add "HKU\mount\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager" /v "ContentDeliveryAllowed" /t REG_DWORD /d 0 /f</Path>
|
|
||||||
</RunSynchronousCommand>
|
|
||||||
<RunSynchronousCommand wcm:action="add">
|
|
||||||
<Order>4</Order>
|
|
||||||
<Path>reg.exe add "HKU\mount\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager" /v "FeatureManagementEnabled" /t REG_DWORD /d 0 /f</Path>
|
|
||||||
</RunSynchronousCommand>
|
|
||||||
<RunSynchronousCommand wcm:action="add">
|
|
||||||
<Order>5</Order>
|
|
||||||
<Path>reg.exe add "HKU\mount\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager" /v "OEMPreInstalledAppsEnabled" /t REG_DWORD /d 0 /f</Path>
|
|
||||||
</RunSynchronousCommand>
|
|
||||||
<RunSynchronousCommand wcm:action="add">
|
|
||||||
<Order>6</Order>
|
|
||||||
<Path>reg.exe add "HKU\mount\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager" /v "PreInstalledAppsEnabled" /t REG_DWORD /d 0 /f</Path>
|
|
||||||
</RunSynchronousCommand>
|
|
||||||
<RunSynchronousCommand wcm:action="add">
|
|
||||||
<Order>7</Order>
|
|
||||||
<Path>reg.exe add "HKU\mount\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager" /v "PreInstalledAppsEverEnabled" /t REG_DWORD /d 0 /f</Path>
|
|
||||||
</RunSynchronousCommand>
|
|
||||||
<RunSynchronousCommand wcm:action="add">
|
|
||||||
<Order>8</Order>
|
|
||||||
<Path>reg.exe add "HKU\mount\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager" /v "SilentInstalledAppsEnabled" /t REG_DWORD /d 0 /f</Path>
|
|
||||||
</RunSynchronousCommand>
|
|
||||||
<RunSynchronousCommand wcm:action="add">
|
|
||||||
<Order>9</Order>
|
|
||||||
<Path>reg.exe add "HKU\mount\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager" /v "SoftLandingEnabled" /t REG_DWORD /d 0 /f</Path>
|
|
||||||
</RunSynchronousCommand>
|
|
||||||
<RunSynchronousCommand wcm:action="add">
|
|
||||||
<Order>10</Order>
|
|
||||||
<Path>reg.exe add "HKU\mount\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager" /v "SubscribedContentEnabled" /t REG_DWORD /d 0 /f</Path>
|
|
||||||
</RunSynchronousCommand>
|
|
||||||
<RunSynchronousCommand wcm:action="add">
|
|
||||||
<Order>11</Order>
|
|
||||||
<Path>reg.exe add "HKU\mount\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager" /v "SubscribedContent-310093Enabled" /t REG_DWORD /d 0 /f</Path>
|
|
||||||
</RunSynchronousCommand>
|
|
||||||
<RunSynchronousCommand wcm:action="add">
|
|
||||||
<Order>12</Order>
|
|
||||||
<Path>reg.exe add "HKU\mount\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager" /v "SubscribedContent-338387Enabled" /t REG_DWORD /d 0 /f</Path>
|
|
||||||
</RunSynchronousCommand>
|
|
||||||
<RunSynchronousCommand wcm:action="add">
|
|
||||||
<Order>13</Order>
|
|
||||||
<Path>reg.exe add "HKU\mount\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager" /v "SubscribedContent-338388Enabled" /t REG_DWORD /d 0 /f</Path>
|
|
||||||
</RunSynchronousCommand>
|
|
||||||
<RunSynchronousCommand wcm:action="add">
|
|
||||||
<Order>14</Order>
|
|
||||||
<Path>reg.exe add "HKU\mount\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager" /v "SubscribedContent-338389Enabled" /t REG_DWORD /d 0 /f</Path>
|
|
||||||
</RunSynchronousCommand>
|
|
||||||
<RunSynchronousCommand wcm:action="add">
|
|
||||||
<Order>15</Order>
|
|
||||||
<Path>reg.exe add "HKU\mount\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager" /v "SubscribedContent-338393Enabled" /t REG_DWORD /d 0 /f</Path>
|
|
||||||
</RunSynchronousCommand>
|
|
||||||
<RunSynchronousCommand wcm:action="add">
|
|
||||||
<Order>16</Order>
|
|
||||||
<Path>reg.exe add "HKU\mount\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager" /v "SubscribedContent-353698Enabled" /t REG_DWORD /d 0 /f</Path>
|
|
||||||
</RunSynchronousCommand>
|
|
||||||
<RunSynchronousCommand wcm:action="add">
|
|
||||||
<Order>17</Order>
|
|
||||||
<Path>reg.exe add "HKU\mount\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager" /v "SystemPaneSuggestionsEnabled" /t REG_DWORD /d 0 /f</Path>
|
|
||||||
</RunSynchronousCommand>
|
|
||||||
<RunSynchronousCommand wcm:action="add">
|
|
||||||
<Order>18</Order>
|
|
||||||
<Path>reg.exe add "HKU\mount\Software\Policies\Microsoft\Windows\CloudContent" /v "DisableCloudOptimizedContent" /t REG_DWORD /d 1 /f</Path>
|
|
||||||
</RunSynchronousCommand>
|
|
||||||
<RunSynchronousCommand wcm:action="add">
|
|
||||||
<Order>19</Order>
|
|
||||||
<Path>reg.exe add "HKU\mount\Software\Policies\Microsoft\Windows\CloudContent" /v "DisableWindowsConsumerFeatures" /t REG_DWORD /d 1 /f</Path>
|
|
||||||
</RunSynchronousCommand>
|
|
||||||
<RunSynchronousCommand wcm:action="add">
|
|
||||||
<Order>20</Order>
|
|
||||||
<Path>reg.exe add "HKU\mount\Software\Policies\Microsoft\Windows\CloudContent" /v "DisableConsumerAccountStateContent" /t REG_DWORD /d 1 /f</Path>
|
|
||||||
</RunSynchronousCommand>
|
|
||||||
<RunSynchronousCommand wcm:action="add">
|
|
||||||
<Order>21</Order>
|
|
||||||
<Path>reg.exe unload "HKU\mount"</Path>
|
|
||||||
</RunSynchronousCommand>
|
|
||||||
<RunSynchronousCommand wcm:action="add">
|
|
||||||
<Order>22</Order>
|
|
||||||
<Path>reg.exe add "HKLM\Software\Policies\Microsoft\Windows\CloudContent" /v "DisableCloudOptimizedContent" /t REG_DWORD /d 1 /f</Path>
|
|
||||||
</RunSynchronousCommand>
|
|
||||||
<RunSynchronousCommand wcm:action="add">
|
|
||||||
<Order>23</Order>
|
|
||||||
<Path>reg.exe add "HKLM\Software\Policies\Microsoft\Windows\CloudContent" /v "DisableWindowsConsumerFeatures" /t REG_DWORD /d 1 /f</Path>
|
|
||||||
</RunSynchronousCommand>
|
|
||||||
<RunSynchronousCommand wcm:action="add">
|
|
||||||
<Order>24</Order>
|
|
||||||
<Path>reg.exe add "HKLM\Software\Policies\Microsoft\Windows\CloudContent" /v "DisableConsumerAccountStateContent" /t REG_DWORD /d 1 /f</Path>
|
|
||||||
</RunSynchronousCommand>
|
|
||||||
<RunSynchronousCommand wcm:action="add">
|
|
||||||
<Order>25</Order>
|
|
||||||
<Path>reg.exe add "HKLM\SOFTWARE\Policies\Microsoft\Windows NT\CurrentVersion\NetworkList\Signatures\FirstNetwork" /v Category /t REG_DWORD /d 1 /f</Path>
|
|
||||||
<Description>Set Network Location to Home</Description>
|
|
||||||
</RunSynchronousCommand>
|
</RunSynchronousCommand>
|
||||||
</RunSynchronous>
|
</RunSynchronous>
|
||||||
</component>
|
</component>
|
||||||
@@ -341,7 +245,7 @@
|
|||||||
<FirstLogonCommands>
|
<FirstLogonCommands>
|
||||||
<SynchronousCommand wcm:action="add">
|
<SynchronousCommand wcm:action="add">
|
||||||
<Order>1</Order>
|
<Order>1</Order>
|
||||||
<CommandLine>cmd.exe /d /c call "%WINDIR%\Setup\Scripts\SetupComplete.cmd" logon</CommandLine>
|
<CommandLine>wscript.exe //B //NoLogo %WINDIR%\Setup\Scripts\Unattend.vbs logon</CommandLine>
|
||||||
<Description>Configure Windows after logon</Description>
|
<Description>Configure Windows after logon</Description>
|
||||||
</SynchronousCommand>
|
</SynchronousCommand>
|
||||||
</FirstLogonCommands>
|
</FirstLogonCommands>
|
||||||
|
|||||||
@@ -6,15 +6,75 @@ set "SETUP_STARTED=%SCRIPT_DIR%setup.started"
|
|||||||
set "SETUP_COMPLETE=%SCRIPT_DIR%setup.complete"
|
set "SETUP_COMPLETE=%SCRIPT_DIR%setup.complete"
|
||||||
|
|
||||||
if "%~1"=="" goto setup
|
if "%~1"=="" goto setup
|
||||||
|
if /i "%~1"=="pe" goto pe
|
||||||
if /i "%~1"=="setup" goto setup
|
if /i "%~1"=="setup" goto setup
|
||||||
if /i "%~1"=="logon" goto logon
|
if /i "%~1"=="logon" goto logon
|
||||||
|
if /i "%~1"=="specialize" goto specialize
|
||||||
exit /b 2
|
exit /b 2
|
||||||
|
|
||||||
|
:pe
|
||||||
|
|
||||||
|
reg.exe add "HKLM\SYSTEM\Setup\LabConfig" /v BypassTPMCheck /t REG_DWORD /d 1 /f
|
||||||
|
reg.exe add "HKLM\SYSTEM\Setup\LabConfig" /v BypassSecureBootCheck /t REG_DWORD /d 1 /f
|
||||||
|
reg.exe add "HKLM\SYSTEM\Setup\LabConfig" /v BypassRAMCheck /t REG_DWORD /d 1 /f
|
||||||
|
reg.exe add "HKLM\SYSTEM\Setup\MoSetup" /v AllowUpgradesWithUnsupportedTPMOrCPU /t REG_DWORD /d 1 /f
|
||||||
|
|
||||||
|
exit /b 0
|
||||||
|
|
||||||
|
:specialize
|
||||||
|
|
||||||
|
reg.exe add "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\OOBE" /v BypassNRO /t REG_DWORD /d 1 /f
|
||||||
|
reg.exe load "HKU\mount" "C:\Users\Default\NTUSER.DAT"
|
||||||
|
reg.exe add "HKU\mount\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager" /v "ContentDeliveryAllowed" /t REG_DWORD /d 0 /f
|
||||||
|
reg.exe add "HKU\mount\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager" /v "FeatureManagementEnabled" /t REG_DWORD /d 0 /f
|
||||||
|
reg.exe add "HKU\mount\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager" /v "OEMPreInstalledAppsEnabled" /t REG_DWORD /d 0 /f
|
||||||
|
reg.exe add "HKU\mount\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager" /v "PreInstalledAppsEnabled" /t REG_DWORD /d 0 /f
|
||||||
|
reg.exe add "HKU\mount\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager" /v "PreInstalledAppsEverEnabled" /t REG_DWORD /d 0 /f
|
||||||
|
reg.exe add "HKU\mount\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager" /v "SilentInstalledAppsEnabled" /t REG_DWORD /d 0 /f
|
||||||
|
reg.exe add "HKU\mount\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager" /v "SoftLandingEnabled" /t REG_DWORD /d 0 /f
|
||||||
|
reg.exe add "HKU\mount\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager" /v "SubscribedContentEnabled" /t REG_DWORD /d 0 /f
|
||||||
|
reg.exe add "HKU\mount\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager" /v "SubscribedContent-310093Enabled" /t REG_DWORD /d 0 /f
|
||||||
|
reg.exe add "HKU\mount\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager" /v "SubscribedContent-338387Enabled" /t REG_DWORD /d 0 /f
|
||||||
|
reg.exe add "HKU\mount\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager" /v "SubscribedContent-338388Enabled" /t REG_DWORD /d 0 /f
|
||||||
|
reg.exe add "HKU\mount\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager" /v "SubscribedContent-338389Enabled" /t REG_DWORD /d 0 /f
|
||||||
|
reg.exe add "HKU\mount\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager" /v "SubscribedContent-338393Enabled" /t REG_DWORD /d 0 /f
|
||||||
|
reg.exe add "HKU\mount\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager" /v "SubscribedContent-353698Enabled" /t REG_DWORD /d 0 /f
|
||||||
|
reg.exe add "HKU\mount\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager" /v "SystemPaneSuggestionsEnabled" /t REG_DWORD /d 0 /f
|
||||||
|
reg.exe add "HKU\mount\Software\Policies\Microsoft\Windows\CloudContent" /v "DisableCloudOptimizedContent" /t REG_DWORD /d 1 /f
|
||||||
|
reg.exe add "HKU\mount\Software\Policies\Microsoft\Windows\CloudContent" /v "DisableWindowsConsumerFeatures" /t REG_DWORD /d 1 /f
|
||||||
|
reg.exe add "HKU\mount\Software\Policies\Microsoft\Windows\CloudContent" /v "DisableConsumerAccountStateContent" /t REG_DWORD /d 1 /f
|
||||||
|
reg.exe unload "HKU\mount"
|
||||||
|
reg.exe add "HKLM\Software\Policies\Microsoft\Windows\CloudContent" /v "DisableCloudOptimizedContent" /t REG_DWORD /d 1 /f
|
||||||
|
reg.exe add "HKLM\Software\Policies\Microsoft\Windows\CloudContent" /v "DisableWindowsConsumerFeatures" /t REG_DWORD /d 1 /f
|
||||||
|
reg.exe add "HKLM\Software\Policies\Microsoft\Windows\CloudContent" /v "DisableConsumerAccountStateContent" /t REG_DWORD /d 1 /f
|
||||||
|
|
||||||
|
rem Set Network Location to Home
|
||||||
|
reg.exe add "HKLM\SOFTWARE\Policies\Microsoft\Windows NT\CurrentVersion\NetworkList\Signatures\FirstNetwork" /v Category /t REG_DWORD /d 1 /f
|
||||||
|
|
||||||
|
rem Install the VMWare display driver before Windows Setup's final reboot.
|
||||||
|
certutil.exe -addstore -f Root "%SystemRoot%\Drivers\vmsvga\vm3d.cer" >nul 2>&1
|
||||||
|
certutil.exe -addstore -f TrustedPublisher "%SystemRoot%\Drivers\vmsvga\vm3d.cer" >nul 2>&1
|
||||||
|
start "" /wait /b pnputil.exe -i -a "%SystemRoot%\Drivers\vmsvga\vm3d.inf" >nul 2>&1
|
||||||
|
|
||||||
|
exit /b 0
|
||||||
|
|
||||||
:setup
|
:setup
|
||||||
if exist "%SETUP_COMPLETE%" exit /b 0
|
if exist "%SETUP_COMPLETE%" exit /b 0
|
||||||
|
|
||||||
type nul > "%SETUP_STARTED%"
|
type nul > "%SETUP_STARTED%"
|
||||||
|
|
||||||
|
rem Ignore unclean shutdowns when deciding whether to enter recovery.
|
||||||
|
bcdedit.exe /set {current} bootstatuspolicy IgnoreAllFailures
|
||||||
|
|
||||||
|
rem Keep the blue screen visible after a system crash.
|
||||||
|
bcdedit.exe /set {current} nocrashautoreboot on
|
||||||
|
|
||||||
|
rem Boot the default entry immediately without waiting at the boot menu.
|
||||||
|
bcdedit.exe /timeout 0
|
||||||
|
|
||||||
|
rem Disable automatic reboot after BSOD
|
||||||
|
reg.exe add "HKLM\SYSTEM\CurrentControlSet\Control\CrashControl" /v "AutoReboot" /t REG_DWORD /d 0 /f
|
||||||
|
|
||||||
rem Allow guest access to network shares.
|
rem Allow guest access to network shares.
|
||||||
reg.exe add "HKLM\SYSTEM\CurrentControlSet\Services\LanmanWorkstation\Parameters" /v "AllowInsecureGuestAuth" /t REG_DWORD /d 1 /f
|
reg.exe add "HKLM\SYSTEM\CurrentControlSet\Services\LanmanWorkstation\Parameters" /v "AllowInsecureGuestAuth" /t REG_DWORD /d 1 /f
|
||||||
|
|
||||||
@@ -29,6 +89,9 @@ rem Prevent the local user password from expiring.
|
|||||||
powershell.exe -ExecutionPolicy Unrestricted -NoLogo -NoProfile -NonInteractive set-localuser -name "Docker" -passwordneverexpires 1
|
powershell.exe -ExecutionPolicy Unrestricted -NoLogo -NoProfile -NonInteractive set-localuser -name "Docker" -passwordneverexpires 1
|
||||||
rem END LOCAL_ACCOUNT
|
rem END LOCAL_ACCOUNT
|
||||||
|
|
||||||
|
rem Disable per-CPU clock tick scheduling.
|
||||||
|
reg.exe add "HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\kernel" /v "EnablePerCpuClockTickScheduling" /t REG_DWORD /d 2 /f
|
||||||
|
|
||||||
rem Disable hibernation.
|
rem Disable hibernation.
|
||||||
POWERCFG -H OFF
|
POWERCFG -H OFF
|
||||||
|
|
||||||
@@ -54,7 +117,13 @@ rem Disable RemoteApp allowlist.
|
|||||||
reg.exe add "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Terminal Server\TSAppAllowList" /v "fDisabledAllowList" /t REG_DWORD /d 1 /f
|
reg.exe add "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Terminal Server\TSAppAllowList" /v "fDisabledAllowList" /t REG_DWORD /d 1 /f
|
||||||
|
|
||||||
rem Turn off automatic Windows Update downloads.
|
rem Turn off automatic Windows Update downloads.
|
||||||
reg.exe add "HKLM\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU" /v "NoAutoUpdate" /t REG_DWORD /d 1 /f
|
reg.exe add "HKLM\SOFTWARE\Microsoft\WindowsUpdate\UX\Settings" /v "FlightSettingsMaxPauseDays" /t REG_DWORD /d 3650 /f
|
||||||
|
reg.exe add "HKLM\SOFTWARE\Microsoft\WindowsUpdate\UX\Settings" /v "PauseFeatureUpdatesStartTime" /t REG_SZ /d "2026-01-01T00:00:00Z" /f
|
||||||
|
reg.exe add "HKLM\SOFTWARE\Microsoft\WindowsUpdate\UX\Settings" /v "PauseFeatureUpdatesEndTime" /t REG_SZ /d "2035-12-29T00:00:00Z" /f
|
||||||
|
reg.exe add "HKLM\SOFTWARE\Microsoft\WindowsUpdate\UX\Settings" /v "PauseQualityUpdatesStartTime" /t REG_SZ /d "2026-01-01T00:00:00Z" /f
|
||||||
|
reg.exe add "HKLM\SOFTWARE\Microsoft\WindowsUpdate\UX\Settings" /v "PauseQualityUpdatesEndTime" /t REG_SZ /d "2035-12-29T00:00:00Z" /f
|
||||||
|
reg.exe add "HKLM\SOFTWARE\Microsoft\WindowsUpdate\UX\Settings" /v "PauseUpdatesStartTime" /t REG_SZ /d "2026-01-01T00:00:00Z" /f
|
||||||
|
reg.exe add "HKLM\SOFTWARE\Microsoft\WindowsUpdate\UX\Settings" /v "PauseUpdatesExpiryTime" /t REG_SZ /d "2035-12-29T00:00:00Z" /f
|
||||||
|
|
||||||
rem Enable Network Discovery.
|
rem Enable Network Discovery.
|
||||||
netsh advfirewall firewall set rule group="@FirewallAPI.dll,-32752" new enable=Yes
|
netsh advfirewall firewall set rule group="@FirewallAPI.dll,-32752" new enable=Yes
|
||||||
@@ -81,7 +150,7 @@ type nul > "%SETUP_COMPLETE%"
|
|||||||
exit /b 0
|
exit /b 0
|
||||||
|
|
||||||
:logon
|
:logon
|
||||||
rem Run the machine setup here when SetupComplete.cmd was skipped.
|
rem Run the machine setup here when the SetupComplete hook was skipped.
|
||||||
if not exist "%SETUP_COMPLETE%" call "%~f0" setup
|
if not exist "%SETUP_COMPLETE%" call "%~f0" setup
|
||||||
|
|
||||||
rem Hide Copilot button.
|
rem Hide Copilot button.
|
||||||
|
|||||||
@@ -168,104 +168,8 @@
|
|||||||
<RunSynchronous>
|
<RunSynchronous>
|
||||||
<RunSynchronousCommand wcm:action="add">
|
<RunSynchronousCommand wcm:action="add">
|
||||||
<Order>1</Order>
|
<Order>1</Order>
|
||||||
<Path>reg.exe add "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\OOBE" /v BypassNRO /t REG_DWORD /d 1 /f</Path>
|
<Path>wscript.exe //B //NoLogo %WINDIR%\Setup\Scripts\Unattend.vbs specialize</Path>
|
||||||
</RunSynchronousCommand>
|
<Description>Run the specialize pass of the unattended setup script</Description>
|
||||||
<RunSynchronousCommand wcm:action="add">
|
|
||||||
<Order>2</Order>
|
|
||||||
<Path>reg.exe load "HKU\mount" "C:\Users\Default\NTUSER.DAT"</Path>
|
|
||||||
</RunSynchronousCommand>
|
|
||||||
<RunSynchronousCommand wcm:action="add">
|
|
||||||
<Order>3</Order>
|
|
||||||
<Path>reg.exe add "HKU\mount\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager" /v "ContentDeliveryAllowed" /t REG_DWORD /d 0 /f</Path>
|
|
||||||
</RunSynchronousCommand>
|
|
||||||
<RunSynchronousCommand wcm:action="add">
|
|
||||||
<Order>4</Order>
|
|
||||||
<Path>reg.exe add "HKU\mount\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager" /v "FeatureManagementEnabled" /t REG_DWORD /d 0 /f</Path>
|
|
||||||
</RunSynchronousCommand>
|
|
||||||
<RunSynchronousCommand wcm:action="add">
|
|
||||||
<Order>5</Order>
|
|
||||||
<Path>reg.exe add "HKU\mount\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager" /v "OEMPreInstalledAppsEnabled" /t REG_DWORD /d 0 /f</Path>
|
|
||||||
</RunSynchronousCommand>
|
|
||||||
<RunSynchronousCommand wcm:action="add">
|
|
||||||
<Order>6</Order>
|
|
||||||
<Path>reg.exe add "HKU\mount\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager" /v "PreInstalledAppsEnabled" /t REG_DWORD /d 0 /f</Path>
|
|
||||||
</RunSynchronousCommand>
|
|
||||||
<RunSynchronousCommand wcm:action="add">
|
|
||||||
<Order>7</Order>
|
|
||||||
<Path>reg.exe add "HKU\mount\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager" /v "PreInstalledAppsEverEnabled" /t REG_DWORD /d 0 /f</Path>
|
|
||||||
</RunSynchronousCommand>
|
|
||||||
<RunSynchronousCommand wcm:action="add">
|
|
||||||
<Order>8</Order>
|
|
||||||
<Path>reg.exe add "HKU\mount\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager" /v "SilentInstalledAppsEnabled" /t REG_DWORD /d 0 /f</Path>
|
|
||||||
</RunSynchronousCommand>
|
|
||||||
<RunSynchronousCommand wcm:action="add">
|
|
||||||
<Order>9</Order>
|
|
||||||
<Path>reg.exe add "HKU\mount\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager" /v "SoftLandingEnabled" /t REG_DWORD /d 0 /f</Path>
|
|
||||||
</RunSynchronousCommand>
|
|
||||||
<RunSynchronousCommand wcm:action="add">
|
|
||||||
<Order>10</Order>
|
|
||||||
<Path>reg.exe add "HKU\mount\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager" /v "SubscribedContentEnabled" /t REG_DWORD /d 0 /f</Path>
|
|
||||||
</RunSynchronousCommand>
|
|
||||||
<RunSynchronousCommand wcm:action="add">
|
|
||||||
<Order>11</Order>
|
|
||||||
<Path>reg.exe add "HKU\mount\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager" /v "SubscribedContent-310093Enabled" /t REG_DWORD /d 0 /f</Path>
|
|
||||||
</RunSynchronousCommand>
|
|
||||||
<RunSynchronousCommand wcm:action="add">
|
|
||||||
<Order>12</Order>
|
|
||||||
<Path>reg.exe add "HKU\mount\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager" /v "SubscribedContent-338387Enabled" /t REG_DWORD /d 0 /f</Path>
|
|
||||||
</RunSynchronousCommand>
|
|
||||||
<RunSynchronousCommand wcm:action="add">
|
|
||||||
<Order>13</Order>
|
|
||||||
<Path>reg.exe add "HKU\mount\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager" /v "SubscribedContent-338388Enabled" /t REG_DWORD /d 0 /f</Path>
|
|
||||||
</RunSynchronousCommand>
|
|
||||||
<RunSynchronousCommand wcm:action="add">
|
|
||||||
<Order>14</Order>
|
|
||||||
<Path>reg.exe add "HKU\mount\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager" /v "SubscribedContent-338389Enabled" /t REG_DWORD /d 0 /f</Path>
|
|
||||||
</RunSynchronousCommand>
|
|
||||||
<RunSynchronousCommand wcm:action="add">
|
|
||||||
<Order>15</Order>
|
|
||||||
<Path>reg.exe add "HKU\mount\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager" /v "SubscribedContent-338393Enabled" /t REG_DWORD /d 0 /f</Path>
|
|
||||||
</RunSynchronousCommand>
|
|
||||||
<RunSynchronousCommand wcm:action="add">
|
|
||||||
<Order>16</Order>
|
|
||||||
<Path>reg.exe add "HKU\mount\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager" /v "SubscribedContent-353698Enabled" /t REG_DWORD /d 0 /f</Path>
|
|
||||||
</RunSynchronousCommand>
|
|
||||||
<RunSynchronousCommand wcm:action="add">
|
|
||||||
<Order>17</Order>
|
|
||||||
<Path>reg.exe add "HKU\mount\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager" /v "SystemPaneSuggestionsEnabled" /t REG_DWORD /d 0 /f</Path>
|
|
||||||
</RunSynchronousCommand>
|
|
||||||
<RunSynchronousCommand wcm:action="add">
|
|
||||||
<Order>18</Order>
|
|
||||||
<Path>reg.exe add "HKU\mount\Software\Policies\Microsoft\Windows\CloudContent" /v "DisableCloudOptimizedContent" /t REG_DWORD /d 1 /f</Path>
|
|
||||||
</RunSynchronousCommand>
|
|
||||||
<RunSynchronousCommand wcm:action="add">
|
|
||||||
<Order>19</Order>
|
|
||||||
<Path>reg.exe add "HKU\mount\Software\Policies\Microsoft\Windows\CloudContent" /v "DisableWindowsConsumerFeatures" /t REG_DWORD /d 1 /f</Path>
|
|
||||||
</RunSynchronousCommand>
|
|
||||||
<RunSynchronousCommand wcm:action="add">
|
|
||||||
<Order>20</Order>
|
|
||||||
<Path>reg.exe add "HKU\mount\Software\Policies\Microsoft\Windows\CloudContent" /v "DisableConsumerAccountStateContent" /t REG_DWORD /d 1 /f</Path>
|
|
||||||
</RunSynchronousCommand>
|
|
||||||
<RunSynchronousCommand wcm:action="add">
|
|
||||||
<Order>21</Order>
|
|
||||||
<Path>reg.exe unload "HKU\mount"</Path>
|
|
||||||
</RunSynchronousCommand>
|
|
||||||
<RunSynchronousCommand wcm:action="add">
|
|
||||||
<Order>22</Order>
|
|
||||||
<Path>reg.exe add "HKLM\Software\Policies\Microsoft\Windows\CloudContent" /v "DisableCloudOptimizedContent" /t REG_DWORD /d 1 /f</Path>
|
|
||||||
</RunSynchronousCommand>
|
|
||||||
<RunSynchronousCommand wcm:action="add">
|
|
||||||
<Order>23</Order>
|
|
||||||
<Path>reg.exe add "HKLM\Software\Policies\Microsoft\Windows\CloudContent" /v "DisableWindowsConsumerFeatures" /t REG_DWORD /d 1 /f</Path>
|
|
||||||
</RunSynchronousCommand>
|
|
||||||
<RunSynchronousCommand wcm:action="add">
|
|
||||||
<Order>24</Order>
|
|
||||||
<Path>reg.exe add "HKLM\Software\Policies\Microsoft\Windows\CloudContent" /v "DisableConsumerAccountStateContent" /t REG_DWORD /d 1 /f</Path>
|
|
||||||
</RunSynchronousCommand>
|
|
||||||
<RunSynchronousCommand wcm:action="add">
|
|
||||||
<Order>25</Order>
|
|
||||||
<Path>reg.exe add "HKLM\SOFTWARE\Policies\Microsoft\Windows NT\CurrentVersion\NetworkList\Signatures\FirstNetwork" /v Category /t REG_DWORD /d 1 /f</Path>
|
|
||||||
<Description>Set Network Location to Home</Description>
|
|
||||||
</RunSynchronousCommand>
|
</RunSynchronousCommand>
|
||||||
</RunSynchronous>
|
</RunSynchronous>
|
||||||
</component>
|
</component>
|
||||||
@@ -341,7 +245,7 @@
|
|||||||
<FirstLogonCommands>
|
<FirstLogonCommands>
|
||||||
<SynchronousCommand wcm:action="add">
|
<SynchronousCommand wcm:action="add">
|
||||||
<Order>1</Order>
|
<Order>1</Order>
|
||||||
<CommandLine>cmd.exe /d /c call "%WINDIR%\Setup\Scripts\SetupComplete.cmd" logon</CommandLine>
|
<CommandLine>wscript.exe //B //NoLogo %WINDIR%\Setup\Scripts\Unattend.vbs logon</CommandLine>
|
||||||
<Description>Configure Windows after logon</Description>
|
<Description>Configure Windows after logon</Description>
|
||||||
</SynchronousCommand>
|
</SynchronousCommand>
|
||||||
</FirstLogonCommands>
|
</FirstLogonCommands>
|
||||||
|
|||||||
+71
-2
@@ -6,15 +6,75 @@ set "SETUP_STARTED=%SCRIPT_DIR%setup.started"
|
|||||||
set "SETUP_COMPLETE=%SCRIPT_DIR%setup.complete"
|
set "SETUP_COMPLETE=%SCRIPT_DIR%setup.complete"
|
||||||
|
|
||||||
if "%~1"=="" goto setup
|
if "%~1"=="" goto setup
|
||||||
|
if /i "%~1"=="pe" goto pe
|
||||||
if /i "%~1"=="setup" goto setup
|
if /i "%~1"=="setup" goto setup
|
||||||
if /i "%~1"=="logon" goto logon
|
if /i "%~1"=="logon" goto logon
|
||||||
|
if /i "%~1"=="specialize" goto specialize
|
||||||
exit /b 2
|
exit /b 2
|
||||||
|
|
||||||
|
:pe
|
||||||
|
|
||||||
|
reg.exe add "HKLM\SYSTEM\Setup\LabConfig" /v BypassTPMCheck /t REG_DWORD /d 1 /f
|
||||||
|
reg.exe add "HKLM\SYSTEM\Setup\LabConfig" /v BypassSecureBootCheck /t REG_DWORD /d 1 /f
|
||||||
|
reg.exe add "HKLM\SYSTEM\Setup\LabConfig" /v BypassRAMCheck /t REG_DWORD /d 1 /f
|
||||||
|
reg.exe add "HKLM\SYSTEM\Setup\MoSetup" /v AllowUpgradesWithUnsupportedTPMOrCPU /t REG_DWORD /d 1 /f
|
||||||
|
|
||||||
|
exit /b 0
|
||||||
|
|
||||||
|
:specialize
|
||||||
|
|
||||||
|
reg.exe add "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\OOBE" /v BypassNRO /t REG_DWORD /d 1 /f
|
||||||
|
reg.exe load "HKU\mount" "C:\Users\Default\NTUSER.DAT"
|
||||||
|
reg.exe add "HKU\mount\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager" /v "ContentDeliveryAllowed" /t REG_DWORD /d 0 /f
|
||||||
|
reg.exe add "HKU\mount\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager" /v "FeatureManagementEnabled" /t REG_DWORD /d 0 /f
|
||||||
|
reg.exe add "HKU\mount\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager" /v "OEMPreInstalledAppsEnabled" /t REG_DWORD /d 0 /f
|
||||||
|
reg.exe add "HKU\mount\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager" /v "PreInstalledAppsEnabled" /t REG_DWORD /d 0 /f
|
||||||
|
reg.exe add "HKU\mount\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager" /v "PreInstalledAppsEverEnabled" /t REG_DWORD /d 0 /f
|
||||||
|
reg.exe add "HKU\mount\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager" /v "SilentInstalledAppsEnabled" /t REG_DWORD /d 0 /f
|
||||||
|
reg.exe add "HKU\mount\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager" /v "SoftLandingEnabled" /t REG_DWORD /d 0 /f
|
||||||
|
reg.exe add "HKU\mount\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager" /v "SubscribedContentEnabled" /t REG_DWORD /d 0 /f
|
||||||
|
reg.exe add "HKU\mount\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager" /v "SubscribedContent-310093Enabled" /t REG_DWORD /d 0 /f
|
||||||
|
reg.exe add "HKU\mount\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager" /v "SubscribedContent-338387Enabled" /t REG_DWORD /d 0 /f
|
||||||
|
reg.exe add "HKU\mount\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager" /v "SubscribedContent-338388Enabled" /t REG_DWORD /d 0 /f
|
||||||
|
reg.exe add "HKU\mount\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager" /v "SubscribedContent-338389Enabled" /t REG_DWORD /d 0 /f
|
||||||
|
reg.exe add "HKU\mount\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager" /v "SubscribedContent-338393Enabled" /t REG_DWORD /d 0 /f
|
||||||
|
reg.exe add "HKU\mount\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager" /v "SubscribedContent-353698Enabled" /t REG_DWORD /d 0 /f
|
||||||
|
reg.exe add "HKU\mount\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager" /v "SystemPaneSuggestionsEnabled" /t REG_DWORD /d 0 /f
|
||||||
|
reg.exe add "HKU\mount\Software\Policies\Microsoft\Windows\CloudContent" /v "DisableCloudOptimizedContent" /t REG_DWORD /d 1 /f
|
||||||
|
reg.exe add "HKU\mount\Software\Policies\Microsoft\Windows\CloudContent" /v "DisableWindowsConsumerFeatures" /t REG_DWORD /d 1 /f
|
||||||
|
reg.exe add "HKU\mount\Software\Policies\Microsoft\Windows\CloudContent" /v "DisableConsumerAccountStateContent" /t REG_DWORD /d 1 /f
|
||||||
|
reg.exe unload "HKU\mount"
|
||||||
|
reg.exe add "HKLM\Software\Policies\Microsoft\Windows\CloudContent" /v "DisableCloudOptimizedContent" /t REG_DWORD /d 1 /f
|
||||||
|
reg.exe add "HKLM\Software\Policies\Microsoft\Windows\CloudContent" /v "DisableWindowsConsumerFeatures" /t REG_DWORD /d 1 /f
|
||||||
|
reg.exe add "HKLM\Software\Policies\Microsoft\Windows\CloudContent" /v "DisableConsumerAccountStateContent" /t REG_DWORD /d 1 /f
|
||||||
|
|
||||||
|
rem Set Network Location to Home
|
||||||
|
reg.exe add "HKLM\SOFTWARE\Policies\Microsoft\Windows NT\CurrentVersion\NetworkList\Signatures\FirstNetwork" /v Category /t REG_DWORD /d 1 /f
|
||||||
|
|
||||||
|
rem Install the VMWare display driver before Windows Setup's final reboot.
