jagreygoose icon

W10 Setup

jagreygoose | PRO | 10/19/18 02:42:15 PM UTC | 0 ⭐ | 220 👁️ | Never ⏰ | []
PowerShell |

11.66 KB

|

None

|

0 👍

/

0 👎

    #region Environment
    
    # Set UAC to Low
    Set-ItemProperty -Path "HKLM:\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System" -Name "ConsentPromptBehaviorAdmin" -Type DWord -Value 0 -ErrorAction SilentlyContinue | Out-Null
    Set-ItemProperty -Path "HKLM:\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System" -Name "PromptOnSecureDesktop" -Type DWord -Value 0 -ErrorAction SilentlyContinue | Out-Null
 
    # Licence Windows Products with key present
    try{
    Get-CimInstance -ClassName SoftwareLicensingProduct -Filter “PartialProductKey IS NOT NULL” |
    Invoke-CimMethod -MethodName Activate -ErrorAction SilentlyContinue | out-null} catch{}
    
    # Set Windows 10 Active Hours to not interfere with work time. 
    $activeHoursRegPath = "HKLM:\SOFTWARE\Microsoft\WindowsUpdate\UX\Settings"
 
    if (Test-Path -Path "${activeHoursRegPath}") {
 
        $activeHoursStart = 8
        $activeHoursEnd = 17
 
        Set-ItemProperty -Path "${activeHoursRegPath}" -Name "ActiveHoursStart" -Value "${activeHoursStart}" -ErrorAction SilentlyContinue | Out-Null
        Set-ItemProperty -Path "${activeHoursRegPath}" -Name "ActiveHoursEnd" -Value "${activeHoursEnd}" -ErrorAction SilentlyContinue | Out-Null
    }     
 
    # Check for Windows Image Errors
    Dism /Online /NoRestart /Cleanup-Image /RestoreHealth /LimitAccess
 
    # Remove System Restore Point 24 Hour Cooldown
    Set-ItemProperty -Path "HKLM:\Software\Microsoft\Windows NT\CurrentVersion\SystemRestore" -Name "SystemRestorePointCreationFrequency" -Type DWord -Value 0 -ErrorAction SilentlyContinue | Out-Null
 
#endregion Environment 
 
 
#region Local
    # Configure Localization Settings.
 
    Set-TimeZone “GMT Standard Time”
    Set-Culture en-GB
    Set-WinSystemLocale en-GB
    Set-WinHomeLocation  -GeoId 0xf2
    Set-WinUserLanguageList -LanguageList en-GB -Force
    # Set BIOS time to local time
    Remove-ItemProperty -Path "HKLM:\SYSTEM\CurrentControlSet\Control\TimeZoneInformation" -Name "RealTimeIsUniversal" -ErrorAction SilentlyContinue
 
#endregion Local
 
 
#region Power Settings
    # Configure Power Settings.
 
