Thursday, 15 December 2016

SCCM 2016 / SCCM CM1511 Planning work Sheet

SCCM 2016 / SCCM CM1511 Planning work Sheet

 

 

 

 

Active Directory Planning

Active Directory Planning

Example Data Needed, Where Applicable, and by Location

Collected Data

Do you plan on using your Active Directory Sites to define your Configuration Manager  boundaries?

If yes, list the Active Directory sites that you will use.

 

Do you plan on extending your Active Directory schema for Configuration Manager ?

If yes, determine whether you have the appropriate permissions to extend the schema.

 

Do you need to manage Configuration Manager  sites across multiple forests?

If yes, be aware of limitations across forests.

 

 

 

 

Discovery Planning

Discovery planning

Example data needed, where applicable, and by location

Collected Data

Active Directory System Discovery. Active Directory System Discovery retrieves details about the computer, such as computer name, Active Directory container name, IP address, and Active Directory site. It generates a DDR for each computer it discovers in Active Directory.

Active Directory container and location (local domain, local forest, custom LDAP or GC query) Polling schedule

 

Active Directory System Group Discovery. Active Directory System Group Discovery works only for systems that are already discovered and assigned to the local primary site and any direct child secondary sites. Active Directory System Group Discovery is not available for secondary sites. If a resource has been discovered and is assigned to the Configuration Manager  site, Active Directory System Group Discovery extends other discovery methods by retrieving details such as organizational unit, global groups, universal groups, and nested groups.

Active Directory container and location (local domain, local forest, custom LDAP or GC query) Polling schedule

 

Active Directory User Discovery. The Active Directory User Discovery method discovers users and the user groups of which they are members. Active Directory User Discovery returns more information from Active Directory domains than Windows User Account Discovery or Windows User Group Discovery and it continues to work with those domains when you switch them to native mode.

Active Directory container and location (local domain, local forest, custom LDAP or GC query) Polling schedule

 

Network Discovery. The Network Discovery method can be configured to discover the topology of your network, as well as potential client computer information. By querying specified network routers, network discovery retrieves information about the network topology and routers in use. Using discovered router information, or specified Microsoft DHCP server IP address lease information, network discovery can also discover potential client computer information such as IP address and operating system version.

Type of Discovery (Topology, Topology and client, Topology, client, and client operating system), IP subnets to search, and Microsoft DHCP server names to query.

 

Active Directory Forest Discovery
Unlike other Active Directory discovery methods, Active Directory Forest Discovery does not discover resources that you can manage. Instead, this method discovers network locations that are configured in Active Directory and can convert those locations into boundaries for use throughout your hierarchy.

Account requied with permissions to the non-trusted forest

 

 

 

 

 

 

Boundaries Planning

Boundary Type

Example data needed, where applicable, and by location

Collected Data

IP subnet

What subnets will you assign as site boundaries for this site?

 

Active Directory site name

What Active Directory sites will you use as site boundaries for this site?

 

IPv6 prefix

What IPv6 prefixes will you use as boundaries for this site?

 

IP range

What IP ranges will you use for this site?

 

 

 

 

 

 

 

Site Systems  Planning

 

 

 

 

 

Site name

Site code

Primary site? (Note if the site is the central site.)

Secondary site? (Indicate parent site name and site code)

Potential number of clients managed by this site:

IP subnet(s) or Active Directory sites associated with this site.

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

Site Planning Summary Worksheet

 

 

 

 

 

Computer name

Site server

Management point?Indicate whether it is the default or proxy.

Site database server?

Reporting point?Primary site only.

Distribution point and other Roles Servers

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

Configuration Manager Console

 

Computer Name

Location

For Which Users / Groups going to Use

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

Client Installation Planning

Client installation methods

Explanation

Configuration parameters

Install Clients Using Software Update Point Based Installation

The Software update point (SUP) client installation method installs the Configuration Manager  client software on any computer that can communicate with the site's software update point.

To specify the setup parameter information for the client installation you will need to create the SetupParameters registry string value in the following registry key: HKey_Local_Machine \Software \Policies \Microsoft \CCMSetup 

 

CCMSetup.exe will locate the setup parameters using this registry string value. For example: the registry string value information /mp:[ServerName] is read by CCMSetup.exe and the Configuration Manager client is directed to the server name specified. Specifying parameters through the registry key SetupParameters is the equivalent of specifying the installation parameters using the command line.