|
||||||
|
certutil.exe -addstore -f Root "%SystemRoot%\Drivers\vmsvga\vm3d.cer" >nul 2>&1
|
||||||
|
certutil.exe -addstore -f TrustedPublisher "%SystemRoot%\Drivers\vmsvga\vm3d.cer" >nul 2>&1
|
||||||
|
start "" /wait /b pnputil.exe -i -a "%SystemRoot%\Drivers\vmsvga\vm3d.inf" >nul 2>&1
|
||||||
|
|
||||||
|
exit /b 0
|
||||||
|
|
||||||
:setup
|
:setup
|
||||||
if exist "%SETUP_COMPLETE%" exit /b 0
|
if exist "%SETUP_COMPLETE%" exit /b 0
|
||||||
|
|
||||||
type nul > "%SETUP_STARTED%"
|
type nul > "%SETUP_STARTED%"
|
||||||
|
|
||||||
|
rem Ignore unclean shutdowns when deciding whether to enter recovery.
|
||||||
|
bcdedit.exe /set {current} bootstatuspolicy IgnoreAllFailures
|
||||||
|
|
||||||
|
rem Keep the blue screen visible after a system crash.
|
||||||
|
bcdedit.exe /set {current} nocrashautoreboot on
|
||||||
|
|
||||||
|
rem Boot the default entry immediately without waiting at the boot menu.
|
||||||
|
bcdedit.exe /timeout 0
|
||||||
|
|
||||||
|
rem Disable automatic reboot after BSOD
|
||||||
|
reg.exe add "HKLM\SYSTEM\CurrentControlSet\Control\CrashControl" /v "AutoReboot" /t REG_DWORD /d 0 /f
|
||||||
|
|
||||||
rem Allow guest access to network shares.
|
rem Allow guest access to network shares.
|
||||||
reg.exe add "HKLM\SYSTEM\CurrentControlSet\Services\LanmanWorkstation\Parameters" /v "AllowInsecureGuestAuth" /t REG_DWORD /d 1 /f
|
reg.exe add "HKLM\SYSTEM\CurrentControlSet\Services\LanmanWorkstation\Parameters" /v "AllowInsecureGuestAuth" /t REG_DWORD /d 1 /f
|
||||||
|
|
||||||
@@ -29,6 +89,9 @@ rem Prevent the local user password from expiring.
|
|||||||
powershell.exe -ExecutionPolicy Unrestricted -NoLogo -NoProfile -NonInteractive set-localuser -name "Docker" -passwordneverexpires 1
|
powershell.exe -ExecutionPolicy Unrestricted -NoLogo -NoProfile -NonInteractive set-localuser -name "Docker" -passwordneverexpires 1
|
||||||
rem END LOCAL_ACCOUNT
|
rem END LOCAL_ACCOUNT
|
||||||
|
|
||||||
|
rem Disable per-CPU clock tick scheduling.
|
||||||
|
reg.exe add "HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\kernel" /v "EnablePerCpuClockTickScheduling" /t REG_DWORD /d 2 /f
|
||||||
|
|
||||||
rem Disable hibernation.
|
rem Disable hibernation.
|
||||||
POWERCFG -H OFF
|
POWERCFG -H OFF
|
||||||
|
|
||||||
@@ -54,7 +117,13 @@ rem Disable RemoteApp allowlist.
|
|||||||
reg.exe add "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Terminal Server\TSAppAllowList" /v "fDisabledAllowList" /t REG_DWORD /d 1 /f
|
reg.exe add "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Terminal Server\TSAppAllowList" /v "fDisabledAllowList" /t REG_DWORD /d 1 /f
|
||||||
|
|
||||||
rem Turn off automatic Windows Update downloads.
|
rem Turn off automatic Windows Update downloads.
|
||||||
reg.exe add "HKLM\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU" /v "NoAutoUpdate" /t REG_DWORD /d 1 /f
|
reg.exe add "HKLM\SOFTWARE\Microsoft\WindowsUpdate\UX\Settings" /v "FlightSettingsMaxPauseDays" /t REG_DWORD /d 3650 /f
|
||||||
|
reg.exe add "HKLM\SOFTWARE\Microsoft\WindowsUpdate\UX\Settings" /v "PauseFeatureUpdatesStartTime" /t REG_SZ /d "2026-01-01T00:00:00Z" /f
|
||||||
|
reg.exe add "HKLM\SOFTWARE\Microsoft\WindowsUpdate\UX\Settings" /v "PauseFeatureUpdatesEndTime" /t REG_SZ /d "2035-12-29T00:00:00Z" /f
|
||||||
|
reg.exe add "HKLM\SOFTWARE\Microsoft\WindowsUpdate\UX\Settings" /v "PauseQualityUpdatesStartTime" /t REG_SZ /d "2026-01-01T00:00:00Z" /f
|
||||||
|
reg.exe add "HKLM\SOFTWARE\Microsoft\WindowsUpdate\UX\Settings" /v "PauseQualityUpdatesEndTime" /t REG_SZ /d "2035-12-29T00:00:00Z" /f
|
||||||
|
reg.exe add "HKLM\SOFTWARE\Microsoft\WindowsUpdate\UX\Settings" /v "PauseUpdatesStartTime" /t REG_SZ /d "2026-01-01T00:00:00Z" /f
|
||||||
|
reg.exe add "HKLM\SOFTWARE\Microsoft\WindowsUpdate\UX\Settings" /v "PauseUpdatesExpiryTime" /t REG_SZ /d "2035-12-29T00:00:00Z" /f
|
||||||
|
|
||||||
rem Enable Network Discovery.
|
rem Enable Network Discovery.
|
||||||
netsh advfirewall firewall set rule group="@FirewallAPI.dll,-32752" new enable=Yes
|
netsh advfirewall firewall set rule group="@FirewallAPI.dll,-32752" new enable=Yes
|
||||||
@@ -81,7 +150,7 @@ type nul > "%SETUP_COMPLETE%"
|
|||||||
exit /b 0
|
exit /b 0
|
||||||
|
|
||||||
:logon
|
:logon
|
||||||
rem Run the machine setup here when SetupComplete.cmd was skipped.
|
rem Run the machine setup here when the SetupComplete hook was skipped.
|
||||||
if not exist "%SETUP_COMPLETE%" call "%~f0" setup
|
if not exist "%SETUP_COMPLETE%" call "%~f0" setup
|
||||||
|
|
||||||
rem Hide Copilot button.
|
rem Hide Copilot button.
|
||||||
|
|||||||
+3
-99
@@ -168,104 +168,8 @@
|
|||||||
<RunSynchronous>
|
<RunSynchronous>
|
||||||
<RunSynchronousCommand wcm:action="add">
|
<RunSynchronousCommand wcm:action="add">
|
||||||
<Order>1</Order>
|
<Order>1</Order>
|
||||||
<Path>reg.exe add "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\OOBE" /v BypassNRO /t REG_DWORD /d 1 /f</Path>
|
<Path>wscript.exe //B //NoLogo %WINDIR%\Setup\Scripts\Unattend.vbs specialize</Path>
|
||||||
</RunSynchronousCommand>
|
<Description>Run the specialize pass of the unattended setup script</Description>
|
||||||
<RunSynchronousCommand wcm:action="add">
|
|
||||||
<Order>2</Order>
|
|
||||||
<Path>reg.exe load "HKU\mount" "C:\Users\Default\NTUSER.DAT"</Path>
|
|
||||||
</RunSynchronousCommand>
|
|
||||||
<RunSynchronousCommand wcm:action="add">
|
|
||||||
<Order>3</Order>
|
|
||||||
<Path>reg.exe add "HKU\mount\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager" /v "ContentDeliveryAllowed" /t REG_DWORD /d 0 /f</Path>
|
|
||||||
</RunSynchronousCommand>
|
|
||||||
<RunSynchronousCommand wcm:action="add">
|
|
||||||
<Order>4</Order>
|
|
||||||
<Path>reg.exe add "HKU\mount\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager" /v "FeatureManagementEnabled" /t REG_DWORD /d 0 /f</Path>
|
|
||||||
</RunSynchronousCommand>
|
|
||||||
<RunSynchronousCommand wcm:action="add">
|
|
||||||
<Order>5</Order>
|
|
||||||
<Path>reg.exe add "HKU\mount\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager" /v "OEMPreInstalledAppsEnabled" /t REG_DWORD /d 0 /f</Path>
|
|
||||||
</RunSynchronousCommand>
|
|
||||||
<RunSynchronousCommand wcm:action="add">
|
|
||||||
<Order>6</Order>
|
|
||||||
<Path>reg.exe add "HKU\mount\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager" /v "PreInstalledAppsEnabled" /t REG_DWORD /d 0 /f</Path>
|
|
||||||
</RunSynchronousCommand>
|
|
||||||
<RunSynchronousCommand wcm:action="add">
|
|
||||||
<Order>7</Order>
|
|
||||||
<Path>reg.exe add "HKU\mount\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager" /v "PreInstalledAppsEverEnabled" /t REG_DWORD /d 0 /f</Path>
|
|
||||||
</RunSynchronousCommand>
|
|
||||||
<RunSynchronousCommand wcm:action="add">
|
|
||||||
<Order>8</Order>
|
|
||||||
<Path>reg.exe add "HKU\mount\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager" /v "SilentInstalledAppsEnabled" /t REG_DWORD /d 0 /f</Path>
|
|
||||||
</RunSynchronousCommand>
|
|
||||||
<RunSynchronousCommand wcm:action="add">
|
|
||||||
<Order>9</Order>
|
|
||||||
<Path>reg.exe add "HKU\mount\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager" /v "SoftLandingEnabled" /t REG_DWORD /d 0 /f</Path>
|
|
||||||
</RunSynchronousCommand>
|
|
||||||
<RunSynchronousCommand wcm:action="add">
|
|
||||||
<Order>10</Order>
|
|
||||||
<Path>reg.exe add "HKU\mount\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager" /v "SubscribedContentEnabled" /t REG_DWORD /d 0 /f</Path>
|
|
||||||
</RunSynchronousCommand>
|
|
||||||
<RunSynchronousCommand wcm:action="add">
|
|
||||||
<Order>11</Order>
|
|
||||||
<Path>reg.exe add "HKU\mount\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager" /v "SubscribedContent-310093Enabled" /t REG_DWORD /d 0 /f</Path>
|
|
||||||
</RunSynchronousCommand>
|
|
||||||
<RunSynchronousCommand wcm:action="add">
|
|
||||||
<Order>12</Order>
|
|
||||||
<Path>reg.exe add "HKU\mount\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager" /v "SubscribedContent-338387Enabled" /t REG_DWORD /d 0 /f</Path>
|
|
||||||
</RunSynchronousCommand>
|
|
||||||
<RunSynchronousCommand wcm:action="add">
|
|
||||||
<Order>13</Order>
|
|
||||||
<Path>reg.exe add "HKU\mount\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager" /v "SubscribedContent-338388Enabled" /t REG_DWORD /d 0 /f</Path>
|
|
||||||
</RunSynchronousCommand>
|
|
||||||
<RunSynchronousCommand wcm:action="add">
|
|
||||||
<Order>14</Order>
|
|
||||||
<Path>reg.exe add "HKU\mount\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager" /v "SubscribedContent-338389Enabled" /t REG_DWORD /d 0 /f</Path>
|
|
||||||
</RunSynchronousCommand>
|
|
||||||
<RunSynchronousCommand wcm:action="add">
|
|
||||||
<Order>15</Order>
|
|
||||||
<Path>reg.exe add "HKU\mount\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager" /v "SubscribedContent-338393Enabled" /t REG_DWORD /d 0 /f</Path>
|
|
||||||
</RunSynchronousCommand>
|
|
||||||
<RunSynchronousCommand wcm:action="add">
|
|
||||||
<Order>16</Order>
|
|
||||||
<Path>reg.exe add "HKU\mount\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager" /v "SubscribedContent-353698Enabled" /t REG_DWORD /d 0 /f</Path>
|
|
||||||
</RunSynchronousCommand>
|
|
||||||
<RunSynchronousCommand wcm:action="add">
|
|
||||||
<Order>17</Order>
|
|
||||||
<Path>reg.exe add "HKU\mount\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager" /v "SystemPaneSuggestionsEnabled" /t REG_DWORD /d 0 /f</Path>
|
|
||||||
</RunSynchronousCommand>
|
|
||||||
<RunSynchronousCommand wcm:action="add">
|
|
||||||
<Order>18</Order>
|
|
||||||
<Path>reg.exe add "HKU\mount\Software\Policies\Microsoft\Windows\CloudContent" /v "DisableCloudOptimizedContent" /t REG_DWORD /d 1 /f</Path>
|
|
||||||
</RunSynchronousCommand>
|
|
||||||
<RunSynchronousCommand wcm:action="add">
|
|
||||||
<Order>19</Order>
|
|
||||||
<Path>reg.exe add "HKU\mount\Software\Policies\Microsoft\Windows\CloudContent" /v "DisableWindowsConsumerFeatures" /t REG_DWORD /d 1 /f</Path>
|
|
||||||
</RunSynchronousCommand>
|
|
||||||
<RunSynchronousCommand wcm:action="add">
|
|
||||||
<Order>20</Order>
|
|
||||||
<Path>reg.exe add "HKU\mount\Software\Policies\Microsoft\Windows\CloudContent" /v "DisableConsumerAccountStateContent" /t REG_DWORD /d 1 /f</Path>
|
|
||||||
</RunSynchronousCommand>
|
|
||||||
<RunSynchronousCommand wcm:action="add">
|
|
||||||
<Order>21</Order>
|
|
||||||
<Path>reg.exe unload "HKU\mount"</Path>
|
|
||||||
</RunSynchronousCommand>
|
|
||||||
<RunSynchronousCommand wcm:action="add">
|
|
||||||
<Order>22</Order>
|
|
||||||
<Path>reg.exe add "HKLM\Software\Policies\Microsoft\Windows\CloudContent" /v "DisableCloudOptimizedContent" /t REG_DWORD /d 1 /f</Path>
|
|
||||||
</RunSynchronousCommand>
|
|
||||||
<RunSynchronousCommand wcm:action="add">
|
|
||||||
<Order>23</Order>
|
|
||||||
<Path>reg.exe add "HKLM\Software\Policies\Microsoft\Windows\CloudContent" /v "DisableWindowsConsumerFeatures" /t REG_DWORD /d 1 /f</Path>
|
|
||||||
</RunSynchronousCommand>
|
|
||||||
<RunSynchronousCommand wcm:action="add">
|
|
||||||
<Order>24</Order>
|
|
||||||
<Path>reg.exe add "HKLM\Software\Policies\Microsoft\Windows\CloudContent" /v "DisableConsumerAccountStateContent" /t REG_DWORD /d 1 /f</Path>
|
|
||||||
</RunSynchronousCommand>
|
|
||||||
<RunSynchronousCommand wcm:action="add">
|
|
||||||
<Order>25</Order>
|
|
||||||
<Path>reg.exe add "HKLM\SOFTWARE\Policies\Microsoft\Windows NT\CurrentVersion\NetworkList\Signatures\FirstNetwork" /v Category /t REG_DWORD /d 1 /f</Path>
|
|
||||||
<Description>Set Network Location to Home</Description>
|
|
||||||
</RunSynchronousCommand>
|
</RunSynchronousCommand>
|
||||||
</RunSynchronous>
|
</RunSynchronous>
|
||||||
</component>
|
</component>
|
||||||
@@ -341,7 +245,7 @@
|
|||||||
<FirstLogonCommands>
|
<FirstLogonCommands>
|
||||||
<SynchronousCommand wcm:action="add">
|
<SynchronousCommand wcm:action="add">
|
||||||
<Order>1</Order>
|
<Order>1</Order>
|
||||||
<CommandLine>cmd.exe /d /c call "%WINDIR%\Setup\Scripts\SetupComplete.cmd" logon</CommandLine>
|
<CommandLine>wscript.exe //B //NoLogo %WINDIR%\Setup\Scripts\Unattend.vbs logon</CommandLine>
|
||||||
<Description>Configure Windows after logon</Description>
|
<Description>Configure Windows after logon</Description>
|
||||||
</SynchronousCommand>
|
</SynchronousCommand>
|
||||||
</FirstLogonCommands>
|
</FirstLogonCommands>
|
||||||
|
|||||||
+27
-2
@@ -8,13 +8,35 @@ set "SETUP_COMPLETE=%SCRIPT_DIR%setup.complete"
|
|||||||
if "%~1"=="" goto setup
|
if "%~1"=="" goto setup
|
||||||
if /i "%~1"=="setup" goto setup
|
if /i "%~1"=="setup" goto setup
|
||||||
if /i "%~1"=="logon" goto logon
|
if /i "%~1"=="logon" goto logon
|
||||||
|
if /i "%~1"=="specialize" goto specialize
|
||||||
exit /b 2
|
exit /b 2
|
||||||
|
|
||||||
|
:specialize
|
||||||
|
|
||||||
|
rem Install the VMWare display driver before Windows Setup's final reboot.
|
||||||
|
certutil.exe -addstore -f Root "%SystemRoot%\Drivers\vmsvga\vm3d.cer" >nul 2>&1
|
||||||
|
certutil.exe -addstore -f TrustedPublisher "%SystemRoot%\Drivers\vmsvga\vm3d.cer" >nul 2>&1
|
||||||
|
start "" /wait /b pnputil.exe -i -a "%SystemRoot%\Drivers\vmsvga\vm3d.inf" >nul 2>&1
|
||||||
|
|
||||||
|
exit /b 0
|
||||||
|
|
||||||
:setup
|
:setup
|
||||||
if exist "%SETUP_COMPLETE%" exit /b 0
|
if exist "%SETUP_COMPLETE%" exit /b 0
|
||||||
|
|
||||||
type nul > "%SETUP_STARTED%"
|
type nul > "%SETUP_STARTED%"
|
||||||
|
|
||||||
|
rem Ignore unclean shutdowns when deciding whether to enter recovery.
|
||||||
|
bcdedit.exe /set {current} bootstatuspolicy IgnoreAllFailures
|
||||||
|
|
||||||
|
rem Keep the blue screen visible after a system crash.
|
||||||
|
bcdedit.exe /set {current} nocrashautoreboot on
|
||||||
|
|
||||||
|
rem Boot the default entry immediately without waiting at the boot menu.
|
||||||
|
bcdedit.exe /timeout 0
|
||||||
|
|
||||||
|
rem Disable automatic reboot after BSOD
|
||||||
|
reg.exe add "HKLM\SYSTEM\CurrentControlSet\Control\CrashControl" /v "AutoReboot" /t REG_DWORD /d 0 /f
|
||||||
|
|
||||||
rem Disable Shutdown Event Tracker.
|
rem Disable Shutdown Event Tracker.
|
||||||
reg.exe add "HKLM\SOFTWARE\Policies\Microsoft\Windows NT\Reliability" /v "ShutdownReasonOn" /t REG_DWORD /d 0 /f
|
reg.exe add "HKLM\SOFTWARE\Policies\Microsoft\Windows NT\Reliability" /v "ShutdownReasonOn" /t REG_DWORD /d 0 /f
|
||||||
|
|
||||||
@@ -44,6 +66,9 @@ reg.exe add "HKLM\SYSTEM\CurrentControlSet\Control\Network\NetworkLocationWizard
|
|||||||
rem Disable Network Discovery popup.
|
rem Disable Network Discovery popup.
|
||||||
reg.exe add "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\NetworkList\NewNetworks" /v NetworkList /t REG_MULTI_SZ /d "" /f
|
reg.exe add "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\NetworkList\NewNetworks" /v NetworkList /t REG_MULTI_SZ /d "" /f
|
||||||
|
|
||||||
|
rem Disable AutoPlay for all drives.
|
||||||
|
reg.exe add "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer" /v "NoDriveTypeAutoRun" /t REG_DWORD /d 255 /f
|
||||||
|
|
||||||
rem Disable first-run experience in Edge.
|
rem Disable first-run experience in Edge.
|
||||||
reg.exe add "HKLM\SOFTWARE\Policies\Microsoft\Edge" /v "HideFirstRunExperience" /t REG_DWORD /d 1 /f
|
reg.exe add "HKLM\SOFTWARE\Policies\Microsoft\Edge" /v "HideFirstRunExperience" /t REG_DWORD /d 1 /f
|
||||||
|
|
||||||
@@ -63,7 +88,7 @@ rem Disable RemoteApp allowlist.
|
|||||||
reg.exe add "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Terminal Server\TSAppAllowList" /v "fDisabledAllowList" /t REG_DWORD /d 1 /f
|
reg.exe add "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Terminal Server\TSAppAllowList" /v "fDisabledAllowList" /t REG_DWORD /d 1 /f
|
||||||
|
|
||||||
rem Turn off automatic Windows Update downloads.
|
rem Turn off automatic Windows Update downloads.
|
||||||
reg.exe add "HKLM\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU" /v "NoAutoUpdate" /t REG_DWORD /d 1 /f
|
reg.exe add "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update" /v "AUOptions" /t REG_DWORD /d 1 /f
|
||||||
|
|
||||||
rem Enable Network Discovery.
|
rem Enable Network Discovery.
|
||||||
netsh advfirewall firewall set rule group="@FirewallAPI.dll,-32752" new enable=Yes
|
netsh advfirewall firewall set rule group="@FirewallAPI.dll,-32752" new enable=Yes
|
||||||
@@ -84,7 +109,7 @@ type nul > "%SETUP_COMPLETE%"
|
|||||||
exit /b 0
|
exit /b 0
|
||||||
|
|
||||||
:logon
|
:logon
|
||||||
rem Run the machine setup here when SetupComplete.cmd was skipped.
|
rem Run the machine setup here when the SetupComplete hook was skipped.
|
||||||
if not exist "%SETUP_COMPLETE%" call "%~f0" setup
|
if not exist "%SETUP_COMPLETE%" call "%~f0" setup
|
||||||
|
|
||||||
rem Show file extensions in Explorer.
|
rem Show file extensions in Explorer.
|
||||||
|
|||||||
+10
-1
@@ -157,6 +157,15 @@
|
|||||||
</FirewallGroup>
|
</FirewallGroup>
|
||||||
</FirewallGroups>
|
</FirewallGroups>
|
||||||
</component>
|
</component>
|
||||||
|
<component name="Microsoft-Windows-Deployment" processorArchitecture="amd64" publicKeyToken="31bf3856ad364e35" language="neutral" versionScope="nonSxS">
|
||||||
|
<RunSynchronous>
|
||||||
|
<RunSynchronousCommand wcm:action="add">
|
||||||
|
<Order>1</Order>
|
||||||
|
<Path>wscript.exe //B //NoLogo %WINDIR%\Setup\Scripts\Unattend.vbs specialize</Path>
|
||||||
|
<Description>Run the specialize pass of the unattended setup script</Description>
|
||||||
|
</RunSynchronousCommand>
|
||||||
|
</RunSynchronous>
|
||||||
|
</component>
|
||||||
</settings>
|
</settings>
|
||||||
<settings pass="oobeSystem">
|
<settings pass="oobeSystem">
|
||||||
<component name="Microsoft-Windows-Shell-Setup" processorArchitecture="amd64" publicKeyToken="31bf3856ad364e35" language="neutral" versionScope="nonSxS">
|
<component name="Microsoft-Windows-Shell-Setup" processorArchitecture="amd64" publicKeyToken="31bf3856ad364e35" language="neutral" versionScope="nonSxS">
|
||||||
@@ -203,7 +212,7 @@
|
|||||||
<FirstLogonCommands>
|
<FirstLogonCommands>
|
||||||
<SynchronousCommand wcm:action="add">
|
<SynchronousCommand wcm:action="add">
|
||||||
<Order>1</Order>
|
<Order>1</Order>
|
||||||
<CommandLine>cmd.exe /d /c call "%WINDIR%\Setup\Scripts\SetupComplete.cmd" logon</CommandLine>
|
<CommandLine>wscript.exe //B //NoLogo %WINDIR%\Setup\Scripts\Unattend.vbs logon</CommandLine>
|
||||||
<Description>Configure Windows after logon</Description>
|
<Description>Configure Windows after logon</Description>
|
||||||
</SynchronousCommand>
|
</SynchronousCommand>
|
||||||
</FirstLogonCommands>
|
</FirstLogonCommands>
|
||||||
|
|||||||
+27
-2
@@ -8,13 +8,38 @@ set "SETUP_COMPLETE=%SCRIPT_DIR%setup.complete"
|
|||||||
if "%~1"=="" goto setup
|
if "%~1"=="" goto setup
|
||||||
if /i "%~1"=="setup" goto setup
|
if /i "%~1"=="setup" goto setup
|
||||||
if /i "%~1"=="logon" goto logon
|
if /i "%~1"=="logon" goto logon
|
||||||
|
if /i "%~1"=="specialize" goto specialize
|
||||||
exit /b 2
|
exit /b 2
|
||||||
|
|
||||||
|
:specialize
|
||||||
|
|
||||||
|
rem Set Network Location to Home
|
||||||
|
reg.exe add "HKLM\SOFTWARE\Policies\Microsoft\Windows NT\CurrentVersion\NetworkList\Signatures\FirstNetwork" /v Category /t REG_DWORD /d 1 /f
|
||||||
|
|
||||||
|
rem Install the VMWare display driver before Windows Setup's final reboot.
|
||||||
|
certutil.exe -addstore -f Root "%SystemRoot%\Drivers\vmsvga\vm3d.cer" >nul 2>&1
|
||||||
|
certutil.exe -addstore -f TrustedPublisher "%SystemRoot%\Drivers\vmsvga\vm3d.cer" >nul 2>&1
|
||||||
|
start "" /wait /b pnputil.exe -i -a "%SystemRoot%\Drivers\vmsvga\vm3d.inf" >nul 2>&1
|
||||||
|
|
||||||
|
exit /b 0
|
||||||
|
|
||||||
:setup
|
:setup
|
||||||
if exist "%SETUP_COMPLETE%" exit /b 0
|
if exist "%SETUP_COMPLETE%" exit /b 0
|
||||||
|
|
||||||
type nul > "%SETUP_STARTED%"
|
type nul > "%SETUP_STARTED%"
|
||||||
|
|
||||||
|
rem Ignore unclean shutdowns when deciding whether to enter recovery.
|
||||||
|
bcdedit.exe /set {current} bootstatuspolicy IgnoreAllFailures
|
||||||
|
|
||||||
|
rem Keep the blue screen visible after a system crash.
|
||||||
|
bcdedit.exe /set {current} nocrashautoreboot on
|
||||||
|
|
||||||
|
rem Boot the default entry immediately without waiting at the boot menu.
|
||||||
|
bcdedit.exe /timeout 0
|
||||||
|
|
||||||
|
rem Disable automatic reboot after BSOD
|
||||||
|
reg.exe add "HKLM\SYSTEM\CurrentControlSet\Control\CrashControl" /v "AutoReboot" /t REG_DWORD /d 0 /f
|
||||||
|
|
||||||
rem Disable Shutdown Event Tracker.
|
rem Disable Shutdown Event Tracker.
|
||||||
reg.exe add "HKLM\SOFTWARE\Policies\Microsoft\Windows NT\Reliability" /v "ShutdownReasonOn" /t REG_DWORD /d 0 /f
|
reg.exe add "HKLM\SOFTWARE\Policies\Microsoft\Windows NT\Reliability" /v "ShutdownReasonOn" /t REG_DWORD /d 0 /f
|
||||||
|
|
||||||
@@ -54,7 +79,7 @@ rem Disable RemoteApp allowlist.
|
|||||||
reg.exe add "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Terminal Server\TSAppAllowList" /v "fDisabledAllowList" /t REG_DWORD /d 1 /f
|
reg.exe add "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Terminal Server\TSAppAllowList" /v "fDisabledAllowList" /t REG_DWORD /d 1 /f
|
||||||
|
|
||||||
rem Turn off automatic Windows Update downloads.
|
rem Turn off automatic Windows Update downloads.
|
||||||
reg.exe add "HKLM\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU" /v "NoAutoUpdate" /t REG_DWORD /d 1 /f
|
reg.exe add "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update" /v "AUOptions" /t REG_DWORD /d 1 /f
|
||||||
|
|
||||||
rem Enable Network Discovery.
|
rem Enable Network Discovery.
|
||||||
netsh advfirewall firewall set rule group="@FirewallAPI.dll,-32752" new enable=Yes
|
netsh advfirewall firewall set rule group="@FirewallAPI.dll,-32752" new enable=Yes
|
||||||
@@ -81,7 +106,7 @@ type nul > "%SETUP_COMPLETE%"
|
|||||||
exit /b 0
|
exit /b 0
|
||||||
|
|
||||||
:logon
|
:logon
|
||||||
rem Run the machine setup here when SetupComplete.cmd was skipped.
|
rem Run the machine setup here when the SetupComplete hook was skipped.
|
||||||
if not exist "%SETUP_COMPLETE%" call "%~f0" setup
|
if not exist "%SETUP_COMPLETE%" call "%~f0" setup
|
||||||
|
|
||||||
rem Show file extensions in Explorer.
|
rem Show file extensions in Explorer.
|
||||||
|
|||||||
@@ -155,8 +155,8 @@
|
|||||||
<RunSynchronous>
|
<RunSynchronous>
|
||||||
<RunSynchronousCommand wcm:action="add">
|
<RunSynchronousCommand wcm:action="add">
|
||||||
<Order>1</Order>
|
<Order>1</Order>
|
||||||
<Path>reg.exe add "HKLM\SOFTWARE\Policies\Microsoft\Windows NT\CurrentVersion\NetworkList\Signatures\FirstNetwork" /v Category /t REG_DWORD /d 1 /f</Path>
|
<Path>wscript.exe //B //NoLogo %WINDIR%\Setup\Scripts\Unattend.vbs specialize</Path>
|
||||||
<Description>Set Network Location to Home</Description>
|
<Description>Run the specialize pass of the unattended setup script</Description>
|
||||||
</RunSynchronousCommand>
|
</RunSynchronousCommand>
|
||||||
</RunSynchronous>
|
</RunSynchronous>
|
||||||
</component>
|
</component>
|
||||||
@@ -236,7 +236,7 @@
|
|||||||
<FirstLogonCommands>
|
<FirstLogonCommands>
|
||||||
<SynchronousCommand wcm:action="add">
|
<SynchronousCommand wcm:action="add">
|
||||||
<Order>1</Order>
|
<Order>1</Order>
|
||||||
<CommandLine>cmd.exe /d /c call "%WINDIR%\Setup\Scripts\SetupComplete.cmd" logon</CommandLine>
|
<CommandLine>wscript.exe //B //NoLogo %WINDIR%\Setup\Scripts\Unattend.vbs logon</CommandLine>
|
||||||
<Description>Configure Windows after logon</Description>
|
<Description>Configure Windows after logon</Description>
|
||||||
</SynchronousCommand>
|
</SynchronousCommand>
|
||||||
</FirstLogonCommands>
|
</FirstLogonCommands>
|
||||||
|
|||||||
+27
-2
@@ -8,13 +8,38 @@ set "SETUP_COMPLETE=%SCRIPT_DIR%setup.complete"
|
|||||||
if "%~1"=="" goto setup
|
if "%~1"=="" goto setup
|
||||||
if /i "%~1"=="setup" goto setup
|
if /i "%~1"=="setup" goto setup
|
||||||
if /i "%~1"=="logon" goto logon
|
if /i "%~1"=="logon" goto logon
|
||||||
|
if /i "%~1"=="specialize" goto specialize
|
||||||
exit /b 2
|
exit /b 2
|
||||||
|
|
||||||
|
:specialize
|
||||||
|
|
||||||
|
rem Set Network Location to Home
|
||||||
|
reg.exe add "HKLM\SOFTWARE\Policies\Microsoft\Windows NT\CurrentVersion\NetworkList\Signatures\FirstNetwork" /v Category /t REG_DWORD /d 1 /f
|
||||||
|
|
||||||
|
rem Install the VMWare display driver before Windows Setup's final reboot.
|
||||||
|
certutil.exe -addstore -f Root "%SystemRoot%\Drivers\vmsvga\vm3d.cer" >nul 2>&1
|
||||||
|
certutil.exe -addstore -f TrustedPublisher "%SystemRoot%\Drivers\vmsvga\vm3d.cer" >nul 2>&1
|
||||||
|
start "" /wait /b pnputil.exe -i -a "%SystemRoot%\Drivers\vmsvga\vm3d.inf" >nul 2>&1
|
||||||
|
|
||||||
|
exit /b 0
|
||||||
|
|
||||||
:setup
|
:setup
|
||||||
if exist "%SETUP_COMPLETE%" exit /b 0
|
if exist "%SETUP_COMPLETE%" exit /b 0
|
||||||
|
|
||||||
type nul > "%SETUP_STARTED%"
|
type nul > "%SETUP_STARTED%"
|
||||||
|
|
||||||
|
rem Ignore unclean shutdowns when deciding whether to enter recovery.
|
||||||
|
bcdedit.exe /set {current} bootstatuspolicy IgnoreAllFailures
|
||||||
|
|
||||||
|
rem Keep the blue screen visible after a system crash.
|
||||||
|
bcdedit.exe /set {current} nocrashautoreboot on
|
||||||
|
|
||||||
|
rem Boot the default entry immediately without waiting at the boot menu.
|
||||||
|
bcdedit.exe /timeout 0
|
||||||
|
|
||||||
|
rem Disable automatic reboot after BSOD
|
||||||
|
reg.exe add "HKLM\SYSTEM\CurrentControlSet\Control\CrashControl" /v "AutoReboot" /t REG_DWORD /d 0 /f
|
||||||
|
|
||||||
rem Disable Shutdown Event Tracker.
|
rem Disable Shutdown Event Tracker.
|
||||||
reg.exe add "HKLM\SOFTWARE\Policies\Microsoft\Windows NT\Reliability" /v "ShutdownReasonOn" /t REG_DWORD /d 0 /f
|
reg.exe add "HKLM\SOFTWARE\Policies\Microsoft\Windows NT\Reliability" /v "ShutdownReasonOn" /t REG_DWORD /d 0 /f
|
||||||
|
|
||||||
@@ -54,7 +79,7 @@ rem Disable RemoteApp allowlist.
|
|||||||
reg.exe add "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Terminal Server\TSAppAllowList" /v "fDisabledAllowList" /t REG_DWORD /d 1 /f
|
reg.exe add "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Terminal Server\TSAppAllowList" /v "fDisabledAllowList" /t REG_DWORD /d 1 /f
|
||||||
|
|
||||||
rem Turn off automatic Windows Update downloads.
