Files
windows-unattend/README.md
Timmy b1e5b6912a unattend.xml 直接以 User(首字大寫)建帳號;Setup.ps1 拿掉 rename-LocalUser
把 Order 3 的 net user 命令直接寫成 net user User,省掉「先建小寫 user 再
Rename-LocalUser 改成大寫 User」這個迂迴。Setup.ps1 的 rename-hide-accounts
段同時改名為 hide-admin-account,內容只剩設 SpecialAccounts\\UserList\\Admin=0
這一行——隱藏 Admin 仍然由 Setup.ps1 負責。

文件全部同步:DEPLOY/QUICKSTART/SUMMARY/README/CLAUDE 把「先建小寫再改名」的
bulletproof 解釋與相關段名都拿掉。

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
2026-04-27 13:59:15 +08:00

124 lines
7.5 KiB
Markdown
Raw Blame History

This file contains ambiguous Unicode characters
This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.
# Windows Unattend 自動部署
`unattend.xml` 回應檔自動化 Windows 10/11 安裝流程。涵蓋語系、磁碟分割、帳號建立、產品序號、首次登入腳本執行。
---
## 檔案
| 檔案 | 用途 |
|---|---|
| `unattend.xml` | 主回應檔,部署到 Ventoy USB 的 `/ventoy/script/unattend.xml`**不**改名為 `autounattend.xml`Ventoy Auto Install plugin 走 `ventoy.json` 注入) |
| `Setup.ps1` | 首次登入後的 post-install PowerShell部署到 USB 的 `/ventoy/script/Setup.ps1`FirstLogonCommands 會掃磁碟自動複製到 `C:\Scripts\` 後執行 |
| `ventoy.json` | Ventoy Auto Install plugin 設定,把 ISO 對到 `unattend.xml` |
| `QUICKSTART.md` | 操作步驟:如何產生 USB、掛載 ISO、跑 VM 測試 |
| `DEPLOY.md` | 本機 USB 實機部署紀錄+ FirstLogonCommands / Setup.ps1 詳細排查 |
| `SUMMARY.md` | 本專案的來由與設計脈絡 |
---
## Pass 架構
Windows Setup 在不同階段套用不同 `<settings pass="...">`
| Pass | 時機 | 本檔負責 |
|---|---|---|
| `windowsPE` | WinPE 啟動、安裝前 | UI 語系、磁碟分割UEFI+GPT、產品序號、EULA |
| `specialize` | 映像套用後、第一次開機前 | 電腦名稱、時區、擁有者資訊 |
| `oobeSystem` | 首次開機 OOBE 階段 | 略過 OOBE、建立本機帳號、AutoLogon、FirstLogonCommands |
---
## 元件與設定項
### windowsPE
- **Microsoft-Windows-International-Core-WinPE** — `SetupUILanguage` / `InputLocale` / `SystemLocale` / `UILanguage` / `UserLocale` 皆為 `zh-TW``InputLocale``0404:00000404`(繁中鍵盤)。
- **Microsoft-Windows-Setup**
- `DiskConfiguration` — 清空第一顆非-Ventoy 磁碟(`$$VT_WINDOWS_DISK_1ST_NONVTOY$$`,由 Ventoy Auto Install plugin 於執行期替換成實際 DiskID建立三個分割
- EFI 500 MBFAT32, Label `System`
- MSR 128 MB
- Primary 其餘全部NTFS, Label `Windows`, 掛 `C:`
- `ImageInstall` — 安裝到同一顆磁碟的 Partition 3
- `UserData``ProductKey`(範本為 `XXXXX-XXXXX-XXXXX-XXXXX-XXXXX`KMS 可用通用金鑰)、`AcceptEula=true``FullName``Organization`
### specialize
- **Microsoft-Windows-Shell-Setup**
- `ComputerName``*`Setup 自動產生隨機名,`FirstLogonCommands` 再用 `Rename-Computer` 改成 `PC-XXXXX`,重開後生效)。**不可寫 `PC-%RAND:5%`**——那是 MDT/SCCM 變數,直接放這裡會被當字面字串送進 NetBIOS 驗證而失敗
- `TimeZone``Taipei Standard Time`
- `RegisteredOwner` / `RegisteredOrganization`
### oobeSystem
- **Microsoft-Windows-International-Core** — 重複設定語系OOBE 階段需要)
- **Microsoft-Windows-Shell-Setup**
- `OOBE` — 全部略過EULA、OEM 註冊、線上帳號、無線設定、機器與使用者 OOBE`NetworkLocation=Work``ProtectYourPC=3`
- `UserAccounts.LocalAccounts` — 建立 `Admin`Administrators 群組,密碼 `P@ssw0rd!`,明碼)
- `AutoLogon` — 以 `Admin` 自動登入一次(`LogonCount=1`
- `FirstLogonCommands` — 按 `Order` 依序執行:
1. `cmd.exe /c net accounts /maxpwage:unlimited`(密碼永不過期)
2. `Rename-Computer` 改主機名成 `PC-XXXXX`(重開後生效)
