jagreygoose icon

Windows 10 Setup

jagreygoose | PRO | 10/19/18 02:40:52 PM UTC | 0 ⭐ | 530 👁️ | Never ⏰ | []
PowerShell |

12.31 KB

|

None

|

0 👍

/

0 👎

    #region Environment
    
        # Set UAC to Low
        Set-ItemProperty -Path "HKLM:\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System" -Name "ConsentPromptBehaviorAdmin" -Type DWord -Value 0 -ErrorAction SilentlyContinue | Out-Null
        Set-ItemProperty -Path "HKLM:\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System" -Name "PromptOnSecureDesktop" -Type DWord -Value 0 -ErrorAction SilentlyContinue | Out-Null
 
        # Licence Windows Products with key present
        try{
        Get-CimInstance -ClassName SoftwareLicensingProduct -Filter “PartialProductKey IS NOT NULL” |
        Invoke-CimMethod -MethodName Activate -ErrorAction SilentlyContinue | out-null} catch{}
    
        # Set Windows 10 Active Hours to not interfere with work time. 
        $activeHoursRegPath = "HKLM:\SOFTWARE\Microsoft\WindowsUpdate\UX\Settings"
 
        if (Test-Path -Path "${activeHoursRegPath}") {
 
          $activeHoursStart = 8
          $activeHoursEnd = 17
 
          Set-ItemProperty -Path "${activeHoursRegPath}" -Name "ActiveHoursStart" -Value "${activeHoursStart}" -ErrorAction SilentlyContinue | Out-Null
          Set-ItemProperty -Path "${activeHoursRegPath}" -Name "ActiveHoursEnd" -Value "${activeHoursEnd}" -ErrorAction SilentlyContinue | Out-Null
        }     
 
        # Check for Windows Image Errors
        Dism /Online /NoRestart /Cleanup-Image /RestoreHealth /LimitAccess
 
        # Remove System Restore Point 24 Hour Cooldown
        Set-ItemProperty -Path "HKLM:\Software\Microsoft\Windows NT\CurrentVersion\SystemRestore" -Name "SystemRestorePointCreationFrequency" -Type DWord -Value 0 -ErrorAction SilentlyContinue | Out-Null
 
    #endregion Environment 
 
 
    #region Local
        # Configure Localization Settings.
 
        Set-TimeZone “GMT Standard Time”
        Set-Culture en-GB
        Set-WinSystemLocale en-GB
        Set-WinHomeLocation  -GeoId 0xf2
        Set-WinUserLanguageList -LanguageList en-GB -Force
        # Set BIOS time to local time
        Remove-ItemProperty -Path "HKLM:\SYSTEM\CurrentControlSet\Control\TimeZoneInformation" -Name "RealTimeIsUniversal" -ErrorAction SilentlyContinue
 
    #endregion Local
 
 
    #region Power Settings
        # Configure Power Settings.
 
