201 lines
9.2 KiB
XML
201 lines
9.2 KiB
XML
<?xml version="1.0" encoding="utf-8"?>
|
|
<!--
|
|
Unattend file for Windows 11 25H2 (Pro), Hyper-V Gen 2, UEFI + Secure Boot.
|
|
|
|
Goals:
|
|
- Fully unattended install on the only VHDX presented by the VM.
|
|
- Create local user `vagrant` (password `vagrant`) in Administrators.
|
|
- Skip every OOBE wizard page (including the network-required screen).
|
|
- Bring WinRM online with basic auth and unencrypted transport so Packer
|
|
and Vagrant can talk to the guest.
|
|
|
|
The BypassNRO trick is set in `specialize` rather than relying on the
|
|
removed BypassNRO.cmd script, so this works on 24H2/25H2.
|
|
-->
|
|
<unattend xmlns="urn:schemas-microsoft-com:unattend">
|
|
|
|
<settings pass="windowsPE">
|
|
<component name="Microsoft-Windows-International-Core-WinPE" processorArchitecture="amd64" publicKeyToken="31bf3856ad364e35" language="neutral" versionScope="nonSxS" xmlns:wcm="http://schemas.microsoft.com/WMIConfig/2002/State" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance">
|
|
<SetupUILanguage>
|
|
<UILanguage>en-US</UILanguage>
|
|
</SetupUILanguage>
|
|
<InputLocale>0409:00000409</InputLocale>
|
|
<SystemLocale>en-US</SystemLocale>
|
|
<UILanguage>en-US</UILanguage>
|
|
<UserLocale>en-US</UserLocale>
|
|
</component>
|
|
|
|
<component name="Microsoft-Windows-Setup" processorArchitecture="amd64" publicKeyToken="31bf3856ad364e35" language="neutral" versionScope="nonSxS" xmlns:wcm="http://schemas.microsoft.com/WMIConfig/2002/State" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance">
|
|
<DiskConfiguration>
|
|
<Disk wcm:action="add">
|
|
<DiskID>0</DiskID>
|
|
<WillWipeDisk>true</WillWipeDisk>
|
|
<CreatePartitions>
|
|
<CreatePartition wcm:action="add">
|
|
<Order>1</Order>
|
|
<Type>EFI</Type>
|
|
<Size>300</Size>
|
|
</CreatePartition>
|
|
<CreatePartition wcm:action="add">
|
|
<Order>2</Order>
|
|
<Type>MSR</Type>
|
|
<Size>128</Size>
|
|
</CreatePartition>
|
|
<CreatePartition wcm:action="add">
|
|
<Order>3</Order>
|
|
<Type>Primary</Type>
|
|
<Extend>true</Extend>
|
|
</CreatePartition>
|
|
</CreatePartitions>
|
|
<ModifyPartitions>
|
|
<ModifyPartition wcm:action="add">
|
|
<Order>1</Order>
|
|
<PartitionID>1</PartitionID>
|
|
<Format>FAT32</Format>
|
|
<Label>System</Label>
|
|
</ModifyPartition>
|
|
<ModifyPartition wcm:action="add">
|
|
<Order>2</Order>
|
|
<PartitionID>2</PartitionID>
|
|
</ModifyPartition>
|
|
<ModifyPartition wcm:action="add">
|
|
<Order>3</Order>
|
|
<PartitionID>3</PartitionID>
|
|
<Format>NTFS</Format>
|
|
<Label>Windows</Label>
|
|
<Letter>C</Letter>
|
|
</ModifyPartition>
|
|
</ModifyPartitions>
|
|
</Disk>
|
|
</DiskConfiguration>
|
|
|
|
<ImageInstall>
|
|
<OSImage>
|
|
<InstallTo>
|
|
<DiskID>0</DiskID>
|
|
<PartitionID>3</PartitionID>
|
|
</InstallTo>
|
|
<InstallFrom>
|
|
<MetaData wcm:action="add">
|
|