 

Client imaging

You can load client software components on the computer when it is originally prepared for service in your organization. Typically, computer preparation work is done by an IT team in a staging area. The client is installed on a computer master image by installing core client components without specifying a site code for assignment. The computer is ready to be assigned to a site when it arrives at the location where will be used in production.

Identify the CCMSetup.exe command line options you will use when installing the client on the master computer to be imaged.

 

Identify any registry modifications that need to be made for the preferred client type.

 

Identify the site code that the client should be assigned to.

 

Client Push installation

Client Push Installation is useful for installing the client software on computers that:

Enabled?

 

 

Have been discovered by Configuration Manager  but do not have the client software installed.

For computers running Windows Vista you must enable the remote registry service or the client push installation will fail on those clients.

 

 

Rarely log on to the network because the users lock their Windows sessions instead of logging out.

Identify the client push installation account that will be used.

 

 

Log on with a user account that does not run a logon script or does not have administrative permissions on the computer.

Identify whether you will push the client to servers, workstations, or domain controllers.

 

 

Are servers that users might not log on to for a long period of time.

 

 

 

Manual installation

You can use CCMSetup.exe to manually install the Configuration Manager  client software to a computer. CCMSetup.exe uses the Client.msi program to install the client software. CCMSetup.exe copies all the files necessary to complete the client installation, including the Client.msi and language-specific files and folders, to the computer.

Identify how and when CCMSetup.exe will be run on each client

 

Identify any specific command line options required.

 

Active Directory Group Policy

You can distribute the Configuration Manager  client software using Active Directory Group Policy. Because of the limitations with customizing this installation method, Group Policy installations should be used for targeting small groups of computers. You can publish or assign the client installation program to computers based on their organizational unit location in Active Directory.

Identify the name(s) of any Group Policy objects.

 

Name(s) of OU, domain, or site the Group Policy object is linked to.

 

Identify any additional Group Policy object settings such as No Override or group filtering.

 

Identify Group Policy object security settings

 

Logon scripts installation

You can use the file CCMSetup.exe in a login script to trigger the client installation.

Identify any logon scripts being used and the commands being processed.

 

Logon script installations can be configured using the same method that you would configure a manual client installation. You can specify the /logon switch with CCMSetup.exe which will cause CCMSetup.exe to skip the installation if there is already a Configuration Manager Client installed.

 

If no installation source is specified using the /Source switch and no management point is specified using the /MP switch, CCMSetup.exe can locate the management point if there is a server locator point and Active Directory Services has been extended.

 

Software distribution

Software distribution can be used to upgrade existing SMS 2003 Advanced Clients.

Identify how and when CCMSetup.exe will be distributed on each client

Outline your plan to distribute CCMSetup.exe to run on each client.

 

 

Identify any specific command line options required.

 

 

 

 

 

 

 

Client Installation Planning

 Agent

Example Data Needed, Where Applicable, and by Location

Client Agent Settings Name

Target Collections Name

Background Intelligent Transfer

Enabled?

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

Client Cache Settings

Enabled?

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

Client Policy

Enabled?

 

 

 

 

 

 

 

 

 

 

Compliance Settings

Enabled?

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

Computer Agent

Enabled?

 

 

 

 

 

 

 

 


Computer Restart

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

Endpoint Protection

Enabled?

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

Hardware Inventory

Enabled?

 

 

 

 

 

 

 

 

Metered Internet Connections

Enabled?

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

Power Management

Enabled?

 

 

Remote Tools

Enabled?

 

 

Software Deployment

Enabled?

 

 

Software Inventory

Enabled?

 

 

Software Updates

Enabled?

 

 

User and Device Affinity

Enabled?

 

 

Mobile Devices

Enabled?

 

 

Enrollment

Enabled?

 

 

User and Device Affinity

Enabled?