        powercfg.exe -restoredefaultschemes
        # https://www.symantec.com/connect/articles/tweaking-windows-7-power-plans-using-powercfg-command-line-options
        # Switch Off Display Setting (0-4294967295) =Seconds
        powercfg /SETDCVALUEINDEX SCHEME_CURRENT 7516b95f-f776-4464-8c53-06167f40cc99 3c0bc021-c8a8-4e07-a973-6b14cbcb2b7e 300   
        powercfg /SETACVALUEINDEX SCHEME_CURRENT 7516b95f-f776-4464-8c53-06167f40cc99 3c0bc021-c8a8-4e07-a973-6b14cbcb2b7e 3600
        # Display Brighness Setting (percent): 0-100 
        powercfg /SETDCVALUEINDEX SCHEME_CURRENT 7516b95f-f776-4464-8c53-06167f40cc99 aded5e82-b909-4619-9949-f5d71dac0bcb 50 
        powercfg /SETACVALUEINDEX SCHEME_CURRENT 7516b95f-f776-4464-8c53-06167f40cc99 aded5e82-b909-4619-9949-f5d71dac0bcb 100
        # Graphics Quality
        powercfg /SETDCVALUEINDEX SCHEME_CURRENT 44f3beca-a7c0-460e-9df2-bb8b99e0cba6 3619c3f2-afb2-4afc-b0e9-e7fef372de36 0     
        powercfg /SETACVALUEINDEX SCHEME_CURRENT 44f3beca-a7c0-460e-9df2-bb8b99e0cba6 3619c3f2-afb2-4afc-b0e9-e7fef372de36 2 
        # Sleep Timeout Setting (seconds) =Seconds after which sleep to occur
        powercfg /SETDCVALUEINDEX SCHEME_CURRENT 238c9fa8-0aad-41ed-83f4-97be242c8f20 29f6c1db-86da-48c5-9fdb-f2b67b1f44da 900     
        powercfg /SETACVALUEINDEX SCHEME_CURRENT 238c9fa8-0aad-41ed-83f4-97be242c8f20 29f6c1db-86da-48c5-9fdb-f2b67b1f44da 3600
        # DC - On Battery | Wireless Adapter Settings -> Power Saving Mode -> Maximum Performance 
        powercfg /SETDCVALUEINDEX SCHEME_CURRENT 19cbb8fa-5279-450e-9fac-8a3d5fedd0c1 12bbebe6-58d6-4636-95bb-3217ef867c1a 0
        # AC - Power Adapter | Wireless Adapter Settings -> Power Saving Mode -> Maximum Performance
        powercfg /SETACVALUEINDEX SCHEME_CURRENT 19cbb8fa-5279-450e-9fac-8a3d5fedd0c1 12bbebe6-58d6-4636-95bb-3217ef867c1a 0      
 
    #endregion Power Settings
 
 
    #region Certificates
 
        # Add Certificate to Local Trusted Root CA
 
        $CertString = "blahblahcertificateasstringhereblahblah"
 
        $Cert = New-Object System.Security.Cryptography.X509Certificates.X509Certificate2
        $Cert.Import([Convert]::FromBase64String($CertString))
 
 
        $store = new-object System.Security.Cryptography.X509Certificates.X509Store(
            [System.Security.Cryptography.X509Certificates.StoreName]::Root,
            "localmachine"
        )
 
        $store.Open([System.Security.Cryptography.X509Certificates.OpenFlags]::"ReadWrite")
        $store.Add($Cert)
        $store.Close()
    
    #endregion Certificates
 
    #region Bitlocker
        # Allow Bitlocker Without a Compatible TPM
 
        $gpopath= "HKLM:\SOFTWARE\Policies\Microsoft"
        New-Item –Path "$gpopath" –Name FVE -Force -ErrorAction SilentlyContinue | out-null
        New-ItemProperty -Path "$gpopath\FVE" -Name 'UseAdvancedStartup' -Value '1' -PropertyType DWORD -Force -ErrorAction SilentlyContinue | out-null
        New-ItemProperty -Path "$gpopath\FVE" -Name 'EnableBDEWithNoTPM' -Value '1' -PropertyType DWORD -Force -ErrorAction SilentlyContinue | out-null
        New-ItemProperty -Path "$gpopath\FVE" -Name 'UseTPM' -Value '2' -PropertyType DWORD -Force -ErrorAction SilentlyContinue | out-null
        New-ItemProperty -Path "$gpopath\FVE" -Name 'UseTPMPIN' -Value '2' -PropertyType DWORD -Force -ErrorAction SilentlyContinue | out-null
        New-ItemProperty -Path "$gpopath\FVE" -Name 'UseTPMKEY' -Value '2' -PropertyType DWORD -Force -ErrorAction SilentlyContinue | out-null
        New-ItemProperty -Path "$gpopath\FVE" -Name 'UseTPMKeyPIN' -Value '2' -PropertyType DWORD -Force -ErrorAction SilentlyContinue | out-null
 