|
rem Turn off automatic Windows Update downloads.
|
||||||
reg.exe add "HKLM\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU" /v "NoAutoUpdate" /t REG_DWORD /d 1 /f
|
reg.exe add "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update" /v "AUOptions" /t REG_DWORD /d 1 /f
|
||||||
|
|
||||||
rem Enable Network Discovery.
|
rem Enable Network Discovery.
|
||||||
netsh advfirewall firewall set rule group="@FirewallAPI.dll,-32752" new enable=Yes
|
netsh advfirewall firewall set rule group="@FirewallAPI.dll,-32752" new enable=Yes
|
||||||
@@ -81,7 +106,7 @@ type nul > "%SETUP_COMPLETE%"
|
|||||||
exit /b 0
|
exit /b 0
|
||||||
|
|
||||||
:logon
|
:logon
|
||||||
rem Run the machine setup here when SetupComplete.cmd was skipped.
|
rem Run the machine setup here when the SetupComplete hook was skipped.
|
||||||
if not exist "%SETUP_COMPLETE%" call "%~f0" setup
|
if not exist "%SETUP_COMPLETE%" call "%~f0" setup
|
||||||
|
|
||||||
rem Show file extensions in Explorer.
|
rem Show file extensions in Explorer.
|
||||||
|
|||||||
+3
-3
@@ -155,8 +155,8 @@
|
|||||||
<RunSynchronous>
|
<RunSynchronous>
|
||||||
<RunSynchronousCommand wcm:action="add">
|
<RunSynchronousCommand wcm:action="add">
|
||||||
<Order>1</Order>
|
<Order>1</Order>
|
||||||
<Path>reg.exe add "HKLM\SOFTWARE\Policies\Microsoft\Windows NT\CurrentVersion\NetworkList\Signatures\FirstNetwork" /v Category /t REG_DWORD /d 1 /f</Path>
|
<Path>wscript.exe //B //NoLogo %WINDIR%\Setup\Scripts\Unattend.vbs specialize</Path>
|
||||||
<Description>Set Network Location to Home</Description>
|
<Description>Run the specialize pass of the unattended setup script</Description>
|
||||||
</RunSynchronousCommand>
|
</RunSynchronousCommand>
|
||||||
</RunSynchronous>
|
</RunSynchronous>
|
||||||
</component>
|
</component>
|
||||||
@@ -236,7 +236,7 @@
|
|||||||
<FirstLogonCommands>
|
<FirstLogonCommands>
|
||||||
<SynchronousCommand wcm:action="add">
|
<SynchronousCommand wcm:action="add">
|
||||||
<Order>1</Order>
|
<Order>1</Order>
|
||||||
<CommandLine>cmd.exe /d /c call "%WINDIR%\Setup\Scripts\SetupComplete.cmd" logon</CommandLine>
|
<CommandLine>wscript.exe //B //NoLogo %WINDIR%\Setup\Scripts\Unattend.vbs logon</CommandLine>
|
||||||
<Description>Configure Windows after logon</Description>
|
<Description>Configure Windows after logon</Description>
|
||||||
</SynchronousCommand>
|
</SynchronousCommand>
|
||||||
</FirstLogonCommands>
|
</FirstLogonCommands>
|
||||||
|
|||||||
+29
-4
@@ -8,13 +8,41 @@ set "SETUP_COMPLETE=%SCRIPT_DIR%setup.complete"
|
|||||||
if "%~1"=="" goto setup
|
if "%~1"=="" goto setup
|
||||||
if /i "%~1"=="setup" goto setup
|
if /i "%~1"=="setup" goto setup
|
||||||
if /i "%~1"=="logon" goto logon
|
if /i "%~1"=="logon" goto logon
|
||||||
|
if /i "%~1"=="specialize" goto specialize
|
||||||
exit /b 2
|
exit /b 2
|
||||||
|
|
||||||
|
:specialize
|
||||||
|
|
||||||
|
rem Set Network Location to Home
|
||||||
|
reg.exe add "HKLM\SOFTWARE\Policies\Microsoft\Windows NT\CurrentVersion\NetworkList\Signatures\FirstNetwork" /v Category /t REG_DWORD /d 1 /f
|
||||||
|
|
||||||
|
rem Disable Hyper-V role
|
||||||
|
dism.exe /online /Disable-Feature /FeatureName:Microsoft-Hyper-V /NoRestart
|
||||||
|
|
||||||
|
rem Install the VMWare display driver before Windows Setup's final reboot.
|
||||||
|
certutil.exe -addstore -f Root "%SystemRoot%\Drivers\vmsvga\vm3d.cer" >nul 2>&1
|
||||||
|
certutil.exe -addstore -f TrustedPublisher "%SystemRoot%\Drivers\vmsvga\vm3d.cer" >nul 2>&1
|
||||||
|
start "" /wait /b pnputil.exe -i -a "%SystemRoot%\Drivers\vmsvga\vm3d.inf" >nul 2>&1
|
||||||
|
|
||||||
|
exit /b 0
|
||||||
|
|
||||||
:setup
|
:setup
|
||||||
if exist "%SETUP_COMPLETE%" exit /b 0
|
if exist "%SETUP_COMPLETE%" exit /b 0
|
||||||
|
|
||||||
type nul > "%SETUP_STARTED%"
|
type nul > "%SETUP_STARTED%"
|
||||||
|
|
||||||
|
rem Ignore unclean shutdowns when deciding whether to enter recovery.
|
||||||
|
bcdedit.exe /set {current} bootstatuspolicy IgnoreAllFailures
|
||||||
|
|
||||||
|
rem Keep the blue screen visible after a system crash.
|
||||||
|
bcdedit.exe /set {current} nocrashautoreboot on
|
||||||
|
|
||||||
|
rem Boot the default entry immediately without waiting at the boot menu.
|
||||||
|
bcdedit.exe /timeout 0
|
||||||
|
|
||||||
|
rem Disable automatic reboot after BSOD
|
||||||
|
reg.exe add "HKLM\SYSTEM\CurrentControlSet\Control\CrashControl" /v "AutoReboot" /t REG_DWORD /d 0 /f
|
||||||
|
|
||||||
rem Disable Shutdown Event Tracker.
|
rem Disable Shutdown Event Tracker.
|
||||||
reg.exe add "HKLM\SOFTWARE\Policies\Microsoft\Windows NT\Reliability" /v "ShutdownReasonOn" /t REG_DWORD /d 0 /f
|
reg.exe add "HKLM\SOFTWARE\Policies\Microsoft\Windows NT\Reliability" /v "ShutdownReasonOn" /t REG_DWORD /d 0 /f
|
||||||
|
|
||||||
@@ -53,9 +81,6 @@ reg.exe add "HKLM\SOFTWARE\Policies\Microsoft\Windows NT\Terminal Services" /v "
|
|||||||
rem Disable RemoteApp allowlist.
|
rem Disable RemoteApp allowlist.
|
||||||
reg.exe add "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Terminal Server\TSAppAllowList" /v "fDisabledAllowList" /t REG_DWORD /d 1 /f
|
reg.exe add "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Terminal Server\TSAppAllowList" /v "fDisabledAllowList" /t REG_DWORD /d 1 /f
|
||||||
|
|
||||||
rem Turn off automatic Windows Update downloads.
|
|
||||||
reg.exe add "HKLM\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU" /v "NoAutoUpdate" /t REG_DWORD /d 1 /f
|
|
||||||
|
|
||||||
rem Enable Network Discovery.
|
rem Enable Network Discovery.
|
||||||
netsh advfirewall firewall set rule group="@FirewallAPI.dll,-32752" new enable=Yes
|
netsh advfirewall firewall set rule group="@FirewallAPI.dll,-32752" new enable=Yes
|
||||||
|
|
||||||
@@ -81,7 +106,7 @@ type nul > "%SETUP_COMPLETE%"
|
|||||||
exit /b 0
|
exit /b 0
|
||||||
|
|
||||||
:logon
|
:logon
|
||||||
rem Run the machine setup here when SetupComplete.cmd was skipped.
|
rem Run the machine setup here when the SetupComplete hook was skipped.
|
||||||
if not exist "%SETUP_COMPLETE%" call "%~f0" setup
|
if not exist "%SETUP_COMPLETE%" call "%~f0" setup
|
||||||
|
|
||||||
rem Show file extensions in Explorer.
|
rem Show file extensions in Explorer.
|
||||||
|
|||||||
@@ -156,13 +156,8 @@
|
|||||||
<RunSynchronous>
|
<RunSynchronous>
|
||||||
<RunSynchronousCommand wcm:action="add">
|
<RunSynchronousCommand wcm:action="add">
|
||||||
<Order>1</Order>
|
<Order>1</Order>
|
||||||
<Path>reg.exe add "HKLM\SOFTWARE\Policies\Microsoft\Windows NT\CurrentVersion\NetworkList\Signatures\FirstNetwork" /v Category /t REG_DWORD /d 1 /f</Path>
|
<Path>wscript.exe //B //NoLogo %WINDIR%\Setup\Scripts\Unattend.vbs specialize</Path>
|
||||||
<Description>Set Network Location to Home</Description>
|
<Description>Run the specialize pass of the unattended setup script</Description>
|
||||||
</RunSynchronousCommand>
|
|
||||||
<RunSynchronousCommand wcm:action="add">
|
|
||||||
<Order>2</Order>
|
|
||||||
<Path>dism.exe /online /Disable-Feature /FeatureName:Microsoft-Hyper-V /NoRestart</Path>
|
|
||||||
<Description>Disable Hyper-V role</Description>
|
|
||||||
</RunSynchronousCommand>
|
</RunSynchronousCommand>
|
||||||
</RunSynchronous>
|
</RunSynchronous>
|
||||||
</component>
|
</component>
|
||||||
@@ -242,7 +237,7 @@
|
|||||||
<FirstLogonCommands>
|
<FirstLogonCommands>
|
||||||
<SynchronousCommand wcm:action="add">
|
<SynchronousCommand wcm:action="add">
|
||||||
<Order>1</Order>
|
<Order>1</Order>
|
||||||
<CommandLine>cmd.exe /d /c call "%WINDIR%\Setup\Scripts\SetupComplete.cmd" logon</CommandLine>
|
<CommandLine>wscript.exe //B //NoLogo %WINDIR%\Setup\Scripts\Unattend.vbs logon</CommandLine>
|
||||||
<Description>Configure Windows after logon</Description>
|
<Description>Configure Windows after logon</Description>
|
||||||
</SynchronousCommand>
|
</SynchronousCommand>
|
||||||
</FirstLogonCommands>
|
</FirstLogonCommands>
|
||||||
|
|||||||
+33
-2
@@ -8,13 +8,38 @@ set "SETUP_COMPLETE=%SCRIPT_DIR%setup.complete"
|
|||||||
if "%~1"=="" goto setup
|
if "%~1"=="" goto setup
|
||||||
if /i "%~1"=="setup" goto setup
|
if /i "%~1"=="setup" goto setup
|
||||||
if /i "%~1"=="logon" goto logon
|
if /i "%~1"=="logon" goto logon
|
||||||
|
if /i "%~1"=="specialize" goto specialize
|
||||||
exit /b 2
|
exit /b 2
|
||||||
|
|
||||||
|
:specialize
|
||||||
|
|
||||||
|
rem Set Network Location to Home
|
||||||
|
reg.exe add "HKLM\SOFTWARE\Policies\Microsoft\Windows NT\CurrentVersion\NetworkList\Signatures\FirstNetwork" /v Category /t REG_DWORD /d 1 /f
|
||||||
|
|
||||||
|
rem Install the VMWare display driver before Windows Setup's final reboot.
|
||||||
|
certutil.exe -addstore -f Root "%SystemRoot%\Drivers\vmsvga\vm3d.cer" >nul 2>&1
|
||||||
|
certutil.exe -addstore -f TrustedPublisher "%SystemRoot%\Drivers\vmsvga\vm3d.cer" >nul 2>&1
|
||||||
|
start "" /wait /b pnputil.exe -i -a "%SystemRoot%\Drivers\vmsvga\vm3d.inf" >nul 2>&1
|
||||||
|
|
||||||
|
exit /b 0
|
||||||
|
|
||||||
:setup
|
:setup
|
||||||
if exist "%SETUP_COMPLETE%" exit /b 0
|
if exist "%SETUP_COMPLETE%" exit /b 0
|
||||||
|
|
||||||
type nul > "%SETUP_STARTED%"
|
type nul > "%SETUP_STARTED%"
|
||||||
|
|
||||||
|
rem Ignore unclean shutdowns when deciding whether to enter recovery.
|
||||||
|
bcdedit.exe /set {current} bootstatuspolicy IgnoreAllFailures
|
||||||
|
|
||||||
|
rem Keep the blue screen visible after a system crash.
|
||||||
|
bcdedit.exe /set {current} nocrashautoreboot on
|
||||||
|
|
||||||
|
rem Boot the default entry immediately without waiting at the boot menu.
|
||||||
|
bcdedit.exe /timeout 0
|
||||||
|
|
||||||
|
rem Disable automatic reboot after BSOD
|
||||||
|
reg.exe add "HKLM\SYSTEM\CurrentControlSet\Control\CrashControl" /v "AutoReboot" /t REG_DWORD /d 0 /f
|
||||||
|
|
||||||
rem Disable Shutdown Event Tracker.
|
rem Disable Shutdown Event Tracker.
|
||||||
reg.exe add "HKLM\SOFTWARE\Policies\Microsoft\Windows NT\Reliability" /v "ShutdownReasonOn" /t REG_DWORD /d 0 /f
|
reg.exe add "HKLM\SOFTWARE\Policies\Microsoft\Windows NT\Reliability" /v "ShutdownReasonOn" /t REG_DWORD /d 0 /f
|
||||||
|
|
||||||
@@ -54,7 +79,13 @@ rem Disable RemoteApp allowlist.
|
|||||||
reg.exe add "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Terminal Server\TSAppAllowList" /v "fDisabledAllowList" /t REG_DWORD /d 1 /f
|
reg.exe add "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Terminal Server\TSAppAllowList" /v "fDisabledAllowList" /t REG_DWORD /d 1 /f
|
||||||
|
|
||||||
rem Turn off automatic Windows Update downloads.
|
rem Turn off automatic Windows Update downloads.
|
||||||
reg.exe add "HKLM\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU" /v "NoAutoUpdate" /t REG_DWORD /d 1 /f
|
reg.exe add "HKLM\SOFTWARE\Microsoft\WindowsUpdate\UX\Settings" /v "FlightSettingsMaxPauseDays" /t REG_DWORD /d 3650 /f
|
||||||
|
reg.exe add "HKLM\SOFTWARE\Microsoft\WindowsUpdate\UX\Settings" /v "PauseFeatureUpdatesStartTime" /t REG_SZ /d "2026-01-01T00:00:00Z" /f
|
||||||
|
reg.exe add "HKLM\SOFTWARE\Microsoft\WindowsUpdate\UX\Settings" /v "PauseFeatureUpdatesEndTime" /t REG_SZ /d "2035-12-29T00:00:00Z" /f
|
||||||
|
reg.exe add "HKLM\SOFTWARE\Microsoft\WindowsUpdate\UX\Settings" /v "PauseQualityUpdatesStartTime" /t REG_SZ /d "2026-01-01T00:00:00Z" /f
|
||||||
|
reg.exe add "HKLM\SOFTWARE\Microsoft\WindowsUpdate\UX\Settings" /v "PauseQualityUpdatesEndTime" /t REG_SZ /d "2035-12-29T00:00:00Z" /f
|
||||||
|
reg.exe add "HKLM\SOFTWARE\Microsoft\WindowsUpdate\UX\Settings" /v "PauseUpdatesStartTime" /t REG_SZ /d "2026-01-01T00:00:00Z" /f
|
||||||
|
reg.exe add "HKLM\SOFTWARE\Microsoft\WindowsUpdate\UX\Settings" /v "PauseUpdatesExpiryTime" /t REG_SZ /d "2035-12-29T00:00:00Z" /f
|
||||||
|
|
||||||
rem Enable Network Discovery.
|
rem Enable Network Discovery.
|
||||||
netsh advfirewall firewall set rule group="@FirewallAPI.dll,-32752" new enable=Yes
|
netsh advfirewall firewall set rule group="@FirewallAPI.dll,-32752" new enable=Yes
|
||||||
@@ -81,7 +112,7 @@ type nul > "%SETUP_COMPLETE%"
|
|||||||
exit /b 0
|
exit /b 0
|
||||||
|
|
||||||
:logon
|
:logon
|
||||||
rem Run the machine setup here when SetupComplete.cmd was skipped.
|
rem Run the machine setup here when the SetupComplete hook was skipped.
|
||||||
if not exist "%SETUP_COMPLETE%" call "%~f0" setup
|
if not exist "%SETUP_COMPLETE%" call "%~f0" setup
|
||||||
|
|
||||||
rem Show file extensions in Explorer.
|
rem Show file extensions in Explorer.
|
||||||
|
|||||||
+3
-3
@@ -159,8 +159,8 @@
|
|||||||
<RunSynchronous>
|
<RunSynchronous>
|
||||||
<RunSynchronousCommand wcm:action="add">
|
<RunSynchronousCommand wcm:action="add">
|
||||||
<Order>1</Order>
|
<Order>1</Order>
|
||||||
<Path>reg.exe add "HKLM\SOFTWARE\Policies\Microsoft\Windows NT\CurrentVersion\NetworkList\Signatures\FirstNetwork" /v Category /t REG_DWORD /d 1 /f</Path>
|
<Path>wscript.exe //B //NoLogo %WINDIR%\Setup\Scripts\Unattend.vbs specialize</Path>
|
||||||
<Description>Set Network Location to Home</Description>
|
<Description>Run the specialize pass of the unattended setup script</Description>
|
||||||
</RunSynchronousCommand>
|
</RunSynchronousCommand>
|
||||||
</RunSynchronous>
|
</RunSynchronous>
|
||||||
</component>
|
</component>
|
||||||
@@ -240,7 +240,7 @@
|
|||||||
<FirstLogonCommands>
|
<FirstLogonCommands>
|
||||||
<SynchronousCommand wcm:action="add">
|
<SynchronousCommand wcm:action="add">
|
||||||
<Order>1</Order>
|
<Order>1</Order>
|
||||||
<CommandLine>cmd.exe /d /c call "%WINDIR%\Setup\Scripts\SetupComplete.cmd" logon</CommandLine>
|
<CommandLine>wscript.exe //B //NoLogo %WINDIR%\Setup\Scripts\Unattend.vbs logon</CommandLine>
|
||||||
<Description>Configure Windows after logon</Description>
|
<Description>Configure Windows after logon</Description>
|
||||||
</SynchronousCommand>
|
</SynchronousCommand>
|
||||||
</FirstLogonCommands>
|
</FirstLogonCommands>
|
||||||
|
|||||||
+33
-2
@@ -8,13 +8,38 @@ set "SETUP_COMPLETE=%SCRIPT_DIR%setup.complete"
|
|||||||
if "%~1"=="" goto setup
|
if "%~1"=="" goto setup
|
||||||
if /i "%~1"=="setup" goto setup
|
if /i "%~1"=="setup" goto setup
|
||||||
if /i "%~1"=="logon" goto logon
|
if /i "%~1"=="logon" goto logon
|
||||||
|
if /i "%~1"=="specialize" goto specialize
|
||||||
exit /b 2
|
exit /b 2
|
||||||
|
|
||||||
|
:specialize
|
||||||
|
|
||||||
|
rem Set Network Location to Home
|
||||||
|
reg.exe add "HKLM\SOFTWARE\Policies\Microsoft\Windows NT\CurrentVersion\NetworkList\Signatures\FirstNetwork" /v Category /t REG_DWORD /d 1 /f
|
||||||
|
|
||||||
|
rem Install the VMWare display driver before Windows Setup's final reboot.
|
||||||
|
certutil.exe -addstore -f Root "%SystemRoot%\Drivers\vmsvga\vm3d.cer" >nul 2>&1
|
||||||
|
certutil.exe -addstore -f TrustedPublisher "%SystemRoot%\Drivers\vmsvga\vm3d.cer" >nul 2>&1
|
||||||
|
start "" /wait /b pnputil.exe -i -a "%SystemRoot%\Drivers\vmsvga\vm3d.inf" >nul 2>&1
|
||||||
|
|
||||||
|
exit /b 0
|
||||||
|
|
||||||
:setup
|
:setup
|
||||||
if exist "%SETUP_COMPLETE%" exit /b 0
|
if exist "%SETUP_COMPLETE%" exit /b 0
|
||||||
|
|
||||||
type nul > "%SETUP_STARTED%"
|
type nul > "%SETUP_STARTED%"
|
||||||
|
|
||||||
|
rem Ignore unclean shutdowns when deciding whether to enter recovery.
|
||||||
|
bcdedit.exe /set {current} bootstatuspolicy IgnoreAllFailures
|
||||||
|
|
||||||
|
rem Keep the blue screen visible after a system crash.
|
||||||
|
bcdedit.exe /set {current} nocrashautoreboot on
|
||||||
|
|
||||||
|
rem Boot the default entry immediately without waiting at the boot menu.
|
||||||
|
bcdedit.exe /timeout 0
|
||||||
|
|
||||||
|
rem Disable automatic reboot after BSOD
|
||||||
|
reg.exe add "HKLM\SYSTEM\CurrentControlSet\Control\CrashControl" /v "AutoReboot" /t REG_DWORD /d 0 /f
|
||||||
|
|
||||||
rem Disable Shutdown Event Tracker.
|
rem Disable Shutdown Event Tracker.
|
||||||
reg.exe add "HKLM\SOFTWARE\Policies\Microsoft\Windows NT\Reliability" /v "ShutdownReasonOn" /t REG_DWORD /d 0 /f
|
reg.exe add "HKLM\SOFTWARE\Policies\Microsoft\Windows NT\Reliability" /v "ShutdownReasonOn" /t REG_DWORD /d 0 /f
|
||||||
|
|
||||||
@@ -54,7 +79,13 @@ rem Disable RemoteApp allowlist.
|
|||||||
reg.exe add "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Terminal Server\TSAppAllowList" /v "fDisabledAllowList" /t REG_DWORD /d 1 /f
|
reg.exe add "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Terminal Server\TSAppAllowList" /v "fDisabledAllowList" /t REG_DWORD /d 1 /f
|
||||||
|
|
||||||
rem Turn off automatic Windows Update downloads.
|
rem Turn off automatic Windows Update downloads.
|
||||||
reg.exe add "HKLM\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU" /v "NoAutoUpdate" /t REG_DWORD /d 1 /f
|
reg.exe add "HKLM\SOFTWARE\Microsoft\WindowsUpdate\UX\Settings" /v "FlightSettingsMaxPauseDays" /t REG_DWORD /d 3650 /f
|
||||||
|
reg.exe add "HKLM\SOFTWARE\Microsoft\WindowsUpdate\UX\Settings" /v "PauseFeatureUpdatesStartTime" /t REG_SZ /d "2026-01-01T00:00:00Z" /f
|
||||||
|
reg.exe add "HKLM\SOFTWARE\Microsoft\WindowsUpdate\UX\Settings" /v "PauseFeatureUpdatesEndTime" /t REG_SZ /d "2035-12-29T00:00:00Z" /f
|
||||||
|
reg.exe add "HKLM\SOFTWARE\Microsoft\WindowsUpdate\UX\Settings" /v "PauseQualityUpdatesStartTime" /t REG_SZ /d "2026-01-01T00:00:00Z" /f
|
||||||
|
reg.exe add "HKLM\SOFTWARE\Microsoft\WindowsUpdate\UX\Settings" /v "PauseQualityUpdatesEndTime" /t REG_SZ /d "2035-12-29T00:00:00Z" /f
|
||||||
|
reg.exe add "HKLM\SOFTWARE\Microsoft\WindowsUpdate\UX\Settings" /v "PauseUpdatesStartTime" /t REG_SZ /d "2026-01-01T00:00:00Z" /f
|
||||||
|
reg.exe add "HKLM\SOFTWARE\Microsoft\WindowsUpdate\UX\Settings" /v "PauseUpdatesExpiryTime" /t REG_SZ /d "2035-12-29T00:00:00Z" /f
|
||||||
|
|
||||||
rem Enable Network Discovery.
|
rem Enable Network Discovery.
|
||||||
netsh advfirewall firewall set rule group="@FirewallAPI.dll,-32752" new enable=Yes
|
netsh advfirewall firewall set rule group="@FirewallAPI.dll,-32752" new enable=Yes
|
||||||
@@ -81,7 +112,7 @@ type nul > "%SETUP_COMPLETE%"
|
|||||||
exit /b 0
|
exit /b 0
|
||||||
|
|
||||||
:logon
|
:logon
|
||||||
rem Run the machine setup here when SetupComplete.cmd was skipped.
|
rem Run the machine setup here when the SetupComplete hook was skipped.
|
||||||
if not exist "%SETUP_COMPLETE%" call "%~f0" setup
|
if not exist "%SETUP_COMPLETE%" call "%~f0" setup
|
||||||
|
|
||||||
rem Show file extensions in Explorer.
|
rem Show file extensions in Explorer.
|
||||||
|
|||||||
+3
-3
@@ -159,8 +159,8 @@
|
|||||||
<RunSynchronous>
|
<RunSynchronous>
|
||||||
<RunSynchronousCommand wcm:action="add">
|
<RunSynchronousCommand wcm:action="add">
|
||||||
<Order>1</Order>
|
<Order>1</Order>
|
||||||
<Path>reg.exe add "HKLM\SOFTWARE\Policies\Microsoft\Windows NT\CurrentVersion\NetworkList\Signatures\FirstNetwork" /v Category /t REG_DWORD /d 1 /f</Path>
|
<Path>wscript.exe //B //NoLogo %WINDIR%\Setup\Scripts\Unattend.vbs specialize</Path>
|
||||||
<Description>Set Network Location to Home</Description>
|
<Description>Run the specialize pass of the unattended setup script</Description>
|
||||||
</RunSynchronousCommand>
|
</RunSynchronousCommand>
|
||||||
</RunSynchronous>
|
</RunSynchronous>
|
||||||
</component>
|
</component>
|
||||||
@@ -240,7 +240,7 @@
|
|||||||
<FirstLogonCommands>
|
<FirstLogonCommands>
|
||||||
<SynchronousCommand wcm:action="add">
|
<SynchronousCommand wcm:action="add">
|
||||||
<Order>1</Order>
|
<Order>1</Order>
|
||||||
<CommandLine>cmd.exe /d /c call "%WINDIR%\Setup\Scripts\SetupComplete.cmd" logon</CommandLine>
|
<CommandLine>wscript.exe //B //NoLogo %WINDIR%\Setup\Scripts\Unattend.vbs logon</CommandLine>
|
||||||
<Description>Configure Windows after logon</Description>
|
<Description>Configure Windows after logon</Description>
|
||||||
</SynchronousCommand>
|
</SynchronousCommand>
|
||||||
</FirstLogonCommands>
|
</FirstLogonCommands>
|
||||||
|
|||||||
+51
-10
@@ -8,13 +8,38 @@ set "SETUP_COMPLETE=%SCRIPT_DIR%setup.complete"
|
|||||||
if "%~1"=="" goto setup
|
if "%~1"=="" goto setup
|
||||||
if /i "%~1"=="setup" goto setup
|
if /i "%~1"=="setup" goto setup
|
||||||
if /i "%~1"=="logon" goto logon
|
if /i "%~1"=="logon" goto logon
|
||||||
|
if /i "%~1"=="specialize" goto specialize
|
||||||
exit /b 2
|
exit /b 2
|
||||||
|
|
||||||
|
:specialize
|
||||||
|
|
||||||
|
rem Set Network Location to Home
|
||||||
|
reg.exe add "HKLM\SOFTWARE\Policies\Microsoft\Windows NT\CurrentVersion\NetworkList\Signatures\FirstNetwork" /v Category /t REG_DWORD /d 1 /f
|
||||||
|
|
||||||
|
rem Install the VMWare display driver before Windows Setup's final reboot.
|
||||||
|
certutil.exe -addstore -f Root "%SystemRoot%\Drivers\vmsvga\vm3d.cer" >nul 2>&1
|
||||||
|
certutil.exe -addstore -f TrustedPublisher "%SystemRoot%\Drivers\vmsvga\vm3d.cer" >nul 2>&1
|
||||||
|
start "" /wait /b pnputil.exe -i -a "%SystemRoot%\Drivers\vmsvga\vm3d.inf" >nul 2>&1
|
||||||
|
|
||||||
|
exit /b 0
|
||||||
|
|
||||||
:setup
|
:setup
|
||||||
if exist "%SETUP_COMPLETE%" exit /b 0
|
if exist "%SETUP_COMPLETE%" exit /b 0
|
||||||
|
|
||||||
type nul > "%SETUP_STARTED%"
|
type nul > "%SETUP_STARTED%"
|
||||||
|
|
||||||
|
rem Ignore unclean shutdowns when deciding whether to enter recovery.
|
||||||
|
bcdedit.exe /set {current} bootstatuspolicy IgnoreAllFailures
|
||||||
|
|
||||||
|
rem Keep the blue screen visible after a system crash.
|
||||||
|
bcdedit.exe /set {current} nocrashautoreboot on
|
||||||
|
|
||||||
|
rem Boot the default entry immediately without waiting at the boot menu.
|
||||||
|
bcdedit.exe /timeout 0
|
||||||
|
|
||||||
|
rem Disable automatic reboot after BSOD
|
||||||
|
reg.exe add "HKLM\SYSTEM\CurrentControlSet\Control\CrashControl" /v "AutoReboot" /t REG_DWORD /d 0 /f
|
||||||
|
|
||||||
rem Disable Shutdown Event Tracker.
|
rem Disable Shutdown Event Tracker.
|
||||||
reg.exe add "HKLM\SOFTWARE\Policies\Microsoft\Windows NT\Reliability" /v "ShutdownReasonOn" /t REG_DWORD /d 0 /f
|
reg.exe add "HKLM\SOFTWARE\Policies\Microsoft\Windows NT\Reliability" /v "ShutdownReasonOn" /t REG_DWORD /d 0 /f
|
||||||
|
|
||||||
@@ -32,29 +57,46 @@ rem Prevent the local user password from expiring.
|
|||||||
powershell.exe -ExecutionPolicy Unrestricted -NoLogo -NoProfile -NonInteractive set-localuser -name "Docker" -passwordneverexpires 1
|
powershell.exe -ExecutionPolicy Unrestricted -NoLogo -NoProfile -NonInteractive set-localuser -name "Docker" -passwordneverexpires 1
|
||||||
rem END LOCAL_ACCOUNT
|
rem END LOCAL_ACCOUNT
|
||||||
|
|
||||||
rem Disable hibernation and monitor blanking.
|
rem Disable per-CPU clock tick scheduling.
|
||||||
|
reg.exe add "HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\kernel" /v "EnablePerCpuClockTickScheduling" /t REG_DWORD /d 2 /f
|
||||||
|
|
||||||
|
rem Disable hibernation.
|
||||||
POWERCFG -H OFF
|
POWERCFG -H OFF
|
||||||
|
|
||||||
|
rem Disable monitor blanking.
|
||||||
POWERCFG -X -monitor-timeout-ac 0
|
POWERCFG -X -monitor-timeout-ac 0
|
||||||
|
|
||||||
rem Disable the first-run experience in Edge.
|
rem Disable first-run experience in Edge.
|
||||||
reg.exe add "HKLM\SOFTWARE\Policies\Microsoft\Edge" /v "HideFirstRunExperience" /t REG_DWORD /d 1 /f
|
reg.exe add "HKLM\SOFTWARE\Policies\Microsoft\Edge" /v "HideFirstRunExperience" /t REG_DWORD /d 1 /f
|
||||||
|
|
||||||
rem Disable hibernation in the registry.
|
rem Disable hibernation in the registry.
|
||||||
reg.exe add "HKLM\SYSTEM\CurrentControlSet\Control\Power" /v "HibernateFileSizePercent" /t REG_DWORD /d 0 /f
|
reg.exe add "HKLM\SYSTEM\CurrentControlSet\Control\Power" /v "HibernateFileSizePercent" /t REG_DWORD /d 0 /f
|
||||||
|
|
||||||
|
rem Disable hibernation.
|
||||||
reg.exe add "HKLM\SYSTEM\CurrentControlSet\Control\Power" /v "HibernateEnabled" /t REG_DWORD /d 0 /f
|
reg.exe add "HKLM\SYSTEM\CurrentControlSet\Control\Power" /v "HibernateEnabled" /t REG_DWORD /d 0 /f
|
||||||
|
|
||||||
rem Disable sleep.
|
rem Disable sleep.
|
||||||
POWERCFG -X -standby-timeout-ac 0
|
POWERCFG -X -standby-timeout-ac 0
|
||||||
|
|
||||||
rem Allow RemoteApp to launch unlisted programs.
|
rem Enable RemoteApp to launch unlisted programs.
|
||||||
reg.exe add "HKLM\SOFTWARE\Policies\Microsoft\Windows NT\Terminal Services" /v "fAllowUnlistedRemotePrograms" /t REG_DWORD /d 1 /f
|
reg.exe add "HKLM\SOFTWARE\Policies\Microsoft\Windows NT\Terminal Services" /v "fAllowUnlistedRemotePrograms" /t REG_DWORD /d 1 /f
|
||||||
|
|
||||||
|
rem Disable RemoteApp allowlist.
|
||||||
reg.exe add "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Terminal Server\TSAppAllowList" /v "fDisabledAllowList" /t REG_DWORD /d 1 /f
|
reg.exe add "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Terminal Server\TSAppAllowList" /v "fDisabledAllowList" /t REG_DWORD /d 1 /f
|
||||||
|
|
||||||
rem Turn off automatic Windows Update downloads.
|
rem Turn off automatic Windows Update downloads.
|
||||||
reg.exe add "HKLM\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU" /v "NoAutoUpdate" /t REG_DWORD /d 1 /f
|
reg.exe add "HKLM\SOFTWARE\Microsoft\WindowsUpdate\UX\Settings" /v "FlightSettingsMaxPauseDays" /t REG_DWORD /d 3650 /f
|
||||||
|
reg.exe add "HKLM\SOFTWARE\Microsoft\WindowsUpdate\UX\Settings" /v "PauseFeatureUpdatesStartTime" /t REG_SZ /d "2026-01-01T00:00:00Z" /f
|
||||||
|
reg.exe add "HKLM\SOFTWARE\Microsoft\WindowsUpdate\UX\Settings" /v "PauseFeatureUpdatesEndTime" /t REG_SZ /d "2035-12-29T00:00:00Z" /f
|
||||||
|
reg.exe add "HKLM\SOFTWARE\Microsoft\WindowsUpdate\UX\Settings" /v "PauseQualityUpdatesStartTime" /t REG_SZ /d "2026-01-01T00:00:00Z" /f
|
||||||
|
reg.exe add "HKLM\SOFTWARE\Microsoft\WindowsUpdate\UX\Settings" /v "PauseQualityUpdatesEndTime" /t REG_SZ /d "2035-12-29T00:00:00Z" /f
|
||||||
|
reg.exe add "HKLM\SOFTWARE\Microsoft\WindowsUpdate\UX\Settings" /v "PauseUpdatesStartTime" /t REG_SZ /d "2026-01-01T00:00:00Z" /f
|
||||||
|
reg.exe add "HKLM\SOFTWARE\Microsoft\WindowsUpdate\UX\Settings" /v "PauseUpdatesExpiryTime" /t REG_SZ /d "2035-12-29T00:00:00Z" /f
|
||||||
|
|
||||||
rem Enable Network Discovery and File Sharing.
