lJ2aoFo=gjBXf)X0o52Z?Fn|?l7nC zt;>eR8={YGKUjL`JS2!mPaaztnM)4W9bQ^dV$jNq*iw7qocN=cECGK8odp!)NVD7 z@;mZ|Qa5o5hYGa679OOl3qjr9n>w0BvE8;{t!*5IZ`#H&Uu$wr2<#jGK+!n1{gr3O z*LoNvRVw{CFlLscHN^+j@SUb3ts&U%yJghznhqQ?e?(KG9T4Q?2%hGHb(e!{z@kpv z!qE$i)i~sph%LZ&46%hVi!1N2VohYA5)>Z~R=f#Pu=){v`rkW``x1+DLn8gHpY-Qi z<~g~?mDSnUoYoZ4wp96Pn@Fhe>K`kA@Uk24??{tH?^8<%{6#u+fo6E_y0iQ3S&3^N z*YMjT9le+DTUW1X=3ACIYI)xkHFWLv5s3Lvc}swUsyGfx$tO@?;72l`ARwFq^M?Io zQ3W&ZE8cZh6qnYRp(V}Bv#HUEaPUwIZ TDZ^f31v+rWzGI=-@ zpaw`j>11rDudB$F kRgKLGRM;I2-pGQI!dAbp|+Ve25}Yg*+dfJ&dY#$3gryW(ICzX4oDbj;`{0b7#J z&cl8(WS}w`z|Uuz{ni8^&5`fc6DTb4!KR4V$|zo0-Vx&|1PwjIrjH$lSqnSR>wYu( z$UsW6D0)a$$axS<8mOo@@c1P~#@a}=Nh31y7>AhC*!b2u3$jm`b$|(VUB*cdJE4XN z1Lt}}Yi4Jlpzxbvt(WEbs+E(c)D1=i94cxFGP>UwrhEQyD1QJ1$Yt-!ap(hB(=YTu zMomGP<+uI(kMQ`{fX%?A8G5AsB_RODwr%q5n0!IyNt3Z1{rU31;|=qw6MQSob8}d0 zz7%U&b|V4dzuuZpat$Ps<_*g(lkXxp{R5 zbAO`9iuw06iUdh{u2oc4AE?qlY P{00_6n8h< SDs1&@lgf}7U+6!_7izt2}qR(uv_5{nAdZbAPINg2E+kd z=4QMsyDl@LG9$KhaQ5x0XKzk#7oSJ4pCr%he+KlPoF_|vTsto%JiYb;j6Ux#V)w~+ zd6dX+UG+|(vo0RgOETQrjXaGO8g1o17X%ipK}~r8YHM80SSQv_NSmp#eK?AOI_@O z{L9meSJ~WqQghWqZPO+l+R9;{#MVE?E#ZH}Z6o$i*Kj`nyKne^#y7nFCJKSFE4+x_ zzZI;F7Y-6J!+ppMU;d2`xZ;qdG6JH&n-Hx f!J`!S0?EAeTAgH{+`N0A9M%P^E{YAc6W15sJj CLvn0^Q>SxoU(iDp zNf^ u~60I(TbMPVz^OYWh*aq@h+Y%-!gQOxY^>979H;!FIY2OHX-XT_kiKXlK{o!P<{Z z8qwsD#wYiI274MmUY$tpr}H%E=!3>E`e5yD&`jN<&x~LH#nT6kWFzBTWXgK;ZXv)N zoV7sir$Fa~h5@BMQtkgRGygZ&VgsJ?#c=4Yk+Ct-2zEA1Z5wCX4T6RHZ|vXXNkAjc zj7*Jd2{vhuVX}bP6nKI?G2J-yWYsjHmr^eNSwc w+8LsW3C4NO~<<@ZKsm?>sJYr z35*X3s}6anCl{C_1FJcVZ!Er@Uq7{szYF_F5<%RMD+V!Fw2TdWNftSEM=q;)$Rs#x zY+oL yE;&*7t yZjQ!Q_(wi5)t9N;5L=RYBiFxsSs9PZ}H;}kLw~Ch<&L?6^Mp)WdB%y@P zQ#uT?jefu={ZJ{8hla35Fp(yNJ;g@qPB31>=prHjgK-G9++}A=HYVSQLp`o#(Y7rJ zYXrGO<($Tr0LPmri^0HMc67Q57Q-P3Yb}s9sv1jh2>{fwvjst~A*H)2{cLck_ySlx zdd^Gx_k@7|iwv^7uvjhk4jz$&L$|2&tw?Tw-@V4>Ak`&2K)YrQ!8`%s8= m-cr zfSD_gzD`EEj1bJm-_A4ubS^W&QwH0yWWm@-PLB--`9`iU8(lw9F=^1aQWV|xJ|>fl zs?oqSU__|XK;qE#3FLTie-~;9IKMYxx`6bJSc2{E`5+}J0?j7@#SD$T!3AOKC$J@J z(vE#hkxTu?{=X;L&&|{e2yY|EnN$gE`3+9>bk+kp4rv;%jxPYc&qM+Itz_eiv_}9Y z=783p1HZ%KJ1qVauzzP*MEqXJiNBy1Y&@Uxo|Gn9Mwae}=lg3hlWFtZVm545;@*mX zUn97maG-jg%~}T|(M@0j*n9od$h9T;#*2i5?#1^>oZNZa!d!1J(KjpWcweW~-m-4( zUFY;Gt)JSj-CP~L$l{iMwwvmN<%x~q>a-Ae$Dg@yEL9z+{!padWOI$xk8_TH02}Y( fv;nnqxl(NkDJSUs`8OXv_&e f)F==y8?M^lmtN%V60ET zDk>O|R%X>55a_b<5DdW#L6m^_;L#9X0b-g$xCRmk3E6WQ_+$Urc88ta* Ke`-%wYt3lI}Wljqtbe6guH+|K-*v! zzK`Y4QtV-ETAe%gB5X9|`gT^F%j=Nawed$o`OCr&k^dyQ?}pj*;`~oN=aZM;c_=-; z)p^qV!Ux}aee_9+oM1gZeU7<%%ZFI ;#KwbY&ysKDda8|w8Ig$_UM4Ni~J~ zk8`tg3}h#cR)41Ln`#Wy{Ix}LaO7)pR1lruu*@7Po-=(LJzeo5AA}^LqJLZdU{_(9 zj11f0gfu^mLYr%yCTRPok_e7+RQlLAFO5P(TaQ!GA%Q_tD|mlDxE~eXE(!l5IpAV| ze}Moki=mZRc=x}xBrN4%sScLr!qDhy(6w8MscSwC1Rb6Yi(Vt3pU}U&=8pd01j<7< zLg)uvLK+HLPi)_1p{@V}B9fGor(TtW6nFCZ`#E+H#J4Oy&+owc-Fv*E!vs`{1O22S zCY5KEPTb|&el20J{Q94UmnB;h!|z8L?`0+EDj?fByK;%H`~pi0;XQz}HNjn{s9aZ0 zjL-tN+@*vqP&(Q%Ah>cLQsr=gDN2|xyVBtuB+ZfOe^#jav1Af`YsIe?@H;TC-)+)~ z0`1Oupw;|~KwCZ!v=RR)pp`fPpc2f^&f@X-waLlJGTo%|u3wuh!XqDEr81cenL=bQ zWri7Ta5exm%7ZW^2855?cBU3L#E9t(^@tehK34eXlEaOY+A%3(Ml;$VVMtBNqhSc# zsF sYR@9kr8VkAJKMF!!==gKdJ9}$=zp&E6p980zE`XQ{reW4ZWK!boQS7R z3{-p4KAYC7+s Uy04~5|h|qI2Wul%8 zncE#4;BJPz)9!a1j r zfGHB}%x7J^05{1w_kH4sfcz|CLYUxvo$`n@LyLKE_(h*6@sIO0^mjy;>=G0d)Jov= zI>GWglm{KGLM9Y1x3v{&bKZj|I$!n!?iswVudiAUCldhoeuD>Om)6?Az<#hWij8=U zMq>v2U#G0r1v=+h0S9{nJv?(b*LGdD6VX>q#8G?jtQQ%@&(P17hkDGl#mXBmhF4Kx zXmg
Gu)@w%I%uO`tEWFuoB6I^TjF9F48cADZez;;#rrMbILs|1rhlXAZSvKp7OdU50Z? z=!o)BDq=^izDH*?+Zfw5RVLPHk(6ESone_5Yiq*HW!(pxdTr2fxh$GlX40YN3?$w$ dvq)Z6pir6VtNqwl{Oq6=> Date: Thu, 10 Apr 2025 15:27:40 +0200 Subject: [PATCH 07/18] Update network-unlock.md --- .../data-protection/bitlocker/network-unlock.