 

 

 

Pre-Planing and Planing Worksheets for SCCM 2016 / SCCM 1511 Implementation

Below are the Pre-Planing and Planing Worksheets for SCCM 2016 / SCCM 1511 Implementation

 

 

 

 

 

Organizational Data Preplanning Worksheet

Organizational structure

Example data needed, where applicable, and by location

Collected Data

 

 

 

High-level organization charts to help determine the divisional structure of your organization, the design of your Configuration Manager hierarchy, and your method of communicating Configuration Manager implementation updates to departments

 

Organizational structure

 

Reporting hierarchy

 

Communications methods

 

Service level agreements (SLAs)

 

IT organization and administrative policies

You should consider the following factors:

 

 

The structure and technical level of local and remote IT divisions, their reporting hierarchies, and local and global IT administrative policies

 

Organizational structure

 

Reporting hierarchy

 

Local administrative policies and SLAs

 

Global IT administrative policies and SLAs

 

Long-term business direction

Any major business changes planned for the future, such as mergers, acquisitions, major physical moves, or network migrations

 

 

 

 

Information Technology Organization Preplanning Worksheet

IT organization

Example data needed, where applicable, and by location

Data collected

IT Organization

Collect information about your IT organization. You should also create an organization chart that maps your IT organization to your geographic profile.

 

 

IT reporting hierarchy.

 

 

IT departmental divisions that produce an overlap in Configuration Manager  tasks (for example, a department separate from the Configuration Manager team manages all database servers, including computers running Microsoft SQL Server)

 

 

Points where management control or policy issues exist.

 

 

Level of technical sophistication and security clearance of IT staff members who will be working with Configuration Manager  before, during, or after deployment.

 

 

Auditing policies.

 

 

Service level agreements for departments, end users, and IT groups.

 

 

Operating systems used to support the network and end users.

 

 

Sensitivity to security risks.

 

 

Change control policy.

 

 

 

 

Geographic Profile Preplanning 

Geographic information

Example data needed, where applicable, and by location

Collected Data

Date and time zone information

List the time zone for each location, and list any date and time difference between the remote site and headquarters.

 

 

 

 

 

Time zone.

 

 

 

 

 

Date and time differences.

 

 

 

 

Operating systems and international operating system versions

List the operating systems in use and locations that use language versions that are different from those of your platform operating systems.

 

 

 

 

Active Directory Preplanning

Active Directory preplanning

Example data needed, where applicable, and by location

Data collected

Logical Structure

The logical structure of your organization is represented by the following Active Directory components: organizational units, domains, trees, and forests.

 

Physical Structure

The physical structure of your organization is represented by the following Active Directory components: Active Directory sites (physical subnets) and domain controllers.

 

 

 

 

Network Topology Preplanning

Network topology

Example data needed, where applicable, and by location

Data Collected

High-level WAN/LAN architecture

Links, gateways, firewalls, extranets, virtual private networks, and

 

perimeter networks

Network size

Number of servers and clients at each location

 

Network bandwidth

Link speeds and available bandwidth, including any known bandwidth issues

 

Network usage and traffic patterns

Categorize as Light, moderate, or heavy, and note times of day when network usage is heaviest (peak times) and scheduled times for backup and maintenance (nonpeak times)

 

Network types

Windows NT, Windows 2000, or Novell NetWare and other third-party network operating systems

 

Network protocols

TCP/IP, IPv6, NetBEUI, IPX/SPX, AppleTalk, DLC, and so on, and name resolution methods such as DNS and WINS

 

IP subnet structure

The Internet Protocol (IP) subnets on your network by subnet ID

 

Active Directory site structure

Active Directory organizational units, site names, trees, and forest

 

 

 

 

Server Environment Preplanning

Server

Example data needed, where applicable, and by location

Data collected

Location and function

Document the location and function of the computers that run the core services of your network, such as global catalog servers, domain controllers, DNS and WINS servers, Internet Information Services (IIS) servers, computers running Microsoft SQL Server or Terminal Services, Microsoft Exchange servers, print servers, and file servers.

 

Naming conventions

Document current naming conventions for products you use with Configuration Manager , such as computers running Windows Server 2003 and SQL Server. This helps you establish and document naming conventions for Configuration Manager  hierarchy elements. These elements include sites, site codes, servers, and the objects that are used by or created in the Configuration Manager console. Because the Configuration Manager site code is used to uniquely identify each Configuration Manager site, it is especially important that these codes be assigned and tracked by the Configuration Manager central site administrators.