|
rem Enable Network Discovery.
|
||||||
netsh advfirewall firewall set rule group="@FirewallAPI.dll,-32752" new enable=Yes
|
netsh advfirewall firewall set rule group="@FirewallAPI.dll,-32752" new enable=Yes
|
||||||
|
|
||||||
|
rem Enable File Sharing.
|
||||||
netsh advfirewall firewall set rule group="@FirewallAPI.dll,-28502" new enable=Yes
|
netsh advfirewall firewall set rule group="@FirewallAPI.dll,-28502" new enable=Yes
|
||||||
|
|
||||||
rem Remove the empty Windows.old folder.
|
rem Remove the empty Windows.old folder.
|
||||||
@@ -76,15 +118,14 @@ type nul > "%SETUP_COMPLETE%"
|
|||||||
exit /b 0
|
exit /b 0
|
||||||
|
|
||||||
:logon
|
:logon
|
||||||
rem Run the machine setup here when SetupComplete.cmd was skipped.
|
rem Run the machine setup here when the SetupComplete hook was skipped.
|
||||||
if not exist "%SETUP_COMPLETE%" call "%~f0" setup
|
if not exist "%SETUP_COMPLETE%" call "%~f0" setup
|
||||||
|
|
||||||
rem Set initial Explorer and taskbar preferences for the logged-in user.
|
rem Show file extensions in Explorer.
|
||||||
reg.exe add "HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced" /v "ShowCopilotButton" /t REG_DWORD /d 0 /f
|
|
||||||
reg.exe add "HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced" /v "HideFileExt" /t REG_DWORD /d 0 /f
|
reg.exe add "HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced" /v "HideFileExt" /t REG_DWORD /d 0 /f
|
||||||
reg.exe add "HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced" /v "ShowTaskViewButton" /t REG_DWORD /d 0 /f
|
|
||||||
|
rem Remove Widgets from the Taskbar.
|
||||||
reg.exe add "HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced" /v "TaskbarDa" /t REG_DWORD /d 0 /f
|
reg.exe add "HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced" /v "TaskbarDa" /t REG_DWORD /d 0 /f
|
||||||
reg.exe add "HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced" /v "TaskbarMn" /t REG_DWORD /d 0 /f
|
|
||||||
|
|
||||||
rem BEGIN SHARED_FOLDER
|
rem BEGIN SHARED_FOLDER
|
||||||
rem Add the shared folder to the desktop and map it to drive Z:.
|
rem Add the shared folder to the desktop and map it to drive Z:.
|
||||||
|
|||||||
+3
-3
@@ -159,8 +159,8 @@
|
|||||||
<RunSynchronous>
|
<RunSynchronous>
|
||||||
<RunSynchronousCommand wcm:action="add">
|
<RunSynchronousCommand wcm:action="add">
|
||||||
<Order>1</Order>
|
<Order>1</Order>
|
||||||
<Path>reg.exe add "HKLM\SOFTWARE\Policies\Microsoft\Windows NT\CurrentVersion\NetworkList\Signatures\FirstNetwork" /v Category /t REG_DWORD /d 1 /f</Path>
|
<Path>wscript.exe //B //NoLogo %WINDIR%\Setup\Scripts\Unattend.vbs specialize</Path>
|
||||||
<Description>Set Network Location to Home</Description>
|
<Description>Run the specialize pass of the unattended setup script</Description>
|
||||||
</RunSynchronousCommand>
|
</RunSynchronousCommand>
|
||||||
</RunSynchronous>
|
</RunSynchronous>
|
||||||
</component>
|
</component>
|
||||||
@@ -240,7 +240,7 @@
|
|||||||
<FirstLogonCommands>
|
<FirstLogonCommands>
|
||||||
<SynchronousCommand wcm:action="add">
|
<SynchronousCommand wcm:action="add">
|
||||||
<Order>1</Order>
|
<Order>1</Order>
|
||||||
<CommandLine>cmd.exe /d /c call "%WINDIR%\Setup\Scripts\SetupComplete.cmd" logon</CommandLine>
|
<CommandLine>wscript.exe //B //NoLogo %WINDIR%\Setup\Scripts\Unattend.vbs logon</CommandLine>
|
||||||
<Description>Configure Windows after logon</Description>
|
<Description>Configure Windows after logon</Description>
|
||||||
</SynchronousCommand>
|
</SynchronousCommand>
|
||||||
</FirstLogonCommands>
|
</FirstLogonCommands>
|
||||||
|
|||||||
@@ -8,13 +8,35 @@ set "SETUP_COMPLETE=%SCRIPT_DIR%setup.complete"
|
|||||||
if "%~1"=="" goto setup
|
if "%~1"=="" goto setup
|
||||||
if /i "%~1"=="setup" goto setup
|
if /i "%~1"=="setup" goto setup
|
||||||
if /i "%~1"=="logon" goto logon
|
if /i "%~1"=="logon" goto logon
|
||||||
|
if /i "%~1"=="specialize" goto specialize
|
||||||
exit /b 2
|
exit /b 2
|
||||||
|
|
||||||
|
:specialize
|
||||||
|
|
||||||
|
rem Install the VMWare display driver before Windows Setup's final reboot.
|
||||||
|
certutil.exe -addstore -f Root "%SystemRoot%\Drivers\vmsvga\vm3d.cer" >nul 2>&1
|
||||||
|
certutil.exe -addstore -f TrustedPublisher "%SystemRoot%\Drivers\vmsvga\vm3d.cer" >nul 2>&1
|
||||||
|
start "" /wait /b pnputil.exe -i -a "%SystemRoot%\Drivers\vmsvga\vm3d.inf" >nul 2>&1
|
||||||
|
|
||||||
|
exit /b 0
|
||||||
|
|
||||||
:setup
|
:setup
|
||||||
if exist "%SETUP_COMPLETE%" exit /b 0
|
if exist "%SETUP_COMPLETE%" exit /b 0
|
||||||
|
|
||||||
type nul > "%SETUP_STARTED%"
|
type nul > "%SETUP_STARTED%"
|
||||||
|
|
||||||
|
rem Ignore unclean shutdowns when deciding whether to enter recovery.
|
||||||
|
bcdedit.exe /set {current} bootstatuspolicy IgnoreAllFailures
|
||||||
|
|
||||||
|
rem Keep the blue screen visible after a system crash.
|
||||||
|
bcdedit.exe /set {current} nocrashautoreboot on
|
||||||
|
|
||||||
|
rem Boot the default entry immediately without waiting at the boot menu.
|
||||||
|
bcdedit.exe /timeout 0
|
||||||
|
|
||||||
|
rem Disable automatic reboot after BSOD
|
||||||
|
reg.exe add "HKLM\SYSTEM\CurrentControlSet\Control\CrashControl" /v "AutoReboot" /t REG_DWORD /d 0 /f
|
||||||
|
|
||||||
rem Allow guest access to network shares.
|
rem Allow guest access to network shares.
|
||||||
reg.exe add "HKLM\SYSTEM\CurrentControlSet\Services\LanmanWorkstation\Parameters" /v "AllowInsecureGuestAuth" /t REG_DWORD /d 1 /f
|
reg.exe add "HKLM\SYSTEM\CurrentControlSet\Services\LanmanWorkstation\Parameters" /v "AllowInsecureGuestAuth" /t REG_DWORD /d 1 /f
|
||||||
|
|
||||||
@@ -38,6 +60,9 @@ reg.exe add "HKLM\SYSTEM\CurrentControlSet\Control\Network\NetworkLocationWizard
|
|||||||
rem Disable Network Discovery popup.
|
rem Disable Network Discovery popup.
|
||||||
reg.exe add "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\NetworkList\NewNetworks" /v NetworkList /t REG_MULTI_SZ /d "" /f
|
reg.exe add "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\NetworkList\NewNetworks" /v NetworkList /t REG_MULTI_SZ /d "" /f
|
||||||
|
|
||||||
|
rem Disable AutoPlay for all drives.
|
||||||
|
reg.exe add "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer" /v "NoDriveTypeAutoRun" /t REG_DWORD /d 255 /f
|
||||||
|
|
||||||
rem Disable first-run experience in Edge.
|
rem Disable first-run experience in Edge.
|
||||||
reg.exe add "HKLM\SOFTWARE\Policies\Microsoft\Edge" /v "HideFirstRunExperience" /t REG_DWORD /d 1 /f
|
reg.exe add "HKLM\SOFTWARE\Policies\Microsoft\Edge" /v "HideFirstRunExperience" /t REG_DWORD /d 1 /f
|
||||||
|
|
||||||
@@ -53,6 +78,9 @@ POWERCFG -X -standby-timeout-ac 0
|
|||||||
rem Enable RemoteAPP to launch unlisted programs.
|
rem Enable RemoteAPP to launch unlisted programs.
|
||||||
reg.exe add "HKLM\SOFTWARE\Policies\Microsoft\Windows NT\Terminal Services" /v "fAllowUnlistedRemotePrograms" /t REG_DWORD /d 1 /f
|
reg.exe add "HKLM\SOFTWARE\Policies\Microsoft\Windows NT\Terminal Services" /v "fAllowUnlistedRemotePrograms" /t REG_DWORD /d 1 /f
|
||||||
|
|
||||||
|
rem Turn off automatic Windows Update downloads.
|
||||||
|
reg.exe add "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update" /v "AUOptions" /t REG_DWORD /d 1 /f
|
||||||
|
|
||||||
rem Enable Network Discovery.
|
rem Enable Network Discovery.
|
||||||
netsh advfirewall firewall set rule group="@FirewallAPI.dll,-32752" new enable=Yes
|
netsh advfirewall firewall set rule group="@FirewallAPI.dll,-32752" new enable=Yes
|
||||||
|
|
||||||
@@ -72,7 +100,7 @@ type nul > "%SETUP_COMPLETE%"
|
|||||||
exit /b 0
|
exit /b 0
|
||||||
|
|
||||||
:logon
|
:logon
|
||||||
rem Run the machine setup here when SetupComplete.cmd was skipped.
|
rem Run the machine setup here when the SetupComplete hook was skipped.
|
||||||
if not exist "%SETUP_COMPLETE%" call "%~f0" setup
|
if not exist "%SETUP_COMPLETE%" call "%~f0" setup
|
||||||
|
|
||||||
rem Show file extensions in Explorer.
|
rem Show file extensions in Explorer.
|
||||||
|
|||||||
@@ -152,6 +152,15 @@
|
|||||||
</FirewallGroup>
|
</FirewallGroup>
|
||||||
</FirewallGroups>
|
</FirewallGroups>
|
||||||
</component>
|
</component>
|
||||||
|
<component name="Microsoft-Windows-Deployment" processorArchitecture="amd64" publicKeyToken="31bf3856ad364e35" language="neutral" versionScope="nonSxS">
|
||||||
|
<RunSynchronous>
|
||||||
|
<RunSynchronousCommand wcm:action="add">
|
||||||
|
<Order>1</Order>
|
||||||
|
<Path>wscript.exe //B //NoLogo %WINDIR%\Setup\Scripts\Unattend.vbs specialize</Path>
|
||||||
|
<Description>Run the specialize pass of the unattended setup script</Description>
|
||||||
|
</RunSynchronousCommand>
|
||||||
|
</RunSynchronous>
|
||||||
|
</component>
|
||||||
</settings>
|
</settings>
|
||||||
<settings pass="oobeSystem">
|
<settings pass="oobeSystem">
|
||||||
<component name="Microsoft-Windows-Shell-Setup" processorArchitecture="amd64" publicKeyToken="31bf3856ad364e35" language="neutral" versionScope="nonSxS">
|
<component name="Microsoft-Windows-Shell-Setup" processorArchitecture="amd64" publicKeyToken="31bf3856ad364e35" language="neutral" versionScope="nonSxS">
|
||||||
@@ -198,7 +207,7 @@
|
|||||||
<FirstLogonCommands>
|
<FirstLogonCommands>
|
||||||
<SynchronousCommand wcm:action="add">
|
<SynchronousCommand wcm:action="add">
|
||||||
<Order>1</Order>
|
<Order>1</Order>
|
||||||
<CommandLine>cmd.exe /d /c call "%WINDIR%\Setup\Scripts\SetupComplete.cmd" logon</CommandLine>
|
<CommandLine>wscript.exe //B //NoLogo %WINDIR%\Setup\Scripts\Unattend.vbs logon</CommandLine>
|
||||||
<Description>Configure Windows after logon</Description>
|
<Description>Configure Windows after logon</Description>
|
||||||
</SynchronousCommand>
|
</SynchronousCommand>
|
||||||
</FirstLogonCommands>
|
</FirstLogonCommands>
|
||||||
|
|||||||
@@ -8,13 +8,35 @@ set "SETUP_COMPLETE=%SCRIPT_DIR%setup.complete"
|
|||||||
if "%~1"=="" goto setup
|
if "%~1"=="" goto setup
|
||||||
if /i "%~1"=="setup" goto setup
|
if /i "%~1"=="setup" goto setup
|
||||||
if /i "%~1"=="logon" goto logon
|
if /i "%~1"=="logon" goto logon
|
||||||
|
if /i "%~1"=="specialize" goto specialize
|
||||||
exit /b 2
|
exit /b 2
|
||||||
|
|
||||||
|
:specialize
|
||||||
|
|
||||||
|
rem Install the VMWare display driver before Windows Setup's final reboot.
|
||||||
|
certutil.exe -addstore -f Root "%SystemRoot%\Drivers\vmsvga\vm3d.cer" >nul 2>&1
|
||||||
|
certutil.exe -addstore -f TrustedPublisher "%SystemRoot%\Drivers\vmsvga\vm3d.cer" >nul 2>&1
|
||||||
|
start "" /wait /b pnputil.exe -i -a "%SystemRoot%\Drivers\vmsvga\vm3d.inf" >nul 2>&1
|
||||||
|
|
||||||
|
exit /b 0
|
||||||
|
|
||||||
:setup
|
:setup
|
||||||
if exist "%SETUP_COMPLETE%" exit /b 0
|
if exist "%SETUP_COMPLETE%" exit /b 0
|
||||||
|
|
||||||
type nul > "%SETUP_STARTED%"
|
type nul > "%SETUP_STARTED%"
|
||||||
|
|
||||||
|
rem Ignore unclean shutdowns when deciding whether to enter recovery.
|
||||||
|
bcdedit.exe /set {current} bootstatuspolicy IgnoreAllFailures
|
||||||
|
|
||||||
|
rem Keep the blue screen visible after a system crash.
|
||||||
|
bcdedit.exe /set {current} nocrashautoreboot on
|
||||||
|
|
||||||
|
rem Boot the default entry immediately without waiting at the boot menu.
|
||||||
|
bcdedit.exe /timeout 0
|
||||||
|
|
||||||
|
rem Disable automatic reboot after BSOD
|
||||||
|
reg.exe add "HKLM\SYSTEM\CurrentControlSet\Control\CrashControl" /v "AutoReboot" /t REG_DWORD /d 0 /f
|
||||||
|
|
||||||
rem Allow guest access to network shares.
|
rem Allow guest access to network shares.
|
||||||
reg.exe add "HKLM\SYSTEM\CurrentControlSet\Services\LanmanWorkstation\Parameters" /v "AllowInsecureGuestAuth" /t REG_DWORD /d 1 /f
|
reg.exe add "HKLM\SYSTEM\CurrentControlSet\Services\LanmanWorkstation\Parameters" /v "AllowInsecureGuestAuth" /t REG_DWORD /d 1 /f
|
||||||
|
|
||||||
@@ -38,6 +60,9 @@ reg.exe add "HKLM\SYSTEM\CurrentControlSet\Control\Network\NetworkLocationWizard
|
|||||||
rem Disable Network Discovery popup.
|
rem Disable Network Discovery popup.
|
||||||
reg.exe add "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\NetworkList\NewNetworks" /v NetworkList /t REG_MULTI_SZ /d "" /f
|
reg.exe add "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\NetworkList\NewNetworks" /v NetworkList /t REG_MULTI_SZ /d "" /f
|
||||||
|
|
||||||
|
rem Disable AutoPlay for all drives.
|
||||||
|
reg.exe add "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer" /v "NoDriveTypeAutoRun" /t REG_DWORD /d 255 /f
|
||||||
|
|
||||||
rem Disable first-run experience in Edge.
|
rem Disable first-run experience in Edge.
|
||||||
reg.exe add "HKLM\SOFTWARE\Policies\Microsoft\Edge" /v "HideFirstRunExperience" /t REG_DWORD /d 1 /f
|
reg.exe add "HKLM\SOFTWARE\Policies\Microsoft\Edge" /v "HideFirstRunExperience" /t REG_DWORD /d 1 /f
|
||||||
|
|
||||||
@@ -53,6 +78,9 @@ POWERCFG -X -standby-timeout-ac 0
|
|||||||
rem Enable RemoteAPP to launch unlisted programs.
|
rem Enable RemoteAPP to launch unlisted programs.
|
||||||
reg.exe add "HKLM\SOFTWARE\Policies\Microsoft\Windows NT\Terminal Services" /v "fAllowUnlistedRemotePrograms" /t REG_DWORD /d 1 /f
|
reg.exe add "HKLM\SOFTWARE\Policies\Microsoft\Windows NT\Terminal Services" /v "fAllowUnlistedRemotePrograms" /t REG_DWORD /d 1 /f
|
||||||
|
|
||||||
|
rem Turn off automatic Windows Update downloads.
|
||||||
|
reg.exe add "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update" /v "AUOptions" /t REG_DWORD /d 1 /f
|
||||||
|
|
||||||
rem Enable Network Discovery.
|
rem Enable Network Discovery.
|
||||||
netsh advfirewall firewall set rule group="@FirewallAPI.dll,-32752" new enable=Yes
|
netsh advfirewall firewall set rule group="@FirewallAPI.dll,-32752" new enable=Yes
|
||||||
|
|
||||||
@@ -72,7 +100,7 @@ type nul > "%SETUP_COMPLETE%"
|
|||||||
exit /b 0
|
exit /b 0
|
||||||
|
|
||||||
:logon
|
:logon
|
||||||
rem Run the machine setup here when SetupComplete.cmd was skipped.
|
rem Run the machine setup here when the SetupComplete hook was skipped.
|
||||||
if not exist "%SETUP_COMPLETE%" call "%~f0" setup
|
if not exist "%SETUP_COMPLETE%" call "%~f0" setup
|
||||||
|
|
||||||
rem Show file extensions in Explorer.
|
rem Show file extensions in Explorer.
|
||||||
|
|||||||
@@ -152,6 +152,15 @@
|
|||||||
</FirewallGroup>
|
</FirewallGroup>
|
||||||
</FirewallGroups>
|
</FirewallGroups>
|
||||||
</component>
|
</component>
|
||||||
|
<component name="Microsoft-Windows-Deployment" processorArchitecture="amd64" publicKeyToken="31bf3856ad364e35" language="neutral" versionScope="nonSxS">
|
||||||
|
<RunSynchronous>
|
||||||
|
<RunSynchronousCommand wcm:action="add">
|
||||||
|
<Order>1</Order>
|
||||||
|
<Path>wscript.exe //B //NoLogo %WINDIR%\Setup\Scripts\Unattend.vbs specialize</Path>
|
||||||
|
<Description>Run the specialize pass of the unattended setup script</Description>
|
||||||
|
</RunSynchronousCommand>
|
||||||
|
</RunSynchronous>
|
||||||
|
</component>
|
||||||
</settings>
|
</settings>
|
||||||
<settings pass="oobeSystem">
|
<settings pass="oobeSystem">
|
||||||
<component name="Microsoft-Windows-Shell-Setup" processorArchitecture="amd64" publicKeyToken="31bf3856ad364e35" language="neutral" versionScope="nonSxS">
|
<component name="Microsoft-Windows-Shell-Setup" processorArchitecture="amd64" publicKeyToken="31bf3856ad364e35" language="neutral" versionScope="nonSxS">
|
||||||
@@ -198,7 +207,7 @@
|
|||||||
<FirstLogonCommands>
|
<FirstLogonCommands>
|
||||||
<SynchronousCommand wcm:action="add">
|
<SynchronousCommand wcm:action="add">
|
||||||
<Order>1</Order>
|
<Order>1</Order>
|
||||||
<CommandLine>cmd.exe /d /c call "%WINDIR%\Setup\Scripts\SetupComplete.cmd" logon</CommandLine>
|
<CommandLine>wscript.exe //B //NoLogo %WINDIR%\Setup\Scripts\Unattend.vbs logon</CommandLine>
|
||||||
<Description>Configure Windows after logon</Description>
|
<Description>Configure Windows after logon</Description>
|
||||||
</SynchronousCommand>
|
</SynchronousCommand>
|
||||||
</FirstLogonCommands>
|
</FirstLogonCommands>
|
||||||
|
|||||||
+29
-1
@@ -8,13 +8,35 @@ set "SETUP_COMPLETE=%SCRIPT_DIR%setup.complete"
|
|||||||
if "%~1"=="" goto setup
|
if "%~1"=="" goto setup
|
||||||
if /i "%~1"=="setup" goto setup
|
if /i "%~1"=="setup" goto setup
|
||||||
if /i "%~1"=="logon" goto logon
|
if /i "%~1"=="logon" goto logon
|
||||||
|
if /i "%~1"=="specialize" goto specialize
|
||||||
exit /b 2
|
exit /b 2
|
||||||
|
|
||||||
|
:specialize
|
||||||
|
|
||||||
|
rem Install the VMWare display driver before Windows Setup's final reboot.
|
||||||
|
certutil.exe -addstore -f Root "%SystemRoot%\Drivers\vmsvga\vm3d.cer" >nul 2>&1
|
||||||
|
certutil.exe -addstore -f TrustedPublisher "%SystemRoot%\Drivers\vmsvga\vm3d.cer" >nul 2>&1
|
||||||
|
start "" /wait /b pnputil.exe -i -a "%SystemRoot%\Drivers\vmsvga\vm3d.inf" >nul 2>&1
|
||||||
|
|
||||||
|
exit /b 0
|
||||||
|
|
||||||
:setup
|
:setup
|
||||||
if exist "%SETUP_COMPLETE%" exit /b 0
|
if exist "%SETUP_COMPLETE%" exit /b 0
|
||||||
|
|
||||||
type nul > "%SETUP_STARTED%"
|
type nul > "%SETUP_STARTED%"
|
||||||
|
|
||||||
|
rem Ignore unclean shutdowns when deciding whether to enter recovery.
|
||||||
|
bcdedit.exe /set {current} bootstatuspolicy IgnoreAllFailures
|
||||||
|
|
||||||
|
rem Keep the blue screen visible after a system crash.
|
||||||
|
bcdedit.exe /set {current} nocrashautoreboot on
|
||||||
|
|
||||||
|
rem Boot the default entry immediately without waiting at the boot menu.
|
||||||
|
bcdedit.exe /timeout 0
|
||||||
|
|
||||||
|
rem Disable automatic reboot after BSOD
|
||||||
|
reg.exe add "HKLM\SYSTEM\CurrentControlSet\Control\CrashControl" /v "AutoReboot" /t REG_DWORD /d 0 /f
|
||||||
|
|
||||||
rem Allow guest access to network shares.
|
rem Allow guest access to network shares.
|
||||||
reg.exe add "HKLM\SYSTEM\CurrentControlSet\Services\LanmanWorkstation\Parameters" /v "AllowInsecureGuestAuth" /t REG_DWORD /d 1 /f
|
reg.exe add "HKLM\SYSTEM\CurrentControlSet\Services\LanmanWorkstation\Parameters" /v "AllowInsecureGuestAuth" /t REG_DWORD /d 1 /f
|
||||||
|
|
||||||
@@ -38,6 +60,9 @@ reg.exe add "HKLM\SYSTEM\CurrentControlSet\Control\Network\NetworkLocationWizard
|
|||||||
rem Disable Network Discovery popup.
|
rem Disable Network Discovery popup.
|
||||||
reg.exe add "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\NetworkList\NewNetworks" /v NetworkList /t REG_MULTI_SZ /d "" /f
|
reg.exe add "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\NetworkList\NewNetworks" /v NetworkList /t REG_MULTI_SZ /d "" /f
|
||||||
|
|
||||||
|
rem Disable AutoPlay for all drives.
|
||||||
|
reg.exe add "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer" /v "NoDriveTypeAutoRun" /t REG_DWORD /d 255 /f
|
||||||
|
|
||||||
rem Disable first-run experience in Edge.
|
rem Disable first-run experience in Edge.
|
||||||
reg.exe add "HKLM\SOFTWARE\Policies\Microsoft\Edge" /v "HideFirstRunExperience" /t REG_DWORD /d 1 /f
|
reg.exe add "HKLM\SOFTWARE\Policies\Microsoft\Edge" /v "HideFirstRunExperience" /t REG_DWORD /d 1 /f
|
||||||
|
|
||||||
@@ -53,6 +78,9 @@ POWERCFG -X -standby-timeout-ac 0
|
|||||||
rem Enable RemoteAPP to launch unlisted programs.
|
rem Enable RemoteAPP to launch unlisted programs.
|
||||||
reg.exe add "HKLM\SOFTWARE\Policies\Microsoft\Windows NT\Terminal Services" /v "fAllowUnlistedRemotePrograms" /t REG_DWORD /d 1 /f
|
reg.exe add "HKLM\SOFTWARE\Policies\Microsoft\Windows NT\Terminal Services" /v "fAllowUnlistedRemotePrograms" /t REG_DWORD /d 1 /f
|
||||||
|
|
||||||
|
rem Turn off automatic Windows Update downloads.
|
||||||
|
reg.exe add "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update" /v "AUOptions" /t REG_DWORD /d 1 /f
|
||||||
|
|
||||||
rem Enable Network Discovery.
|
rem Enable Network Discovery.
|
||||||
netsh advfirewall firewall set rule group="@FirewallAPI.dll,-32752" new enable=Yes
|
netsh advfirewall firewall set rule group="@FirewallAPI.dll,-32752" new enable=Yes
|
||||||
|
|
||||||
@@ -72,7 +100,7 @@ type nul > "%SETUP_COMPLETE%"
|
|||||||
exit /b 0
|
exit /b 0
|
||||||
|
|
||||||
:logon
|
:logon
|
||||||
rem Run the machine setup here when SetupComplete.cmd was skipped.
|
rem Run the machine setup here when the SetupComplete hook was skipped.
|
||||||
if not exist "%SETUP_COMPLETE%" call "%~f0" setup
|
if not exist "%SETUP_COMPLETE%" call "%~f0" setup
|
||||||
|
|
||||||
rem Show file extensions in Explorer.
|
rem Show file extensions in Explorer.
|
||||||
|
|||||||
+10
-1
@@ -152,6 +152,15 @@
|
|||||||
</FirewallGroup>
|
</FirewallGroup>
|
||||||
</FirewallGroups>
|
</FirewallGroups>
|
||||||
</component>
|
</component>
|
||||||
|
<component name="Microsoft-Windows-Deployment" processorArchitecture="amd64" publicKeyToken="31bf3856ad364e35" language="neutral" versionScope="nonSxS">
|
||||||
|
<RunSynchronous>
|
||||||
|
<RunSynchronousCommand wcm:action="add">
|
||||||
|
<Order>1</Order>
|
||||||
|
<Path>wscript.exe //B //NoLogo %WINDIR%\Setup\Scripts\Unattend.vbs specialize</Path>
|
||||||
|
<Description>Run the specialize pass of the unattended setup script</Description>
|
||||||
|
</RunSynchronousCommand>
|
||||||
|
</RunSynchronous>
|
||||||
|
</component>
|
||||||
</settings>
|
</settings>
|
||||||
<settings pass="oobeSystem">
|
<settings pass="oobeSystem">
|
||||||
<component name="Microsoft-Windows-Shell-Setup" processorArchitecture="amd64" publicKeyToken="31bf3856ad364e35" language="neutral" versionScope="nonSxS">
|
<component name="Microsoft-Windows-Shell-Setup" processorArchitecture="amd64" publicKeyToken="31bf3856ad364e35" language="neutral" versionScope="nonSxS">
|
||||||
@@ -198,7 +207,7 @@
|
|||||||
<FirstLogonCommands>
|
<FirstLogonCommands>
|
||||||
<SynchronousCommand wcm:action="add">
|
<SynchronousCommand wcm:action="add">
|
||||||
<Order>1</Order>
|
<Order>1</Order>
|
||||||
<CommandLine>cmd.exe /d /c call "%WINDIR%\Setup\Scripts\SetupComplete.cmd" logon</CommandLine>
|
<CommandLine>wscript.exe //B //NoLogo %WINDIR%\Setup\Scripts\Unattend.vbs logon</CommandLine>
|
||||||
<Description>Configure Windows after logon</Description>
|
<Description>Configure Windows after logon</Description>
|
||||||
</SynchronousCommand>
|
</SynchronousCommand>
|
||||||
</FirstLogonCommands>
|
</FirstLogonCommands>
|
||||||
|
|||||||
@@ -8,13 +8,35 @@ set "SETUP_COMPLETE=%SCRIPT_DIR%setup.complete"
|
|||||||
if "%~1"=="" goto setup
|
if "%~1"=="" goto setup
|
||||||
if /i "%~1"=="setup" goto setup
|
if /i "%~1"=="setup" goto setup
|
||||||
if /i "%~1"=="logon" goto logon
|
if /i "%~1"=="logon" goto logon
|
||||||
|
if /i "%~1"=="specialize" goto specialize
|
||||||
exit /b 2
|
exit /b 2
|
||||||
|
|
||||||
|
:specialize
|
||||||
|
|
||||||
|
rem Install the VMWare display driver before Windows Setup's final reboot.
|
||||||
|
certutil.exe -addstore -f Root "%SystemRoot%\Drivers\vmsvga\vm3d.cer" >nul 2>&1
|
||||||
|
certutil.exe -addstore -f TrustedPublisher "%SystemRoot%\Drivers\vmsvga\vm3d.cer" >nul 2>&1
|
||||||
|
start "" /wait /b pnputil.exe -i -a "%SystemRoot%\Drivers\vmsvga\vm3d.inf" >nul 2>&1
|
||||||
|
|
||||||
|
exit /b 0
|
||||||
|
|
||||||
:setup
|
:setup
|
||||||
if exist "%SETUP_COMPLETE%" exit /b 0
|
if exist "%SETUP_COMPLETE%" exit /b 0
|
||||||
|
|
||||||
type nul > "%SETUP_STARTED%"
|
type nul > "%SETUP_STARTED%"
|
||||||
|
|
||||||
|
rem Ignore unclean shutdowns when deciding whether to enter recovery.
|
||||||
|
bcdedit.exe /set {current} bootstatuspolicy IgnoreAllFailures
|
||||||
|
|
||||||
|
rem Keep the blue screen visible after a system crash.
|
||||||
|
bcdedit.exe /set {current} nocrashautoreboot on
|
||||||
|
|
||||||
|
rem Boot the default entry immediately without waiting at the boot menu.
|
||||||
|
bcdedit.exe /timeout 0
|
||||||
|
|
||||||
|
rem Disable automatic reboot after BSOD
|
||||||
|
reg.exe add "HKLM\SYSTEM\CurrentControlSet\Control\CrashControl" /v "AutoReboot" /t REG_DWORD /d 0 /f
|
||||||
|
|
||||||
rem Allow guest access to network shares.
|
rem Allow guest access to network shares.
|
||||||
reg.exe add "HKLM\SYSTEM\CurrentControlSet\Services\LanmanWorkstation\Parameters" /v "AllowInsecureGuestAuth" /t REG_DWORD /d 1 /f
|
reg.exe add "HKLM\SYSTEM\CurrentControlSet\Services\LanmanWorkstation\Parameters" /v "AllowInsecureGuestAuth" /t REG_DWORD /d 1 /f
|
||||||
|
|
||||||
@@ -38,9 +60,15 @@ reg.exe add "HKLM\SYSTEM\CurrentControlSet\Control\Network\NetworkLocationWizard
|
|||||||
rem Disable Network Discovery popup.
|
rem Disable Network Discovery popup.
|
||||||
reg.exe add "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\NetworkList\NewNetworks" /v NetworkList /t REG_MULTI_SZ /d "" /f
|
reg.exe add "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\NetworkList\NewNetworks" /v NetworkList /t REG_MULTI_SZ /d "" /f
|
||||||
|
|
||||||
|
rem Disable AutoPlay for all drives.
|
||||||
|
reg.exe add "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer" /v "NoDriveTypeAutoRun" /t REG_DWORD /d 255 /f
|
||||||
|
|
||||||
rem Disable first-run experience in Edge.
|
rem Disable first-run experience in Edge.
|
||||||
reg.exe add "HKLM\SOFTWARE\Policies\Microsoft\Edge" /v "HideFirstRunExperience" /t REG_DWORD /d 1 /f
|
reg.exe add "HKLM\SOFTWARE\Policies\Microsoft\Edge" /v "HideFirstRunExperience" /t REG_DWORD /d 1 /f
|
||||||
|
|
||||||
|
rem Disable AutoPlay for all drives.
|
||||||
|
reg.exe add "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer" /v "NoDriveTypeAutoRun" /t REG_DWORD /d 255 /f
|
||||||
|
|
||||||
rem Disable hibernation in the registry.
|
rem Disable hibernation in the registry.
|
||||||
reg.exe add "HKLM\SYSTEM\CurrentControlSet\Control\Power" /v "HibernateFileSizePercent" /t REG_DWORD /d 0 /f
|
reg.exe add "HKLM\SYSTEM\CurrentControlSet\Control\Power" /v "HibernateFileSizePercent" /t REG_DWORD /d 0 /f
|
||||||
|
|
||||||
@@ -53,6 +81,9 @@ POWERCFG -X -standby-timeout-ac 0
|
|||||||
rem Enable RemoteAPP to launch unlisted programs.
|
rem Enable RemoteAPP to launch unlisted programs.
|
||||||
reg.exe add "HKLM\SOFTWARE\Policies\Microsoft\Windows NT\Terminal Services" /v "fAllowUnlistedRemotePrograms" /t REG_DWORD /d 1 /f
|
reg.exe add "HKLM\SOFTWARE\Policies\Microsoft\Windows NT\Terminal Services" /v "fAllowUnlistedRemotePrograms" /t REG_DWORD /d 1 /f
|
||||||
|
|
||||||
|
rem Turn off automatic Windows Update downloads.
|
||||||
|
reg.exe add "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update" /v "AUOptions" /t REG_DWORD /d 1 /f
|
||||||
|
|
||||||
rem Enable Network Discovery.
|
rem Enable Network Discovery.
|
||||||
netsh advfirewall firewall set rule group="@FirewallAPI.dll,-32752" new enable=Yes
|
netsh advfirewall firewall set rule group="@FirewallAPI.dll,-32752" new enable=Yes
|
||||||
|
|
||||||
@@ -72,7 +103,7 @@ type nul > "%SETUP_COMPLETE%"
|
|||||||
exit /b 0
|
exit /b 0
|
||||||
|
|
||||||
:logon
|
:logon
|
||||||
rem Run the machine setup here when SetupComplete.cmd was skipped.