<Key>/IMAGE/NAME</Key>
|
|
<Value>Windows 11 Pro</Value>
|
|
</MetaData>
|
|
</InstallFrom>
|
|
</OSImage>
|
|
</ImageInstall>
|
|
|
|
<UserData>
|
|
<!-- KMS client setup key for Windows 11 Pro; lets the installer pick
|
|
the right edition without prompting. Replaced at activation. -->
|
|
<ProductKey>
|
|
<Key>W269N-WFGWX-YVC9B-4J6C9-T83GX</Key>
|
|
<WillShowUI>OnError</WillShowUI>
|
|
</ProductKey>
|
|
<AcceptEula>true</AcceptEula>
|
|
<FullName>vagrant</FullName>
|
|
<Organization>vagrant</Organization>
|
|
</UserData>
|
|
</component>
|
|
</settings>
|
|
|
|
<settings pass="specialize">
|
|
<component name="Microsoft-Windows-Shell-Setup" processorArchitecture="amd64" publicKeyToken="31bf3856ad364e35" language="neutral" versionScope="nonSxS" xmlns:wcm="http://schemas.microsoft.com/WMIConfig/2002/State" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance">
|
|
<ComputerName>bootstrap-win11</ComputerName>
|
|
<TimeZone>UTC</TimeZone>
|
|
</component>
|
|
|
|
<component name="Microsoft-Windows-Deployment" processorArchitecture="amd64" publicKeyToken="31bf3856ad364e35" language="neutral" versionScope="nonSxS" xmlns:wcm="http://schemas.microsoft.com/WMIConfig/2002/State" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance">
|
|
<RunSynchronous>
|
|
<!-- BypassNRO: allows OOBE without a network/Microsoft account.
|
|
24H2/25H2 removed the BypassNRO.cmd helper, so we set the
|
|
registry key directly during specialize. -->
|
|
<RunSynchronousCommand wcm:action="add">
|
|
<Order>1</Order>
|
|
<Path>reg add HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\OOBE /v BypassNRO /t REG_DWORD /d 1 /f</Path>
|
|
</RunSynchronousCommand>
|
|
<!-- Allow WinRM remote-elevated tokens (#3 mitigation). -->
|
|
<RunSynchronousCommand wcm:action="add">
|
|
<Order>2</Order>
|
|
<Path>reg add HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System /v LocalAccountTokenFilterPolicy /t REG_DWORD /d 1 /f</Path>
|
|
</RunSynchronousCommand>
|
|
</RunSynchronous>
|
|
</component>
|
|
</settings>
|
|
|
|
<settings pass="oobeSystem">
|
|
<component name="Microsoft-Windows-Shell-Setup" processorArchitecture="amd64" publicKeyToken="31bf3856ad364e35" language="neutral" versionScope="nonSxS" xmlns:wcm="http://schemas.microsoft.com/WMIConfig/2002/State" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance">
|
|
<OOBE>
|
|
<HideEULAPage>true</HideEULAPage>
|
|
<HideLocalAccountScreen>true</HideLocalAccountScreen>
|
|
<HideOnlineAccountScreens>true</HideOnlineAccountScreens>
|
|
<HideWirelessSetupInOOBE>true</HideWirelessSetupInOOBE>
|
|
<NetworkLocation>Work</NetworkLocation>
|
|
<ProtectYourPC>3</ProtectYourPC>
|
|
<SkipMachineOOBE>true</SkipMachineOOBE>
|
|
<SkipUserOOBE>true</SkipUserOOBE>
|
|
</OOBE>
|
|
|
|
<UserAccounts>
|
|
<LocalAccounts>
|
|
<LocalAccount wcm:action="add">
|
|
<Name>vagrant</Name>
|
|
<Group>Administrators</Group>
