This repository defines and applies a controlled baseline for Windows 11 Enterprise LTSC 2024, including IoT Enterprise, with a clean, quiet and predictable system profile. The baseline uses native Windows configuration mechanisms and system-recognized states, validated by project testing. It avoids binary patching, ACL weakening, and invasive component changes.
It uses a staged deployment pipeline that treats continuation, cleanup, and recovery as explicit, verifiable states.
- Automated Setup: Build your ISO with the ISO Builder.
- Manual Setup: Prepare your ISO step by step.
-
Staged deployment pipeline. The baseline moves through explicit preparation, orchestration and finalization boundaries instead of relying on one broad setup phase.
-
Gated continuation. Normal first-logon continuation is armed only after the required validation and handoff conditions succeed in sequence. A completed setup phase does not, by itself, imply a trusted continuation path.
-
Verify-driven cleanup. Cleanup and teardown are part of completion semantics, not cosmetic follow-up. Temporary state is removed only when restoration and cleanup checks actually verify.
-
Deliberate recovery posture. If safe finalization cannot be established, the project retains recovery-signaling state for inspection and controlled recovery instead of claiming a falsely clean success.
This baseline is intended for a specific system and operating context.
Good fit:
- Windows 11 Enterprise LTSC 2024 systems
- standalone or simple-network environments without enterprise integration by default
- operators who want deterministic setup and reviewable outcomes
- workflows where the primary local admin secret is supplied explicitly by the operator
Not a fit:
- general-purpose hardening across arbitrary Windows editions
- convenience-first setups that expect automatic permanent admin credential generation
- enterprise-heavy environments that expect domain-centric onboarding by default
- aggressive debloat workflows that prioritize removal over controlled baseline behavior
-
Autounattend.xmlsets a narrow unattended entry and shapes the OOBE path. -
PreOOBE.cmdprepares early machine state before the user logon boundary. -
SetupComplete.cmdapplies the baseline, invokes the retainedConfigureDefenderPrivacy.ps1component, checks the required continuation conditions, and prepares the finalization handoff. -
CreatePrimaryAdmin.ps1completes permanent admin finalization, then either tears down temporary state or preserves recovery-signaling state.
- Guide - documentation guide and reading map
- ISO Builder - automated installation ISO preparation
- Quick Start - minimal setup path
- Pipeline Flow - runtime sequence and stage flow
- Operations and Troubleshooting - operations, troubleshooting and recovery guidance
- Security and Decisions - security posture, design rationale and trade-offs
- Validation and Audit Checklist - validation and audit checks
These baseline decisions come with explicit trade-offs:
- SmartScreen policy layers are disabled, reducing prompts and reputation-based checks at the cost of SmartScreen-based protection.
- Microsoft Defender Antivirus remains enabled. Real-time protection, On-Access protection, IOAV protection, applicable NIS protection, and PUA protection remain enabled, while Tamper Protection is intentionally Off in the prepared deployment and Behavior Monitoring is intentionally disabled through persistent Local GPO records. The policy-backed Defender Threat ID
2147741622action value6protects that materialization during Security Intelligence reevaluation. The retained privacy component configures cloud/MAPS and automatic sample submission off, and reports a non-fatal warning when the point-in-time effective privacy posture cannot be verified; see Operations for post-deployment verification and remediation. - Automatic component cleanup is not forced, preserving predictability and reversibility at the cost of a larger system footprint.
- With WPAD disabled, proxy configuration must be made explicitly later.
For repository changes, start with Contributing.
For Codex CLI or other agent-assisted work, follow AGENTS.md and the Interaction Contract.
MIT License