    powercfg.exe -restoredefaultschemes
    # https://www.symantec.com/connect/articles/tweaking-windows-7-power-plans-using-powercfg-command-line-options
    # Switch Off Display Setting (0-4294967295) =Seconds
    powercfg /SETDCVALUEINDEX SCHEME_CURRENT 7516b95f-f776-4464-8c53-06167f40cc99 3c0bc021-c8a8-4e07-a973-6b14cbcb2b7e 300   
    powercfg /SETACVALUEINDEX SCHEME_CURRENT 7516b95f-f776-4464-8c53-06167f40cc99 3c0bc021-c8a8-4e07-a973-6b14cbcb2b7e 3600
    # Display Brighness Setting (percent): 0-100 
    powercfg /SETDCVALUEINDEX SCHEME_CURRENT 7516b95f-f776-4464-8c53-06167f40cc99 aded5e82-b909-4619-9949-f5d71dac0bcb 50 
    powercfg /SETACVALUEINDEX SCHEME_CURRENT 7516b95f-f776-4464-8c53-06167f40cc99 aded5e82-b909-4619-9949-f5d71dac0bcb 100
    # Graphics Quality
    powercfg /SETDCVALUEINDEX SCHEME_CURRENT 44f3beca-a7c0-460e-9df2-bb8b99e0cba6 3619c3f2-afb2-4afc-b0e9-e7fef372de36 0     
    powercfg /SETACVALUEINDEX SCHEME_CURRENT 44f3beca-a7c0-460e-9df2-bb8b99e0cba6 3619c3f2-afb2-4afc-b0e9-e7fef372de36 2 
    # Sleep Timeout Setting (seconds) =Seconds after which sleep to occur
    powercfg /SETDCVALUEINDEX SCHEME_CURRENT 238c9fa8-0aad-41ed-83f4-97be242c8f20 29f6c1db-86da-48c5-9fdb-f2b67b1f44da 900     
    powercfg /SETACVALUEINDEX SCHEME_CURRENT 238c9fa8-0aad-41ed-83f4-97be242c8f20 29f6c1db-86da-48c5-9fdb-f2b67b1f44da 3600
    # DC - On Battery | Wireless Adapter Settings -> Power Saving Mode -> Maximum Performance 
    powercfg /SETDCVALUEINDEX SCHEME_CURRENT 19cbb8fa-5279-450e-9fac-8a3d5fedd0c1 12bbebe6-58d6-4636-95bb-3217ef867c1a 0
    # AC - Power Adapter | Wireless Adapter Settings -> Power Saving Mode -> Maximum Performance
    powercfg /SETACVALUEINDEX SCHEME_CURRENT 19cbb8fa-5279-450e-9fac-8a3d5fedd0c1 12bbebe6-58d6-4636-95bb-3217ef867c1a 0      
 
#endregion Power Settings
 
 
#region Certificates
 
    # Add Certificate to Local Trusted Root CA
 
    $CertString = "blahblahcertificateasstringhereblahblah"
 
    $Cert = New-Object System.Security.Cryptography.X509Certificates.X509Certificate2
    $Cert.Import([Convert]::FromBase64String($CertString))
 
 
    $store = new-object System.Security.Cryptography.X509Certificates.X509Store(
        [System.Security.Cryptography.X509Certificates.StoreName]::Root,
        "localmachine"
    )
 
    $store.Open([System.Security.Cryptography.X509Certificates.OpenFlags]::"ReadWrite")
    $store.Add($Cert)
    $store.Close()
    
#endregion Certificates
 
#region Bitlocker
    # Allow Bitlocker Without a Compatible TPM
 
    $gpopath= "HKLM:\SOFTWARE\Policies\Microsoft"
    New-Item –Path "$gpopath" –Name FVE -Force -ErrorAction SilentlyContinue | out-null
    New-ItemProperty -Path "$gpopath\FVE" -Name 'UseAdvancedStartup' -Value '1' -PropertyType DWORD -Force -ErrorAction SilentlyContinue | out-null
    New-ItemProperty -Path "$gpopath\FVE" -Name 'EnableBDEWithNoTPM' -Value '1' -PropertyType DWORD -Force -ErrorAction SilentlyContinue | out-null
    New-ItemProperty -Path "$gpopath\FVE" -Name 'UseTPM' -Value '2' -PropertyType DWORD -Force -ErrorAction SilentlyContinue | out-null
    New-ItemProperty -Path "$gpopath\FVE" -Name 'UseTPMPIN' -Value '2' -PropertyType DWORD -Force -ErrorAction SilentlyContinue | out-null
    New-ItemProperty -Path "$gpopath\FVE" -Name 'UseTPMKEY' -Value '2' -PropertyType DWORD -Force -ErrorAction SilentlyContinue | out-null
    New-ItemProperty -Path "$gpopath\FVE" -Name 'UseTPMKeyPIN' -Value '2' -PropertyType DWORD -Force -ErrorAction SilentlyContinue | out-null
 
