Skip to content

Creating a New Profile

This guide walks you through creating a custom Profile for a new device or customer, including testing and validation procedures.

1. Initialize the Profile Directory Structure

Section titled “1. Initialize the Profile Directory Structure”

Create a new directory under EASYDEPLOY\Profiles\ on the USB. It is recommended to prefix the name with a number for organized sorting:

[USB]:\EASYDEPLOY\Profiles\
├── 1.Tweaks ← Built-in profile (system tweaks only)
├── 2.TweaksApp ← Built-in profile (tweaks + automatic app installation)
└── 3.AcmeBank ← New custom profile (MSP Advanced only)
├── unattend.xml
└── post-setup.ps1

2. Build the unattend.xml Configuration File

Section titled “2. Build the unattend.xml Configuration File”

The fastest approach: Use schneegans.de/windows/unattend-generator to configure parameters, download the file, then:

  1. Open the file in a code editor.
  2. Verify that FirstLogonCommands correctly points to C:\CoreSystem\Post-setup.ps1 (see unattend.xml for details).
  3. Encrypt the password in the PlainText field if the file will be shared among multiple technicians.

Extend the script based on the sample file (see detailed guide at Post-setup.ps1):

Terminal window
Write-Host "=== [CoreSystem] POST-SETUP: AcmeBank ===" -ForegroundColor Cyan
$GlobalTimeoutSec = 300
function Wait-ForInternet { … } # Use the sample network check function
$HasInternet = Wait-ForInternet
# [Step 1/5] Automatically install AcmeBank standard applications
# [Step 2/5] Apply registry and local policy customizations
# [Step 3/5] Download corporate wallpaper and create Notes.txt support file
# [Step 4/5] Clean up system (clear logs, configure RunOnce to clean temp directories)
# [Step 5/5] Restore script ExecutionPolicy security policy
Restart-Computer # Automatically reboot the device after setup completes
  • Free: edit 1.Tweaks/2.TweaksApp directly and overwrite them on the USB at EASYDEPLOY\Profiles\ — no rebuild required.
  • Advanced: copy unlimited new profiles to EASYDEPLOY\Profiles\ — no rebuild required (details bundled with the .lic).

Recommended testing procedure before production use:

  1. Check script syntax: Run the validation command in PowerShell: [ScriptBlock]::Create((Get-Content .\post-setup.ps1 -Raw)) — if no error is returned, the script syntax is fully valid.
  2. Test on a virtual machine:
    • Boot the VM from the USB into WinPE → Select deployment mode Business (key 2) → Select the newly created profile → Click Deploy.
    • Monitor the activity log [EASYDEPLOY][STEP x/11] until the installation completes and the device reboots.
    • After transitioning to the OOBE screen: Verify automatic account creation, verify automatic logon, verify that the Post-setup.ps1 script executes completely and the Desktop appears as configured.
  3. Stability verification: Reinstall the device a second time using the same profile to verify that the script runs stably and produces no errors when re-executed on an already configured environment.
  4. Test on a physical device: Perform 1 complete cycle on a physical workstation before large-scale rollout.

After the Profile passes testing, hand over the following resources:

  • The profile configuration directory (containing unattend.xml and the post-setup.ps1 script).
  • The deployment configuration file user-config.json (for the Express flow: update the deploy.profile key to point to the new profile directory name).
  • Accompanying technical documentation: List of apps requiring Internet during installation, default administrator password (if any), and estimated total script execution time.
  • Profile directory is placed correctly under EASYDEPLOY\Profiles\ on the USB (directory name uses an ordered numeric prefix).
  • unattend.xml contains a FirstLogonCommands declaration pointing exactly to C:\CoreSystem\Post-setup.ps1.
  • post-setup.ps1 includes a built-in Internet connectivity check and wait function before invoking network-dependent tasks.
  • No sensitive information (passwords, API keys, etc.) is stored in plain text in the files.
  • Script is verified to be idempotent (re-running multiple times causes no conflicts or system errors).
  • Testing completed successfully: at least 2 cycles on VM and 1 cycle on a physical device.
  • user-config.json configuration file (for the Express flow) correctly declares the new profile directory name.