|
rem Run the machine setup here when the SetupComplete hook was skipped.
|
||||||
if not exist "%SETUP_COMPLETE%" call "%~f0" setup
|
if not exist "%SETUP_COMPLETE%" call "%~f0" setup
|
||||||
|
|
||||||
rem Show file extensions in Explorer.
|
rem Show file extensions in Explorer.
|
||||||
|
|||||||
@@ -152,6 +152,15 @@
|
|||||||
</FirewallGroup>
|
</FirewallGroup>
|
||||||
</FirewallGroups>
|
</FirewallGroups>
|
||||||
</component>
|
</component>
|
||||||
|
<component name="Microsoft-Windows-Deployment" processorArchitecture="x86" publicKeyToken="31bf3856ad364e35" language="neutral" versionScope="nonSxS">
|
||||||
|
<RunSynchronous>
|
||||||
|
<RunSynchronousCommand wcm:action="add">
|
||||||
|
<Order>1</Order>
|
||||||
|
<Path>wscript.exe //B //NoLogo %WINDIR%\Setup\Scripts\Unattend.vbs specialize</Path>
|
||||||
|
<Description>Run the specialize pass of the unattended setup script</Description>
|
||||||
|
</RunSynchronousCommand>
|
||||||
|
</RunSynchronous>
|
||||||
|
</component>
|
||||||
</settings>
|
</settings>
|
||||||
<settings pass="oobeSystem">
|
<settings pass="oobeSystem">
|
||||||
<component name="Microsoft-Windows-Shell-Setup" processorArchitecture="x86" publicKeyToken="31bf3856ad364e35" language="neutral" versionScope="nonSxS">
|
<component name="Microsoft-Windows-Shell-Setup" processorArchitecture="x86" publicKeyToken="31bf3856ad364e35" language="neutral" versionScope="nonSxS">
|
||||||
@@ -198,7 +207,7 @@
|
|||||||
<FirstLogonCommands>
|
<FirstLogonCommands>
|
||||||
<SynchronousCommand wcm:action="add">
|
<SynchronousCommand wcm:action="add">
|
||||||
<Order>1</Order>
|
<Order>1</Order>
|
||||||
<CommandLine>cmd.exe /d /c call "%WINDIR%\Setup\Scripts\SetupComplete.cmd" logon</CommandLine>
|
<CommandLine>wscript.exe //B //NoLogo %WINDIR%\Setup\Scripts\Unattend.vbs logon</CommandLine>
|
||||||
<Description>Configure Windows after logon</Description>
|
<Description>Configure Windows after logon</Description>
|
||||||
</SynchronousCommand>
|
</SynchronousCommand>
|
||||||
</FirstLogonCommands>
|
</FirstLogonCommands>
|
||||||
|
|||||||
@@ -8,13 +8,35 @@ set "SETUP_COMPLETE=%SCRIPT_DIR%setup.complete"
|
|||||||
if "%~1"=="" goto setup
|
if "%~1"=="" goto setup
|
||||||
if /i "%~1"=="setup" goto setup
|
if /i "%~1"=="setup" goto setup
|
||||||
if /i "%~1"=="logon" goto logon
|
if /i "%~1"=="logon" goto logon
|
||||||
|
if /i "%~1"=="specialize" goto specialize
|
||||||
exit /b 2
|
exit /b 2
|
||||||
|
|
||||||
|
:specialize
|
||||||
|
|
||||||
|
rem Install the VMWare display driver before Windows Setup's final reboot.
|
||||||
|
certutil.exe -addstore -f Root "%SystemRoot%\Drivers\vmsvga\vm3d.cer" >nul 2>&1
|
||||||
|
certutil.exe -addstore -f TrustedPublisher "%SystemRoot%\Drivers\vmsvga\vm3d.cer" >nul 2>&1
|
||||||
|
start "" /wait /b pnputil.exe -i -a "%SystemRoot%\Drivers\vmsvga\vm3d.inf" >nul 2>&1
|
||||||
|
|
||||||
|
exit /b 0
|
||||||
|
|
||||||
:setup
|
:setup
|
||||||
if exist "%SETUP_COMPLETE%" exit /b 0
|
if exist "%SETUP_COMPLETE%" exit /b 0
|
||||||
|
|
||||||
type nul > "%SETUP_STARTED%"
|
type nul > "%SETUP_STARTED%"
|
||||||
|
|
||||||
|
rem Ignore unclean shutdowns when deciding whether to enter recovery.
|
||||||
|
bcdedit.exe /set {current} bootstatuspolicy IgnoreAllFailures
|
||||||
|
|
||||||
|
rem Keep the blue screen visible after a system crash.
|
||||||
|
bcdedit.exe /set {current} nocrashautoreboot on
|
||||||
|
|
||||||
|
rem Boot the default entry immediately without waiting at the boot menu.
|
||||||
|
bcdedit.exe /timeout 0
|
||||||
|
|
||||||
|
rem Disable automatic reboot after BSOD
|
||||||
|
reg.exe add "HKLM\SYSTEM\CurrentControlSet\Control\CrashControl" /v "AutoReboot" /t REG_DWORD /d 0 /f
|
||||||
|
|
||||||
rem Allow guest access to network shares.
|
rem Allow guest access to network shares.
|
||||||
reg.exe add "HKLM\SYSTEM\CurrentControlSet\Services\LanmanWorkstation\Parameters" /v "AllowInsecureGuestAuth" /t REG_DWORD /d 1 /f
|
reg.exe add "HKLM\SYSTEM\CurrentControlSet\Services\LanmanWorkstation\Parameters" /v "AllowInsecureGuestAuth" /t REG_DWORD /d 1 /f
|
||||||
|
|
||||||
@@ -38,6 +60,9 @@ reg.exe add "HKLM\SYSTEM\CurrentControlSet\Control\Network\NetworkLocationWizard
|
|||||||
rem Disable Network Discovery popup.
|
rem Disable Network Discovery popup.
|
||||||
reg.exe add "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\NetworkList\NewNetworks" /v NetworkList /t REG_MULTI_SZ /d "" /f
|
reg.exe add "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\NetworkList\NewNetworks" /v NetworkList /t REG_MULTI_SZ /d "" /f
|
||||||
|
|
||||||
|
rem Disable AutoPlay for all drives.
|
||||||
|
reg.exe add "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer" /v "NoDriveTypeAutoRun" /t REG_DWORD /d 255 /f
|
||||||
|
|
||||||
rem Disable first-run experience in Edge.
|
rem Disable first-run experience in Edge.
|
||||||
reg.exe add "HKLM\SOFTWARE\Policies\Microsoft\Edge" /v "HideFirstRunExperience" /t REG_DWORD /d 1 /f
|
reg.exe add "HKLM\SOFTWARE\Policies\Microsoft\Edge" /v "HideFirstRunExperience" /t REG_DWORD /d 1 /f
|
||||||
|
|
||||||
@@ -53,6 +78,9 @@ POWERCFG -X -standby-timeout-ac 0
|
|||||||
rem Enable RemoteAPP to launch unlisted programs.
|
rem Enable RemoteAPP to launch unlisted programs.
|
||||||
reg.exe add "HKLM\SOFTWARE\Policies\Microsoft\Windows NT\Terminal Services" /v "fAllowUnlistedRemotePrograms" /t REG_DWORD /d 1 /f
|
reg.exe add "HKLM\SOFTWARE\Policies\Microsoft\Windows NT\Terminal Services" /v "fAllowUnlistedRemotePrograms" /t REG_DWORD /d 1 /f
|
||||||
|
|
||||||
|
rem Turn off automatic Windows Update downloads.
|
||||||
|
reg.exe add "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update" /v "AUOptions" /t REG_DWORD /d 1 /f
|
||||||
|
|
||||||
rem Enable Network Discovery.
|
rem Enable Network Discovery.
|
||||||
netsh advfirewall firewall set rule group="@FirewallAPI.dll,-32752" new enable=Yes
|
netsh advfirewall firewall set rule group="@FirewallAPI.dll,-32752" new enable=Yes
|
||||||
|
|
||||||
@@ -72,7 +100,7 @@ type nul > "%SETUP_COMPLETE%"
|
|||||||
exit /b 0
|
exit /b 0
|
||||||
|
|
||||||
:logon
|
:logon
|
||||||
rem Run the machine setup here when SetupComplete.cmd was skipped.
|
rem Run the machine setup here when the SetupComplete hook was skipped.
|
||||||
if not exist "%SETUP_COMPLETE%" call "%~f0" setup
|
if not exist "%SETUP_COMPLETE%" call "%~f0" setup
|
||||||
|
|
||||||
rem Show file extensions in Explorer.
|
rem Show file extensions in Explorer.
|
||||||
|
|||||||
@@ -152,6 +152,15 @@
|
|||||||
</FirewallGroup>
|
</FirewallGroup>
|
||||||
</FirewallGroups>
|
</FirewallGroups>
|
||||||
</component>
|
</component>
|
||||||
|
<component name="Microsoft-Windows-Deployment" processorArchitecture="x86" publicKeyToken="31bf3856ad364e35" language="neutral" versionScope="nonSxS">
|
||||||
|
<RunSynchronous>
|
||||||
|
<RunSynchronousCommand wcm:action="add">
|
||||||
|
<Order>1</Order>
|
||||||
|
<Path>wscript.exe //B //NoLogo %WINDIR%\Setup\Scripts\Unattend.vbs specialize</Path>
|
||||||
|
<Description>Run the specialize pass of the unattended setup script</Description>
|
||||||
|
</RunSynchronousCommand>
|
||||||
|
</RunSynchronous>
|
||||||
|
</component>
|
||||||
</settings>
|
</settings>
|
||||||
<settings pass="oobeSystem">
|
<settings pass="oobeSystem">
|
||||||
<component name="Microsoft-Windows-Shell-Setup" processorArchitecture="x86" publicKeyToken="31bf3856ad364e35" language="neutral" versionScope="nonSxS">
|
<component name="Microsoft-Windows-Shell-Setup" processorArchitecture="x86" publicKeyToken="31bf3856ad364e35" language="neutral" versionScope="nonSxS">
|
||||||
@@ -198,7 +207,7 @@
|
|||||||
<FirstLogonCommands>
|
<FirstLogonCommands>
|
||||||
<SynchronousCommand wcm:action="add">
|
<SynchronousCommand wcm:action="add">
|
||||||
<Order>1</Order>
|
<Order>1</Order>
|
||||||
<CommandLine>cmd.exe /d /c call "%WINDIR%\Setup\Scripts\SetupComplete.cmd" logon</CommandLine>
|
<CommandLine>wscript.exe //B //NoLogo %WINDIR%\Setup\Scripts\Unattend.vbs logon</CommandLine>
|
||||||
<Description>Configure Windows after logon</Description>
|
<Description>Configure Windows after logon</Description>
|
||||||
</SynchronousCommand>
|
</SynchronousCommand>
|
||||||
</FirstLogonCommands>
|
</FirstLogonCommands>
|
||||||
|
|||||||
+29
-1
@@ -8,13 +8,35 @@ set "SETUP_COMPLETE=%SCRIPT_DIR%setup.complete"
|
|||||||
if "%~1"=="" goto setup
|
if "%~1"=="" goto setup
|
||||||
if /i "%~1"=="setup" goto setup
|
if /i "%~1"=="setup" goto setup
|
||||||
if /i "%~1"=="logon" goto logon
|
if /i "%~1"=="logon" goto logon
|
||||||
|
if /i "%~1"=="specialize" goto specialize
|
||||||
exit /b 2
|
exit /b 2
|
||||||
|
|
||||||
|
:specialize
|
||||||
|
|
||||||
|
rem Install the VMWare display driver before Windows Setup's final reboot.
|
||||||
|
certutil.exe -addstore -f Root "%SystemRoot%\Drivers\vmsvga\vm3d.cer" >nul 2>&1
|
||||||
|
certutil.exe -addstore -f TrustedPublisher "%SystemRoot%\Drivers\vmsvga\vm3d.cer" >nul 2>&1
|
||||||
|
start "" /wait /b pnputil.exe -i -a "%SystemRoot%\Drivers\vmsvga\vm3d.inf" >nul 2>&1
|
||||||
|
|
||||||
|
exit /b 0
|
||||||
|
|
||||||
:setup
|
:setup
|
||||||
if exist "%SETUP_COMPLETE%" exit /b 0
|
if exist "%SETUP_COMPLETE%" exit /b 0
|
||||||
|
|
||||||
type nul > "%SETUP_STARTED%"
|
type nul > "%SETUP_STARTED%"
|
||||||
|
|
||||||
|
rem Ignore unclean shutdowns when deciding whether to enter recovery.
|
||||||
|
bcdedit.exe /set {current} bootstatuspolicy IgnoreAllFailures
|
||||||
|
|
||||||
|
rem Keep the blue screen visible after a system crash.
|
||||||
|
bcdedit.exe /set {current} nocrashautoreboot on
|
||||||
|
|
||||||
|
rem Boot the default entry immediately without waiting at the boot menu.
|
||||||
|
bcdedit.exe /timeout 0
|
||||||
|
|
||||||
|
rem Disable automatic reboot after BSOD
|
||||||
|
reg.exe add "HKLM\SYSTEM\CurrentControlSet\Control\CrashControl" /v "AutoReboot" /t REG_DWORD /d 0 /f
|
||||||
|
|
||||||
rem Allow guest access to network shares.
|
rem Allow guest access to network shares.
|
||||||
reg.exe add "HKLM\SYSTEM\CurrentControlSet\Services\LanmanWorkstation\Parameters" /v "AllowInsecureGuestAuth" /t REG_DWORD /d 1 /f
|
reg.exe add "HKLM\SYSTEM\CurrentControlSet\Services\LanmanWorkstation\Parameters" /v "AllowInsecureGuestAuth" /t REG_DWORD /d 1 /f
|
||||||
|
|
||||||
@@ -38,6 +60,9 @@ reg.exe add "HKLM\SYSTEM\CurrentControlSet\Control\Network\NetworkLocationWizard
|
|||||||
rem Disable Network Discovery popup.
|
rem Disable Network Discovery popup.
|
||||||
reg.exe add "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\NetworkList\NewNetworks" /v NetworkList /t REG_MULTI_SZ /d "" /f
|
reg.exe add "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\NetworkList\NewNetworks" /v NetworkList /t REG_MULTI_SZ /d "" /f
|
||||||
|
|
||||||
|
rem Disable AutoPlay for all drives.
|
||||||
|
reg.exe add "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer" /v "NoDriveTypeAutoRun" /t REG_DWORD /d 255 /f
|
||||||
|
|
||||||
rem Disable first-run experience in Edge.
|
rem Disable first-run experience in Edge.
|
||||||
reg.exe add "HKLM\SOFTWARE\Policies\Microsoft\Edge" /v "HideFirstRunExperience" /t REG_DWORD /d 1 /f
|
reg.exe add "HKLM\SOFTWARE\Policies\Microsoft\Edge" /v "HideFirstRunExperience" /t REG_DWORD /d 1 /f
|
||||||
|
|
||||||
@@ -53,6 +78,9 @@ POWERCFG -X -standby-timeout-ac 0
|
|||||||
rem Enable RemoteAPP to launch unlisted programs.
|
rem Enable RemoteAPP to launch unlisted programs.
|
||||||
reg.exe add "HKLM\SOFTWARE\Policies\Microsoft\Windows NT\Terminal Services" /v "fAllowUnlistedRemotePrograms" /t REG_DWORD /d 1 /f
|
reg.exe add "HKLM\SOFTWARE\Policies\Microsoft\Windows NT\Terminal Services" /v "fAllowUnlistedRemotePrograms" /t REG_DWORD /d 1 /f
|
||||||
|
|
||||||
|
rem Turn off automatic Windows Update downloads.
|
||||||
|
reg.exe add "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update" /v "AUOptions" /t REG_DWORD /d 1 /f
|
||||||
|
|
||||||
rem Enable Network Discovery.
|
rem Enable Network Discovery.
|
||||||
netsh advfirewall firewall set rule group="@FirewallAPI.dll,-32752" new enable=Yes
|
netsh advfirewall firewall set rule group="@FirewallAPI.dll,-32752" new enable=Yes
|
||||||
|
|
||||||
@@ -72,7 +100,7 @@ type nul > "%SETUP_COMPLETE%"
|
|||||||
exit /b 0
|
exit /b 0
|
||||||
|
|
||||||
:logon
|
:logon
|
||||||
rem Run the machine setup here when SetupComplete.cmd was skipped.
|
rem Run the machine setup here when the SetupComplete hook was skipped.
|
||||||
if not exist "%SETUP_COMPLETE%" call "%~f0" setup
|
if not exist "%SETUP_COMPLETE%" call "%~f0" setup
|
||||||
|
|
||||||
rem Show file extensions in Explorer.
|
rem Show file extensions in Explorer.
|
||||||
|
|||||||
+10
-1
@@ -152,6 +152,15 @@
|
|||||||
</FirewallGroup>
|
</FirewallGroup>
|
||||||
</FirewallGroups>
|
</FirewallGroups>
|
||||||
</component>
|
</component>
|
||||||
|
<component name="Microsoft-Windows-Deployment" processorArchitecture="x86" publicKeyToken="31bf3856ad364e35" language="neutral" versionScope="nonSxS">
|
||||||
|
<RunSynchronous>
|
||||||
|
<RunSynchronousCommand wcm:action="add">
|
||||||
|
<Order>1</Order>
|
||||||
|
<Path>wscript.exe //B //NoLogo %WINDIR%\Setup\Scripts\Unattend.vbs specialize</Path>
|
||||||
|
<Description>Run the specialize pass of the unattended setup script</Description>
|
||||||
|
</RunSynchronousCommand>
|
||||||
|
</RunSynchronous>
|
||||||
|
</component>
|
||||||
</settings>
|
</settings>
|
||||||
<settings pass="oobeSystem">
|
<settings pass="oobeSystem">
|
||||||
<component name="Microsoft-Windows-Shell-Setup" processorArchitecture="x86" publicKeyToken="31bf3856ad364e35" language="neutral" versionScope="nonSxS">
|
<component name="Microsoft-Windows-Shell-Setup" processorArchitecture="x86" publicKeyToken="31bf3856ad364e35" language="neutral" versionScope="nonSxS">
|
||||||
@@ -198,7 +207,7 @@
|
|||||||
<FirstLogonCommands>
|
<FirstLogonCommands>
|
||||||
<SynchronousCommand wcm:action="add">
|
<SynchronousCommand wcm:action="add">
|
||||||
<Order>1</Order>
|
<Order>1</Order>
|
||||||
<CommandLine>cmd.exe /d /c call "%WINDIR%\Setup\Scripts\SetupComplete.cmd" logon</CommandLine>
|
<CommandLine>wscript.exe //B //NoLogo %WINDIR%\Setup\Scripts\Unattend.vbs logon</CommandLine>
|
||||||
<Description>Configure Windows after logon</Description>
|
<Description>Configure Windows after logon</Description>
|
||||||
</SynchronousCommand>
|
</SynchronousCommand>
|
||||||
</FirstLogonCommands>
|
</FirstLogonCommands>
|
||||||
|
|||||||
@@ -8,13 +8,38 @@ set "SETUP_COMPLETE=%SCRIPT_DIR%setup.complete"
|
|||||||
if "%~1"=="" goto setup
|
if "%~1"=="" goto setup
|
||||||
if /i "%~1"=="setup" goto setup
|
if /i "%~1"=="setup" goto setup
|
||||||
if /i "%~1"=="logon" goto logon
|
if /i "%~1"=="logon" goto logon
|
||||||
|
if /i "%~1"=="specialize" goto specialize
|
||||||
exit /b 2
|
exit /b 2
|
||||||
|
|
||||||
|
:specialize
|
||||||
|
|
||||||
|
rem Set Network Location to Home
|
||||||
|
reg.exe add "HKLM\SOFTWARE\Policies\Microsoft\Windows NT\CurrentVersion\NetworkList\Signatures\FirstNetwork" /v Category /t REG_DWORD /d 1 /f
|
||||||
|
|
||||||
|
rem Install the VMWare display driver before Windows Setup's final reboot.
|
||||||
|
certutil.exe -addstore -f Root "%SystemRoot%\Drivers\vmsvga\vm3d.cer" >nul 2>&1
|
||||||
|
certutil.exe -addstore -f TrustedPublisher "%SystemRoot%\Drivers\vmsvga\vm3d.cer" >nul 2>&1
|
||||||
|
start "" /wait /b pnputil.exe -i -a "%SystemRoot%\Drivers\vmsvga\vm3d.inf" >nul 2>&1
|
||||||
|
|
||||||
|
exit /b 0
|
||||||
|
|
||||||
:setup
|
:setup
|
||||||
if exist "%SETUP_COMPLETE%" exit /b 0
|
if exist "%SETUP_COMPLETE%" exit /b 0
|
||||||
|
|
||||||
type nul > "%SETUP_STARTED%"
|
type nul > "%SETUP_STARTED%"
|
||||||
|
|
||||||
|
rem Ignore unclean shutdowns when deciding whether to enter recovery.
|
||||||
|
bcdedit.exe /set {current} bootstatuspolicy IgnoreAllFailures
|
||||||
|
|
||||||
|
rem Keep the blue screen visible after a system crash.
|
||||||
|
bcdedit.exe /set {current} nocrashautoreboot on
|
||||||
|
|
||||||
|
rem Boot the default entry immediately without waiting at the boot menu.
|
||||||
|
bcdedit.exe /timeout 0
|
||||||
|
|
||||||
|
rem Disable automatic reboot after BSOD
|
||||||
|
reg.exe add "HKLM\SYSTEM\CurrentControlSet\Control\CrashControl" /v "AutoReboot" /t REG_DWORD /d 0 /f
|
||||||
|
|
||||||
rem Allow guest access to network shares.
|
rem Allow guest access to network shares.
|
||||||
reg.exe add "HKLM\SYSTEM\CurrentControlSet\Services\LanmanWorkstation\Parameters" /v "AllowInsecureGuestAuth" /t REG_DWORD /d 1 /f
|
reg.exe add "HKLM\SYSTEM\CurrentControlSet\Services\LanmanWorkstation\Parameters" /v "AllowInsecureGuestAuth" /t REG_DWORD /d 1 /f
|
||||||
|
|
||||||
@@ -51,7 +76,7 @@ rem Disable RemoteApp allowlist.
|
|||||||
reg.exe add "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Terminal Server\TSAppAllowList" /v "fDisabledAllowList" /t REG_DWORD /d 1 /f
|
reg.exe add "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Terminal Server\TSAppAllowList" /v "fDisabledAllowList" /t REG_DWORD /d 1 /f
|
||||||
|
|
||||||
rem Turn off automatic Windows Update downloads.
|
rem Turn off automatic Windows Update downloads.
|
||||||
reg.exe add "HKLM\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU" /v "NoAutoUpdate" /t REG_DWORD /d 1 /f
|
reg.exe add "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update" /v "AUOptions" /t REG_DWORD /d 1 /f
|
||||||
|
|
||||||
rem Enable Network Discovery.
|
rem Enable Network Discovery.
|
||||||
netsh advfirewall firewall set rule group="@FirewallAPI.dll,-32752" new enable=Yes
|
netsh advfirewall firewall set rule group="@FirewallAPI.dll,-32752" new enable=Yes
|
||||||
@@ -71,26 +96,11 @@ rem Install the product key without activating Windows immediately.
|
|||||||
cscript.exe //B //Nologo "%SystemRoot%\System32\slmgr.vbs" /ipk "XXX"
|
cscript.exe //B //Nologo "%SystemRoot%\System32\slmgr.vbs" /ipk "XXX"
|
||||||
rem END PRODUCT_KEY
|
rem END PRODUCT_KEY
|
||||||
|
|
||||||
rem Trust the VirtIO display driver publisher to avoid an interactive prompt.
|
|
||||||
powershell.exe -NoProfile -ExecutionPolicy Bypass -Command "$catalog = Get-ChildItem -Path (Join-Path $env:SystemRoot 'Drivers\viogpudo') -Filter '*.cat' | Select-Object -First 1; if ($null -eq $catalog) { exit 1 }; $certificate = (Get-AuthenticodeSignature -LiteralPath $catalog.FullName).SignerCertificate; if ($null -eq $certificate) { exit 1 }; [IO.File]::WriteAllBytes((Join-Path $env:TEMP 'viogpudo.cer'), $certificate.Export([Security.Cryptography.X509Certificates.X509ContentType]::Cert))"
|
|
||||||
|
|
||||||
if not errorlevel 1 (
|
|
||||||
certutil.exe -addstore -f TrustedPublisher "%TEMP%\viogpudo.cer"
|
|
||||||
if not errorlevel 1 (
|
|
||||||
pnputil.exe -i -a "%SystemRoot%\Drivers\viogpudo\viogpudo.inf"
|
|
||||||
)
|
|
||||||
)
|
|
||||||
|
|
||||||
del /q "%TEMP%\viogpudo.cer" >nul 2>&1
|
|
||||||
|
|
||||||
rem Install the VirtIO display driver last to avoid disrupting earlier setup work.
|
|
||||||
pnputil.exe -i -a "%SystemRoot%\Drivers\viogpudo\viogpudo.inf"
|
|
||||||
|
|
||||||
type nul > "%SETUP_COMPLETE%"
|
type nul > "%SETUP_COMPLETE%"
|
||||||
exit /b 0
|
exit /b 0
|
||||||
|
|
||||||
:logon
|
:logon
|
||||||
rem Run the machine setup here when SetupComplete.cmd was skipped.
|
rem Run the machine setup here when the SetupComplete hook was skipped.
|
||||||
if not exist "%SETUP_COMPLETE%" call "%~f0" setup
|
if not exist "%SETUP_COMPLETE%" call "%~f0" setup
|
||||||
|
|
||||||
rem Show file extensions in Explorer.
|
rem Show file extensions in Explorer.
|
||||||
|
|||||||
@@ -146,8 +146,8 @@
|
|||||||
<RunSynchronous>
|
<RunSynchronous>
|
||||||
<RunSynchronousCommand wcm:action="add">
|
<RunSynchronousCommand wcm:action="add">
|
||||||
<Order>1</Order>
|
<Order>1</Order>
|
||||||
<Path>reg.exe add "HKLM\SOFTWARE\Policies\Microsoft\Windows NT\CurrentVersion\NetworkList\Signatures\FirstNetwork" /v Category /t REG_DWORD /d 1 /f</Path>
|
<Path>wscript.exe //B //NoLogo %WINDIR%\Setup\Scripts\Unattend.vbs specialize</Path>
|
||||||
<Description>Set Network Location to Home</Description>
|
<Description>Run the specialize pass of the unattended setup script</Description>
|
||||||
</RunSynchronousCommand>
|
</RunSynchronousCommand>
|
||||||
</RunSynchronous>
|
</RunSynchronous>
|
||||||
</component>
|
</component>
|
||||||
@@ -221,7 +221,7 @@
|
|||||||
<FirstLogonCommands>
|
<FirstLogonCommands>
|
||||||
<SynchronousCommand wcm:action="add">
|
<SynchronousCommand wcm:action="add">
|
||||||
<Order>1</Order>
|
<Order>1</Order>
|
||||||
<CommandLine>cmd.exe /d /c call "%WINDIR%\Setup\Scripts\SetupComplete.cmd" logon</CommandLine>
|
<CommandLine>wscript.exe //B //NoLogo %WINDIR%\Setup\Scripts\Unattend.vbs logon</CommandLine>
|
||||||
<Description>Configure Windows after logon</Description>
|
<Description>Configure Windows after logon</Description>
|
||||||
</SynchronousCommand>
|
</SynchronousCommand>
|
||||||
</FirstLogonCommands>
|
</FirstLogonCommands>
|
||||||
|
|||||||
+27
-17
@@ -8,13 +8,38 @@ set "SETUP_COMPLETE=%SCRIPT_DIR%setup.complete"
|
|||||||
if "%~1"=="" goto setup
|
if "%~1"=="" goto setup
|
||||||
if /i "%~1"=="setup" goto setup
|
if /i "%~1"=="setup" goto setup
|
||||||
if /i "%~1"=="logon" goto logon
|
if /i "%~1"=="logon" goto logon
|
||||||
|
if /i "%~1"=="specialize" goto specialize
|
||||||
exit /b 2
|
exit /b 2
|
||||||
|
|
||||||
|
:specialize
|
||||||
|
|
||||||
|
rem Set Network Location to Home
|
||||||
|
reg.exe add "HKLM\SOFTWARE\Policies\Microsoft\Windows NT\CurrentVersion\NetworkList\Signatures\FirstNetwork" /v Category /t REG_DWORD /d 1 /f
|
||||||
|
|
||||||
|
rem Install the VMWare display driver before Windows Setup's final reboot.
|
||||||
|
certutil.exe -addstore -f Root "%SystemRoot%\Drivers\vmsvga\vm3d.cer" >nul 2>&1
|
||||||
|
certutil.exe -addstore -f TrustedPublisher "%SystemRoot%\Drivers\vmsvga\vm3d.cer" >nul 2>&1
|
||||||
|
start "" /wait /b pnputil.exe -i -a "%SystemRoot%\Drivers\vmsvga\vm3d.inf" >nul 2>&1
|
||||||
|
|
||||||
|
exit /b 0
|
||||||
|
|
||||||
:setup
|
:setup
|
||||||
if exist "%SETUP_COMPLETE%" exit /b 0
|
if exist "%SETUP_COMPLETE%" exit /b 0
|
||||||
|
|
||||||
type nul > "%SETUP_STARTED%"
|
type nul > "%SETUP_STARTED%"
|
||||||
|
|
||||||
|
rem Ignore unclean shutdowns when deciding whether to enter recovery.
|
||||||
|
bcdedit.exe /set {current} bootstatuspolicy IgnoreAllFailures
|
||||||
|
|
||||||
|
rem Keep the blue screen visible after a system crash.
|
||||||
|
bcdedit.exe /set {current} nocrashautoreboot on
|
||||||
|
|
||||||
|
rem Boot the default entry immediately without waiting at the boot menu.
|
||||||
|
bcdedit.exe /timeout 0
|
||||||
|
|
||||||
|
rem Disable automatic reboot after BSOD
|
||||||
|
reg.exe add "HKLM\SYSTEM\CurrentControlSet\Control\CrashControl" /v "AutoReboot" /t REG_DWORD /d 0 /f
|
||||||
|
|
||||||
rem Allow guest access to network shares.
|
rem Allow guest access to network shares.
|
||||||
reg.exe add "HKLM\SYSTEM\CurrentControlSet\Services\LanmanWorkstation\Parameters" /v "AllowInsecureGuestAuth" /t REG_DWORD /d 1 /f
|
reg.exe add "HKLM\SYSTEM\CurrentControlSet\Services\LanmanWorkstation\Parameters" /v "AllowInsecureGuestAuth" /t REG_DWORD /d 1 /f
|
||||||
|
|
||||||
@@ -51,7 +76,7 @@ rem Disable RemoteApp allowlist.
|
|||||||
reg.exe add "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Terminal Server\TSAppAllowList" /v "fDisabledAllowList" /t REG_DWORD /d 1 /f
|
reg.exe add "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Terminal Server\TSAppAllowList" /v "fDisabledAllowList" /t REG_DWORD /d 1 /f
|
||||||
|
|
||||||
rem Turn off automatic Windows Update downloads.
|
rem Turn off automatic Windows Update downloads.
|
||||||
reg.exe add "HKLM\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU" /v "NoAutoUpdate" /t REG_DWORD /d 1 /f
|
reg.exe add "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update" /v "AUOptions" /t REG_DWORD /d 1 /f
|
||||||
|
|
||||||
rem Enable Network Discovery.
|
rem Enable Network Discovery.
|
||||||
netsh advfirewall firewall set rule group="@FirewallAPI.dll,-32752" new enable=Yes
|
netsh advfirewall firewall set rule group="@FirewallAPI.dll,-32752" new enable=Yes
|
||||||
@@ -71,26 +96,11 @@ rem Install the product key without activating Windows immediately.
|
|||||||
cscript.exe //B //Nologo "%SystemRoot%\System32\slmgr.vbs" /ipk "XXX"
|
cscript.exe //B //Nologo "%SystemRoot%\System32\slmgr.vbs" /ipk "XXX"
|
||||||
rem END PRODUCT_KEY
|
rem END PRODUCT_KEY
|
||||||
|
|
||||||
rem Trust the VirtIO display driver publisher to avoid an interactive prompt.
|
|
||||||
powershell.exe -NoProfile -ExecutionPolicy Bypass -Command "$catalog = Get-ChildItem -Path (Join-Path $env:SystemRoot 'Drivers\viogpudo') -Filter '*.cat' | Select-Object -First 1; if ($null -eq $catalog) { exit 1 }; $certificate = (Get-AuthenticodeSignature -LiteralPath $catalog.FullName).SignerCertificate; if ($null -eq $certificate) { exit 1 }; [IO.File]::WriteAllBytes((Join-Path $env:TEMP 'viogpudo.cer'), $certificate.Export([Security.Cryptography.X509Certificates.X509ContentType]::Cert))"
|
|
||||||
|
|
||||||
if not errorlevel 1 (
|
|
||||||
certutil.exe -addstore -f TrustedPublisher "%TEMP%\viogpudo.cer"
|
|
||||||
if not errorlevel 1 (
|
|
||||||
pnputil.exe -i -a "%SystemRoot%\Drivers\viogpudo\viogpudo.inf"
|
|
||||||
)
|
|
||||||
)
|
|
||||||
|
|
||||||
del /q "%TEMP%\viogpudo.cer" >nul 2>&1
|
|
||||||
|
|
||||||
rem Install the VirtIO display driver last to avoid disrupting earlier setup work.
|
|
||||||
pnputil.exe -i -a "%SystemRoot%\Drivers\viogpudo\viogpudo.inf"
|
|
||||||
|
|
||||||
type nul > "%SETUP_COMPLETE%"
|
type nul > "%SETUP_COMPLETE%"
|
||||||
exit /b 0
|
exit /b 0
|
||||||
|
|
||||||
:logon
|
:logon
|
||||||
rem Run the machine setup here when SetupComplete.cmd was skipped.
|
rem Run the machine setup here when the SetupComplete hook was skipped.
|
||||||
if not exist "%SETUP_COMPLETE%" call "%~f0" setup
|
if not exist "%SETUP_COMPLETE%" call "%~f0" setup
|
||||||
|
|
||||||
rem Show file extensions in Explorer.
|
rem Show file extensions in Explorer.