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/windows/security/operating-system-security/data-protection/bitlocker/network-unlock.md b/windows/security/operating-system-security/data-protection/bitlocker/network-unlock.md index ff99a2de31..729a225e25 100644 --- a/windows/security/operating-system-security/data-protection/bitlocker/network-unlock.md +++ b/windows/security/operating-system-security/data-protection/bitlocker/network-unlock.md @@ -139,7 +139,7 @@ To enroll a certificate from an existing certificate authority: 1. Select **All Tasks** > **Request New Certificate** 1. When the Certificate Enrollment wizard opens, select **Next** 1. Select **Active Directory Enrollment Policy** -1. Choose the certificate template that was created for Network Unlock on the domain controller. Then select **Enroll** +1. Choose the certificate template that was created for Network Unlock on the domain controller. In case the message "More information is required to enroll for this certificate. Click here to configure settings." is shown, click on it. On the new window, in **Subject** tab, under **Alternative names**, select **DNS** and set the FQDN of the WDS server. Save the changes by clicking **OK** and then select **Enroll** 1. When prompted for more information, select **Subject Name** and provide a friendly name value. The friendly name should include information for the domain or organizational unit for the certificate For example: *BitLocker Network Unlock Certificate for Contoso domain* 1. Create the certificate. Ensure the certificate appears in the **Personal** folder 1. Export the public key certificate for Network Unlock: From 1b528f43d2c372908cacada772840af6fe6498f8 Mon Sep 17 00:00:00 2001 From: Paolo Matarazzo <74918781+paolomatarazzo@users.noreply.github.com> Date: Thu, 10 Apr 2025 13:29:05 -0400 Subject: [PATCH 08/18] updates --- windows/configuration/unbranded-boot/index.md | 34 ++++++++++++++----- 1 file changed, 25 insertions(+), 9 deletions(-) diff --git a/windows/configuration/unbranded-boot/index.md b/windows/configuration/unbranded-boot/index.md index d5ee69d2e4..2d958f32b4 100644 --- a/windows/configuration/unbranded-boot/index.md +++ b/windows/configuration/unbranded-boot/index.md @@ -13,23 +13,40 @@ Unbranded Boot is a Windows feature that allows you to suppress Windows elements ## Enable Unbranded Boot -> [!IMPORTANT] -> The first user to sign in to the device must be an administrator. This ensures that the **RunOnce** registry settings correctly apply the settings. Also, when using auto sign-in, you must not configure auto sign-in on your device at design time. Instead, auto sign-in should be configured manually after first signing in as an administrator. - -Unbranded Boot is an optional component and isn't enabled by default in Windows. It must be enabled prior to configuring. +Unbranded Boot is an optional component and isn't enabled by default in Windows. To configure it, you must first enable it. If Windows is already installed, you can't apply a provisioning package to configure Unbranded Boot. You must use the Boot Configuration Data Editor (`bcdedit.exe`) to configure Unbranded Boot if Windows is installed. > [!NOTE] > `Bcdedit.exe` is a command-line tool for editing the Boot Configuration Data (BCD) of Windows. Administrator privileges are required to use BCDEdit to modify the BCD. -### Turn on Unbranded Boot by using Control Panel +There are different ways to enable Unbranded Boot, select the method that best fits your needs to learn more. -1. In the Windows search bar, type **Turn Windows features on or off** and either press **Enter** or tap or select **Turn Windows features on or off** to open the **Windows Features** window -1. In the **Windows Features** window, expand the **Device Lockdown** node, and select (to turn on) or clear (to turn off) the checkbox for **Unbranded Boot** -1. Select **OK**. The **Windows Features** window indicates that Windows is searching for required files and displays a progress bar. Once found, the window indicates that Windows is applying the changes. When completed, the window indicates the requested changes are completed +#### [:::image type="icon" source="../images/icons/control-panel.svg"::: **Control Panel**](#tab/control-panel1) + +To enable Unbranded Boot using Control Panel, follow these steps: + +1. Open **Control Panel** > **Programs** > **Turn Windows features on or off** or use the command `optionalfeatures.exe` +1. Expand **Device Lockdown** and select **Unbranded Boot** +1. Select **OK** to enable Unbranded Boot 1. Restart your device to apply the changes +#### [:::image