Skip to content

Customizing the unattend.xml Configuration File

The unattend.xml file is the standard Answer File for Windows Setup. EASYDEPLOY copies this file to C:\Windows\Panther\unattend.xml on the target OS partition. Settings take effect on the first boot (system configuration phase, not offline on WinPE).

<?xml version="1.0" encoding="utf-8"?>
<unattend xmlns="urn:schemas-microsoft-com:unattend">
<!-- Pass 1: windowsPE — Configuration before Windows completes installation -->
<settings pass="windowsPE">
<component name="Microsoft-Windows-International-Core-WinPE" …>
<!-- System language, keyboard, and time zone -->
</component>
</settings>
<!-- Pass 2: Specialize — Device identity initialization -->
<settings pass="specialize">
<component name="Microsoft-Windows-Deployment" …>
<RunSynchronous>
<!-- Synchronous commands before OOBE -->
</RunSynchronous>
</component>
</settings>
<!-- Pass 3: oobeSystem — Initial OOBE screen setup -->
<settings pass="oobeSystem">
<component name="Microsoft-Windows-Shell-Setup" …>
<UserAccounts>…</UserAccounts>
<AutoLogon>…</AutoLogon>
<OOBE>…</OOBE>
<FirstLogonCommands>…</FirstLogonCommands>
</component>
</settings>
</unattend>

2.1. Default Administrator Account (oobeSystem → UserAccounts)

Section titled “2.1. Default Administrator Account (oobeSystem → UserAccounts)”

Automatically create a local user account and assign it to the Administrators group:

<UserAccounts>
<LocalAccounts>
<LocalAccount wcm:action="add">
<Name>ITAdmin</Name>
<DisplayName>Administrator</DisplayName>
<Group>Administrators</Group>
<Password>
<Value>to-strong-password</Value>
<PlainText>true</PlainText>
</Password>
</LocalAccount>
</LocalAccounts>
</UserAccounts>

Allows the Post-setup.ps1 script to run automatically after installation without requiring manual logon:

<AutoLogon>
<Enabled>true</Enabled>
<Username>ITAdmin</Username>
<LogonCount>1</LogonCount>
<Password>
<Value>to-strong-password</Value>
<PlainText>true</PlainText>
</Password>
</AutoLogon>

The pass that lets EASYDEPLOY invoke Post-setup.ps1. The sample configuration runs the PowerShell script and unblocks it:

<FirstLogonCommands>
<SynchronousCommand wcm:action="add">
<Order>1</Order>
<Description>Run CoreSystem post-setup</Description>
<CommandLine>powershell.exe -ExecutionPolicy Bypass -Command "if (Test-Path 'C:\CoreSystem\Post-setup.ps1') { Unblock-File -Path 'C:\CoreSystem\Post-setup.ps1' -ErrorAction SilentlyContinue; & 'C:\CoreSystem\Post-setup.ps1' }"</CommandLine>
</SynchronousCommand>
</FirstLogonCommands>

2.4. Synchronous Commands in the Specialize Pass

Section titled “2.4. Synchronous Commands in the Specialize Pass”

Execute commands before the OOBE screen appears. Suitable for system optimization (registry overrides, removing default apps, etc.):

<RunSynchronous>
<RunSynchronousCommand wcm:action="add">
<Order>1</Order>
<Path>reg add HKLM\SOFTWARE\Policies\Microsoft\Windows /v DisableAppSuggestions /t REG_DWORD /d 1 /f</Path>
</RunSynchronousCommand>
</RunSynchronous>
Customization Category Pass Notes
Time Zone & Language windowsPE Example: time zone SE Asia Standard Time, display language en-us
OOBE Automation oobeSystem → OOBE hide EULA HideEULAPage, security ProtectYourPC: 3, skip OOBE SkipMachineOOBE, etc.
Remove UWP Apps specialize / oobeSystem Remove-AppxPackage command by package name
Enable Long Paths & Remove Windows.old specialize Registry EnableLongPaths and cleanup of old backup directory
Disable Automatic BitLocker oobeSystem PreventDeviceEncryption: true — prevents automatic drive encryption
Explorer & Taskbar oobeSystem → Shell-Setup Restore classic context menu, left-align Taskbar, etc.
  • Data structure: Validate XML syntax using Notepad or a dedicated code editor.
  • Passes: Use exact Pass and Component names. An incorrect identifier will cause the OS to silently ignore the configuration without reporting an error.
  • Testing: Test the installation on a virtual machine before large-scale deployment (see Creating a New Profile).