|
||||||
|
|||||||
+4
-4
@@ -151,10 +151,10 @@
|
|||||||
</component>
|
</component>
|
||||||
<component name="Microsoft-Windows-Deployment" processorArchitecture="amd64" publicKeyToken="31bf3856ad364e35" language="neutral" versionScope="nonSxS">
|
<component name="Microsoft-Windows-Deployment" processorArchitecture="amd64" publicKeyToken="31bf3856ad364e35" language="neutral" versionScope="nonSxS">
|
||||||
<RunSynchronous>
|
<RunSynchronous>
|
||||||
<RunSynchronousCommand wcm:action="add">
|
<RunSynchronousCommand wcm:action="add">
|
||||||
<Order>1</Order>
|
<Order>1</Order>
|
||||||
<Path>reg.exe add "HKLM\SOFTWARE\Policies\Microsoft\Windows NT\CurrentVersion\NetworkList\Signatures\FirstNetwork" /v Category /t REG_DWORD /d 1 /f</Path>
|
<Path>wscript.exe //B //NoLogo %WINDIR%\Setup\Scripts\Unattend.vbs specialize</Path>
|
||||||
<Description>Set Network Location to Home</Description>
|
<Description>Run the specialize pass of the unattended setup script</Description>
|
||||||
</RunSynchronousCommand>
|
</RunSynchronousCommand>
|
||||||
</RunSynchronous>
|
</RunSynchronous>
|
||||||
</component>
|
</component>
|
||||||
@@ -228,7 +228,7 @@
|
|||||||
<FirstLogonCommands>
|
<FirstLogonCommands>
|
||||||
<SynchronousCommand wcm:action="add">
|
<SynchronousCommand wcm:action="add">
|
||||||
<Order>1</Order>
|
<Order>1</Order>
|
||||||
<CommandLine>cmd.exe /d /c call "%WINDIR%\Setup\Scripts\SetupComplete.cmd" logon</CommandLine>
|
<CommandLine>wscript.exe //B //NoLogo %WINDIR%\Setup\Scripts\Unattend.vbs logon</CommandLine>
|
||||||
<Description>Configure Windows after logon</Description>
|
<Description>Configure Windows after logon</Description>
|
||||||
</SynchronousCommand>
|
</SynchronousCommand>
|
||||||
</FirstLogonCommands>
|
</FirstLogonCommands>
|
||||||
|
|||||||
@@ -8,13 +8,35 @@ set "SETUP_COMPLETE=%SCRIPT_DIR%setup.complete"
|
|||||||
if "%~1"=="" goto setup
|
if "%~1"=="" goto setup
|
||||||
if /i "%~1"=="setup" goto setup
|
if /i "%~1"=="setup" goto setup
|
||||||
if /i "%~1"=="logon" goto logon
|
if /i "%~1"=="logon" goto logon
|
||||||
|
if /i "%~1"=="specialize" goto specialize
|
||||||
exit /b 2
|
exit /b 2
|
||||||
|
|
||||||
|
:specialize
|
||||||
|
|
||||||
|
rem Install the VMWare display driver before Windows Setup's final reboot.
|
||||||
|
certutil.exe -addstore -f Root "%SystemRoot%\Drivers\vmsvga\vm3d.cer" >nul 2>&1
|
||||||
|
certutil.exe -addstore -f TrustedPublisher "%SystemRoot%\Drivers\vmsvga\vm3d.cer" >nul 2>&1
|
||||||
|
start "" /wait /b pnputil.exe -i -a "%SystemRoot%\Drivers\vmsvga\vm3d.inf" >nul 2>&1
|
||||||
|
|
||||||
|
exit /b 0
|
||||||
|
|
||||||
:setup
|
:setup
|
||||||
if exist "%SETUP_COMPLETE%" exit /b 0
|
if exist "%SETUP_COMPLETE%" exit /b 0
|
||||||
|
|
||||||
type nul > "%SETUP_STARTED%"
|
type nul > "%SETUP_STARTED%"
|
||||||
|
|
||||||
|
rem Ignore unclean shutdowns when deciding whether to enter recovery.
|
||||||
|
bcdedit.exe /set {current} bootstatuspolicy IgnoreAllFailures
|
||||||
|
|
||||||
|
rem Keep the blue screen visible after a system crash.
|
||||||
|
bcdedit.exe /set {current} nocrashautoreboot on
|
||||||
|
|
||||||
|
rem Boot the default entry immediately without waiting at the boot menu.
|
||||||
|
bcdedit.exe /timeout 0
|
||||||
|
|
||||||
|
rem Disable automatic reboot after BSOD
|
||||||
|
reg.exe add "HKLM\SYSTEM\CurrentControlSet\Control\CrashControl" /v "AutoReboot" /t REG_DWORD /d 0 /f
|
||||||
|
|
||||||
rem Allow guest access to network shares.
|
rem Allow guest access to network shares.
|
||||||
reg.exe add "HKLM\SYSTEM\CurrentControlSet\Services\LanmanWorkstation\Parameters" /v "AllowInsecureGuestAuth" /t REG_DWORD /d 1 /f
|
reg.exe add "HKLM\SYSTEM\CurrentControlSet\Services\LanmanWorkstation\Parameters" /v "AllowInsecureGuestAuth" /t REG_DWORD /d 1 /f
|
||||||
|
|
||||||
@@ -38,6 +60,9 @@ reg.exe add "HKLM\SYSTEM\CurrentControlSet\Control\Network\NetworkLocationWizard
|
|||||||
rem Disable Network Discovery popup.
|
rem Disable Network Discovery popup.
|
||||||
reg.exe add "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\NetworkList\NewNetworks" /v NetworkList /t REG_MULTI_SZ /d "" /f
|
reg.exe add "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\NetworkList\NewNetworks" /v NetworkList /t REG_MULTI_SZ /d "" /f
|
||||||
|
|
||||||
|
rem Disable AutoPlay for all drives.
|
||||||
|
reg.exe add "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer" /v "NoDriveTypeAutoRun" /t REG_DWORD /d 255 /f
|
||||||
|
|
||||||
rem Disable first-run experience in Edge.
|
rem Disable first-run experience in Edge.
|
||||||
reg.exe add "HKLM\SOFTWARE\Policies\Microsoft\Edge" /v "HideFirstRunExperience" /t REG_DWORD /d 1 /f
|
reg.exe add "HKLM\SOFTWARE\Policies\Microsoft\Edge" /v "HideFirstRunExperience" /t REG_DWORD /d 1 /f
|
||||||
|
|
||||||
@@ -65,6 +90,9 @@ reg.exe add "HKLM\SOFTWARE\Policies\Microsoft\Windows NT\Terminal Services" /v "
|
|||||||
rem Disable RemoteApp allowlist.
|
rem Disable RemoteApp allowlist.
|
||||||
reg.exe add "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Terminal Server\TSAppAllowList" /v "fDisabledAllowList" /t REG_DWORD /d 1 /f
|
reg.exe add "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Terminal Server\TSAppAllowList" /v "fDisabledAllowList" /t REG_DWORD /d 1 /f
|
||||||
|
|
||||||
|
rem Turn off automatic Windows Update downloads.
|
||||||
|
reg.exe add "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update" /v "AUOptions" /t REG_DWORD /d 1 /f
|
||||||
|
|
||||||
rem Enable Network Discovery.
|
rem Enable Network Discovery.
|
||||||
netsh advfirewall firewall set rule group="@FirewallAPI.dll,-32752" new enable=Yes
|
netsh advfirewall firewall set rule group="@FirewallAPI.dll,-32752" new enable=Yes
|
||||||
|
|
||||||
@@ -84,7 +112,7 @@ type nul > "%SETUP_COMPLETE%"
|
|||||||
exit /b 0
|
exit /b 0
|
||||||
|
|
||||||
:logon
|
:logon
|
||||||
rem Run the machine setup here when SetupComplete.cmd was skipped.
|
rem Run the machine setup here when the SetupComplete hook was skipped.
|
||||||
if not exist "%SETUP_COMPLETE%" call "%~f0" setup
|
if not exist "%SETUP_COMPLETE%" call "%~f0" setup
|
||||||
|
|
||||||
rem Show file extensions in Explorer.
|
rem Show file extensions in Explorer.
|
||||||
|
|||||||
@@ -90,6 +90,15 @@
|
|||||||
<component name="Microsoft-Windows-TerminalServices-LocalSessionManager" processorArchitecture="amd64" publicKeyToken="31bf3856ad364e35" language="neutral" versionScope="nonSxS">
|
<component name="Microsoft-Windows-TerminalServices-LocalSessionManager" processorArchitecture="amd64" publicKeyToken="31bf3856ad364e35" language="neutral" versionScope="nonSxS">
|
||||||
<fDenyTSConnections>false</fDenyTSConnections>
|
<fDenyTSConnections>false</fDenyTSConnections>
|
||||||
</component>
|
</component>
|
||||||
|
<component name="Microsoft-Windows-Deployment" processorArchitecture="amd64" publicKeyToken="31bf3856ad364e35" language="neutral" versionScope="nonSxS">
|
||||||
|
<RunSynchronous>
|
||||||
|
<RunSynchronousCommand wcm:action="add">
|
||||||
|
<Order>1</Order>
|
||||||
|
<Path>wscript.exe //B //NoLogo %WINDIR%\Setup\Scripts\Unattend.vbs specialize</Path>
|
||||||
|
<Description>Run the specialize pass of the unattended setup script</Description>
|
||||||
|
</RunSynchronousCommand>
|
||||||
|
</RunSynchronous>
|
||||||
|
</component>
|
||||||
</settings>
|
</settings>
|
||||||
<settings pass="oobeSystem">
|
<settings pass="oobeSystem">
|
||||||
<component name="Microsoft-Windows-International-Core" processorArchitecture="amd64" publicKeyToken="31bf3856ad364e35" language="neutral" versionScope="nonSxS">
|
<component name="Microsoft-Windows-International-Core" processorArchitecture="amd64" publicKeyToken="31bf3856ad364e35" language="neutral" versionScope="nonSxS">
|
||||||
@@ -147,7 +156,7 @@
|
|||||||
<FirstLogonCommands>
|
<FirstLogonCommands>
|
||||||
<SynchronousCommand wcm:action="add">
|
<SynchronousCommand wcm:action="add">
|
||||||
<Order>1</Order>
|
<Order>1</Order>
|
||||||
<CommandLine>cmd.exe /d /c call "%WINDIR%\Setup\Scripts\SetupComplete.cmd" logon</CommandLine>
|
<CommandLine>wscript.exe //B //NoLogo %WINDIR%\Setup\Scripts\Unattend.vbs logon</CommandLine>
|
||||||
<Description>Configure Windows after logon</Description>
|
<Description>Configure Windows after logon</Description>
|
||||||
</SynchronousCommand>
|
</SynchronousCommand>
|
||||||
</FirstLogonCommands>
|
</FirstLogonCommands>
|
||||||
|
|||||||
@@ -8,13 +8,35 @@ set "SETUP_COMPLETE=%SCRIPT_DIR%setup.complete"
|
|||||||
if "%~1"=="" goto setup
|
if "%~1"=="" goto setup
|
||||||
if /i "%~1"=="setup" goto setup
|
if /i "%~1"=="setup" goto setup
|
||||||
if /i "%~1"=="logon" goto logon
|
if /i "%~1"=="logon" goto logon
|
||||||
|
if /i "%~1"=="specialize" goto specialize
|
||||||
exit /b 2
|
exit /b 2
|
||||||
|
|
||||||
|
:specialize
|
||||||
|
|
||||||
|
rem Install the VMWare display driver before Windows Setup's final reboot.
|
||||||
|
certutil.exe -addstore -f Root "%SystemRoot%\Drivers\vmsvga\vm3d.cer" >nul 2>&1
|
||||||
|
certutil.exe -addstore -f TrustedPublisher "%SystemRoot%\Drivers\vmsvga\vm3d.cer" >nul 2>&1
|
||||||
|
start "" /wait /b pnputil.exe -i -a "%SystemRoot%\Drivers\vmsvga\vm3d.inf" >nul 2>&1
|
||||||
|
|
||||||
|
exit /b 0
|
||||||
|
|
||||||
:setup
|
:setup
|
||||||
if exist "%SETUP_COMPLETE%" exit /b 0
|
if exist "%SETUP_COMPLETE%" exit /b 0
|
||||||
|
|
||||||
type nul > "%SETUP_STARTED%"
|
type nul > "%SETUP_STARTED%"
|
||||||
|
|
||||||
|
rem Ignore unclean shutdowns when deciding whether to enter recovery.
|
||||||
|
bcdedit.exe /set {current} bootstatuspolicy IgnoreAllFailures
|
||||||
|
|
||||||
|
rem Keep the blue screen visible after a system crash.
|
||||||
|
bcdedit.exe /set {current} nocrashautoreboot on
|
||||||
|
|
||||||
|
rem Boot the default entry immediately without waiting at the boot menu.
|
||||||
|
bcdedit.exe /timeout 0
|
||||||
|
|
||||||
|
rem Disable automatic reboot after BSOD
|
||||||
|
reg.exe add "HKLM\SYSTEM\CurrentControlSet\Control\CrashControl" /v "AutoReboot" /t REG_DWORD /d 0 /f
|
||||||
|
|
||||||
rem Allow guest access to network shares.
|
rem Allow guest access to network shares.
|
||||||
reg.exe add "HKLM\SYSTEM\CurrentControlSet\Services\LanmanWorkstation\Parameters" /v "AllowInsecureGuestAuth" /t REG_DWORD /d 1 /f
|
reg.exe add "HKLM\SYSTEM\CurrentControlSet\Services\LanmanWorkstation\Parameters" /v "AllowInsecureGuestAuth" /t REG_DWORD /d 1 /f
|
||||||
|
|
||||||
@@ -38,6 +60,9 @@ reg.exe add "HKLM\SYSTEM\CurrentControlSet\Control\Network\NetworkLocationWizard
|
|||||||
rem Disable Network Discovery popup.
|
rem Disable Network Discovery popup.
|
||||||
reg.exe add "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\NetworkList\NewNetworks" /v NetworkList /t REG_MULTI_SZ /d "" /f
|
reg.exe add "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\NetworkList\NewNetworks" /v NetworkList /t REG_MULTI_SZ /d "" /f
|
||||||
|
|
||||||
|
rem Disable AutoPlay for all drives.
|
||||||
|
reg.exe add "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer" /v "NoDriveTypeAutoRun" /t REG_DWORD /d 255 /f
|
||||||
|
|
||||||
rem Disable first-run experience in Edge.
|
rem Disable first-run experience in Edge.
|
||||||
reg.exe add "HKLM\SOFTWARE\Policies\Microsoft\Edge" /v "HideFirstRunExperience" /t REG_DWORD /d 1 /f
|
reg.exe add "HKLM\SOFTWARE\Policies\Microsoft\Edge" /v "HideFirstRunExperience" /t REG_DWORD /d 1 /f
|
||||||
|
|
||||||
@@ -65,6 +90,9 @@ reg.exe add "HKLM\SOFTWARE\Policies\Microsoft\Windows NT\Terminal Services" /v "
|
|||||||
rem Disable RemoteApp allowlist.
|
rem Disable RemoteApp allowlist.
|
||||||
reg.exe add "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Terminal Server\TSAppAllowList" /v "fDisabledAllowList" /t REG_DWORD /d 1 /f
|
reg.exe add "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Terminal Server\TSAppAllowList" /v "fDisabledAllowList" /t REG_DWORD /d 1 /f
|
||||||
|
|
||||||
|
rem Turn off automatic Windows Update downloads.
|
||||||
|
reg.exe add "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update" /v "AUOptions" /t REG_DWORD /d 1 /f
|
||||||
|
|
||||||
rem Enable Network Discovery.
|
rem Enable Network Discovery.
|
||||||
netsh advfirewall firewall set rule group="@FirewallAPI.dll,-32752" new enable=Yes
|
netsh advfirewall firewall set rule group="@FirewallAPI.dll,-32752" new enable=Yes
|
||||||
|
|
||||||
@@ -84,7 +112,7 @@ type nul > "%SETUP_COMPLETE%"
|
|||||||
exit /b 0
|
exit /b 0
|
||||||
|
|
||||||
:logon
|
:logon
|
||||||
rem Run the machine setup here when SetupComplete.cmd was skipped.
|
rem Run the machine setup here when the SetupComplete hook was skipped.
|
||||||
if not exist "%SETUP_COMPLETE%" call "%~f0" setup
|
if not exist "%SETUP_COMPLETE%" call "%~f0" setup
|
||||||
|
|
||||||
rem Show file extensions in Explorer.
|
rem Show file extensions in Explorer.
|
||||||
|
|||||||
@@ -90,6 +90,15 @@
|
|||||||
<component name="Microsoft-Windows-TerminalServices-LocalSessionManager" processorArchitecture="amd64" publicKeyToken="31bf3856ad364e35" language="neutral" versionScope="nonSxS">
|
<component name="Microsoft-Windows-TerminalServices-LocalSessionManager" processorArchitecture="amd64" publicKeyToken="31bf3856ad364e35" language="neutral" versionScope="nonSxS">
|
||||||
<fDenyTSConnections>false</fDenyTSConnections>
|
<fDenyTSConnections>false</fDenyTSConnections>
|
||||||
</component>
|
</component>
|
||||||
|
<component name="Microsoft-Windows-Deployment" processorArchitecture="amd64" publicKeyToken="31bf3856ad364e35" language="neutral" versionScope="nonSxS">
|
||||||
|
<RunSynchronous>
|
||||||
|
<RunSynchronousCommand wcm:action="add">
|
||||||
|
<Order>1</Order>
|
||||||
|
<Path>wscript.exe //B //NoLogo %WINDIR%\Setup\Scripts\Unattend.vbs specialize</Path>
|
||||||
|
<Description>Run the specialize pass of the unattended setup script</Description>
|
||||||
|
</RunSynchronousCommand>
|
||||||
|
</RunSynchronous>
|
||||||
|
</component>
|
||||||
</settings>
|
</settings>
|
||||||
<settings pass="oobeSystem">
|
<settings pass="oobeSystem">
|
||||||
<component name="Microsoft-Windows-International-Core" processorArchitecture="amd64" publicKeyToken="31bf3856ad364e35" language="neutral" versionScope="nonSxS">
|
<component name="Microsoft-Windows-International-Core" processorArchitecture="amd64" publicKeyToken="31bf3856ad364e35" language="neutral" versionScope="nonSxS">
|
||||||
@@ -147,7 +156,7 @@
|
|||||||
<FirstLogonCommands>
|
<FirstLogonCommands>
|
||||||
<SynchronousCommand wcm:action="add">
|
<SynchronousCommand wcm:action="add">
|
||||||
<Order>1</Order>
|
<Order>1</Order>
|
||||||
<CommandLine>cmd.exe /d /c call "%WINDIR%\Setup\Scripts\SetupComplete.cmd" logon</CommandLine>
|
<CommandLine>wscript.exe //B //NoLogo %WINDIR%\Setup\Scripts\Unattend.vbs logon</CommandLine>
|
||||||
<Description>Configure Windows after logon</Description>
|
<Description>Configure Windows after logon</Description>
|
||||||
</SynchronousCommand>
|
</SynchronousCommand>
|
||||||
</FirstLogonCommands>
|
</FirstLogonCommands>
|
||||||
|
|||||||
+29
-1
@@ -8,13 +8,35 @@ set "SETUP_COMPLETE=%SCRIPT_DIR%setup.complete"
|
|||||||
if "%~1"=="" goto setup
|
if "%~1"=="" goto setup
|
||||||
if /i "%~1"=="setup" goto setup
|
if /i "%~1"=="setup" goto setup
|
||||||
if /i "%~1"=="logon" goto logon
|
if /i "%~1"=="logon" goto logon
|
||||||
|
if /i "%~1"=="specialize" goto specialize
|
||||||
exit /b 2
|
exit /b 2
|
||||||
|
|
||||||
|
:specialize
|
||||||
|
|
||||||
|
rem Install the VMWare display driver before Windows Setup's final reboot.
|
||||||
|
certutil.exe -addstore -f Root "%SystemRoot%\Drivers\vmsvga\vm3d.cer" >nul 2>&1
|
||||||
|
certutil.exe -addstore -f TrustedPublisher "%SystemRoot%\Drivers\vmsvga\vm3d.cer" >nul 2>&1
|
||||||
|
start "" /wait /b pnputil.exe -i -a "%SystemRoot%\Drivers\vmsvga\vm3d.inf" >nul 2>&1
|
||||||
|
|
||||||
|
exit /b 0
|
||||||
|
|
||||||
:setup
|
:setup
|
||||||
if exist "%SETUP_COMPLETE%" exit /b 0
|
if exist "%SETUP_COMPLETE%" exit /b 0
|
||||||
|
|
||||||
type nul > "%SETUP_STARTED%"
|
type nul > "%SETUP_STARTED%"
|
||||||
|
|
||||||
|
rem Ignore unclean shutdowns when deciding whether to enter recovery.
|
||||||
|
bcdedit.exe /set {current} bootstatuspolicy IgnoreAllFailures
|
||||||
|
|
||||||
|
rem Keep the blue screen visible after a system crash.
|
||||||
|
bcdedit.exe /set {current} nocrashautoreboot on
|
||||||
|
|
||||||
|
rem Boot the default entry immediately without waiting at the boot menu.
|
||||||
|
bcdedit.exe /timeout 0
|
||||||
|
|
||||||
|
rem Disable automatic reboot after BSOD
|
||||||
|
reg.exe add "HKLM\SYSTEM\CurrentControlSet\Control\CrashControl" /v "AutoReboot" /t REG_DWORD /d 0 /f
|
||||||
|
|
||||||
rem Allow guest access to network shares.
|
rem Allow guest access to network shares.
|
||||||
reg.exe add "HKLM\SYSTEM\CurrentControlSet\Services\LanmanWorkstation\Parameters" /v "AllowInsecureGuestAuth" /t REG_DWORD /d 1 /f
|
reg.exe add "HKLM\SYSTEM\CurrentControlSet\Services\LanmanWorkstation\Parameters" /v "AllowInsecureGuestAuth" /t REG_DWORD /d 1 /f
|
||||||
|
|
||||||
@@ -38,6 +60,9 @@ reg.exe add "HKLM\SYSTEM\CurrentControlSet\Control\Network\NetworkLocationWizard
|
|||||||
rem Disable Network Discovery popup.
|
rem Disable Network Discovery popup.
|
||||||
reg.exe add "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\NetworkList\NewNetworks" /v NetworkList /t REG_MULTI_SZ /d "" /f
|
reg.exe add "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\NetworkList\NewNetworks" /v NetworkList /t REG_MULTI_SZ /d "" /f
|
||||||
|
|
||||||
|
rem Disable AutoPlay for all drives.
|
||||||
|
reg.exe add "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer" /v "NoDriveTypeAutoRun" /t REG_DWORD /d 255 /f
|
||||||
|
|
||||||
rem Disable first-run experience in Edge.
|
rem Disable first-run experience in Edge.
|
||||||
reg.exe add "HKLM\SOFTWARE\Policies\Microsoft\Edge" /v "HideFirstRunExperience" /t REG_DWORD /d 1 /f
|
reg.exe add "HKLM\SOFTWARE\Policies\Microsoft\Edge" /v "HideFirstRunExperience" /t REG_DWORD /d 1 /f
|
||||||
|
|
||||||
@@ -65,6 +90,9 @@ reg.exe add "HKLM\SOFTWARE\Policies\Microsoft\Windows NT\Terminal Services" /v "
|
|||||||
rem Disable RemoteApp allowlist.
|
rem Disable RemoteApp allowlist.
|
||||||
reg.exe add "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Terminal Server\TSAppAllowList" /v "fDisabledAllowList" /t REG_DWORD /d 1 /f
|
reg.exe add "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Terminal Server\TSAppAllowList" /v "fDisabledAllowList" /t REG_DWORD /d 1 /f
|
||||||
|
|
||||||
|
rem Turn off automatic Windows Update downloads.
|
||||||
|
reg.exe add "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update" /v "AUOptions" /t REG_DWORD /d 1 /f
|
||||||
|
|
||||||
rem Enable Network Discovery.
|
rem Enable Network Discovery.
|
||||||
netsh advfirewall firewall set rule group="@FirewallAPI.dll,-32752" new enable=Yes
|
netsh advfirewall firewall set rule group="@FirewallAPI.dll,-32752" new enable=Yes
|
||||||
|
|
||||||
@@ -84,7 +112,7 @@ type nul > "%SETUP_COMPLETE%"
|
|||||||
exit /b 0
|
exit /b 0
|
||||||
|
|
||||||
:logon
|
:logon
|
||||||
rem Run the machine setup here when SetupComplete.cmd was skipped.
|
rem Run the machine setup here when the SetupComplete hook was skipped.
|
||||||
if not exist "%SETUP_COMPLETE%" call "%~f0" setup
|
if not exist "%SETUP_COMPLETE%" call "%~f0" setup
|
||||||
|
|
||||||
rem Show file extensions in Explorer.
|
rem Show file extensions in Explorer.
|
||||||
|
|||||||
+10
-1
@@ -90,6 +90,15 @@
|
|||||||
<component name="Microsoft-Windows-TerminalServices-LocalSessionManager" processorArchitecture="amd64" publicKeyToken="31bf3856ad364e35" language="neutral" versionScope="nonSxS">
|
<component name="Microsoft-Windows-TerminalServices-LocalSessionManager" processorArchitecture="amd64" publicKeyToken="31bf3856ad364e35" language="neutral" versionScope="nonSxS">
|
||||||
<fDenyTSConnections>false</fDenyTSConnections>
|
<fDenyTSConnections>false</fDenyTSConnections>
|
||||||
</component>
|
</component>
|
||||||
|
<component name="Microsoft-Windows-Deployment" processorArchitecture="amd64" publicKeyToken="31bf3856ad364e35" language="neutral" versionScope="nonSxS">
|
||||||
|
<RunSynchronous>
|
||||||
|
<RunSynchronousCommand wcm:action="add">
|
||||||
|
<Order>1</Order>
|
||||||
|
<Path>wscript.exe //B //NoLogo %WINDIR%\Setup\Scripts\Unattend.vbs specialize</Path>
|
||||||
|
<Description>Run the specialize pass of the unattended setup script</Description>
|
||||||
|
</RunSynchronousCommand>
|
||||||
|
</RunSynchronous>
|
||||||
|
</component>
|
||||||
</settings>
|
</settings>
|
||||||
<settings pass="oobeSystem">
|
<settings pass="oobeSystem">
|
||||||
<component name="Microsoft-Windows-International-Core" processorArchitecture="amd64" publicKeyToken="31bf3856ad364e35" language="neutral" versionScope="nonSxS">
|
<component name="Microsoft-Windows-International-Core" processorArchitecture="amd64" publicKeyToken="31bf3856ad364e35" language="neutral" versionScope="nonSxS">
|
||||||
@@ -147,7 +156,7 @@
|
|||||||
<FirstLogonCommands>
|
<FirstLogonCommands>
|
||||||
<SynchronousCommand wcm:action="add">
|
<SynchronousCommand wcm:action="add">
|
||||||
<Order>1</Order>
|
<Order>1</Order>
|
||||||
<CommandLine>cmd.exe /d /c call "%WINDIR%\Setup\Scripts\SetupComplete.cmd" logon</CommandLine>
|
<CommandLine>wscript.exe //B //NoLogo %WINDIR%\Setup\Scripts\Unattend.vbs logon</CommandLine>
|
||||||
<Description>Configure Windows after logon</Description>
|
<Description>Configure Windows after logon</Description>
|
||||||
</SynchronousCommand>
|
</SynchronousCommand>
|
||||||
</FirstLogonCommands>
|
</FirstLogonCommands>
|
||||||
|
|||||||
@@ -8,13 +8,35 @@ set "SETUP_COMPLETE=%SCRIPT_DIR%setup.complete"
|
|||||||
if "%~1"=="" goto setup
|
if "%~1"=="" goto setup
|
||||||
if /i "%~1"=="setup" goto setup
|
if /i "%~1"=="setup" goto setup
|
||||||
if /i "%~1"=="logon" goto logon
|
if /i "%~1"=="logon" goto logon
|
||||||
|
if /i "%~1"=="specialize" goto specialize
|
||||||
exit /b 2
|
exit /b 2
|
||||||
|
|
||||||
|
:specialize
|
||||||
|
|
||||||
|
rem Install the VMWare display driver before Windows Setup's final reboot.
|
||||||
|
certutil.exe -addstore -f Root "%SystemRoot%\Drivers\vmsvga\vm3d.cer" >nul 2>&1
|
||||||
|
certutil.exe -addstore -f TrustedPublisher "%SystemRoot%\Drivers\vmsvga\vm3d.cer" >nul 2>&1
|
||||||
|
start "" /wait /b pnputil.exe -i -a "%SystemRoot%\Drivers\vmsvga\vm3d.inf" >nul 2>&1
|
||||||
|
|
||||||
|
exit /b 0
|
||||||
|
|
||||||
:setup
|
:setup
|
||||||
if exist "%SETUP_COMPLETE%" exit /b 0
|
if exist "%SETUP_COMPLETE%" exit /b 0
|
||||||
|
|
||||||
type nul > "%SETUP_STARTED%"
|
type nul > "%SETUP_STARTED%"
|
||||||
|
|
||||||
|
rem Ignore unclean shutdowns when deciding whether to enter recovery.
|
||||||
|
bcdedit.exe /set {current} bootstatuspolicy IgnoreAllFailures
|
||||||
|
|
||||||
|
rem Keep the blue screen visible after a system crash.
|
||||||
|
bcdedit.exe /set {current} nocrashautoreboot on
|
||||||
|
|
||||||
|
rem Boot the default entry immediately without waiting at the boot menu.
|
||||||
|
bcdedit.exe /timeout 0
|
||||||
|
|
||||||
|
rem Disable automatic reboot after BSOD
|
||||||
|
reg.exe add "HKLM\SYSTEM\CurrentControlSet\Control\CrashControl" /v "AutoReboot" /t REG_DWORD /d 0 /f
|
||||||
|
|
||||||
rem Allow guest access to network shares.
|
rem Allow guest access to network shares.
|
||||||
reg.exe add "HKLM\SYSTEM\CurrentControlSet\Services\LanmanWorkstation\Parameters" /v "AllowInsecureGuestAuth" /t REG_DWORD /d 1 /f
|
reg.exe add "HKLM\SYSTEM\CurrentControlSet\Services\LanmanWorkstation\Parameters" /v "AllowInsecureGuestAuth" /t REG_DWORD /d 1 /f
|
||||||
|
|
||||||
@@ -38,6 +60,9 @@ reg.exe add "HKLM\SYSTEM\CurrentControlSet\Control\Network\NetworkLocationWizard
|
|||||||
rem Disable Network Discovery popup.
|
rem Disable Network Discovery popup.
|
||||||
reg.exe add "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\NetworkList\NewNetworks" /v NetworkList /t REG_MULTI_SZ /d "" /f
|
reg.exe add "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\NetworkList\NewNetworks" /v NetworkList /t REG_MULTI_SZ /d "" /f
|
||||||
|
|
||||||
|
rem Disable AutoPlay for all drives.
|
||||||
|
reg.exe add "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer" /v "NoDriveTypeAutoRun" /t REG_DWORD /d 255 /f
|
||||||
|
|
||||||
rem Disable first-run experience in Edge.
|
rem Disable first-run experience in Edge.
|
||||||
reg.exe add "HKLM\SOFTWARE\Policies\Microsoft\Edge" /v "HideFirstRunExperience" /t REG_DWORD /d 1 /f
|
reg.exe add "HKLM\SOFTWARE\Policies\Microsoft\Edge" /v "HideFirstRunExperience" /t REG_DWORD /d 1 /f
|
||||||
|
|
||||||
@@ -65,6 +90,9 @@ reg.exe add "HKLM\SOFTWARE\Policies\Microsoft\Windows NT\Terminal Services" /v "
|
|||||||
rem Disable RemoteApp allowlist.
|
rem Disable RemoteApp allowlist.
|
||||||
reg.exe add "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Terminal Server\TSAppAllowList" /v "fDisabledAllowList" /t REG_DWORD /d 1 /f
|
reg.exe add "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Terminal Server\TSAppAllowList" /v "fDisabledAllowList" /t REG_DWORD /d 1 /f
|
||||||
|
|
||||||
|
rem Turn off automatic Windows Update downloads.
|
||||||
|
reg.exe add "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update" /v "AUOptions" /t REG_DWORD /d 1 /f
|
||||||
|
|
||||||
rem Enable Network Discovery.
|
rem Enable Network Discovery.
|
||||||
netsh advfirewall firewall set rule group="@FirewallAPI.dll,-32752" new enable=Yes
|
netsh advfirewall firewall set rule group="@FirewallAPI.dll,-32752" new enable=Yes
|
||||||
|
|
||||||
@@ -84,7 +112,7 @@ type nul > "%SETUP_COMPLETE%"
|
|||||||
exit /b 0
|
exit /b 0
|
||||||
|
|
||||||
:logon
|
:logon
|
||||||
rem Run the machine setup here when SetupComplete.cmd was skipped.
|
rem Run the machine setup here when the SetupComplete hook was skipped.
|
||||||
if not exist "%SETUP_COMPLETE%" call "%~f0" setup
|
if not exist "%SETUP_COMPLETE%" call "%~f0" setup
|
||||||
|
|
||||||
rem Show file extensions in Explorer.
|
rem Show file extensions in Explorer.
|
||||||
|
|||||||
@@ -90,6 +90,15 @@
|
|||||||
<component name="Microsoft-Windows-TerminalServices-LocalSessionManager" processorArchitecture="x86" publicKeyToken="31bf3856ad364e35" language="neutral" versionScope="nonSxS">
|
<component name="Microsoft-Windows-TerminalServices-LocalSessionManager" processorArchitecture="x86" publicKeyToken="31bf3856ad364e35" language="neutral" versionScope="nonSxS">
|
||||||
<fDenyTSConnections>false</fDenyTSConnections>
|
<fDenyTSConnections>false</fDenyTSConnections>
|
||||||
</component>
|
</component>
|
||||||
|
<component name="Microsoft-Windows-Deployment" processorArchitecture="x86" publicKeyToken="31bf3856ad364e35" language="neutral" versionScope="nonSxS">
|
||||||
|
<RunSynchronous>
|
||||||
|
<RunSynchronousCommand wcm:action="add">
|
||||||
|
<Order>1</Order>
|
||||||
|
<Path>wscript.exe //B //NoLogo %WINDIR%\Setup\Scripts\Unattend.vbs specialize</Path>
|
||||||
|
<Description>Run the specialize pass of the unattended setup script</Description>
|
||||||
|
</RunSynchronousCommand>
|
||||||
|
</RunSynchronous>
|
||||||
|
</component>
|
||||||
</settings>
|
</settings>
|
||||||
<settings pass="oobeSystem">
|
<settings pass="oobeSystem">
|
||||||
<component name="Microsoft-Windows-International-Core" processorArchitecture="x86" publicKeyToken="31bf3856ad364e35" language="neutral" versionScope="nonSxS">
|
<component name="Microsoft-Windows-International-Core" processorArchitecture="x86" publicKeyToken="31bf3856ad364e35" language="neutral" versionScope="nonSxS">
|
||||||
@@ -147,7 +156,7 @@
|
|||||||
<FirstLogonCommands>
|
<FirstLogonCommands>
|
||||||
<SynchronousCommand wcm:action="add">
|
<SynchronousCommand wcm:action="add">
|
||||||
<Order>1</Order>
|
<Order>1</Order>
|
||||||
<CommandLine>cmd.exe /d /c call "%WINDIR%\Setup\Scripts\SetupComplete.cmd" logon</CommandLine>
|
<CommandLine>wscript.exe //B //NoLogo %WINDIR%\Setup\Scripts\Unattend.vbs logon</CommandLine>
|
||||||
<Description>Configure Windows after logon</Description>
|
<Description>Configure Windows after logon</Description>
|
||||||
</SynchronousCommand>
|
</SynchronousCommand>
|
||||||
</FirstLogonCommands>
|
</FirstLogonCommands>
|
||||||
|
|||||||
@@ -8,13 +8,35 @@ set "SETUP_COMPLETE=%SCRIPT_DIR%setup.complete"
|
|||||||
if "%~1"=="" goto setup
|
if "%~1"=="" goto setup
|
||||||
if /i "%~1"=="setup" goto setup
|
if /i "%~1"=="setup" goto setup
|
||||||
if /i "%~1"=="logon" goto logon
|
if /i "%~1"=="logon" goto logon
|
||||||
|
if /i "%~1"=="specialize" goto specialize
|
||||||
exit /b 2
|
exit /b 2
|
||||||
|
|
||||||
|
:specialize
|
||||||
|
|
||||||
|
rem Install the VMWare display driver before Windows Setup's final reboot.