type="icon" source="../images/icons/powershell.svg"::: **PowerShell**](#tab/powershell1) + +To enable Unbranded Boot using PowerShell, follow these steps: + +1. Open a PowerShell window with administrator privileges +1. Run the following command: + ```powershell + Enable-WindowsOptionalFeature -FeatureName Client-DeviceLockdown,Client-EmbeddedBootExp -Online + ``` +1. Restart your device to apply the changes + +--- + +> [!IMPORTANT] +> The first user to sign in to the device must be an administrator. This ensures that the **RunOnce** registry settings correctly apply the settings. Also, when using auto sign-in, you must not configure auto sign-in on your device at design time. Instead, auto sign-in should be configured manually after first signing in as an administrator. + ## Configure Unbranded Boot The following instructions provide details about how to configure your devices. Select the option that best suits your needs. @@ -94,7 +111,6 @@ You must enable Unbranded Boot on the installation media with DISM before you ca |`Runtime settings/SMISettings/HideBootLogo`| `TRUE` or `FALSE`| |`Runtime settings/SMISettings/HideBootStatusIndicator`| `TRUE` or `FALSE`| |`Runtime settings/SMISettings/HideBootStatusMessage`| `TRUE` or `FALSE`| -|`Runtime settings/SMISettings/CrashDumpEnabled`| `Full dump`| [!INCLUDE [provisioning-package-2](../../../includes/configure/provisioning-package-2.md)] From e2725e2eb076cb957b6e9f3c848cdcf13cd3aee4 Mon Sep 17 00:00:00 2001 From: Paolo Matarazzo <74918781+paolomatarazzo@users.noreply.github.com> Date: Thu, 10 Apr 2025 13:54:19 -0400 Subject: [PATCH 09/18] updates --- windows/configuration/unbranded-boot/index.md | 10 +++++----- 1 file changed, 5 insertions(+), 5 deletions(-) diff --git a/windows/configuration/unbranded-boot/index.md b/windows/configuration/unbranded-boot/index.md index 2d958f32b4..73c7bb1301 100644 --- a/windows/configuration/unbranded-boot/index.md +++ b/windows/configuration/unbranded-boot/index.md @@ -15,11 +15,6 @@ Unbranded Boot is a Windows feature that allows you to suppress Windows elements Unbranded Boot is an optional component and isn't enabled by default in Windows. To configure it, you must first enable it. -If Windows is already installed, you can't apply a provisioning package to configure Unbranded Boot. You must use the Boot Configuration Data Editor (`bcdedit.exe`) to configure Unbranded Boot if Windows is installed. - -> [!NOTE] -> `Bcdedit.exe` is a command-line tool for editing the Boot Configuration Data (BCD) of Windows. Administrator privileges are required to use BCDEdit to modify the BCD. - There are different ways to enable Unbranded Boot, select the method that best fits your needs to learn more. #### [:::image type="icon" source="../images/icons/control-panel.svg"::: **Control Panel**](#tab/control-panel1) @@ -55,6 +50,9 @@ The following instructions provide details about how to configure your devices. You can use the `bcdedit.exe` command to configure Unbranded Boot settings at runtime. +> [!NOTE] +> `Bcdedit.exe` is a command-line tool for editing the Boot Configuration Data (BCD) of Windows. Administrator privileges are required to use BCDEdit to modify the BCD. + 1. Open a command prompt as an administrator 1. Run the following command to disable the F8 key during startup to prevent access to the **Advanced startup options** menu @@ -103,6 +101,8 @@ Customize the boot screen using Windows Configuration Designer and Deployment Im You must enable Unbranded Boot on the installation media with DISM before you can apply settings for Unbranded Boot using either Windows Configuration Designer or applying a provisioning package during setup. +If Windows is already installed, you can't apply a provisioning package to configure Unbranded Boot. You must use the [command prompt](#tab/cmd) to configure Unbranded Boot if Windows is installed. + [!INCLUDE [provisioning-package-1](../../../includes/configure/provisioning-package-1.md)] |Path|Value| From 98844f1cb30e9cc1ae464639c5db724418305924 Mon Sep 17 00:00:00 2001 From: Paolo Matarazzo <74918781+paolomatarazzo@users.noreply.github.com> Date: Thu, 10 Apr 