 

Hardware, software, network

Document hardware, software, and network information for each server that might be assigned a site role in your Configuration Manager site hierarchy.

 

For example, you should document at least the following information from each server that will be part of your Configuration Manager  hierarchy:

 

 

 

Azure Machine Type

 

Processor type and speed

 

Amount of RAM installed

 

 

 

Disk and array controller configuration and characteristics, including size, MB of cache, and the drive models and types (for example, ultra-wide SCSI, 18 GB, 7200 RPM)

 

 

 

Platform operating system, version, and language

 

 

 

Whether the Windows Cluster service or Windows Network Load Balancing Service is enabled

 

 

 

Relevant software applications located on servers, including antivirus software

 

 

 

 

 

 

Client Environment Preplanning

Clients

Example data needed, where applicable, and by location

Data collected

Number of clients

Total number of client computers in use on your network, and the physical and logical groupings of clients.

 

IP subnet size

Number and types (operating systems) of client computers on each IP subnet, including projected number of clients in the upcoming year.

 

Logon scripts

Whether or not users use logon scripts, and if those scripts are customized. Note file name and location of each script, and users and groups associated with each script.

 

Security rights

Desktop security rights granted to end users

 

Operating systems

Platform operating systems (including language version) in use on each IP subnet.

 

Client stability/mobility

Computers that are shared by multiple users, those that travel from one location to another, all home-based client computers having remote access to the network, and any other client computer environments.

 

Software

A database or spreadsheet of all major applications in use in the enterprise, categorized by organizational division or by IP subnet.

 

Special applications

Divisions or departments that use Windows Terminal Services to run applications, or use other special applications, such as internally manufactured or obsolete applications.

 

Connectivity

Types of connectivity different organizational groups are using, including remote client connection speeds (dependent on the remote access method in use, such as ADSL, wireless, dial-up, ISDN, or Site to Site VPN, Express Route or other).

 

 

 

 

Client Environment Preplanning

Security

Example data needed, where applicable, and by location

Data collected

Security policies

Collect information about your organization’s security policies, such as the following:

 

 

Account password policies

 

Account cycling policies

 

Account rights policies

 

Client and server lockdown policies (restrictions on disks and registry, services that are stopped, whether services use Domain Administrator accounts, and hidden shared folders that are removed)

 

Auditing policies

 

 

Separation of or delegation of duties between IT divisions within the enterprise.

 

 

The degree to which users must retain control of clients, and any exceptions to such policies (such as servers, or computers used by programmers).

 

 

You should collect information about how security-related issues will be handled and supported, such as the following information:

 

 

Sensitivity to security risks

 

Importance of ease of administration

 

Special needs you have for secure data access and transmission

 

Service level agreements (SLAs) for applying security updates

 

Mobile Devices Management

Is it required ?
If so are we planning for INTUNE or MDM

 

 

Friday, 2 December 2016

Windows 10 few Customisation based on batch file


%~d0
CD %~dp0

REM **********************Start of Modify Default User Hive ******************
REM **Load Default User Hive**
mapdu.exe

:: Windows 10  Time zone
tzutil /s "Pacific Standard Time"

:: Windows 10  Personalisation settings
:: Windows 10  Personalize your speech, typing, and inking input by sending contacts and calendar details, along with other associated input data to Microsoft
Reg Add "HKCU\SOFTWARE\Microsoft\Personalization\Settings" /v AcceptedPrivacyPolicy /t REG_DWORD /d 0 /f
Reg Add "HKU\Defaultuser\SOFTWARE\Microsoft\Personalization\Settings" /v AcceptedPrivacyPolicy /t REG_DWORD /d 0 /f
Reg Add "HKCU\SOFTWARE\Microsoft\InputPersonalization\TrainedDataStore" /v HarvestContacts /t REG_DWORD /d 0 /f
Reg Add "HKU\Defaultuser\SOFTWARE\Microsoft\InputPersonalization\TrainedDataStore" /v HarvestContacts /t REG_DWORD /d 0 /f

:: Windows 10  Send typing and inking data to Microsoft to improve the recognition and suggestion platform
Reg Add "HKLM\SOFTWARE\Policies\Microsoft\Windows\DataCollection" /v AllowTelemetry /t REG_DWORD /d 0 /f