|
|
<DisplayName>vagrant</DisplayName>
|
|
<Description>Vagrant Box Build</Description>
|
|
<Password>
|
|
<Value>vagrant</Value>
|
|
<PlainText>true</PlainText>
|
|
</Password>
|
|
</LocalAccount>
|
|
</LocalAccounts>
|
|
</UserAccounts>
|
|
|
|
<AutoLogon>
|
|
<Enabled>true</Enabled>
|
|
<Username>vagrant</Username>
|
|
<LogonCount>3</LogonCount>
|
|
<Password>
|
|
<Value>vagrant</Value>
|
|
<PlainText>true</PlainText>
|
|
</Password>
|
|
</AutoLogon>
|
|
|
|
<FirstLogonCommands>
|
|
<!-- Allow PowerShell scripts unsigned (machine scope). -->
|
|
<SynchronousCommand wcm:action="add">
|
|
<Order>1</Order>
|
|
<CommandLine>powershell.exe -NoProfile -ExecutionPolicy Bypass -Command "Set-ExecutionPolicy -Scope LocalMachine -ExecutionPolicy Bypass -Force"</CommandLine>
|
|
<Description>Set ExecutionPolicy Bypass</Description>
|
|
</SynchronousCommand>
|
|
<!-- Enable WinRM inline so we don't depend on the PROVISION ISO
|
|
still being mounted at first logon (Windows Setup sometimes
|
|
detaches secondary DVDs after install). Mirrors the contents
|
|
of scripts/oobe-enable-winrm.ps1 (now unused) and writes a
|
|
transcript to C:\Windows\Temp\firstlogon.log for debugging. -->
|
|
<SynchronousCommand wcm:action="add">
|
|
<Order>2</Order>
|
|
<CommandLine>cmd.exe /c winrm quickconfig -force -q > C:\Windows\Temp\firstlogon.log 2>&1</CommandLine>
|
|
<Description>WinRM quickconfig</Description>
|
|
</SynchronousCommand>
|
|
<SynchronousCommand wcm:action="add">
|
|
<Order>3</Order>
|
|
<CommandLine>powershell.exe -NoProfile -ExecutionPolicy Bypass -Command "Set-NetConnectionProfile -NetworkCategory Private -ErrorAction SilentlyContinue; Set-Item WSMan:\localhost\Service\Auth\Basic $true; Set-Item WSMan:\localhost\Service\AllowUnencrypted $true; Set-Item WSMan:\localhost\Service\MaxConcurrentOperationsPerUser 12000; Set-Item WSMan:\localhost\Shell\MaxMemoryPerShellMB 1024" >> C:\Windows\Temp\firstlogon.log 2>&1</CommandLine>
|
|
<Description>Configure WinRM auth and limits</Description>
|
|
</SynchronousCommand>
|
|
<SynchronousCommand wcm:action="add">
|
|
<Order>4</Order>
|
|
<CommandLine>powershell.exe -NoProfile -ExecutionPolicy Bypass -Command "New-NetFirewallRule -Name WinRM-HTTP -DisplayName 'WinRM HTTP' -Protocol TCP -LocalPort 5985 -Action Allow -Profile Any -ErrorAction SilentlyContinue" >> C:\Windows\Temp\firstlogon.log 2>&1</CommandLine>
|
|
<Description>Open firewall for WinRM HTTP</Description>
|
|
</SynchronousCommand>
|
|
<SynchronousCommand wcm:action="add">
|
|
<Order>5</Order>
|
|
<CommandLine>cmd.exe /c sc config WinRM start= auto && net stop WinRM && net start WinRM >> C:\Windows\Temp\firstlogon.log 2>&1</CommandLine>
|
|
<Description>Restart WinRM service</Description>
|
|
</SynchronousCommand>
|
|
</FirstLogonCommands>
|
|
|
|
<TimeZone>UTC</TimeZone>
|
|
</component>
|
|
</settings>
|
|
</unattend>
|