#endregion Bitlocker
 
 
#region Network
    
 
    # Prevent Mapped Drives From Auto Disconnecting
    net config server /autodisconnect:-1 | Out-Null
 
#endregion Network
 
#region Firewall
    
    # Configure Firewall Rules
 
    # Allow WMI
 
    netsh advfirewall firewall set rule group="windows management instrumentation (wmi)" new enable=yes | out-null
    New-ItemProperty -Path "HKLM:\SOFTWARE\Microsoft\Wbem\CIMOM" -Name "AllowAnonymousCallback" -Type DWord -Value 1  -Force | out-null 
   
    # Allow NetBIOS
 
    if (-not $(Get-NetFirewallRule –DisplayName 'NetBIOS' | Get-NetFirewallPortFilter | Where { $_.LocalPort -eq '137' })){
        netsh advfirewall firewall add rule name="NetBIOS" dir=in action=allow protocol=TCP localport=137 | out-null 
    }
    if (-not $(Get-NetFirewallRule –DisplayName 'NetBIOS_1NetBIOS_2' | Get-NetFirewallPortFilter | Where { $_.LocalPort -eq '138' })){
        netsh advfirewall firewall add rule name="NetBIOS_1NetBIOS_2" dir=in action=allow protocol=UDP localport=138 | out-null
    }
    if (-not $(Get-NetFirewallRule –DisplayName 'NetBIOS_2' | Get-NetFirewallPortFilter | Where { $_.LocalPort -eq '139' })){
        netsh advfirewall firewall add rule name="NetBIOS_2" dir=in action=allow protocol=UDP localport=139 | out-null
    }
 
    # Allow ICMP - http://shouldiblockicmp.com/
   
    if (-not $(Get-NetFirewallRule –DisplayName 'All ICMP V4' | Where {$_.Enabled -eq $true})){
        netsh advfirewall firewall add rule name="All ICMP V4" protocol=icmpv4:any,any dir=in action=allow | out-null 
    }       
    if (-not $(Get-NetFirewallRule –DisplayName 'All ICMP V6' | Where {$_.Enabled -eq $true})){
        netsh advfirewall firewall add rule name="All ICMP V6" protocol=icmpv6:any,any dir=in action=allow | out-null
    }
 
    # Allow Remote Administration
    
    netsh advfirewall firewall set rule group="Remote Administration" new enable=yes | out-null 
    New-ItemProperty -Path "HKLM:\SYSTEM\CurrentControlSet\Control\Terminal Server" -Name "AllowRemoteRPC" -Type DWord -Value 1  -Force | out-null
    New-ItemProperty -Path "HKLM:\SYSTEM\CurrentControlSet\Control\Terminal Server" -Name "fDenyTSConnections" -Type DWord -Value 0  -Force | out-null
    
    # Allow File Printer Sharing
 
    netsh advfirewall firewall set rule group="File and Printer Sharing" new enable=yes | out-null 
   
    # Allow Network Discovery
 
    netsh advfirewall firewall set rule group="network discovery" new enable=yes | out-null
 
    # Allow SQL
 
    if (-not $(Get-NetFirewallRule –DisplayName 'SQL Port 1433' | Get-NetFirewallPortFilter | Where { $_.LocalPort -eq '1433' })){
        netsh advfirewall firewall add rule name="SQL Port 1433" dir=in action=allow protocol=TCP localport=1433 | out-null
    }
    if (-not $(Get-NetFirewallRule –DisplayName 'SQL Port 1434' | Get-NetFirewallPortFilter | Where { $_.LocalPort -eq '1434' })){
        netsh advfirewall firewall add rule name="SQL Port 1434" dir=in action=allow protocol=UDP localport=1434 | out-null
    }
 