3. 建立本機帳號 `User`(密碼 `1234``net user /logonpasswordchg:yes` 強制首次登入改密)
4. 掃所有掛載中的 FileSystem PSDrive 找 `\ventoy\script\Setup.ps1`,複製到 `C:\Scripts\Setup.ps1`log 寫到 `C:\Windows\Temp\firstlogon-copysetup.log`
5.`C:\Scripts\Setup.ps1`13 段 post-install 詳見 `Setup.ps1``DEPLOY.md`log 寫到 `C:\Windows\Temp\setup.log`;找不到檔案時改寫 `firstlogon-runsetup.log` 並跳過)
6. `shutdown /r /t 5`(重開機)
### `Setup.ps1` 涵蓋的 13 段(首次登入由 Order 5 執行)
**Phase 1不需網路** SSH 22/TCP 防火牆、RDP+3389、ICMP Echo Inbound、WinRM`TrustedHosts=*`、OneDrive 解除安裝、Cortana/Web Search 關閉、Default profile 套 Dark mode顯示副檔名隱藏檔工作列靠左預設英數鍵盤停 IME 切換熱鍵、從登入畫面隱藏 `Admin`
**Phase 2需網路`wait-network` 後執行):** OpenSSH Server FoD、KMS 啟用(先試 `$InternalKmsServers` 再 fallback 公開 KMS、winget 裝 Chrome、`zoicware/RemoveWindowsAI -AllOptions``Raphire/Win11Debloat -Silent -Config`、22 個 UWP AppxPackage 移除(與 `windows-remote-toolkit/config/remove-apps-config.json` 同步、Telegram 靜默安裝、刪 `C:\Windows\Panther\unattend.xml` 殘留。
---
## 關鍵參數參考
| 參數 | 說明 |
|---|---|
| `processorArchitecture` | x64 用 `amd64`、ARM64 用 `arm64` |
| `publicKeyToken` | 微軟元件簽章,固定 `31bf3856ad364e35` |
| `ProductKey` | 目前填的是 **Win11/10 專業版 GVLK**`W269N-WFGWX-YVC9B-4J6C9-T83GX`[微軟文件](https://learn.microsoft.com/zh-tw/windows-server/get-started/kms-client-activation-keys)用來選版本略過序號畫面。GVLK 只在 KMS 主機環境下才會真正啟用,獨立機器會進 30 天寬限期。其他版本/零售序號直接換這串即可 |
| `PlainText` | `true` 用明碼、`false` 用 Base64SIM 會自動產生) |
| `ComputerName` | 只接受字面名稱、`*`(自動產生如 `DESKTOP-ABC123D`)或空值。**不支援 `%RAND:N%`**——那是 MDT/SCCM task-sequence 變數,直接放進 `unattend.xml` 會被當字面字串送進 NetBIOS 驗證而失敗。本檔的做法是 `<ComputerName>*</ComputerName>``FirstLogonCommands` 裡的 `Rename-Computer` 改成 `PC-XXXXX`,重開後生效 |
| `WillShowUI` | `OnError` / `Always` / `Never` |
| `FirstLogonCommands` | 需搭配 `AutoLogon` 才會觸發;按 `Order` 同步執行 |
---
## 放置位置(擇一)
| 方式 | 位置 | 檔名 |
|---|---|---|
| **Ventoy Auto Install plugin本 repo 預設)** | Ventoy USB 的 `/ventoy/script/unattend.xml``/ventoy/script/Setup.ps1`,並在 `/ventoy/ventoy.json` 指定 | 任意(本 repo 用 `unattend.xml` |
| 傳統 USB 安裝碟 | USB 根目錄 | `autounattend.xml`注意FirstLogonCommands Order 4 的磁碟掃描還是會找 `\ventoy\script\Setup.ps1`,要嘛把 `Setup.ps1` 放對位置,要嘛改 Order 4 的搜尋路徑) |
| ISO `sources\` 目錄 | ISO 根 | `autounattend.xml`(同上) |
| DISM 離線注入已掛載映像 | — | 任意名稱,用 `/Apply-Unattend:` 指定(這條路徑下 `Setup.ps1` 通常會直接烘進 image 而不再走 USB 掃描) |
---
## 驗證工具
- **Windows SIM**Windows System Image ManagerWindows ADK 內含)— 視覺化編輯、驗證、自動產生 Base64 密碼。
- **VM 試跑**Hyper-V / VirtualBox / VMware— 正式部署前先在 VM 全跑一次。
---
## 安全性
- 本範本密碼為明碼,僅適合內網測試;生產環境請改 Base64 或交由 MDT/SCCM 管理。
- `Setup.ps1``cleanup-unattend-files` 段已經會在收尾時刪掉 `C:\Windows\Panther\unattend.xml``Panther\Unattend\unattend.xml`(含明碼密碼)。
- WinRM `AllowUnencrypted=true` + `TrustedHosts=*` 是測試環境設定;正式環境要改 HTTPS5986+ 限制 TrustedHosts。
- KMS 預設 fallback 到第三方公開伺服器(`kms.digiboy.ir` 等);正式環境改 `Setup.ps1``$InternalKmsServers`
---
## 客製延伸
可在既有結構上擴充:
- 加入網域(`Microsoft-Windows-UnattendedJoin.Identification`
- 安裝特定軟體(`FirstLogonCommands` 呼叫 winget / choco / MSI
- 整合 WDS / MDT / SCCM 部署流程
- 多硬碟或 BIOS/MBR 分割配置