    #endregion Bitlocker
 
 
    #region Network
    
 
        # Prevent Mapped Drives From Auto Disconnecting
        net config server /autodisconnect:-1 | Out-Null
 
    #endregion Network
 
    #region Firewall
    
       # Configure Firewall Rules
 
        # Allow WMI
 
        netsh advfirewall firewall set rule group="windows management instrumentation (wmi)" new enable=yes | out-null
        New-ItemProperty -Path "HKLM:\SOFTWARE\Microsoft\Wbem\CIMOM" -Name "AllowAnonymousCallback" -Type DWord -Value 1  -Force | out-null 
   
        # Allow NetBIOS
 
        if (-not $(Get-NetFirewallRule –DisplayName 'NetBIOS' | Get-NetFirewallPortFilter | Where { $_.LocalPort -eq '137' })){
            netsh advfirewall firewall add rule name="NetBIOS" dir=in action=allow protocol=TCP localport=137 | out-null 
        }
        if (-not $(Get-NetFirewallRule –DisplayName 'NetBIOS_1NetBIOS_2' | Get-NetFirewallPortFilter | Where { $_.LocalPort -eq '138' })){
            netsh advfirewall firewall add rule name="NetBIOS_1NetBIOS_2" dir=in action=allow protocol=UDP localport=138 | out-null
        }
        if (-not $(Get-NetFirewallRule –DisplayName 'NetBIOS_2' | Get-NetFirewallPortFilter | Where { $_.LocalPort -eq '139' })){
            netsh advfirewall firewall add rule name="NetBIOS_2" dir=in action=allow protocol=UDP localport=139 | out-null
        }
 
        # Allow ICMP - http://shouldiblockicmp.com/
   
        if (-not $(Get-NetFirewallRule –DisplayName 'All ICMP V4' | Where {$_.Enabled -eq $true})){
            netsh advfirewall firewall add rule name="All ICMP V4" protocol=icmpv4:any,any dir=in action=allow | out-null 
        }       
        if (-not $(Get-NetFirewallRule –DisplayName 'All ICMP V6' | Where {$_.Enabled -eq $true})){
            netsh advfirewall firewall add rule name="All ICMP V6" protocol=icmpv6:any,any dir=in action=allow | out-null
        }
 
        # Allow Remote Administration
    
        netsh advfirewall firewall set rule group="Remote Administration" new enable=yes | out-null 
        New-ItemProperty -Path "HKLM:\SYSTEM\CurrentControlSet\Control\Terminal Server" -Name "AllowRemoteRPC" -Type DWord -Value 1  -Force | out-null
        New-ItemProperty -Path "HKLM:\SYSTEM\CurrentControlSet\Control\Terminal Server" -Name "fDenyTSConnections" -Type DWord -Value 0  -Force | out-null
    
        # Allow File Printer Sharing
 
        netsh advfirewall firewall set rule group="File and Printer Sharing" new enable=yes | out-null 
   
        # Allow Network Discovery
 
        netsh advfirewall firewall set rule group="network discovery" new enable=yes | out-null
 
        # Allow SQL
 
        if (-not $(Get-NetFirewallRule –DisplayName 'SQL Port 1433' | Get-NetFirewallPortFilter | Where { $_.LocalPort -eq '1433' })){
            netsh advfirewall firewall add rule name="SQL Port 1433" dir=in action=allow protocol=TCP localport=1433 | out-null
        }
        if (-not $(Get-NetFirewallRule –DisplayName 'SQL Port 1434' | Get-NetFirewallPortFilter | Where { $_.LocalPort -eq '1434' })){
            netsh advfirewall firewall add rule name="SQL Port 1434" dir=in action=allow protocol=UDP localport=1434 | out-null
        }
 