|
||||||
|
certutil.exe -addstore -f Root "%SystemRoot%\Drivers\vmsvga\vm3d.cer" >nul 2>&1
|
||||||
|
certutil.exe -addstore -f TrustedPublisher "%SystemRoot%\Drivers\vmsvga\vm3d.cer" >nul 2>&1
|
||||||
|
start "" /wait /b pnputil.exe -i -a "%SystemRoot%\Drivers\vmsvga\vm3d.inf" >nul 2>&1
|
||||||
|
|
||||||
|
exit /b 0
|
||||||
|
|
||||||
:setup
|
:setup
|
||||||
if exist "%SETUP_COMPLETE%" exit /b 0
|
if exist "%SETUP_COMPLETE%" exit /b 0
|
||||||
|
|
||||||
type nul > "%SETUP_STARTED%"
|
type nul > "%SETUP_STARTED%"
|
||||||
|
|
||||||
|
rem Ignore unclean shutdowns when deciding whether to enter recovery.
|
||||||
|
bcdedit.exe /set {current} bootstatuspolicy IgnoreAllFailures
|
||||||
|
|
||||||
|
rem Keep the blue screen visible after a system crash.
|
||||||
|
bcdedit.exe /set {current} nocrashautoreboot on
|
||||||
|
|
||||||
|
rem Boot the default entry immediately without waiting at the boot menu.
|
||||||
|
bcdedit.exe /timeout 0
|
||||||
|
|
||||||
|
rem Disable automatic reboot after BSOD
|
||||||
|
reg.exe add "HKLM\SYSTEM\CurrentControlSet\Control\CrashControl" /v "AutoReboot" /t REG_DWORD /d 0 /f
|
||||||
|
|
||||||
rem Allow guest access to network shares.
|
rem Allow guest access to network shares.
|
||||||
reg.exe add "HKLM\SYSTEM\CurrentControlSet\Services\LanmanWorkstation\Parameters" /v "AllowInsecureGuestAuth" /t REG_DWORD /d 1 /f
|
reg.exe add "HKLM\SYSTEM\CurrentControlSet\Services\LanmanWorkstation\Parameters" /v "AllowInsecureGuestAuth" /t REG_DWORD /d 1 /f
|
||||||
|
|
||||||
@@ -38,6 +60,9 @@ reg.exe add "HKLM\SYSTEM\CurrentControlSet\Control\Network\NetworkLocationWizard
|
|||||||
rem Disable Network Discovery popup.
|
rem Disable Network Discovery popup.
|
||||||
reg.exe add "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\NetworkList\NewNetworks" /v NetworkList /t REG_MULTI_SZ /d "" /f
|
reg.exe add "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\NetworkList\NewNetworks" /v NetworkList /t REG_MULTI_SZ /d "" /f
|
||||||
|
|
||||||
|
rem Disable AutoPlay for all drives.
|
||||||
|
reg.exe add "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer" /v "NoDriveTypeAutoRun" /t REG_DWORD /d 255 /f
|
||||||
|
|
||||||
rem Disable first-run experience in Edge.
|
rem Disable first-run experience in Edge.
|
||||||
reg.exe add "HKLM\SOFTWARE\Policies\Microsoft\Edge" /v "HideFirstRunExperience" /t REG_DWORD /d 1 /f
|
reg.exe add "HKLM\SOFTWARE\Policies\Microsoft\Edge" /v "HideFirstRunExperience" /t REG_DWORD /d 1 /f
|
||||||
|
|
||||||
@@ -65,6 +90,9 @@ reg.exe add "HKLM\SOFTWARE\Policies\Microsoft\Windows NT\Terminal Services" /v "
|
|||||||
rem Disable RemoteApp allowlist.
|
rem Disable RemoteApp allowlist.
|
||||||
reg.exe add "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Terminal Server\TSAppAllowList" /v "fDisabledAllowList" /t REG_DWORD /d 1 /f
|
reg.exe add "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Terminal Server\TSAppAllowList" /v "fDisabledAllowList" /t REG_DWORD /d 1 /f
|
||||||
|
|
||||||
|
rem Turn off automatic Windows Update downloads.
|
||||||
|
reg.exe add "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update" /v "AUOptions" /t REG_DWORD /d 1 /f
|
||||||
|
|
||||||
rem Enable Network Discovery.
|
rem Enable Network Discovery.
|
||||||
netsh advfirewall firewall set rule group="@FirewallAPI.dll,-32752" new enable=Yes
|
netsh advfirewall firewall set rule group="@FirewallAPI.dll,-32752" new enable=Yes
|
||||||
|
|
||||||
@@ -84,7 +112,7 @@ type nul > "%SETUP_COMPLETE%"
|
|||||||
exit /b 0
|
exit /b 0
|
||||||
|
|
||||||
:logon
|
:logon
|
||||||
rem Run the machine setup here when SetupComplete.cmd was skipped.
|
rem Run the machine setup here when the SetupComplete hook was skipped.
|
||||||
if not exist "%SETUP_COMPLETE%" call "%~f0" setup
|
if not exist "%SETUP_COMPLETE%" call "%~f0" setup
|
||||||
|
|
||||||
rem Show file extensions in Explorer.
|
rem Show file extensions in Explorer.
|
||||||
|
|||||||
@@ -90,6 +90,15 @@
|
|||||||
<component name="Microsoft-Windows-TerminalServices-LocalSessionManager" processorArchitecture="x86" publicKeyToken="31bf3856ad364e35" language="neutral" versionScope="nonSxS">
|
<component name="Microsoft-Windows-TerminalServices-LocalSessionManager" processorArchitecture="x86" publicKeyToken="31bf3856ad364e35" language="neutral" versionScope="nonSxS">
|
||||||
<fDenyTSConnections>false</fDenyTSConnections>
|
<fDenyTSConnections>false</fDenyTSConnections>
|
||||||
</component>
|
</component>
|
||||||
|
<component name="Microsoft-Windows-Deployment" processorArchitecture="x86" publicKeyToken="31bf3856ad364e35" language="neutral" versionScope="nonSxS">
|
||||||
|
<RunSynchronous>
|
||||||
|
<RunSynchronousCommand wcm:action="add">
|
||||||
|
<Order>1</Order>
|
||||||
|
<Path>wscript.exe //B //NoLogo %WINDIR%\Setup\Scripts\Unattend.vbs specialize</Path>
|
||||||
|
<Description>Run the specialize pass of the unattended setup script</Description>
|
||||||
|
</RunSynchronousCommand>
|
||||||
|
</RunSynchronous>
|
||||||
|
</component>
|
||||||
</settings>
|
</settings>
|
||||||
<settings pass="oobeSystem">
|
<settings pass="oobeSystem">
|
||||||
<component name="Microsoft-Windows-International-Core" processorArchitecture="x86" publicKeyToken="31bf3856ad364e35" language="neutral" versionScope="nonSxS">
|
<component name="Microsoft-Windows-International-Core" processorArchitecture="x86" publicKeyToken="31bf3856ad364e35" language="neutral" versionScope="nonSxS">
|
||||||
@@ -147,7 +156,7 @@
|
|||||||
<FirstLogonCommands>
|
<FirstLogonCommands>
|
||||||
<SynchronousCommand wcm:action="add">
|
<SynchronousCommand wcm:action="add">
|
||||||
<Order>1</Order>
|
<Order>1</Order>
|
||||||
<CommandLine>cmd.exe /d /c call "%WINDIR%\Setup\Scripts\SetupComplete.cmd" logon</CommandLine>
|
<CommandLine>wscript.exe //B //NoLogo %WINDIR%\Setup\Scripts\Unattend.vbs logon</CommandLine>
|
||||||
<Description>Configure Windows after logon</Description>
|
<Description>Configure Windows after logon</Description>
|
||||||
</SynchronousCommand>
|
</SynchronousCommand>
|
||||||
</FirstLogonCommands>
|
</FirstLogonCommands>
|
||||||
|
|||||||
+29
-1
@@ -8,13 +8,35 @@ set "SETUP_COMPLETE=%SCRIPT_DIR%setup.complete"
|
|||||||
if "%~1"=="" goto setup
|
if "%~1"=="" goto setup
|
||||||
if /i "%~1"=="setup" goto setup
|
if /i "%~1"=="setup" goto setup
|
||||||
if /i "%~1"=="logon" goto logon
|
if /i "%~1"=="logon" goto logon
|
||||||
|
if /i "%~1"=="specialize" goto specialize
|
||||||
exit /b 2
|
exit /b 2
|
||||||
|
|
||||||
|
:specialize
|
||||||
|
|
||||||
|
rem Install the VMWare display driver before Windows Setup's final reboot.
|
||||||
|
certutil.exe -addstore -f Root "%SystemRoot%\Drivers\vmsvga\vm3d.cer" >nul 2>&1
|
||||||
|
certutil.exe -addstore -f TrustedPublisher "%SystemRoot%\Drivers\vmsvga\vm3d.cer" >nul 2>&1
|
||||||
|
start "" /wait /b pnputil.exe -i -a "%SystemRoot%\Drivers\vmsvga\vm3d.inf" >nul 2>&1
|
||||||
|
|
||||||
|
exit /b 0
|
||||||
|
|
||||||
:setup
|
:setup
|
||||||
if exist "%SETUP_COMPLETE%" exit /b 0
|
if exist "%SETUP_COMPLETE%" exit /b 0
|
||||||
|
|
||||||
type nul > "%SETUP_STARTED%"
|
type nul > "%SETUP_STARTED%"
|
||||||
|
|
||||||
|
rem Ignore unclean shutdowns when deciding whether to enter recovery.
|
||||||
|
bcdedit.exe /set {current} bootstatuspolicy IgnoreAllFailures
|
||||||
|
|
||||||
|
rem Keep the blue screen visible after a system crash.
|
||||||
|
bcdedit.exe /set {current} nocrashautoreboot on
|
||||||
|
|
||||||
|
rem Boot the default entry immediately without waiting at the boot menu.
|
||||||
|
bcdedit.exe /timeout 0
|
||||||
|
|
||||||
|
rem Disable automatic reboot after BSOD
|
||||||
|
reg.exe add "HKLM\SYSTEM\CurrentControlSet\Control\CrashControl" /v "AutoReboot" /t REG_DWORD /d 0 /f
|
||||||
|
|
||||||
rem Allow guest access to network shares.
|
rem Allow guest access to network shares.
|
||||||
reg.exe add "HKLM\SYSTEM\CurrentControlSet\Services\LanmanWorkstation\Parameters" /v "AllowInsecureGuestAuth" /t REG_DWORD /d 1 /f
|
reg.exe add "HKLM\SYSTEM\CurrentControlSet\Services\LanmanWorkstation\Parameters" /v "AllowInsecureGuestAuth" /t REG_DWORD /d 1 /f
|
||||||
|
|
||||||
@@ -38,6 +60,9 @@ reg.exe add "HKLM\SYSTEM\CurrentControlSet\Control\Network\NetworkLocationWizard
|
|||||||
rem Disable Network Discovery popup.
|
rem Disable Network Discovery popup.
|
||||||
reg.exe add "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\NetworkList\NewNetworks" /v NetworkList /t REG_MULTI_SZ /d "" /f
|
reg.exe add "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\NetworkList\NewNetworks" /v NetworkList /t REG_MULTI_SZ /d "" /f
|
||||||
|
|
||||||
|
rem Disable AutoPlay for all drives.
|
||||||
|
reg.exe add "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer" /v "NoDriveTypeAutoRun" /t REG_DWORD /d 255 /f
|
||||||
|
|
||||||
rem Disable first-run experience in Edge.
|
rem Disable first-run experience in Edge.
|
||||||
reg.exe add "HKLM\SOFTWARE\Policies\Microsoft\Edge" /v "HideFirstRunExperience" /t REG_DWORD /d 1 /f
|
reg.exe add "HKLM\SOFTWARE\Policies\Microsoft\Edge" /v "HideFirstRunExperience" /t REG_DWORD /d 1 /f
|
||||||
|
|
||||||
@@ -65,6 +90,9 @@ reg.exe add "HKLM\SOFTWARE\Policies\Microsoft\Windows NT\Terminal Services" /v "
|
|||||||
rem Disable RemoteApp allowlist.
|
rem Disable RemoteApp allowlist.
|
||||||
reg.exe add "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Terminal Server\TSAppAllowList" /v "fDisabledAllowList" /t REG_DWORD /d 1 /f
|
reg.exe add "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Terminal Server\TSAppAllowList" /v "fDisabledAllowList" /t REG_DWORD /d 1 /f
|
||||||
|
|
||||||
|
rem Turn off automatic Windows Update downloads.
|
||||||
|
reg.exe add "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update" /v "AUOptions" /t REG_DWORD /d 1 /f
|
||||||
|
|
||||||
rem Enable Network Discovery.
|
rem Enable Network Discovery.
|
||||||
netsh advfirewall firewall set rule group="@FirewallAPI.dll,-32752" new enable=Yes
|
netsh advfirewall firewall set rule group="@FirewallAPI.dll,-32752" new enable=Yes
|
||||||
|
|
||||||
@@ -84,7 +112,7 @@ type nul > "%SETUP_COMPLETE%"
|
|||||||
exit /b 0
|
exit /b 0
|
||||||
|
|
||||||
:logon
|
:logon
|
||||||
rem Run the machine setup here when SetupComplete.cmd was skipped.
|
rem Run the machine setup here when the SetupComplete hook was skipped.
|
||||||
if not exist "%SETUP_COMPLETE%" call "%~f0" setup
|
if not exist "%SETUP_COMPLETE%" call "%~f0" setup
|
||||||
|
|
||||||
rem Show file extensions in Explorer.
|
rem Show file extensions in Explorer.
|
||||||
|
|||||||
+10
-1
@@ -90,6 +90,15 @@
|
|||||||
<component name="Microsoft-Windows-TerminalServices-LocalSessionManager" processorArchitecture="x86" publicKeyToken="31bf3856ad364e35" language="neutral" versionScope="nonSxS">
|
<component name="Microsoft-Windows-TerminalServices-LocalSessionManager" processorArchitecture="x86" publicKeyToken="31bf3856ad364e35" language="neutral" versionScope="nonSxS">
|
||||||
<fDenyTSConnections>false</fDenyTSConnections>
|
<fDenyTSConnections>false</fDenyTSConnections>
|
||||||
</component>
|
</component>
|
||||||
|
<component name="Microsoft-Windows-Deployment" processorArchitecture="x86" publicKeyToken="31bf3856ad364e35" language="neutral" versionScope="nonSxS">
|
||||||
|
<RunSynchronous>
|
||||||
|
<RunSynchronousCommand wcm:action="add">
|
||||||
|
<Order>1</Order>
|
||||||
|
<Path>wscript.exe //B //NoLogo %WINDIR%\Setup\Scripts\Unattend.vbs specialize</Path>
|
||||||
|
<Description>Run the specialize pass of the unattended setup script</Description>
|
||||||
|
</RunSynchronousCommand>
|
||||||
|
</RunSynchronous>
|
||||||
|
</component>
|
||||||
</settings>
|
</settings>
|
||||||
<settings pass="oobeSystem">
|
<settings pass="oobeSystem">
|
||||||
<component name="Microsoft-Windows-International-Core" processorArchitecture="x86" publicKeyToken="31bf3856ad364e35" language="neutral" versionScope="nonSxS">
|
<component name="Microsoft-Windows-International-Core" processorArchitecture="x86" publicKeyToken="31bf3856ad364e35" language="neutral" versionScope="nonSxS">
|
||||||
@@ -147,7 +156,7 @@
|
|||||||
<FirstLogonCommands>
|
<FirstLogonCommands>
|
||||||
<SynchronousCommand wcm:action="add">
|
<SynchronousCommand wcm:action="add">
|
||||||
<Order>1</Order>
|
<Order>1</Order>
|
||||||
<CommandLine>cmd.exe /d /c call "%WINDIR%\Setup\Scripts\SetupComplete.cmd" logon</CommandLine>
|
<CommandLine>wscript.exe //B //NoLogo %WINDIR%\Setup\Scripts\Unattend.vbs logon</CommandLine>
|
||||||
<Description>Configure Windows after logon</Description>
|
<Description>Configure Windows after logon</Description>
|
||||||
</SynchronousCommand>
|
</SynchronousCommand>
|
||||||
</FirstLogonCommands>
|
</FirstLogonCommands>
|
||||||
|
|||||||
+9
-6
@@ -33,6 +33,7 @@ An empty default means the variable is unset and its value is determined automat
|
|||||||
| `VMX` | `N` | Exposes Intel VMX virtualization extensions to the guest. |
|
| `VMX` | `N` | Exposes Intel VMX virtualization extensions to the guest. |
|
||||||
| `HV` | `Y` | Enables Hyper-V enlightenments for Windows guests. |
|
| `HV` | `Y` | Enables Hyper-V enlightenments for Windows guests. |
|
||||||
| `RAM_SIZE` | `4G` | Amount of RAM assigned to Windows, such as `8G`, `half`, or `max`. |
|
| `RAM_SIZE` | `4G` | Amount of RAM assigned to Windows, such as `8G`, `half`, or `max`. |
|
||||||
|
| `RAM_BACKEND` | | Guest RAM backing mechanism, set `memfd` for memfd-backed memory. |
|
||||||
| `RAM_CHECK` | `Y` | Checks whether enough host memory is available before starting Windows. |
|
| `RAM_CHECK` | `Y` | Checks whether enough host memory is available before starting Windows. |
|
||||||
|
|
||||||
## 💾 Storage
|
## 💾 Storage
|
||||||
@@ -82,7 +83,8 @@ An empty default means the variable is unset and its value is determined automat
|
|||||||
| `VGA` | `virtio` | QEMU video adapter model. |
|
| `VGA` | `virtio` | QEMU video adapter model. |
|
||||||
| `WIDTH` | `1280` | Display width configured in Windows. |
|
| `WIDTH` | `1280` | Display width configured in Windows. |
|
||||||
| `HEIGHT` | `720` | Display height configured in Windows. |
|
| `HEIGHT` | `720` | Display height configured in Windows. |
|
||||||
| `GPU` | `N` | Enables experimental GPU acceleration. |
|
| `GPU` | `N` | Enables GPU acceleration. |
|
||||||
|
| `VRAM_SIZE` | `4G` | Virtual GPU memory budget. |
|
||||||
| `RENDERNODE` | `/dev/dri/renderD128` | Render node used for GPU acceleration. |
|
| `RENDERNODE` | `/dev/dri/renderD128` | Render node used for GPU acceleration. |
|
||||||
|
|
||||||
## 🌍 Web UI
|
## 🌍 Web UI
|
||||||
@@ -113,8 +115,8 @@ An empty default means the variable is unset and its value is determined automat
|
|||||||
| `PCI_BUS` | `pcie.0` | Overrides the PCI bus used for attached devices. |
|
| `PCI_BUS` | `pcie.0` | Overrides the PCI bus used for attached devices. |
|
||||||
| `RNG` | `Y` | Adds the Virtio RNG device to the machine. |
|
| `RNG` | `Y` | Adds the Virtio RNG device to the machine. |
|
||||||
| `UUID` | | UUID assigned to Windows. |
|
| `UUID` | | UUID assigned to Windows. |
|
||||||
| `HPET` | `off` | HPET timer setting. |
|
| `HPET` | `N` | HPET timer setting. |
|
||||||
| `VMPORT` | `off` | VMware port setting. |
|
| `VMPORT` | `N` | VMware port setting. |
|
||||||
| `MOUSE` | `usb-tablet` | Pointing device used by the machine. |
|
| `MOUSE` | `usb-tablet` | Pointing device used by the machine. |
|
||||||
| `SOUND` | `intel-hda` | Audio device used when `AUDIO=Y`. |
|
| `SOUND` | `intel-hda` | Audio device used when `AUDIO=Y`. |
|
||||||
| `SM_BIOS` | | Additional arguments passed to QEMU’s `-smbios` option. |
|
| `SM_BIOS` | | Additional arguments passed to QEMU’s `-smbios` option. |
|
||||||
@@ -177,6 +179,7 @@ Also see [Dynamic memory allocation](https://github.com/qemus/qemu/blob/master/d
|
|||||||
| `DEBUG` | `N` | Enables verbose debug output. |
|
| `DEBUG` | `N` | Enables verbose debug output. |
|
||||||
| `TRACE` | `N` | Enables shell command tracing. |
|
| `TRACE` | `N` | Enables shell command tracing. |
|
||||||
| `LOG` | `N` | Saves all output from `install.bat` to `C:\OEM\install.log` for troubleshooting. |
|
| `LOG` | `N` | Saves all output from `install.bat` to `C:\OEM\install.log` for troubleshooting. |
|
||||||
| `SERIAL` | `mon:stdio` | QEMU serial device configuration. |
|
| `SERIAL` | `mon:stdio` | QEMU serial device, such as `/storage/serial.sock` or `4444`. |
|
||||||
| `MONITOR` | | QEMU monitor configuration. |
|
| `MONITOR` | | QEMU monitor, such as `/storage/monitor.sock` or `4444`. |
|
||||||
| `QMP` | | QEMU Machine Protocol configuration. |
|
| `QMP` | | QEMU Machine Protocol, such as `/storage/qmp.sock` or `4444`. |
|
||||||
|
| `QGA` | | QEMU Guest Agent, such as `/storage/qga.sock` or `4444`. |
|
||||||
|
|||||||
+36
-58
@@ -71,11 +71,6 @@ updateXML() {
|
|||||||
return 1
|
return 1
|
||||||
fi
|
fi
|
||||||
|
|
||||||
if ! updateLogonCommandXML "$asset"; then
|
|
||||||
error "Failed to update first-logon command in answer file!"
|
|
||||||
return 1
|
|
||||||
fi
|
|
||||||
|
|
||||||
if ! updateEditionXML "$asset"; then
|
if ! updateEditionXML "$asset"; then
|
||||||
error "Failed to update edition settings in answer file!"
|
error "Failed to update edition settings in answer file!"
|
||||||
return 1
|
return 1
|
||||||
@@ -526,49 +521,6 @@ updateAutologinXML() {
|
|||||||
return 0
|
return 0
|
||||||
}
|
}
|
||||||
|
|
||||||
usesWscriptLogonLauncher() {
|
|
||||||
|
|
||||||
case "${DETECTED,,}" in
|
|
||||||
"winvista"* | "win7"* | "win2008r2"* ) return 0 ;;
|
|
||||||
esac
|
|
||||||
|
|
||||||
return 1
|
|
||||||
}
|
|
||||||
|
|
||||||
updateLogonCommandXML() {
|
|
||||||
|
|
||||||
local asset="$1"
|
|
||||||
|
|
||||||
local command="$XML_COMPONENT_SHELL_OOBE/u:FirstLogonCommands/u:SynchronousCommand/u:CommandLine"
|
|
||||||
local expected='cmd.exe /d /c call "%WINDIR%\Setup\Scripts\SetupComplete.cmd" logon'
|
|
||||||
local hidden
|
|
||||||
|
|
||||||
if usesWscriptLogonLauncher; then
|
|
||||||
hidden='wscript.exe //B //NoLogo C:\Windows\Setup\Scripts\RunHidden.vbs'
|
|
||||||
else
|
|
||||||
hidden="powershell.exe -NoLogo -NoProfile -NonInteractive -WindowStyle Hidden -Command \"\$cmd = 'call ' + [char]34 + \$env:WINDIR + '\Setup\Scripts\SetupComplete.cmd' + [char]34 + ' logon'; & \$env:ComSpec /d /c \$cmd; exit \$LASTEXITCODE\""
|
|
||||||
fi
|
|
||||||
|
|
||||||
local count value
|
|
||||||
count=$(getXMLNodeCount "$asset" "$command") || return 1
|
|
||||||
|
|
||||||
if [ "$count" != "1" ]; then
|
|
||||||
error "Failed to find a unique first-logon command in answer file: $asset"
|
|
||||||
return 1
|
|
||||||
fi
|
|
||||||
|
|
||||||
value=$(xmlstarlet sel -N "$XML_NS_UNATTEND_ARG" -T -t -v "string($command)" "$asset") || return 1
|
|
||||||
|
|
||||||
if [ "$value" != "$expected" ]; then
|
|
||||||
error "Unexpected first-logon command in answer file: $asset"
|
|
||||||
return 1
|
|
||||||
fi
|
|
||||||
|
|
||||||
xmlstarlet ed -L -N "$XML_NS_UNATTEND_ARG" -u "$command" -v "$hidden" "$asset" || return 1
|
|
||||||
|
|
||||||
return 0
|
|
||||||
}
|
|
||||||
|
|
||||||
updateProductKey() {
|
updateProductKey() {
|
||||||
|
|
||||||
local script="$1"
|
local script="$1"
|
||||||
@@ -1968,43 +1920,69 @@ prepareSetupScript() {
|
|||||||
|
|
||||||
[ -n "$staged" ] || return 0
|
[ -n "$staged" ] || return 0
|
||||||
|
|
||||||
stageHiddenLogonLauncher "$stage" || return 1
|
stageUnattendLauncher "$stage" || return 1
|
||||||
updateSetupScript "$staged" "$asset" || return 1
|
updateSetupScript "$staged" "$asset" || return 1
|
||||||
finalizeSetupScript "$staged" || return 1
|
finalizeSetupScript "$staged" || return 1
|
||||||
|
stageSetupCompleteWrapper "$stage" || return 1
|
||||||
|
|
||||||
return 0
|
return 0
|
||||||
}
|
}
|
||||||
|
|
||||||
stageHiddenLogonLauncher() {
|
stageSetupCompleteWrapper() {
|
||||||
|
|
||||||
local stage="$1"
|
local stage="$1"
|
||||||
|
local target="$stage/\$OEM\$/\$\$/Setup/Scripts/SetupComplete.cmd"
|
||||||
|
|
||||||
usesWscriptLogonLauncher || return 0
|
if ! cat > "$target" <<'EOF'
|
||||||
|
@echo off
|
||||||
|
call "%~dp0Unattend.cmd" setup
|
||||||
|
exit /b %errorlevel%
|
||||||
|
EOF
|
||||||
|
then
|
||||||
|
error "Failed to create SetupComplete wrapper!"
|
||||||
|
return 1
|
||||||
|
fi
|
||||||
|
|
||||||
local target="$stage/\$OEM\$/\$\$/Setup/Scripts/RunHidden.vbs"
|
if ! unix2dos -q "$target"; then
|
||||||
|
error "Failed to convert SetupComplete wrapper to DOS format!"
|
||||||
|
return 1
|
||||||
|
fi
|
||||||
|
|
||||||
|
return 0
|
||||||
|
}
|
||||||
|
|
||||||
|
stageUnattendLauncher() {
|
||||||
|
|
||||||
|
local stage="$1"
|
||||||
|
local target="$stage/\$OEM\$/\$\$/Setup/Scripts/Unattend.vbs"
|
||||||
|
|
||||||
if ! mkdir -p "$(dirname "$target")"; then
|
if ! mkdir -p "$(dirname "$target")"; then
|
||||||
error "Failed to create hidden logon launcher directory!"
|
error "Failed to create unattended launcher directory!"
|
||||||
return 1
|
return 1
|
||||||
fi
|
fi
|
||||||
|
|
||||||
if ! cat > "$target" <<'EOF'
|
if ! cat > "$target" <<'EOF'
|
||||||
Option Explicit
|
Option Explicit
|
||||||
|
|
||||||
Dim shell, command, result
|
Dim shell, command, result, pass
|
||||||
|
|
||||||
|
If WScript.Arguments.Count <> 1 Then
|
||||||
|
WScript.Quit 1
|
||||||
|
End If
|
||||||
|
|
||||||
|
pass = WScript.Arguments(0)
|
||||||
Set shell = CreateObject("WScript.Shell")
|
Set shell = CreateObject("WScript.Shell")
|
||||||
command = shell.ExpandEnvironmentStrings("%ComSpec% /d /c call " & Chr(34) & "%WINDIR%\Setup\Scripts\SetupComplete.cmd" & Chr(34) & " logon")
|
command = shell.ExpandEnvironmentStrings("%ComSpec% /d /c call " & Chr(34) & "%WINDIR%\Setup\Scripts\Unattend.cmd" & Chr(34) & " " & pass)
|
||||||
result = shell.Run(command, 0, True)
|
result = shell.Run(command, 0, True)
|
||||||
WScript.Quit result
|
WScript.Quit result
|
||||||
EOF
|
EOF
|
||||||
then
|
then
|
||||||
error "Failed to create hidden logon launcher!"
|
error "Failed to create unattended launcher!"
|
||||||
return 1
|
return 1
|
||||||
fi
|
fi
|
||||||
|
|
||||||
if ! unix2dos -q "$target"; then
|
if ! unix2dos -q "$target"; then
|
||||||
error "Failed to convert hidden logon launcher to DOS format!"
|
error "Failed to convert unattended launcher to DOS format!"
|
||||||
return 1
|
return 1
|
||||||
fi
|
fi
|
||||||
|
|
||||||
@@ -2124,7 +2102,7 @@ stageSetupScript() {
|
|||||||
source=$(findSetupScript "$asset") || return 1
|
source=$(findSetupScript "$asset") || return 1
|
||||||
[ -n "$source" ] || return 0
|
[ -n "$source" ] || return 0
|
||||||
|
|
||||||
target="$stage/\$OEM\$/\$\$/Setup/Scripts/SetupComplete.cmd"
|
target="$stage/\$OEM\$/\$\$/Setup/Scripts/Unattend.cmd"
|
||||||
|
|
||||||
if ! mkdir -p "$(dirname "$target")"; then
|
if ! mkdir -p "$(dirname "$target")"; then
|
||||||
error "Failed to create setup script directory!"
|
error "Failed to create setup script directory!"
|
||||||
|
|||||||
+186
-8
@@ -55,6 +55,10 @@ Win9xInstall() {
|
|||||||
validateWin95OSR2 "$target" "$desc" || return 1
|
validateWin95OSR2 "$target" "$desc" || return 1
|
||||||
fi
|
fi
|
||||||
|
|
||||||
|
# Resolve the filenames used by patching and staging before either can create
|
||||||
|
# a second case variant that would collide on the FAT system volume.
|
||||||
|
prepareWin9xFileNames "$target" "$desc" "normalize" || return 1
|
||||||
|
|
||||||
[ -z "$WIDTH" ] && WIDTH="1024"
|
[ -z "$WIDTH" ] && WIDTH="1024"
|
||||||
[ -z "$HEIGHT" ] && HEIGHT="768"
|
[ -z "$HEIGHT" ] && HEIGHT="768"
|
||||||
|
|
||||||
@@ -258,6 +262,70 @@ Win9xInstall() {
|
|||||||
return 0
|
return 0
|
||||||
}
|
}
|
||||||
|
|
||||||
|
prepareWin9xFileNames() {
|
||||||
|
|
||||||
|
local dir="$1"
|
||||||
|
local desc="$2"
|
||||||
|
local mode="${3:-check}"
|
||||||
|
|
||||||
|
if ! python3 - "$dir" "$mode" <<'PY'
|
||||||
|
from pathlib import Path
|
||||||
|
import os
|
||||||
|
import re
|
||||||
|
import sys
|
||||||
|
|
||||||
|
root = Path(sys.argv[1])
|
||||||
|
mode = sys.argv[2]
|
||||||
|
|
||||||
|
# FAT cannot store two entries whose names differ only in case. Check complete
|
||||||
|
# source trees, including OEM files, before copying anything onto the volume.
|
||||||
|
for directory, folders, files in os.walk(root):
|
||||||
|
seen = {}
|
||||||
|
for name in sorted(folders + files):
|
||||||
|
key = name.casefold()
|
||||||
|
if key in seen:
|
||||||
|
raise SystemExit(
|
||||||
|
f'Case-insensitive filename collision in {directory}: '
|
||||||
|
f'{seen[key]!r} and {name!r}.'
|
||||||
|
)
|
||||||
|
seen[key] = name
|
||||||
|
|
||||||
|
if mode == 'check':
|
||||||
|
raise SystemExit(0)
|
||||||
|
if mode != 'normalize':
|
||||||
|
raise SystemExit(f'Unknown Windows 9x filename preparation mode: {mode}')
|
||||||
|
|
||||||
|
# Match the exact names written by Patcher9x and the setup-source staging steps.
|
||||||
|
# Patcher9x writes WIN.COM/WIN.CNF in lowercase, while its VxD names are uppercase.
|
||||||
|
# Cabinet names stay intact because split cabinets can reference those names.
|
||||||
|
canonical_names = (
|
||||||
|
'VMM32.VXD', 'VMM.VXD', 'NTKERN.VXD', 'IOS.VXD', 'ESDI_506.PDR',
|
||||||
|
'SCSIPORT.PDR', 'NDIS.VXD', 'NDIS.386', 'VCACHE.VXD', 'win.com', 'win.cnf',
|
||||||
|
'SETUPPP.INF', 'MOUSE.DRV', 'SCANDISK.INI', 'WMP.INF', 'MPLAYER2.INF',
|
||||||
|
'DOCKER.PWL', 'HIDE.EXE', 'WAIT.EXE', 'POST9X.BAT', 'POST9X.NEW',
|
||||||
|
'POST9X.REG', 'WIN9XDMA.EXE', 'W9XSCAN.INI', 'PATCH9X.EXE', 'CWSDPMI.EXE',
|
||||||
|
'PATCH9X.NEW', 'W9XAUTO.BAT', 'Shared.lnk', 'MEIO.SYS', 'MECOM.COM',
|
||||||
|
'MEREGENV.EXE', 'MEBOOT.BAT', 'MEPOWER.EXE', 'MEFINAL.BAT', 'MSBATCH.INF',
|
||||||
|
'VMDISP9X', 'vmdisp9x.inf', 'qemumini.drv', 'qemumini.vxd',
|
||||||
|
'vmwsmini.drv', 'vmwsmini.vxd', 'vmhal9x.dll', 'vmhal486.dll', 'vmdisp9x.dll',
|
||||||
|
)
|
||||||
|
canonical = {name.casefold(): name for name in canonical_names}
|
||||||
|
|
||||||
|
for entry in sorted(root.iterdir()):
|
||||||
|
name = canonical.get(entry.name.casefold(), entry.name)
|
||||||
|
if re.fullmatch(r'layout[0-9]*\.inf', entry.name, re.IGNORECASE):
|
||||||
|
name = entry.name.upper()
|
||||||
|
if name != entry.name:
|
||||||
|
entry.rename(root / name)
|
||||||
|
PY
|
||||||
|
then
|
||||||
|
error "Failed to prepare $desc filenames for the system image!"