:: Windows 10  Let apps use your advertising ID for experience across apps
Reg Add "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\AdvertisingInfo" /v Enabled /t REG_DWORD /d 0 /f

:: Windows 10  Smart Screen filter: Turn off
:: Windows 10  Reg Add "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer" /v SmartScreenEnabled /t REG_SZ /d Off /f
:: Windows 10 Reg Add "HKCU\Software\Microsoft\Windows\CurrentVersion\AppHost" /v EnableWebContentEvaluation /t REG_DWORD /d 0 /f
Reg Add "HKCU\SOFTWARE\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\MicrosoftEdge\PhishingFilter" /v EnabledV9 /t REG_DWORD /d 0 /f
Reg Add "HKCU\SOFTWARE\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\MicrosoftEdge\FlipAhead" /v FPEnabled /t REG_DWORD /d 0 /f
:: Windows 10 Reg Add "HKU\Defaultuser\Software\Microsoft\Windows\CurrentVersion\AppHost" /v EnableWebContentEvaluation /t REG_DWORD /d 0 /f
Reg Add "HKU\Defaultuser\SOFTWARE\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\MicrosoftEdge\FlipAhead" /v FPEnabled /t REG_DWORD /d 0 /f
Reg Add "HKU\Defaultuser\SOFTWARE\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\MicrosoftEdge\PhishingFilter" /v EnabledV9 /t REG_DWORD /d 0 /f

:: Windows 10  TURNOFF NOTIFICATION ON LOCK SCREEN
Reg Add "HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Notifications\Settings" /v NOC_GLOBAL_SETTING_ALLOW_TOASTS_ABOVE_LOCK /t REG_DWORD /d 0 /f
Reg Add "HKU\Defaultuser\SOFTWARE\Microsoft\Windows\CurrentVersion\Notifications\Settings" /v NOC_GLOBAL_SETTING_ALLOW_TOASTS_ABOVE_LOCK /t REG_DWORD /d 0 /f

:: Windows 10  HIDE ONE DRIVE
Reg Add "HKEY_CLASSES_ROOT\CLSID\{018D5C66-4533-4307-9B53-224DE2ED1FE6" /v System.IsPinnedToNameSpaceTree /t REG_DWORD /d 0 /f
Reg Add "HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{018D5C66-4533-4307-9B53-224DE2ED1FE6}" /v System.IsPinnedToNameSpaceTree /t REG_DWORD /d 0 /f

:: Windows 10  DISABLE ONE DRIVE
Reg Add "HKLM\Software\Policies\Microsoft\Windows\OneDrive" /v DisableFileSyncNGSC /t REG_DWORD /d 1

:: Windows 10  TURN ON TABLETMODE
Reg Add "HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\ImmersiveShell" /v TabletMode /t REG_DWORD /d 1
Reg Add "HKU\Defaultuser\SOFTWARE\Microsoft\Windows\CurrentVersion\ImmersiveShell" /v TabletMode /t REG_DWORD /d 1

:: Windows 10  Disable wifi sense (NEED TO BE TESTED ON A MACHINE WITH WIFI)
Reg Add "HKLM\SOFTWARE\Microsoft\WcmSvc\wifinetworkmanager\config" /v AutoConnectAllowedOEM /t REG_DWORD /d 0 /f

:: Windows 10  Show colour on Start, taskbar and action centre AND  Automatically pick a color from my background. 
Reg Add "HKCU\Control Panel\Desktop" /v AutoColorization /t REG_DWORD /d 1 /f
Reg Add "HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Themes\Personalize" /v ColorPrevalence /t REG_DWORD /d 1 /f
Reg Add "HKCU\SOFTWARE\Microsoft\Windows\DWM" /v ColorPrevalence /t REG_DWORD /d 1 /f

Reg Add "HKU\Defaultuser\Control Panel\Desktop" /v AutoColorization /t REG_DWORD /d 1 /f
Reg Add "HKU\Defaultuser\SOFTWARE\Microsoft\Windows\CurrentVersion\Themes\Personalize" /v ColorPrevalence /t REG_DWORD /d 1 /f
Reg Add "HKU\Defaultuser\SOFTWARE\Microsoft\Windows\DWM" /v ColorPrevalence /t REG_DWORD /d 1 /f