2025 13:57:43 -0400 Subject: [PATCH 10/18] updates --- windows/configuration/unbranded-boot/index.md | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/windows/configuration/unbranded-boot/index.md b/windows/configuration/unbranded-boot/index.md index 73c7bb1301..c4c594ffa3 100644 --- a/windows/configuration/unbranded-boot/index.md +++ b/windows/configuration/unbranded-boot/index.md @@ -19,7 +19,7 @@ There are different ways to enable Unbranded Boot, select the method that best f #### [:::image type="icon" source="../images/icons/control-panel.svg"::: **Control Panel**](#tab/control-panel1) -To enable Unbranded Boot using Control Panel, follow these steps: +To enable Unbranded Boot using the Control Panel, follow these steps: 1. Open **Control Panel** > **Programs** > **Turn Windows features on or off** or use the command `optionalfeatures.exe` 1. Expand **Device Lockdown** and select **Unbranded Boot** @@ -144,10 +144,10 @@ If Windows is already installed, you can't apply a provisioning package to confi dism /unmount-wim /MountDir:c:\wim /Commit ``` -In the following image, the BootLogo is outlined in green, the BootStatusIndicator is outlined in red, and the BootStatusMessage is outlined in blue. - --- +In the following image, the BootLogo is outlined in green, the BootStatusIndicator is outlined in red, and the BootStatusMessage is outlined in blue. + :::image type="content" source="images/boot.png" alt-text="Screenshot of the boot screen showing the areas that can be configured with Unbranded Boot. "::: ## Replace the startup logo From dd7cc6629dfb8c91110bafe1b0dfda231969d3c3 Mon Sep 17 00:00:00 2001 From: Paolo Matarazzo <74918781+paolomatarazzo@users.noreply.github.com> Date: Thu, 10 Apr 2025 14:52:12 -0400 Subject: [PATCH 11/18] updates --- .../unbranded-boot/images/boot.png | Bin 6501 -> 9295 bytes windows/configuration/unbranded-boot/index.md | 6 +++++- 2 files changed, 5 insertions(+), 1 deletion(-) diff --git a/windows/configuration/unbranded-boot/images/boot.png b/windows/configuration/unbranded-boot/images/boot.png index c192c94c4b9e74b6cdc78e644cc1f3363fe1ed4f..4f8de5713bf49bcd705acc8ba35fa935b84f6140 100644 GIT binary patch literal 9295 zcmeHNX;f2Lw!Vl$DFxa^IS~d+o+5)#q7VidN@WrRktxV*L`3EwGa&(6&_bXT1eqs6 zFboEinE+}B0U-$@$Q0&;K|u&p0wnKTy1Q2YdaKu~^?KEM%OB*DbI;lL>~r?{_P4*A z` LzLHy8n0-&WOtFHxIcKaII`a_VADE!9 (*|sIR@<^P-{ct1`#ob-2gNZy|r-L@+8eN_7 ztd==;!N_yqqS3Uhs+|44-L5}v{wj)AI+R|@Hxhm$Xe)MQ{(aZyP)Em}Qqhw;MR; zxSg!!4HjD@skg+dWQ;s8fT~vMjV|5*bA{?=4ABxdOIpP|oX}sqr(y*d!43Kkcmt@Q z{lD;o`>1eq+=??=>&(jHgXG67f;rj-jeSY9{t?{6|IJ2FQNMk%?9rmK`tYI%Q%Ky& zy@Ynu6E@tK8y#P2QN1^NW7H%P?S{q{!mZ0$Iwum{?#!#Ry8QVKGKcmdK_lMLTIsKt z-v4S%jYNl`vBldRNg8eDl*x6!t?L{)IfR(ULeELit{W9<)E~F9npdn@wcih(;JYi; z#XW@PthCYK!tcc4E?JBp4KhcIQc(SuVM|LrvhibLYWnc5>XwzN_ PiTDiw*9k_@N@6U_`+?AJ4L|f zk*sDuaC!S}(4S=?z}6dn+o5lv`t8hq1FwGr#RY^Qg J&=OR@js9N z?(Bj%pDcpTS~(Zj`1QqsZ;y9>%M<^aFzL>GP$<1EQN}neGBWb;g40EwBBZ
j?&JXQx&*-^!CaX+2AV#c`ee50Suec7K8_%nqaP^yWEx40DlHrx&TWvJV=lkf+ z1U@KdKVTa|-cuVk$sIZYA+?hX F@o6^kUMA;KFT!))H40NnD1 zv@i6+S k zfbd3K%07Hq&C&;(t~p(rU0F>*?Q #K00#Z~%MgQnvhH*+}3l>0o>#6*F2iJLP6W!nvw*-!ATeba9n>yYTVC*zlrK zX5aldExXl>{YVDE+X}=Ha4Wv25;>4cubCLoY)9%WcVaq^^_|fvw?JeTS%|ax#rUD- z?s49CeA9-*N4w)^UMvpW?`zNIO;S3XxXVh$&lCqSwqRqLU}v8WS0bOsWJMHtvgyf7 zcTyrQ*SWCCQ@bEMm+_l9q;aLX=w&`RPNR`_NnW+=gz<25v#zaNa(9yuMAb9_emxB2 zH>jS_SE+F<7lfvRz-CL#+~wC!ai}YSAnM5POj6f?9 Ad4}0D?H_7X8rlySJxB4{j=#Htw@MFtB}+SPmy$Ww+`9`F^t#7*9Qve&XN&%^+cW zNHd?V0U4*}sQ40{ASDl|IC6V^&g&~(cUI#h=68((ehfCyKZb-YvOi(Koj3f)8cN_c z*LS6k7kxmqX1&k?VFw3 ?3Sqf$qR8k*+qjiN@F~mbmKM;mLx%q$~I{?Sv^F^1Rq+8G7a1f-d zeg`xV{xV+LHzH>fzVvGqWl}9Wl%YSId=0}7;Zp(ESGXs3)REUVH`Q+DWDB2;nG1~< zJB*#MZK((d%1CMEYmO=wOdzcn9PBuTbh;9)t!=5eHCo_>#R?+=G~4gi>;zG33#N0x zUiilVhX(F=#S-JO>&i(&$0( IqS_sOx6TL?@`4w$Ev7p}+%C zowMeSTVn*^YF(R^C8z-Yja2jdHvc&b29OD L`5q##FyCReUgj&E%ZKU255pJ0RnPKR_A* z!NO~+UUr^QvxRbS|G5zJc>zJUTfTnvJ$(4EY`UtKoJU`oSA?U_Tw37dyN3)h1VTPR zYZb)`T$>;6w1e=b-=FDi1HPINcz%cz?`?z++Esg>9IW!v+<%%e$K6;^(hU53;x>6s z5+88`K+#R(% {RAAs;|z#W?(P5M;Smq*8i&DTB)soyu- z`#3i@_w{DTFh7+duDl0&|J>C5?E2^(*9Cf`&;ev2t}9v?u?K1ne=-U=8!aLGhs~>V zdswIHUhQ{PJ+7v~4A`ry<1Zix#TJtE=yX)Nm`4p!)nwR4!o7r8{OTET^%C~|UGqEo z!