Skip to content

About

Defines and applies a controlled Windows 11 LTSC 2024 baseline through a staged, deterministic setup pipeline with predictable behavior and low background activity.

Topics

Resources

Contributing

Security policy

Stars

49 stars

Watchers

1 watching

Forks

Repository files navigation

Windows 11 Enterprise LTSC 2024 Baseline

This repository defines and applies a controlled baseline for Windows 11 Enterprise LTSC 2024, including IoT Enterprise, with a clean, quiet and predictable system profile. The baseline uses native Windows configuration mechanisms and system-recognized states, validated by project testing. It avoids binary patching, ACL weakening, and invasive component changes.

It uses a staged deployment pipeline that treats continuation, cleanup, and recovery as explicit, verifiable states.

Start here

Key characteristics

  • Staged deployment pipeline. The baseline moves through explicit preparation, orchestration and finalization boundaries instead of relying on one broad setup phase.

  • Gated continuation. Normal first-logon continuation is armed only after the required validation and handoff conditions succeed in sequence. A completed setup phase does not, by itself, imply a trusted continuation path.

  • Verify-driven cleanup. Cleanup and teardown are part of completion semantics, not cosmetic follow-up. Temporary state is removed only when restoration and cleanup checks actually verify.

  • Deliberate recovery posture. If safe finalization cannot be established, the project retains recovery-signaling state for inspection and controlled recovery instead of claiming a falsely clean success.

Fit and boundaries

This baseline is intended for a specific system and operating context.

Good fit:

  • Windows 11 Enterprise LTSC 2024 systems
  • standalone or simple-network environments without enterprise integration by default
  • operators who want deterministic setup and reviewable outcomes
  • workflows where the primary local admin secret is supplied explicitly by the operator

Not a fit:

  • general-purpose hardening across arbitrary Windows editions
  • convenience-first setups that expect automatic permanent admin credential generation
  • enterprise-heavy environments that expect domain-centric onboarding by default
  • aggressive debloat workflows that prioritize removal over controlled baseline behavior

Pipeline at a glance

  1. Autounattend.xml sets a narrow unattended entry and shapes the OOBE path.

  2. PreOOBE.cmd prepares early machine state before the user logon boundary.

  3. SetupComplete.cmd applies the baseline, invokes the retained ConfigureDefenderPrivacy.ps1 component, checks the required continuation conditions, and prepares the finalization handoff.

  4. CreatePrimaryAdmin.ps1 completes permanent admin finalization, then either tears down temporary state or preserves recovery-signaling state.

Documentation map

Key trade-offs

These baseline decisions come with explicit trade-offs:

  • SmartScreen policy layers are disabled, reducing prompts and reputation-based checks at the cost of SmartScreen-based protection.
  • Microsoft Defender Antivirus remains enabled. Real-time protection, On-Access protection, IOAV protection, applicable NIS protection, and PUA protection remain enabled, while Tamper Protection is intentionally Off in the prepared deployment and Behavior Monitoring is intentionally disabled through persistent Local GPO records. The policy-backed Defender Threat ID 2147741622 action value 6 protects that materialization during Security Intelligence reevaluation. The retained privacy component configures cloud/MAPS and automatic sample submission off, and reports a non-fatal warning when the point-in-time effective privacy posture cannot be verified; see Operations for post-deployment verification and remediation.
  • Automatic component cleanup is not forced, preserving predictability and reversibility at the cost of a larger system footprint.
  • With WPAD disabled, proxy configuration must be made explicitly later.

Contributing

For repository changes, start with Contributing.

For Codex CLI or other agent-assisted work, follow AGENTS.md and the Interaction Contract.

License

MIT License

About

Defines and applies a controlled Windows 11 LTSC 2024 baseline through a staged, deterministic setup pipeline with predictable behavior and low background activity.

Topics

Resources

Contributing

Security policy

Stars

49 stars

Watchers

1 watching

Forks

Releases

Contributors

Languages