:: Windows 10  Make Start, taskbar and action centre transparent
Reg Add "HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Themes\Personalize" /v EnableTransparency /t REG_DWORD /d 1 /f
Reg Add "HKU\Defaultuser\SOFTWARE\Microsoft\Windows\CurrentVersion\Themes\Personalize" /v EnableTransparency /t REG_DWORD /d 1 /f

:: Windows 10  Show app notifications - Turn Off
Reg Add "HKCU\Software\Microsoft\Windows\CurrentVersion\PushNotifications" /v ToastEnabled /t REG_DWORD /d 0 /f
Reg Add "HKU\Defaultuser\Software\Microsoft\Windows\CurrentVersion\PushNotifications" /v ToastEnabled /t REG_DWORD /d 0 /f

:: Windows 10  Hide notifications while presenting
Reg Add "HKCU\SOFTWARE\Microsoft\MobilePC\AdaptableSettings" /v SkipBatteryCheck /t REG_DWORD /d 1 /f
Reg Add "HKU\Defaultuser\SOFTWARE\Microsoft\MobilePC\AdaptableSettings" /v SkipBatteryCheck /t REG_DWORD /d 1 /f

Reg Add "HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Notifications\Settings" /v NOC_GLOBAL_SETTING_SUPRESS_TOASTS_WHILE_DUPLICATING /t REG_DWORD /d 1 /f
Reg Add "HKU\Defaultuser\SOFTWARE\Microsoft\Windows\CurrentVersion\Notifications\Settings" /v NOC_GLOBAL_SETTING_SUPRESS_TOASTS_WHILE_DUPLICATING /t REG_DWORD /d 1 /f

:: Windows 10 To also be able to run the Windows Mobility Center on your Desktop computer, you need to add the following value as well 
Reg Add "HKCU\SOFTWARE\Microsoft\MobilePC\MobilityCenter" /v RunOnDesktop /t REG_DWORD /d 1 /f
Reg Add "HKU\Defaultuser\SOFTWARE\Microsoft\MobilePC\MobilityCenter" /v RunOnDesktop /t REG_DWORD /d 1 /f

:: Windows 10 To Turn Off Offline Maps
Reg add "HKLM\SYSTEM\Maps" /v AutoUpdateEnabled /t REG_DWORD /d 0 /f

:: Windows 10  Disable RDP
Reg add "HKLM\SYSTEM\CurrentControlSet\Control\Terminal Server" /v fDenyTSConnections /t REG_DWORD /d 1 /f
Net Stop UmRDPService
Net Stop TermService

:: Windows 10  Disable remote assistance
Reg add "HKLM\SYSTEM\CurrentControlSet\Control\Remote Assistance" /v fAllowToGetHelp /t REG_DWORD /d 0 /f

:: Windows 10  Disable System Restore
Reg add "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore" /v DisableSR /t REG_DWORD /d 1 /f
:: Windows 10  sc config srservice start= disabled
:: Windows 10  net stop srservice

:: Windows 10 feedback and diagnostic disable
Reg Add "HKCU\Software\Microsoft\Siuf\Rules" /v PeriodInNanoSeconds /t REG_DWORD /d 0 /f
Reg Add "HKU\Defaultuser\Software\Microsoft\Siuf\Rules" /v PeriodInNanoSeconds /t REG_DWORD /d 0 /f

Reg Add "HKCU\Software\Microsoft\Siuf\Rules" /v NumberOfSIUFInPeriod /t REG_DWORD /d 0 /f
Reg Add "HKU\Defaultuser\Software\Microsoft\Siuf\Rules" /v NumberOfSIUFInPeriod /t REG_DWORD /d 0 /f

Reg Add "HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\DeviceAccess\Global\{BFA794E4-F964-4FDB-90F6-51056BFE4B44}" /v Value /t REG_SZ /d Deny /f
Reg Add "HKU\Defaultuser\SOFTWARE\Microsoft\Windows\CurrentVersion\DeviceAccess\Global\{BFA794E4-F964-4FDB-90F6-51056BFE4B44}" /v Value /t REG_SZ /d Deny /f

:: Windows 10 Disable Error Reporting
Reg Add "HKLM\SOFTWARE\Microsoft\Windows Error Reporting" /v Disabled /t REG_DWORD /d 1 /f