|_)rWR$|nEg&wjT%-8$yO7 nXp);t&t<>S=12>I zKrE3+v`8?^t~BpkE^wWjB$Kckdoo#df;rjSe6Nm}YwC4-ZZev)##vMC-8!i~f@oar zM0)oWnM> hb2K1`wIx$uKj@O4yCg!3Q>C>;=wEgm<<7hPV4+pj0{$pZP zE1|>4!novG=@?{aDR5$SVPpg|RAgs5-@r0;$rs#SUqv~HdMv=M{ibbjzJ*Tge36Z@ zyNdVOug(0fEJo+J07UhNS ?SjnO&JDwSrpX zC8oF=c3Qjc3bp)m0{iR5JUld=epc>Yk0RTY*jlU^CM|ugEci@!xQIyPTS>L+Vm(2I z`g<^k;_8kSNFKfD^UvkD?fI0rTE&^<+^94CzNh(AqL_N%=ORI^B M``GK4>ZMYUa?Btnnw-6J$nb!AsvZ8rGE| zE8??!!{(W4RtO_iJv(TjaZR;6>72l}h4cD+)9<3YuMHK=BBo|)PDz}aWu8A@Fyz-d zlViRxNNRj}?WqF2R?65&o|Y$hLe3k4WC1hKQ10$ZM0#m#EoKHKV@8{2D096@WW?-; zk>IB $ zXRWt3 %UalO5sM|-*M!Fq5yfj{d59- z!ei(O{ReZ(@TUq_WsCx2fhwb~ub<}T`<}cE+`9<7hc4iExQCG7iD0h>2d_?`=Em~S ztaTP3(7Rv)9a8e%Ld$<*sK%T^e-h&+RQk!6VRh? 07duqFGgwsGNms^h5Iyvn$+mu;rGP-gmrL7Fvt7-6 zkw17N{ax0zFd$hc{(fZ8r6*(ay`O%v@50?j;S#q@kE 9H(J)>;-alo_M9Bx|BWVKZ3y7#>&J&ZixBvt z`E%=3a7;{$5Tq*yk3x8rNVqO#Jn&XmUePiTVyW~U*bkI%Ll~%z%pQ0Y`rUL^cdbDo zDaA`RGu0ys{h{#EF6hW(LJ{<0R9|eaj9l0F@)>{< QOD&|FY)qZ3t4IYARYVb!QbA)kJNpJ&djHs)7&k4G+keM} z&i1EE{{%WC`gEr!KyugX*C!hi76z-!J^L#PertnKgYmrxG%dYXYnfV-(6>%>c@w<@ z`b~cn!fRKAt$DkFcNE5tfM}0>N{;I `-0~NS6;WT6k zO=tWug5zxdcRMJK_VN^%du%Hxd;eUoYXA*HMG4rHD9+({I?2Z6q~ek~Mqx$xa9I0j z`^U~!`dRMP)Zi)h5?Nj;>3jk&=Yh`F%~Z9`b0BIkyTzLyRWLYq?XPf~{S}O8yKOm0 zpq!nFaYs9FBNNUnXf9Jml$5w{kZD9vro97tkn!tZb3NKOv;#)|AqNFaFD|6u`mx#f zfdu&-=&@Kv3b3nPHPa5eC3I0nv576+Df=5!l6%!Z54Hg$7}{)Lk{Ghi-FM1$YQ(d# zK4fEPjbshVTRKxtPPgRlJ%k&UM_wz_0sW`3I|TQ+huXEDBj`-b+VL#F%tO >FiNrCcScY&z4>mFt$rux-#gBX%KE4rX1@7>cDmoMs* z&Dk9GIG%0sOyer?$>25M-zwmN*MMfE*i`#!CQg(0b?HWP(d=Kz2c;rvKl7%D4CX>T zMvp!I#Re&Di0zV5-TOFGNBazOtwdBjz~g;-s}n$0U7u4ed~b^)bFHLEW6Osnf)+x? zEQg9BxO2#MC*JbcV#-K$M2P!G4lc|9UMxWKkC5y3hCiKR(zmLWGC1qZrmW!B2^EZq z-K%h0_m2gAo2J_x!K$KY ba N)c;Q7719+hyyKS`sPfK8V~}3uP8MTRTC=*an^NHnmnJ)l1ij^ql=ZX(;8VG z (n56=22CzRZkXY?9+3StDl~o0s dH*0=lzN6FkRH-Q@JmNamKNEq}=Jhps&V-TH*G5jjq4R?p{zO1j z{$sDBD-cbyiS60X&Oh&VH{RVqhVHGsI^z?c8SrVE-7_N$=nIq+)StKGEt_3Ux*W|L zoL8>Ftdvj)f)66L44T}_K6WU{AxoTS4ZNvE(UW>{?mnc&tLzl5wf*o&P!o>#7{Ah9 zYwWFhZbA@Dn1=)WmW;P0MQhUvR^@aPMAh(yO5CmUUIy{(BAqw=Kv$z~>=Zd-t>t_B zCuxH%da2|sz*6i{Kt0U+2rV)e`?kSKoicgTO3Odr+xS#1Sb23Y#BsQ6seNKZ2?hZB z2$s}i(;oSPvn!=aYW@I4UVjI$?($yAt^O|Fm0o+CaV_V~;DCsPif51ezLY2+gPQCR zeDSnL*Szo7fW9;6*1B|^?# exq>w%_(vXtU1CBg?q@eicm|B$Feh@61MVd!1J zQ-OFQyqdqw5yjLb!RrF>%L)-tSOF0lAjANYy52fK4!to8BxvYJ8w%}}p?!TBXd7Sz zGnbPPS!`zF2X}QRi+LC~I;aM;BH~nNC>XgR=y2efUJ|FJ;`IEcA6i(YS8DrLCv@wC z!S(KCnU1cIuk~@Sh{Wh^*5dP==^f5^ubJHW^=W87DsfwxQ+l3=$W~wLa%F~KGADzp zOiVFq!LXGY>a3M>6BU(zTC2u0S?Mel6(;7 6Qq3`F7Tkr5^h__5opX-* EZ=x}<1^@s6 literal 6501 zcmeHLdr(tX8b1*PMS09(K_o)4tyD`v6iA9mKn1I|g4;R>f)F==y8?M^lmtN%V60ET zDk>O|R%X>55a_b<5DdW#L6m^_;L#9X0b-g$xCRmk3E6WQ_+$Urc88ta* Ke`-%wYt3lI}Wljqtbe6guH+|K-*v! zzK`Y4QtV-ETAe%gB5X9|`gT^F%j=Nawed$o`OCr&k^dyQ?}pj*;`~oN=aZM;c_=-; z)p^qV!Ux}aee_9+oM1gZeU7<%%ZFI ;#KwbY&ysKDda8|w8Ig$_UM4Ni~J~ zk8`tg3}h#cR)41Ln`#Wy{Ix}LaO7)pR1lruu*@7Po-=(LJzeo5AA}^LqJLZdU{_(9 zj11f0gfu^mLYr%yCTRPok_e7+RQlLAFO5P(TaQ!GA%Q_tD|mlDxE~eXE(!l5IpAV| ze}Moki=mZRc=x}xBrN4%sScLr!qDhy(6w8MscSwC1Rb6Yi(Vt3pU}U&=8pd01j<7< zLg)uvLK+HLPi)_1p{@V}B9fGor(TtW6nFCZ`#E+H#J4Oy&+owc-Fv*E!vs`{1O22S zCY5KEPTb|&el20J{Q94UmnB;h!|z8L?`0+EDj?fByK;%H`~pi0;XQz}HNjn{s9aZ0 zjL-tN+@*vqP&(Q%Ah>cLQsr=gDN2|xyVBtuB+ZfOe^#jav1Af`YsIe?@H;TC-)+)~ z0`1Oupw;|~KwCZ!v=RR)pp`fPpc2f^&f@X-waLlJGTo%|u3wuh!XqDEr81cenL=bQ zWri7Ta5exm%7ZW^2855?cBU3L#E9t(^@tehK34eXlEaOY+A%3(Ml;$VVMtBNqhSc# zsF sYR@9kr8VkAJKMF!!==gKdJ9}$=zp&E6p980zE`XQ{reW4ZWK!boQS7R z3{-p4KAYC7+s Uy04~5|h|qI2Wul%8 zncE#4;BJPz)9!a1j r zfGHB}%x7J^05{1w_kH4sfcz|CLYUxvo$`n@LyLKE_(h*6@sIO0^mjy;>=G0d)Jov= zI>GWglm{KGLM9Y1x3v{&bKZj|I$!n!?iswVudiAUCldhoeuD>Om)6?Az<#hWij8=U zMq>v2U#G0r1v=+h0S9{nJv?(b*LGdD6VX>q#8G?jtQQ%@&(P17hkDGl#mXBmhF4Kx zXmg