#endregion Firewall
 
#region Accessibility
 
    # Mouse Acceleration Settings
    Set-ItemProperty "HKCU:\Control Panel\Mouse" "MouseSensitivity" "15" -ErrorAction SilentlyContinue | Out-Null
    Set-ItemProperty "HKCU:\Control Panel\Mouse" "MouseSpeed" "0" -ErrorAction SilentlyContinue | Out-Null
    Set-ItemProperty "HKCU:\Control Panel\Mouse" "MouseThreshold1" "0" -ErrorAction SilentlyContinue | Out-Null
    Set-ItemProperty "HKCU:\Control Panel\Mouse" "MouseThreshold2" "0" -ErrorAction SilentlyContinue | Out-Null
    Set-ItemProperty "HKCU:\Control Panel\Mouse" "SmoothMouseXCurve" ([byte[]](0x00, 0x00, 0x00,
    0x00, 0x00, 0x00, 0x00, 0x00, 0xC0, 0xCC, 0x0C, 0x00, 0x00, 0x00, 0x00, 0x00,
    0x80, 0x99, 0x19, 0x00, 0x00, 0x00, 0x00, 0x00, 0x40, 0x66, 0x26, 0x00, 0x00,
    0x00, 0x00, 0x00, 0x00, 0x33, 0x33, 0x00, 0x00, 0x00, 0x00, 0x00)) -ErrorAction SilentlyContinue | Out-Null
    Set-ItemProperty "HKCU:\Control Panel\Mouse" "SmoothMouseYCurve" ([byte[]](0x00, 0x00, 0x00,
    0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x38, 0x00, 0x00, 0x00, 0x00, 0x00,
    0x00, 0x00, 0x70, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0xA8, 0x00, 0x00,
    0x00, 0x00, 0x00, 0x00, 0x00, 0xE0, 0x00, 0x00, 0x00, 0x00, 0x00)) -ErrorAction SilentlyContinue | Out-Null
    Set-ItemProperty "HKCU:\Control Panel\Desktop" "UserPreferencesMask" ([byte[]](0x9e,
    0x1e, 0x06, 0x80, 0x12, 0x00, 0x00, 0x00)) -ErrorAction SilentlyContinue | Out-Null
 
    $MethodDefinition = @"
    [DllImport("user32.dll", EntryPoint = "SystemParametersInfo")]
    public static extern bool SystemParametersInfo(uint uiAction, uint uiParam, uint pvParam, uint fWinIni);
"@
    $User32Set = Add-Type -MemberDefinition $MethodDefinition -Name "User32Set" -Namespace Win32Functions -PassThru
    $User32Set::SystemParametersInfo(0x0071,0,15,0) | Out-Null
 
 
# endregion Accessibility
 
 
#region Choco
    # Chocolatey Package Manager."
    $env:chocolateyUseWindowsCompression = 'true'
    $packages = @(
        "choco install choco-upgrade-all-at-startup"
        "anydesk"
        "winrar"
        "google-drive-file-stream"
        "adobereader"
        "audacity"
        "google-chrome-x64"
        "sysinternals"
        "vlc"
        "everything"
        "youtube-dl-gui.install"
        "pdfsam.install"
        "adwcleaner"
        "bulkrenameutility.install"
    )
 
 
    If(Test-Path -Path "$env:ProgramData\Chocolatey") {
 
        choco feature enable -n=allowglobalconfirmation
        choco feature enable -n=allowemptychecksums
        choco upgrade chocolatey
        choco upgrade all --ignore-checksums -y
    }
    Else {
 
        [System.Net.WebRequest]::DefaultWebProxy.Credentials = [System.Net.CredentialCache]::DefaultCredentials; iex ((New-Object System.Net.WebClient).DownloadString('https://chocolatey.org/install.ps1'))  
 
        choco feature enable -n=allowglobalconfirmation
        choco feature enable -n=allowemptychecksums
        $packages | %{choco install $_  --ignore-checksums --force -y}
    }
 
 
#endregion Choco

Comments