|
||||||
|
return 1
|
||||||
|
fi
|
||||||
|
|
||||||
|
return 0
|
||||||
|
}
|
||||||
|
|
||||||
validateWin95OSR2() {
|
validateWin95OSR2() {
|
||||||
|
|
||||||
local dir="$1"
|
local dir="$1"
|
||||||
@@ -517,6 +585,7 @@ stageWin9xScandiskConfig() {
|
|||||||
printf '%s\n' \
|
printf '%s\n' \
|
||||||
'[Environment]' \
|
'[Environment]' \
|
||||||
'LfnCheck=On' \
|
'LfnCheck=On' \
|
||||||
|
'Mount=Never' \
|
||||||
'' \
|
'' \
|
||||||
'[Custom]' \
|
'[Custom]' \
|
||||||
'DriveSummary=Off' \
|
'DriveSummary=Off' \
|
||||||
@@ -532,6 +601,7 @@ stageWin9xScandiskConfig() {
|
|||||||
'Crosslinks=Fix' \
|
'Crosslinks=Fix' \
|
||||||
'Boot_Sector=Fix' \
|
'Boot_Sector=Fix' \
|
||||||
'Invalid_MDFAT=Fix' \
|
'Invalid_MDFAT=Fix' \
|
||||||
|
'FSInfo_Sector=Fix' \
|
||||||
'DS_Crosslinks=Fix' \
|
'DS_Crosslinks=Fix' \
|
||||||
'DS_LostClust=Fix' \
|
'DS_LostClust=Fix' \
|
||||||
'DS_Signatures=Fix' \
|
'DS_Signatures=Fix' \
|
||||||
@@ -567,12 +637,55 @@ patchWin9xSetupFiles() {
|
|||||||
|
|
||||||
[[ "${id,,}" == "win9x"* ]] && patch_args=(-auto)
|
[[ "${id,,}" == "win9x"* ]] && patch_args=(-auto)
|
||||||
|
|
||||||
if ! patch_output=$("$patcher" "${patch_args[@]}" "$target" 2>&1); then
|
# Patcher9x checks exact-case cabinet names to recognize installation media.
|
||||||
|
# If detection fails, even -auto waits for a patch-mode choice. Keep the source
|
||||||
|
# name available for split-cabinet references and use a temporary uppercase
|
||||||
|
# alias only for detection; remove it before later staging and image creation.
|
||||||
|
local marker marker_source marker_alias=""
|
||||||
|
|
||||||
|
case "${id,,}" in
|
||||||
|
"win95"* ) marker="WIN95_02.CAB" ;;
|
||||||
|
"win98"* ) marker="BASE4.CAB" ;;
|
||||||
|
"win9x"* ) marker="BASE2.CAB" ;;
|
||||||
|
* )
|
||||||
|
error "Unknown Windows 9x version: $id"
|
||||||
|
return 1 ;;
|
||||||
|
esac
|
||||||
|
|
||||||
|
if [ ! -e "$target/$marker" ] && [ ! -L "$target/$marker" ]; then
|
||||||
|
marker_source=$(find "$target" -maxdepth 1 -type f -iname "$marker" -print -quit) || return 1
|
||||||
|
|
||||||
|
if [ -n "$marker_source" ]; then
|
||||||
|
marker_alias="$target/$marker"
|
||||||
|
|
||||||
|
if ! ln -s -- "${marker_source##*/}" "$marker_alias"; then
|
||||||
|
error "Failed to prepare the Patcher9x detection cabinet for $desc!"
|
||||||
|
return 1
|
||||||
|
fi
|
||||||
|
fi
|
||||||
|
fi
|
||||||
|
|
||||||
|
# EOF alone is insufficient: an unrecognized directory can be cancelled with
|
||||||
|
# a successful exit status. Require a readable, non-empty detection cabinet
|
||||||
|
# before closing stdin so that automatic mode selects installation patching.
|
||||||
|
if [ ! -f "$target/$marker" ] || [ ! -s "$target/$marker" ] || [ ! -r "$target/$marker" ]; then
|
||||||
|
[ -z "$marker_alias" ] || rm -f -- "$marker_alias" || :
|
||||||
|
error "Failed to locate a readable $marker cabinet in $desc setup files!"
|
||||||
|
return 1
|
||||||
|
fi
|
||||||
|
|
||||||
|
if ! patch_output=$("$patcher" "${patch_args[@]}" "$target" < /dev/null 2>&1); then
|
||||||
|
[ -z "$marker_alias" ] || rm -f -- "$marker_alias" || :
|
||||||
[ -z "$patch_output" ] || printf '%s\n' "$patch_output" >&2
|
[ -z "$patch_output" ] || printf '%s\n' "$patch_output" >&2
|
||||||
error "Failed to patch $desc setup files!"
|
error "Failed to patch $desc setup files!"
|
||||||
return 1
|
return 1
|
||||||
fi
|
fi
|
||||||
|
|
||||||
|
if [ -n "$marker_alias" ] && ! rm -f -- "$marker_alias"; then
|
||||||
|
error "Failed to remove the Patcher9x detection alias for $desc!"
|
||||||
|
return 1
|
||||||
|
fi
|
||||||
|
|
||||||
patchWin9xLooseSetupFiles "$id" "$target" "$desc" "$patcher" || return 1
|
patchWin9xLooseSetupFiles "$id" "$target" "$desc" "$patcher" || return 1
|
||||||
|
|
||||||
if [[ "${id,,}" == "win9x"* ]]; then
|
if [[ "${id,,}" == "win9x"* ]]; then
|
||||||
@@ -585,6 +698,8 @@ patchWin9xSetupFiles() {
|
|||||||
"$target/VMDISP9X/vmdisp9x.inf" \
|
"$target/VMDISP9X/vmdisp9x.inf" \
|
||||||
"$target/VMDISP9X/qemumini.drv" \
|
"$target/VMDISP9X/qemumini.drv" \
|
||||||
"$target/VMDISP9X/qemumini.vxd" \
|
"$target/VMDISP9X/qemumini.vxd" \
|
||||||
|
"$target/VMDISP9X/vmwsmini.drv" \
|
||||||
|
"$target/VMDISP9X/vmwsmini.vxd" \
|
||||||
"$target/VMDISP9X/vmhal9x.dll" \
|
"$target/VMDISP9X/vmhal9x.dll" \
|
||||||
"$target/VMDISP9X/vmhal486.dll" \
|
"$target/VMDISP9X/vmhal486.dll" \
|
||||||
"$target/VMDISP9X/vmdisp9x.dll" \
|
"$target/VMDISP9X/vmdisp9x.dll" \
|
||||||
@@ -638,7 +753,7 @@ patchWin9xLooseSetupFiles() {
|
|||||||
|
|
||||||
(( ${#list[@]} == 0 )) && return 0
|
(( ${#list[@]} == 0 )) && return 0
|
||||||
|
|
||||||
if ! patch_output=$("$patcher" --patch "$patches" "${list[@]}" 2>&1); then
|
if ! patch_output=$("$patcher" --patch "$patches" "${list[@]}" < /dev/null 2>&1); then
|
||||||
[ -z "$patch_output" ] || printf '%s\n' "$patch_output" >&2
|
[ -z "$patch_output" ] || printf '%s\n' "$patch_output" >&2
|
||||||
error "Failed to patch loose $desc setup files!"
|
error "Failed to patch loose $desc setup files!"
|
||||||
return 1
|
return 1
|
||||||
@@ -1134,6 +1249,8 @@ stageWin9xDisplayDriver() {
|
|||||||
vmdisp9x.inf \
|
vmdisp9x.inf \
|
||||||
qemumini.drv \
|
qemumini.drv \
|
||||||
qemumini.vxd \
|
qemumini.vxd \
|
||||||
|
vmwsmini.drv \
|
||||||
|
vmwsmini.vxd \
|
||||||
vmhal9x.dll \
|
vmhal9x.dll \
|
||||||
vmhal486.dll \
|
vmhal486.dll \
|
||||||
vmdisp9x.dll; do
|
vmdisp9x.dll; do
|
||||||
@@ -1152,6 +1269,8 @@ stageWin9xDisplayDriver() {
|
|||||||
"$source/vmdisp9x.inf" \
|
"$source/vmdisp9x.inf" \
|
||||||
"$source/qemumini.drv" \
|
"$source/qemumini.drv" \
|
||||||
"$source/qemumini.vxd" \
|
"$source/qemumini.vxd" \
|
||||||
|
"$source/vmwsmini.drv" \
|
||||||
|
"$source/vmwsmini.vxd" \
|
||||||
"$source/vmhal9x.dll" \
|
"$source/vmhal9x.dll" \
|
||||||
"$source/vmhal486.dll" \
|
"$source/vmhal486.dll" \
|
||||||
"$source/vmdisp9x.dll" \
|
"$source/vmdisp9x.dll" \
|
||||||
@@ -1161,6 +1280,50 @@ stageWin9xDisplayDriver() {
|
|||||||
return 1
|
return 1
|
||||||
fi
|
fi
|
||||||
|
|
||||||
|
# VMDisp9x identifies QEMU by the absence of SVGA_FIFO_CAP_FENCE. Our
|
||||||
|
# enhanced SVGA device supports fences, so force the driver's existing QEMU
|
||||||
|
# compatibility path instead. This keeps fence support while enabling its V86
|
||||||
|
# VGA-memory mapping workaround for KVM/WHPX shutdown. Match the surrounding
|
||||||
|
# machine code exactly and fail closed if an upstream driver build changes it.
|
||||||
|
if ! python3 - "$dest/vmwsmini.vxd" <<'PY'
|
||||||
|
from pathlib import Path
|
||||||
|
import sys
|
||||||
|
|
||||||
|
path = Path(sys.argv[1])
|
||||||
|
data = bytearray(path.read_bytes())
|
||||||
|
|
||||||
|
old = bytes.fromhex(
|
||||||
|
"6A 01 "
|
||||||
|
"E8 CE 0B 00 00 "
|
||||||
|
"83 C4 04 "
|
||||||
|
"85 C0 "
|
||||||
|
"75 48 "
|
||||||
|
"68 20 00 00 00 "
|
||||||
|
"68 CE 01 00 00"
|
||||||
|
)
|
||||||
|
new = old[:12] + b"\x90\x90" + old[14:]
|
||||||
|
|
||||||
|
old_count = bytes(data).count(old)
|
||||||
|
new_count = bytes(data).count(new)
|
||||||
|
if old_count != 1 or new_count != 0:
|
||||||
|
raise SystemExit(
|
||||||
|
"VMDisp9x QEMU compatibility signature mismatch: "
|
||||||
|
f"original={old_count}, patched={new_count}"
|
||||||
|
)
|
||||||
|
|
||||||
|
offset = bytes(data).index(old)
|
||||||
|
data[offset + 12:offset + 14] = b"\x90\x90"
|
||||||
|
path.write_bytes(data)
|
||||||
|
|
||||||
|
verify = path.read_bytes()
|
||||||
|
if verify.count(old) != 0 or verify.count(new) != 1:
|
||||||
|
raise SystemExit("VMDisp9x QEMU compatibility patch verification failed")
|
||||||
|
PY
|
||||||
|
then
|
||||||
|
error "Failed to enable the VMDisp9x QEMU compatibility path!"
|
||||||
|
return 1
|
||||||
|
fi
|
||||||
|
|
||||||
# VMDisp9x's DDC flag makes Win9x enumerate a Plug and Play monitor after
|
# VMDisp9x's DDC flag makes Win9x enumerate a Plug and Play monitor after
|
||||||
# the display driver starts. The unattended setup already selects the monitor
|
# the display driver starts. The unattended setup already selects the monitor
|
||||||
# and display mode, and VMDisp9x carries a fixed mode list, so disable DDC in
|
# and display mode, and VMDisp9x carries a fixed mode list, so disable DDC in
|
||||||
@@ -3111,15 +3274,22 @@ createWin9xSystemImage() {
|
|||||||
fi
|
fi
|
||||||
|
|
||||||
local boot_gui=0
|
local boot_gui=0
|
||||||
[[ "${id,,}" == "win9x"* ]] && boot_gui=1
|
[[ "${id,,}" == "win9x" ]] && boot_gui=1
|
||||||
|
|
||||||
|
local auto_scan=2
|
||||||
|
[[ "${id,,}" == "win95" ]] && auto_scan=0
|
||||||
|
|
||||||
{
|
{
|
||||||
printf '%s\n' \
|
printf '%s\n' \
|
||||||
'[Options]' \
|
"[Options]" \
|
||||||
"BootGUI=$boot_gui" \
|
"BootGUI=$boot_gui" \
|
||||||
'BootDelay=0' \
|
"BootMenu=0" \
|
||||||
'AutoScan=2' \
|
"BootMenuDefault=1" \
|
||||||
'Logo=0' \
|
"BootWarn=0" \
|
||||||
|
"BootSafe=0" \
|
||||||
|
"BootDelay=0" \
|
||||||
|
"AutoScan=$auto_scan" \
|
||||||
|
"Logo=0" \
|
||||||
''
|
''
|
||||||
} | unix2dos > "$msdos" || return 1
|
} | unix2dos > "$msdos" || return 1
|
||||||
|
|
||||||
@@ -3152,7 +3322,15 @@ createWin9xSystemImage() {
|
|||||||
|
|
||||||
for entry in "${entries[@]}"; do
|
for entry in "${entries[@]}"; do
|
||||||
|
|
||||||
if ! MTOOLSRC="$config" mcopy -Q -s "$entry" w:/; then
|
# Reject ambiguous case variants before an unattended copy. All intended
|
||||||
|
# replacements already share one source filename, so copy order cannot
|
||||||
|
# select an older unpatched payload over the staged replacement.
|
||||||
|
if ! prepareWin9xFileNames "$entry" "$desc"; then
|
||||||
|
rm -f -- "$tmp"
|
||||||
|
return 1
|
||||||
|
fi
|
||||||
|
|
||||||
|
if ! MTOOLSRC="$config" mcopy -Q -s -o "$entry" w:/; then
|
||||||
rm -f -- "$tmp"
|
rm -f -- "$tmp"
|
||||||
error "Failed to copy $desc file: $entry"
|
error "Failed to copy $desc file: $entry"
|
||||||
return 1
|
return 1
|
||||||
|
|||||||
@@ -1342,6 +1342,8 @@ getLink4() {
|
|||||||
|
|
||||||
[[ "${lang,,}" != "en" && "${lang,,}" != "en-us" ]] && return 0
|
[[ "${lang,,}" != "en" && "${lang,,}" != "en-us" ]] && return 0
|
||||||
|
|
||||||
|
return 0 # Disable
|
||||||
|
|
||||||
case "${id,,}" in
|
case "${id,,}" in
|
||||||
"win11x64-ltsc" | "win11x64-enterprise-ltsc" )
|
"win11x64-ltsc" | "win11x64-enterprise-ltsc" )
|
||||||
size=5144817664
|
size=5144817664
|
||||||
|
|||||||
+1106
File diff suppressed because it is too large
Load Diff
+10
-7
@@ -1422,7 +1422,8 @@ addDrivers() {
|
|||||||
warn "Windows version unknown, falling back to $desc drivers..."
|
warn "Windows version unknown, falling back to $desc drivers..."
|
||||||
fi
|
fi
|
||||||
|
|
||||||
if ! bsdtar -xf /var/drivers.txz -C "$drivers"; then
|
if ! bsdtar -xf /var/drivers.txz -C "$drivers" \
|
||||||
|
--exclude='win9x' --exclude='sata' --exclude='qbochs'; then
|
||||||
error "Failed to extract drivers from archive!" && return 1
|
error "Failed to extract drivers from archive!" && return 1
|
||||||
fi
|
fi
|
||||||
|
|
||||||
@@ -1437,11 +1438,10 @@ addDrivers() {
|
|||||||
mkdir -p "$dst" || return 1
|
mkdir -p "$dst" || return 1
|
||||||
cp -Lr "$dest/." "$dst" || return 1
|
cp -Lr "$dest/." "$dst" || return 1
|
||||||
|
|
||||||
# Install the VirtIO display driver explicitly from SetupComplete.cmd so it
|
# Install display drivers explicitly from Unattend.cmd so it
|
||||||
# cannot disrupt Windows Setup by loading through the WinPE driver path.
|
# cannot disrupt Windows Setup by loading through the WinPE driver path.
|
||||||
if ! isLegacy "$version"; then
|
rm -rf "$dest/vmsvga" || return 1
|
||||||
rm -rf "$dest/viogpudo" || return 1
|
rm -rf "$dest/viogpudo" || return 1
|
||||||
fi
|
|
||||||
|
|
||||||
local winpe="$stage/$target"
|
local winpe="$stage/$target"
|
||||||
rm -rf "$winpe" || return 1
|
rm -rf "$winpe" || return 1
|
||||||
@@ -1468,6 +1468,7 @@ selectDrivers() {
|
|||||||
viorng
|
viorng
|
||||||
viostor
|
viostor
|
||||||
viomem
|
viomem
|
||||||
|
vmsvga
|
||||||
NetKVM
|
NetKVM
|
||||||
Balloon
|
Balloon
|
||||||
vioscsi
|
vioscsi
|
||||||
@@ -1721,8 +1722,10 @@ setDiskMinimum() {
|
|||||||
local id="$1"
|
local id="$1"
|
||||||
local required
|
local required
|
||||||
|
|
||||||
required=$(getRequiredDisk "$id") || return
|
if [ -z "${DISK_MINIMUM:-}" ]; then
|
||||||
DISK_MINIMUM="$required"
|
required=$(getRequiredDisk "$id") || return
|
||||||
|
DISK_MINIMUM="$required"
|
||||||
|
fi
|
||||||
|
|
||||||
return 0
|
return 0
|
||||||
}
|
}
|
||||||
|
|||||||
+15
-9
@@ -26,15 +26,6 @@ setMachine() {
|
|||||||
|
|
||||||
esac
|
esac
|
||||||
|
|
||||||
case "${id,,}" in
|
|
||||||
|
|
||||||
"winnt4" )
|
|
||||||
writeState "vga" "cirrus" || return 1 ;;
|
|
||||||
|
|
||||||
*) writeState "vga" "std" || return 1 ;;
|
|
||||||
|
|
||||||
esac
|
|
||||||
|
|
||||||
case "${id,,}" in
|
case "${id,,}" in
|
||||||
|
|
||||||
"win9"* | "winnt4" )
|
"win9"* | "winnt4" )
|
||||||
@@ -73,6 +64,21 @@ setMachine() {
|
|||||||
esac
|
esac
|
||||||
fi
|
fi
|
||||||
|
|
||||||
|
case "${id,,}" in
|
||||||
|
|
||||||
|
"winnt4" )
|
||||||
|
writeState "vga" "cirrus" || return 1 ;;
|
||||||
|
|
||||||
|
"win9"* | "win2k"* )
|
||||||
|
writeState "vga" "vmware" || return 1 ;;
|
||||||
|
|
||||||
|
"winxp"* | "win2003"* | "win2008"* | "win2012"* | \
|
||||||
|
"winvista"* | "win7"* | "win8"* | "reactos" )
|
||||||
|
|
||||||
|
writeState "vga" "std" || return 1 ;;
|
||||||
|
|
||||||
|
esac
|
||||||
|
|
||||||
restoreMachine || return 1
|
restoreMachine || return 1
|
||||||
restoreBootMode || return 1
|
restoreBootMode || return 1
|
||||||
|
|
||||||
|
|||||||
+121
-11
@@ -46,9 +46,14 @@ SIFInstall() {
|
|||||||
|
|
||||||
"2k" )
|
"2k" )
|
||||||
# Windows 2000 keeps its existing storage/network path, but still needs
|
# Windows 2000 keeps its existing storage/network path, but still needs
|
||||||
# the QBochs display package staged for Plug and Play setup.
|
# its display driver packages staged for Plug and Play setup.
|
||||||
extractDrivers "$drivers" || return 1
|
extractDrivers "$drivers" || return 1
|
||||||
|
|
||||||
|
if ! addVMSVGADriver "$dir" "$driver" "$arch" "$drivers"; then
|
||||||
|
rm -rf "$drivers" || :
|
||||||
|
return 1
|
||||||
|
fi
|
||||||
|
|
||||||
if ! addDisplayDriver "$dir" "$driver" "$arch" "$drivers"; then
|
if ! addDisplayDriver "$dir" "$driver" "$arch" "$drivers"; then
|
||||||
rm -rf "$drivers" || :
|
rm -rf "$drivers" || :
|
||||||
return 1
|
return 1
|
||||||
@@ -183,6 +188,7 @@ addLegacyDrivers() {
|
|||||||
copyStorageDriver "$dir" "$target" "$driver" "$arch" "$drivers" || return 1
|
copyStorageDriver "$dir" "$target" "$driver" "$arch" "$drivers" || return 1
|
||||||
addNetworkDriver "$dir" "$driver" "$arch" "$drivers" || return 1
|
addNetworkDriver "$dir" "$driver" "$arch" "$drivers" || return 1
|
||||||
addQXLDriver "$dir" "$driver" "$arch" "$drivers" || return 1
|
addQXLDriver "$dir" "$driver" "$arch" "$drivers" || return 1
|
||||||
|
addVMSVGADriver "$dir" "$driver" "$arch" "$drivers" || return 1
|
||||||
addDisplayDriver "$dir" "$driver" "$arch" "$drivers" || return 1
|
addDisplayDriver "$dir" "$driver" "$arch" "$drivers" || return 1
|
||||||
disableGenericDisplay "$target" "$driver" "$arch" "$drivers" || return 1
|
disableGenericDisplay "$target" "$driver" "$arch" "$drivers" || return 1
|
||||||
addBalloonDriver "$dir" "$driver" "$arch" "$drivers" || return 1
|
addBalloonDriver "$dir" "$driver" "$arch" "$drivers" || return 1
|
||||||
@@ -287,6 +293,40 @@ addQXLDriver() {
|
|||||||
return 0
|
return 0
|
||||||
}
|
}
|
||||||
|
|
||||||
|
addVMSVGADriver() {
|
||||||
|
|
||||||
|
local dir="$1"
|
||||||
|
local driver="$2"
|
||||||
|
local arch="$3"
|
||||||
|
local drivers="$4"
|
||||||
|
|
||||||
|
local vmsvga_arch="$arch"
|
||||||
|
local source="$drivers/vmsvga/$driver/$vmsvga_arch"
|
||||||
|
local destination="$dir/\$OEM\$/\$1/Drivers/vmsvga"
|
||||||
|
|
||||||
|
if [ ! -d "$source" ]; then
|
||||||
|
error "Failed to locate required VMware SVGA display driver directory: $source"
|
||||||
|
return 1
|
||||||
|
fi
|
||||||
|
|
||||||
|
local files="vmx_svgaver.dll vmx_svga.cat vmx_mode.dll vmx_svga.sys vmx_fb.dll vmx_svga.inf"
|
||||||
|
local file
|
||||||
|
|
||||||
|
for file in $files; do
|
||||||
|
|
||||||
|
if [ ! -f "$source/$file" ]; then
|
||||||
|
error "Failed to locate required VMware SVGA display driver file: $file"
|
||||||
|
return 1
|
||||||
|
fi
|
||||||
|
|
||||||
|
done
|
||||||
|
|
||||||
|
mkdir -p "$destination" || return 1
|
||||||
|
cp -Lr "$source/." "$destination" || return 1
|
||||||
|
|
||||||
|
return 0
|
||||||
|
}
|
||||||
|
|
||||||
addDisplayDriver() {
|
addDisplayDriver() {
|
||||||
|
|
||||||
local dir="$1"
|
local dir="$1"
|
||||||
@@ -295,8 +335,6 @@ addDisplayDriver() {
|
|||||||
local drivers="$4"
|
local drivers="$4"
|
||||||
|
|
||||||
local qbochs_arch="$arch"
|
local qbochs_arch="$arch"
|
||||||
[[ "${qbochs_arch,,}" == "amd64" ]] && qbochs_arch="x64"
|
|
||||||
|
|
||||||
local source="$drivers/qbochs/$driver/$qbochs_arch"
|
local source="$drivers/qbochs/$driver/$qbochs_arch"
|
||||||
local destination="$dir/\$OEM\$/\$1/Drivers/QBochs"
|
local destination="$dir/\$OEM\$/\$1/Drivers/QBochs"
|
||||||
|
|
||||||
@@ -337,7 +375,7 @@ disableGenericDisplay() {
|
|||||||
|
|
||||||
[[ "$driver" == "2k3" && "${arch,,}" == "amd64" ]] || return 0
|
[[ "$driver" == "2k3" && "${arch,,}" == "amd64" ]] || return 0
|
||||||
|
|
||||||
local qbochs_inf="$drivers/qbochs/$driver/x64/qbochs.inf"
|
local qbochs_inf="$drivers/qbochs/$driver/$arch/qbochs.inf"
|
||||||
local qbochs_id='PCI\VEN_1234&DEV_1111&SUBSYS_11001AF4'
|
local qbochs_id='PCI\VEN_1234&DEV_1111&SUBSYS_11001AF4'
|
||||||
|
|
||||||
# Do not remove the generic VGA match unless the exact QBochs device is
|
# Do not remove the generic VGA match unless the exact QBochs device is
|
||||||
@@ -750,8 +788,6 @@ writeSIF() {
|
|||||||
local timezone="${12}"
|
local timezone="${12}"
|
||||||
local bitsPerPel=32
|
local bitsPerPel=32
|
||||||
|
|
||||||
[[ "$driver" == "2k3" ]] && bitsPerPel=16
|
|
||||||
|
|
||||||
find "$target" -maxdepth 1 -type f -iname winnt.sif -delete || return 1
|
find "$target" -maxdepth 1 -type f -iname winnt.sif -delete || return 1
|
||||||
|
|
||||||
{
|
{
|
||||||
@@ -771,7 +807,7 @@ writeSIF() {
|
|||||||
' WaitForReboot="No"' \
|
' WaitForReboot="No"' \
|
||||||
' DriverSigningPolicy="Ignore"' \
|
' DriverSigningPolicy="Ignore"' \
|
||||||
' NonDriverSigningPolicy="Ignore"' \
|
' NonDriverSigningPolicy="Ignore"' \
|
||||||
' OemPnPDriversPath="Drivers\viostor;Drivers\NetKVM;Drivers\sata;Drivers\QXL;Drivers\QBochs;Drivers\Balloon"' \
|
' OemPnPDriversPath="Drivers\viostor;Drivers\NetKVM;Drivers\sata;Drivers\QXL;Drivers\VMSVGA;Drivers\QBochs;Drivers\Balloon"' \
|
||||||
' NoWaitAfterTextMode=1' \
|
' NoWaitAfterTextMode=1' \
|
||||||
' NoWaitAfterGUIMode=1' \
|
' NoWaitAfterGUIMode=1' \
|
||||||
' FileSystem=ConvertNTFS' \
|
' FileSystem=ConvertNTFS' \
|
||||||
@@ -945,7 +981,10 @@ appendRegistry() {
|
|||||||
if [[ "$driver" == "2k" ]]; then
|
if [[ "$driver" == "2k" ]]; then
|
||||||
printf '%s\n' '"UserPreferencesMask"=hex:9c,32,00,80'
|
printf '%s\n' '"UserPreferencesMask"=hex:9c,32,00,80'
|
||||||
else
|
else
|
||||||
printf '%s\n' '"UserPreferencesMask"=hex:9c,32,07,80'
|
printf '%s\n' \
|
||||||
|
'"UserPreferencesMask"=hex:9c,32,07,80' \
|
||||||
|
'"FontSmoothing"="2"' \
|
||||||
|
'"FontSmoothingType"=dword:00000001'
|
||||||
fi
|
fi
|
||||||
|
|
||||||
printf '%s\n' \
|
printf '%s\n' \
|
||||||
@@ -959,10 +998,42 @@ appendRegistry() {
|
|||||||
fi
|
fi
|
||||||
|
|
||||||
if [[ "$driver" == "xp" || "$driver" == "2k3" ]]; then
|
if [[ "$driver" == "xp" || "$driver" == "2k3" ]]; then
|
||||||
|
# Shell32 Active Setup applies these defaults while creating a new profile.
|
||||||
|
# Set them before first logon so it preserves the requested animation state.
|
||||||
{
|
{
|
||||||
printf '%s\n' \
|
printf '%s\n' \
|
||||||
'[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce]' \
|
'[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\VisualEffects\AnimateMinMax]' \
|
||||||
'"PowerPolicy"="Wscript.exe C:\\OEM\\NT5POWER.VBS"' ''
|
'"DefaultValue"=dword:00000000' \
|
||||||
|
'' \
|
||||||
|
'[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\VisualEffects\ComboBoxAnimation]' \
|
||||||
|
'"DefaultValue"=dword:00000001' \
|
||||||
|
'' \
|
||||||
|
'[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\VisualEffects\CursorShadow]' \
|
||||||
|
'"DefaultValue"=dword:00000001' \
|
||||||
|
'' \
|
||||||
|
'[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\VisualEffects\DragFullWindows]' \
|
||||||
|
'"DefaultValue"=dword:00000001' \
|
||||||
|
'"DefaultByAlphaTest"=dword:00000001' \
|
||||||
|
'' \
|
||||||
|
'[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\VisualEffects\FontSmoothing]' \
|
||||||
|
'"DefaultValue"=dword:00000001' \
|
||||||
|
'"DefaultByFontTest"=dword:00000001' \
|
||||||
|
'' \
|
||||||
|
'[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\VisualEffects\ListBoxSmoothScrolling]' \
|
||||||
|
'"DefaultValue"=dword:00000001' \
|
||||||
|
'' \
|
||||||
|
'[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\VisualEffects\MenuAnimation]' \
|
||||||
|
'"DefaultValue"=dword:00000000' \
|
||||||
|
'"DefaultByAlphaTest"=dword:00000000' \
|
||||||
|
'' \
|
||||||
|
'[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\VisualEffects\SelectionFade]' \
|
||||||
|
'"DefaultValue"=dword:00000000' \
|
||||||
|
'"DefaultByAlphaTest"=dword:00000000' \
|
||||||
|
'' \
|
||||||
|
'[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\VisualEffects\TooltipAnimation]' \
|
||||||
|
'"DefaultValue"=dword:00000000' \
|
||||||
|
'"DefaultByAlphaTest"=dword:00000000' \
|
||||||
|
''
|
||||||
} | unix2dos >> "$dir/\$OEM\$/install.reg" || return 1
|
} | unix2dos >> "$dir/\$OEM\$/install.reg" || return 1
|
||||||
fi
|
fi
|
||||||
|
|
||||||
@@ -1015,7 +1086,12 @@ writeVBS() {
|
|||||||
local shortcut="$3"
|
local shortcut="$3"
|
||||||
local driver="$4"
|
local driver="$4"
|
||||||
local balloonExe="$dir/\$OEM\$/\$1/Drivers/Balloon/blnsvr.exe"
|
local balloonExe="$dir/\$OEM\$/\$1/Drivers/Balloon/blnsvr.exe"
|
||||||
local power="$dir/\$OEM\$/\$1/OEM/NT5POWER.VBS"
|
local power="$dir/\$OEM\$/\$\$/NT5POWER.VBS"
|
||||||
|
local powerRunOnce=""
|
||||||
|
|
||||||
|
if [[ "$driver" == "xp" || "$driver" == "2k3" ]]; then
|
||||||
|
powerRunOnce='WshShell.RegWrite "HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce\PowerPolicy", "Wscript.exe //B " & Chr(34) & "%SystemRoot%\NT5POWER.VBS" & Chr(34), "REG_EXPAND_SZ"'
|
||||||
|
fi
|
||||||
|
|
||||||
# Locate the built-in Administrator by its RID 500 SID rather than its
|
# Locate the built-in Administrator by its RID 500 SID rather than its
|
||||||
# localized display name, then rename that account to the requested username.
|
# localized display name, then rename that account to the requested username.
|
||||||
@@ -1023,6 +1099,7 @@ writeVBS() {
|
|||||||
{
|
{
|
||||||
printf '%s\n' \
|
printf '%s\n' \
|
||||||
'Set WshShell = WScript.CreateObject("WScript.Shell")' \
|
'Set WshShell = WScript.CreateObject("WScript.Shell")' \
|
||||||
|
"$powerRunOnce" \
|
||||||
'Set WshNetwork = WScript.CreateObject("WScript.Network")' \
|
'Set WshNetwork = WScript.CreateObject("WScript.Network")' \
|
||||||
'Set Domain = GetObject("WinNT://" & WshNetwork.ComputerName)' \
|
'Set Domain = GetObject("WinNT://" & WshNetwork.ComputerName)' \
|
||||||
'' \
|
'' \
|
||||||
@@ -1077,6 +1154,39 @@ writeVBS() {
|
|||||||
} | unix2dos > "$dir/\$OEM\$/install.vbs" || return 1
|
} | unix2dos > "$dir/\$OEM\$/install.vbs" || return 1
|
||||||
|
|
||||||
if [[ "$driver" == "xp" || "$driver" == "2k3" ]]; then
|
if [[ "$driver" == "xp" || "$driver" == "2k3" ]]; then
|
||||||
|
# Windows XP and Server 2003 store the automatic recovery menu timeout
|
||||||
|
# in byte 0x09 of bootstat.dat. Patch only that byte and leave the boot
|
||||||
|
# success/shutdown state in the rest of the file untouched.
|
||||||
|
{
|
||||||
|
printf '%s\n' \
|
||||||
|
'On Error Resume Next' \
|
||||||
|
'BootStatPath = WshShell.ExpandEnvironmentStrings("%SystemRoot%\bootstat.dat")' \
|
||||||
|
'Set BootStatStream = WScript.CreateObject("ADODB.Stream")' \
|
||||||
|
'Set BootStatXML = WScript.CreateObject("Msxml2.DOMDocument.3.0")' \
|
||||||
|
'Set BootStatByte = BootStatXML.CreateElement("byte")' \
|
||||||
|
'BootStatByte.DataType = "bin.base64"' \
|
||||||
|
'BootStatByte.Text = "Aw=="' \
|
||||||
|
'If IsObject(BootStatStream) And IsObject(BootStatByte) Then' \
|
||||||
|
' BootStatStream.Type = 1' \
|
||||||
|
' BootStatStream.Open' \
|
||||||
|
' Err.Clear' \
|
||||||
|
' BootStatStream.LoadFromFile BootStatPath' \
|
||||||
|
' If Err.Number = 0 Then' \
|
||||||
|
' If BootStatStream.Size > 9 Then' \
|
||||||
|
' BootStatStream.Position = 9' \
|
||||||
|
' BootStatStream.Write BootStatByte.NodeTypedValue' \
|
||||||
|
' BootStatStream.SaveToFile BootStatPath, 2' \
|
||||||
|
' End If' \
|
||||||
|
' End If' \
|
||||||
|
' BootStatStream.Close' \
|
||||||
|
'End If' \
|
||||||
|
'Set BootStatByte = Nothing' \
|
||||||
|
'Set BootStatXML = Nothing' \
|
||||||
|
'Set BootStatStream = Nothing' \
|
||||||
|
'On Error GoTo 0' \
|
||||||
|
''
|
||||||
|
} | unix2dos >> "$dir/\$OEM\$/install.vbs" || return 1
|
||||||
|
|
||||||
mkdir -p "$(dirname "$power")" || return 1
|
mkdir -p "$(dirname "$power")" || return 1
|
||||||
|
|
||||||
{
|
{
|
||||||
|
|||||||
Reference in New Issue
Block a user