    #endregion Firewall
 
    #region Accessibility
 
        # Mouse Acceleration Settings
        Set-ItemProperty "HKCU:\Control Panel\Mouse" "MouseSensitivity" "15" -ErrorAction SilentlyContinue | Out-Null
        Set-ItemProperty "HKCU:\Control Panel\Mouse" "MouseSpeed" "0" -ErrorAction SilentlyContinue | Out-Null
        Set-ItemProperty "HKCU:\Control Panel\Mouse" "MouseThreshold1" "0" -ErrorAction SilentlyContinue | Out-Null
        Set-ItemProperty "HKCU:\Control Panel\Mouse" "MouseThreshold2" "0" -ErrorAction SilentlyContinue | Out-Null
        Set-ItemProperty "HKCU:\Control Panel\Mouse" "SmoothMouseXCurve" ([byte[]](0x00, 0x00, 0x00,
        0x00, 0x00, 0x00, 0x00, 0x00, 0xC0, 0xCC, 0x0C, 0x00, 0x00, 0x00, 0x00, 0x00,
        0x80, 0x99, 0x19, 0x00, 0x00, 0x00, 0x00, 0x00, 0x40, 0x66, 0x26, 0x00, 0x00,
        0x00, 0x00, 0x00, 0x00, 0x33, 0x33, 0x00, 0x00, 0x00, 0x00, 0x00)) -ErrorAction SilentlyContinue | Out-Null
        Set-ItemProperty "HKCU:\Control Panel\Mouse" "SmoothMouseYCurve" ([byte[]](0x00, 0x00, 0x00,
        0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x38, 0x00, 0x00, 0x00, 0x00, 0x00,
        0x00, 0x00, 0x70, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0xA8, 0x00, 0x00,
        0x00, 0x00, 0x00, 0x00, 0x00, 0xE0, 0x00, 0x00, 0x00, 0x00, 0x00)) -ErrorAction SilentlyContinue | Out-Null
        Set-ItemProperty "HKCU:\Control Panel\Desktop" "UserPreferencesMask" ([byte[]](0x9e,
        0x1e, 0x06, 0x80, 0x12, 0x00, 0x00, 0x00)) -ErrorAction SilentlyContinue | Out-Null
 
        $MethodDefinition = @"
       [DllImport("user32.dll", EntryPoint = "SystemParametersInfo")]
       public static extern bool SystemParametersInfo(uint uiAction, uint uiParam, uint pvParam, uint fWinIni);
    "@
        $User32Set = Add-Type -MemberDefinition $MethodDefinition -Name "User32Set" -Namespace Win32Functions -PassThru
        $User32Set::SystemParametersInfo(0x0071,0,15,0) | Out-Null
 
 
    # endregion Accessibility
 
 
    #region Choco
        # Chocolatey Package Manager."
        $env:chocolateyUseWindowsCompression = 'true'
        $packages = @(
            "choco install choco-upgrade-all-at-startup"
            "anydesk"
            "winrar"
            "google-drive-file-stream"
            "adobereader"
            "audacity"
            "google-chrome-x64"
            "sysinternals"
            "vlc"
            "everything"
            "youtube-dl-gui.install"
            "pdfsam.install"
            "adwcleaner"
            "bulkrenameutility.install"
        )
 
 
        If(Test-Path -Path "$env:ProgramData\Chocolatey") {
 
            choco feature enable -n=allowglobalconfirmation
            choco feature enable -n=allowemptychecksums
            choco upgrade chocolatey
            choco upgrade all --ignore-checksums -y
        }
        Else {
 
          [System.Net.WebRequest]::DefaultWebProxy.Credentials = [System.Net.CredentialCache]::DefaultCredentials; iex ((New-Object System.Net.WebClient).DownloadString('https://chocolatey.org/install.ps1'))  
 
          choco feature enable -n=allowglobalconfirmation
          choco feature enable -n=allowemptychecksums
          $packages | %{choco install $_  --ignore-checksums --force -y}
        }
 
 
    #endregion Choco

Comments