Gu)@w%I%uO`tEWFuoB6I^TjF9F48cADZez;;#rrMbILs|1rhlXAZSvKp7OdU50Z? z=!o)BDq=^izDH*?+Zfw5RVLPHk(6ESone_5Yiq*HW!(pxdTr2fxh$GlX40YN3?$w$ dvq)Z6pir6VtNqwl{Oq6=> Date: Thu, 10 Apr 2025 14:53:15 -0400 Subject: [PATCH 12/18] updates --- includes/licensing/unbranded-boot.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/includes/licensing/unbranded-boot.md b/includes/licensing/unbranded-boot.md index bc94014ea5..b83afd7e98 100644 --- a/includes/licensing/unbranded-boot.md +++ b/includes/licensing/unbranded-boot.md @@ -7,7 +7,7 @@ ms.topic: include ### Windows edition requirements -The following list contains the Windows editions that support unbranded boot: +The following list contains the Windows editions that support Unbranded Boot: ✅ Enterprise / Enterprise LTSC\ ✅ Education\ From ea9b4b4692ebe1534ee7da32da79d867707eab32 Mon Sep 17 00:00:00 2001 From: Paolo Matarazzo <74918781+paolomatarazzo@users.noreply.github.com> Date: Thu, 10 Apr 2025 14:58:02 -0400 Subject: [PATCH 13/18] updates --- windows/configuration/unbranded-boot/index.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/windows/configuration/unbranded-boot/index.md b/windows/configuration/unbranded-boot/index.md index 7a2dd20ff5..592e80cdc8 100644 --- a/windows/configuration/unbranded-boot/index.md +++ b/windows/configuration/unbranded-boot/index.md @@ -152,7 +152,7 @@ In the following image: 1. `BootStatusIndicator` is outlined in red 1. `BootStatusMessage` is outlined in blue -:::image type="content" source="images/boot.png" alt-text="Screenshot of the boot screen showing the areas that can be configured with Unbranded Boot. "::: +:::image type="content" source="images/boot.png" alt-text="Screenshot of the boot screen showing the areas that can be configured with Unbranded Boot." border="false"::: ## Replace the startup logo From 409423db75ace979a7e7cb59ec60b928c9d0f099 Mon Sep 17 00:00:00 2001 From: Paolo Matarazzo <74918781+paolomatarazzo@users.noreply.github.com> Date: Thu, 10 Apr 2025 15:01:08 -0400 Subject: [PATCH 14/18] updates --- windows/configuration/unbranded-boot/index.md | 6 ++---- 1 file changed, 2 insertions(+), 4 deletions(-) diff --git a/windows/configuration/unbranded-boot/index.md b/windows/configuration/unbranded-boot/index.md index 592e80cdc8..bc1233023a 100644 --- a/windows/configuration/unbranded-boot/index.md +++ b/windows/configuration/unbranded-boot/index.md @@ -112,10 +112,8 @@ If Windows is already installed, you can't apply a provisioning package to confi |`Runtime settings/SMISettings/HideBootStatusIndicator`| `TRUE` or `FALSE`| |`Runtime settings/SMISettings/HideBootStatusMessage`| `TRUE` or `FALSE`| -[!INCLUDE [provisioning-package-2](../../../includes/configure/provisioning-package-2.md)] - - > [!TIP] - > For more information, see [SMISettings](/windows/configuration/wcd/wcd-smisettings) in the Windows Configuration Designer reference. +> [!TIP] +> For more information, see [SMISettings](/windows/configuration/wcd/wcd-smisettings) in the Windows Configuration Designer reference. 1. Once you have finished configuring the settings and building the package or image, you use DISM to apply the settings. 1. Open a command prompt with administrator privileges. From 3bf4c6137aad6add077138ed8a04ba298b5ed74f Mon Sep 17 00:00:00 2001 From: Paolo Matarazzo <74918781+paolomatarazzo@users.noreply.github.com> Date: Thu, 10 Apr 2025 15:43:01 -0400 Subject: [PATCH 15/18] update --- windows/configuration/unbranded-boot/index.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/windows/configuration/unbranded-boot/index.md b/windows/configuration/unbranded-boot/index.md index bc1233023a..efb6fe6da6 100644 --- a/windows/configuration/unbranded-boot/index.md +++ b/windows/configuration/unbranded-boot/index.md @@ -101,7 +101,7 @@ Customize the boot screen using Windows Configuration Designer and Deployment Im You must enable Unbranded Boot on the installation media with DISM before you can apply settings for Unbranded Boot using either Windows Configuration Designer or applying a provisioning package during setup. -If Windows is already installed, you can't apply a provisioning package to configure Unbranded Boot. You must use the [command prompt](#tab/cmd) to configure Unbranded Boot if Windows is installed. +If Windows is already installed, you can't apply a provisioning package to configure Unbranded Boot. You must use the command prompt to configure Unbranded Boot if Windows is installed. [!INCLUDE [provisioning-package-1](../../../includes/configure/provisioning-package-1.md)] From 72a8494882caa1bd7e229354b2df3c93421e219e Mon Sep 17 00:00:00 2001 From: David Strome <21028455+dstrome@users.noreply.github.com> Date: Thu, 10 Apr 2025 16:37:46 -0700 Subject: [PATCH 16/18] Add AutoPublish workflow to repo --- .github/workflows/AutoPublish.yml | 25 +++++++++++++++++++++++++ 1 file changed, 25 insertions(+) create mode 100644 .github/workflows/AutoPublish.yml diff --git a/.github/workflows/AutoPublish.yml b/.github/workflows/AutoPublish.yml new file mode 100644 index 0000000000..a7e46e4f16 --- /dev/null +++ b/.github/workflows/AutoPublish.yml @@ -0,0 +1,25 @@ +name: (Scheduled) Publish to live + +permissions: + contents: write + pull-requests: write + +on: + schedule: + - cron: "25 5,11,17,22 * * *" # Times are UTC based on Daylight Saving Time. Need to be adjusted for Standard Time. Scheduling at :25 to account for queuing lag. + + workflow_dispatch: + +jobs: + + auto-publish: + if: github.repository_owner == 'MicrosoftDocs' && contains(github.event.repository.topics, 'build') + uses: MicrosoftDocs/microsoft-365-docs/.github/workflows/Shared-AutoPublish.yml@workflows-prod + with: + PayloadJson: ${{ toJSON(github) }} + EnableAutoPublish: true + + secrets: + AccessToken: ${{ secrets.GITHUB_TOKEN }} + PrivateKey: ${{ secrets.M365_APP_PRIVATE_KEY }} + ClientId: ${{ secrets.M365_APP_CLIENT_ID }} \ No newline at end of file From 7cc51b796de9df3c11797bed757885c86bd6a9d5 Mon Sep 17 00:00:00 2001 From: Paolo Matarazzo <74918781+paolomatarazzo@users.noreply.github.com> Date: Fri, 11 Apr 2025 07:18:50 -0400 Subject: [PATCH 17/18] minor fixes for consistency --- windows/configuration/unbranded-boot/index.md | 47 +++++++++---------- 1 file changed, 21 insertions(+), 26 deletions(-) diff --git a/windows/configuration/unbranded-boot/index.md b/windows/configuration/unbranded-boot/index.md index efb6fe6da6..e1ad8ae711 100644 --- a/windows/configuration/unbranded-boot/index.md +++ b/windows/configuration/unbranded-boot/index.md @@ -1,7 +1,7 @@ --- title: Unbranded Boot description: Learn about Unbranded Boot, a feature that suppresses Windows elements that appear when Windows starts. Unbranded Boot can also suppress the crash screen when Windows encounters an error that it can't recover from. -ms.date: 04/09/2025 +ms.date: 04/11/2025 ms.topic: how-to --- @@ -115,38 +115,33 @@ If Windows is already installed, you can't apply a provisioning package to confi > [!TIP] > For more information, see [SMISettings](/windows/configuration/wcd/wcd-smisettings) in the Windows Configuration Designer reference. -1. Once you have finished configuring the settings and building the package or image, you use DISM to apply the settings. - 1. Open a command prompt with administrator privileges. - 1. Copy install.wim to a temporary folder on hard drive (in the following steps, it assumes it's called c:\\wim). - 1. Create a new directory. +Once you finish to configure the settings and building the package or image, use DISM to apply the settings: - ```cmd - md c:\wim - ``` +1. Open a command prompt with administrator privileges +1. Copy `install.wim` to a temporary folder on the hard drive (for example, `c:\wim`) +1. Create a new directory to mount the image: - 1. Mount the image. - - ```cmd - dism /mount-wim /wimfile:c:\bootmedia\sources\install.wim /index:1 /MountDir:c:\wim - ``` - - 1. Enable the feature. - - ```cmd - dism /image:c:\wim /enable-feature /featureName:Client-EmbeddedBootExp - ``` - - 1. Commit the change. - - ```cmd - dism /unmount-wim /MountDir:c:\wim /Commit - ``` + ```cmd + md c:\wim + ``` +1. Mount the image: + ```cmd + dism /mount-wim /wimfile:c:\bootmedia\sources\install.wim /index:1 /MountDir:c:\wim + ``` +1. Enable the feature: + ```cmd + dism /image:c:\wim /enable-feature /featureName:Client-EmbeddedBootExp + ``` +1. Commit the change: + ```cmd + dism /unmount-wim /MountDir:c:\wim /Commit + ``` --- In the following image: -1. `BootLogo` is outlined in green, the +1. `BootLogo` is outlined in green 1. `BootStatusIndicator` is outlined in red 1. `BootStatusMessage` is outlined in blue From 49480b46c0d5283ae630d39b078cbdfbe0973c87 Mon Sep 17 00:00:00 2001 From: Paolo Matarazzo <74918781+paolomatarazzo@users.noreply.github.com> Date: Fri, 11 Apr 2025 07:27:23 -0400 Subject: [PATCH 18/18] updates --- windows/configuration/unbranded-boot/index.md | 11 +++++++---- 1 file changed, 7 insertions(+), 4 deletions(-) diff --git a/windows/configuration/unbranded-boot/index.md b/windows/configuration/unbranded-boot/index.md index e1ad8ae711..a7edd8a9cf 100644 --- a/windows/configuration/unbranded-boot/index.md +++ b/windows/configuration/unbranded-boot/index.md @@ -46,6 +46,9 @@ To enable Unbranded Boot using PowerShell, follow these steps: The following instructions provide details about how to configure your devices. Select the option that best suits your needs. +> [!NOTE] +> If Windows is already installed, you can't apply a provisioning package to configure Unbranded Boot. Instead, you must use the command prompt to configure Unbranded Boot. + #### [:::image type="icon" source="../images/icons/cmd.svg"::: **Command prompt**](#tab/cmd) You can use the `bcdedit.exe` command to configure Unbranded Boot settings at runtime. @@ -72,7 +75,7 @@ You can use the `bcdedit.exe` command to configure Unbranded Boot settings at ru bcdedit.exe -set {globalsettings} bootuxdisabled on ``` -1. Run the following command to suppress any error screens that are displayed during boot. If **noerrordisplay** is on and the boot manager hits a *WinLoad Error* or *Bad Disk Error*, the system displays a black screen +1. Run the following command to suppress any error screens that are displayed during boot. If `noerrordisplay` is set to `on` and the boot manager hits a *WinLoad Error* or *Bad Disk Error*, the system displays a black screen ```cmd bcdedit.exe -set {bootmgr} noerrordisplay on @@ -80,7 +83,7 @@ You can use the `bcdedit.exe` command to configure Unbranded Boot settings at ru #### [:::image type="icon" source="../images/icons/xml.svg"::: **Unattend**](#tab/unattend) -You can configure the Unattend settings in the `Microsoft-Windows-Embedded-BootExp` component to add Unbranded Boot features to your image during the design or imaging phase. You can manually create an Unattend answer file or use Windows System Image Manager (Windows SIM) to add the appropriate settings to your answer file. For more information about the Unbranded Boot settings and XML examples, see the settings in [Microsoft-Windows-Embedded-BootExp](/windows-hardware/customize/desktop/unattend/microsoft-windows-embedded-bootexp). +You can configure the Unattend settings in the `Microsoft-Windows-Embedded-BootExp` component to add Unbranded Boot features to your image during the design or imaging phase. You can manually create an Unattend answer file or use Windows System Image Manager (Windows SIM) to add the appropriate settings to your answer file. ### Unbranded Boot settings @@ -95,14 +98,14 @@ The following table lists Unbranded Boot settings and their values. | `HideBootStatusIndicator` | Contains an integer that suppresses the status indicator that displays during the OS loading phase. | - Set to `1` to suppress the status indicator
- The default value is `0`| | `HideBootStatusMessage` | Contains an integer that suppresses the startup status text that displays during the OS loading phase. | - Set to `1` to suppress the startup status text
- The default value is `0`| +For more information about the Unbranded Boot settings and XML examples, see the settings in [Microsoft-Windows-Embedded-BootExp](/windows-hardware/customize/desktop/unattend/microsoft-windows-embedded-bootexp). + #### [:::image type="icon" source="../images/icons/provisioning-package.svg"::: **PPKG**](#tab/ppkg) Customize the boot screen using Windows Configuration Designer and Deployment Image Servicing and Management (DISM). You must enable Unbranded Boot on the installation media with DISM before you can apply settings for Unbranded Boot using either Windows Configuration Designer or applying a provisioning package during setup. -If Windows is already installed, you can't apply a provisioning package to configure Unbranded Boot. You must use the command prompt to configure Unbranded Boot if Windows is installed. - [!INCLUDE [provisioning-package-1](../../../includes/configure/provisioning-package-1.md)] |Path|Value|