:: Windows 10 Always_install_best_driver_software_from_Windows_Update
Reg Add "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\DriverSearching" /v SearchOrderConfig /t REG_DWORD /d 1 /f

:: Windows 10 Never_Notify_or_Check_for_Updates
Reg Add "HKLM\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU" /v NoAutoUpdate /t REG_DWORD /d 1 /f

:: Windows 10 Turn_Off_alarms_reminders_VoIP-calls_on_Lock_Screen
Reg Add "HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Notifications\Settings" /v NOC_GLOBAL_SETTING_ALLOW_CRITICAL_TOASTS_ABOVE_LOCK /t REG_DWORD /d 0 /f
Reg Add "HKU\Defaultuser\SOFTWARE\Microsoft\Windows\CurrentVersion\Notifications\Settings" /v NOC_GLOBAL_SETTING_ALLOW_CRITICAL_TOASTS_ABOVE_LOCK /t REG_DWORD /d 0 /f

:: Windows 10 Turn_Off_Location_for_this_Device
Reg Add "HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\DeviceAccess\Global\{BFA794E4-F964-4FDB-90F6-51056BFE4B44}" /v Value /t REG_SZ /d Deny /f
Reg Add "HKU\Defaultuser\SOFTWARE\Microsoft\Windows\CurrentVersion\DeviceAccess\Global\{BFA794E4-F964-4FDB-90F6-51056BFE4B44}" /v Value /t REG_SZ /d Deny /f

:: Windows 10 Reg Add "HKCU\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Sensor\Permissions\{BFA794E4-F964-4FDB-90F6-51056BFE4B44}" /v SensorPermissionState /t REG_DWORD /d 0 /f
:: Windows 10 Reg Add "HKU\Defaultuser\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Sensor\Permissions\{BFA794E4-F964-4FDB-90F6-51056BFE4B44}" /v SensorPermissionState /t REG_DWORD /d 0 /f

:: Windows 10 Disable Check for solutions to problem reports
Reg Add "HKLM\SOFTWARE\Microsoft\Windows\Windows Error Reporting" /v Disabled /t REG_DWORD /d 1 /f

:: Windows 10 Enable_Automatic_Maintenance
Reg Add "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\Maintenance" /v MaintenanceDisabled /t REG_DWORD /d - /f

:: Windows 10 Turn Off File History
Reg Add "HKLM\SOFTWARE\Policies\Microsoft\Windows\FileHistory" /v Disabled /t REG_DWORD /d 1 /f

:: Windows 10 Turn Off Windows defender Settings
Reg Add "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Real-Time Protection" /v DisableRealtimeMonitoring /t REG_DWORD /d 1 /f
Reg Add "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Spynet" /v SubmitSamplesConsent /t REG_DWORD /d 2 /f
Reg Add "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Spynet" /v SpynetReporting /t REG_DWORD /d 0 /f
Reg Add "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender" /v DisableAntiSpyware /t REG_DWORD /d 1 /f


:: Windows 10 Turn_Off_Clear_Tile_Notifications_during_log_on
Reg Add "HKCU\SOFTWARE\Policies\Microsoft\Windows\Explorer" /v ClearTilesOnExit /t REG_SZ /d /f
Reg Add "HKU\Defaultuser\SOFTWARE\Policies\Microsoft\Windows\Explorer" /v ClearTilesOnExit /t REG_SZ /d /f
Reg Add "HKLM\SOFTWARE\Policies\Microsoft\Windows\Explorer" /v ClearTilesOnExit /t REG_SZ /d /f

REGPOL.EXE HKCU "Software\Policies\Microsoft\Windows\Control Panel\Desktop" "ScreenSaveActive" REG_SZ "1"
REGPOL.EXE HKCU "Software\Policies\Microsoft\Windows\Control Panel\Desktop" "ScreenSaverIsSecure" REG_SZ "1"
REGPOL.EXE HKCU "Software\Policies\Microsoft\Windows\Control Panel\Desktop" "ScreenSaveTimeOut" REG_SZ "1200"

ping 127.0.0.1 -n 20 > NUL
REM **Unload Default User Hive**
mapdu.exe /U
ping 127.0.0.1 -n 20 > NUL