Initial commit: Windows unattend.xml 自動部署範本與文件

This commit is contained in:
2026-04-19 10:30:53 +08:00
commit 96ea0d5832
4 changed files with 525 additions and 0 deletions

112
README.md Normal file
View File

@@ -0,0 +1,112 @@
# Windows Unattend 自動部署
`unattend.xml` 回應檔自動化 Windows 10/11 安裝流程。涵蓋語系、磁碟分割、帳號建立、產品序號、首次登入腳本執行。
---
## 檔案
| 檔案 | 用途 |
|---|---|
| `unattend.xml` | 主回應檔,放入 USB/ISO 時需改名為 `autounattend.xml` |
| `QUICKSTART.md` | 操作步驟:如何產生 USB、掛載 ISO、跑 VM 測試 |
| `SUMMARY.md` | 本專案的來由與設計脈絡 |
---
## Pass 架構
Windows Setup 在不同階段套用不同 `<settings pass="...">`
| Pass | 時機 | 本檔負責 |
|---|---|---|
| `windowsPE` | WinPE 啟動、安裝前 | UI 語系、磁碟分割UEFI+GPT、產品序號、EULA |
| `specialize` | 映像套用後、第一次開機前 | 電腦名稱、時區、擁有者資訊 |
| `oobeSystem` | 首次開機 OOBE 階段 | 略過 OOBE、建立本機帳號、AutoLogon、FirstLogonCommands |
---
## 元件與設定項
### windowsPE
- **Microsoft-Windows-International-Core-WinPE** — `SetupUILanguage` / `InputLocale` / `SystemLocale` / `UILanguage` / `UserLocale` 皆為 `zh-TW``InputLocale``0404:00000404`(繁中鍵盤)。
- **Microsoft-Windows-Setup**
- `DiskConfiguration` — 清空 Disk 0建立三個分割
- EFI 500 MBFAT32, Label `System`
- MSR 128 MB
- Primary 其餘全部NTFS, Label `Windows`, 掛 `C:`
- `ImageInstall` — 安裝到 Disk 0 Partition 3
- `UserData``ProductKey`(範本為 `XXXXX-XXXXX-XXXXX-XXXXX-XXXXX`KMS 可用通用金鑰)、`AcceptEula=true``FullName``Organization`
### specialize
- **Microsoft-Windows-Shell-Setup**
- `ComputerName``PC-%RAND:5%`5 位隨機數字)
- `TimeZone``Taipei Standard Time`
- `RegisteredOwner` / `RegisteredOrganization`
### oobeSystem
- **Microsoft-Windows-International-Core** — 重複設定語系OOBE 階段需要)
- **Microsoft-Windows-Shell-Setup**
- `OOBE` — 全部略過EULA、OEM 註冊、線上帳號、無線設定、機器與使用者 OOBE`NetworkLocation=Work``ProtectYourPC=3`
- `UserAccounts.LocalAccounts` — 建立 `Admin`Administrators 群組,密碼 `P@ssw0rd!`,明碼)
- `AutoLogon` — 以 `Admin` 自動登入一次(`LogonCount=1`
- `FirstLogonCommands` — 按 `Order` 依序執行:
1. `powershell.exe -ExecutionPolicy Bypass -File C:\Scripts\Setup.ps1`
2. `cmd.exe /c net accounts /maxpwage:unlimited`(密碼永不過期)
3. `shutdown /r /t 5`(重開機)
---
## 關鍵參數參考
| 參數 | 說明 |
|---|---|
| `processorArchitecture` | x64 用 `amd64`、ARM64 用 `arm64` |
| `publicKeyToken` | 微軟元件簽章,固定 `31bf3856ad364e35` |
| `ProductKey` | 零售/OEM 填正式序號KMS/大量授權可用 Generic Volume License Key或留空 |
| `PlainText` | `true` 用明碼、`false` 用 Base64SIM 會自動產生) |
| `%RAND:5%` | 內建變數,產生 5 位隨機數字避免主機名衝突 |
| `WillShowUI` | `OnError` / `Always` / `Never` |
| `FirstLogonCommands` | 需搭配 `AutoLogon` 才會觸發;按 `Order` 同步執行 |
---
## 放置位置(擇一)
| 位置 | 檔名 |
|---|---|
| USB 安裝隨身碟根目錄 | `autounattend.xml` |
| ISO `sources\` 目錄 | `autounattend.xml` |
| DISM 離線注入已掛載映像 | 任意名稱,用 `/Apply-Unattend:` 指定 |
---
## 驗證工具
- **Windows SIM**Windows System Image ManagerWindows ADK 內含)— 視覺化編輯、驗證、自動產生 Base64 密碼。
- **VM 試跑**Hyper-V / VirtualBox / VMware— 正式部署前先在 VM 全跑一次。
---
## 安全性
- 本範本密碼為明碼,僅適合內網測試;生產環境請改 Base64 或交由 MDT/SCCM 管理。
- 部署結束後應刪除殘留的 unattend 檔,例如在 `Setup.ps1` 尾端:
```powershell
Remove-Item C:\Windows\Panther\unattend.xml -Force -ErrorAction SilentlyContinue
Remove-Item C:\Windows\Panther\Unattend\unattend.xml -Force -ErrorAction SilentlyContinue
```
---
## 客製延伸
可在既有結構上擴充:
- 加入網域(`Microsoft-Windows-UnattendedJoin.Identification`
- 安裝特定軟體(`FirstLogonCommands` 呼叫 winget / choco / MSI
- 整合 WDS / MDT / SCCM 部署流程
- 多硬碟或 BIOS/MBR 分割配置