docs(win11creator): correct architecture and guide (#5106)

* docs(win11creator): correct architecture and guide

Update documentation to match actual Win11 Creator implementation:

- Clarify customizations run at first logon via autounattend.xml rather
  than offline WIM modification
- Correct removed bloat AppX count from 40+ to 19 packages
- Update USB partition layout to single FAT32 partition with WIM split
- Clarify OneDrive uninstall timing during first logon
- Document missing helpers including USB functions and oscdimg helpers
- Document edition pinning, $OEM$ fallback scripts, and WIM metadata validation
- Update logging location and remove offline registry tweak wording

* docs(win11creator): clarify timing and media limits
This commit is contained in:
Omar
2026-09-28 13:08:11 -05:00
committed by GitHub
parent abcbc23144
commit 48885d7c1e
2 changed files with 65 additions and 33 deletions
@@ -135,21 +135,31 @@ The **Win11 Creator** is a specialized subsystem within Winutil that creates cus
### Win11 Creator Components
**Core Functions** (`functions/private/`):
- `Invoke-WinUtilISO.ps1`: Main orchestrator containing all Win11 Creator functions
- `Invoke-WinUtilISO.ps1`: Main orchestrator containing ISO workflow and helper functions
- `Invoke-WinUtilISOBrowse`: ISO file selection dialog
- `Invoke-WinUtilISOMountAndVerify`: Validates and mounts ISO, verifies it is an official Windows 11 ISO
- `Invoke-WinUtilISOModify`: Launches modification in background runspace
- `Invoke-WinUtilISOExport`: Handles ISO and USB export
- `Invoke-WinUtilISOExport`: Builds bootable ISO via `oscdimg.exe`
- `Invoke-WinUtilISOCheckExistingWork`: Recovers incomplete work sessions
- `Invoke-WinUtilISOCleanAndReset`: Cleans up temp directories and resets UI
- `Write-WinUtilISOLog`: Posts log messages to UI status box and session log
- `Set-WinUtilISOStep`: Controls wizard navigation state
- `Get-WinUtilEditionIdFromName`: Maps edition display names to setup edition IDs
- `Invoke-WinUtilRobocopy`: Copies files with exit code verification
- `Find-WinUtilOscdimg` / `Get-WinUtilOscdimgPath`: Locates or installs `oscdimg.exe`
- `Invoke-WinUtilISOScript.ps1`: Applies modifications to mounted install.wim
- Removes provisioned AppX packages (40+ bloatware apps)
- Injects drivers (optional) from the current system
- Removes OneDrive setup files
- Applies offline registry tweaks (hardware bypass, privacy, telemetry, OOBE)
- Deletes telemetry scheduled task definitions
- Pre-stages setup scripts from autounattend.xml
- `Invoke-WinUtilISOUSB.ps1`: USB drive detection and formatting
- `Invoke-WinUtilISORefreshUSBDrives`: Enumerates USB drives
- `Get-WinUtilFreeDriveLetter`: Finds available drive letters
- `Invoke-WinUtilISOWriteUSB`: Formats USB drive as GPT/FAT32, splits WIM if needed, and copies files
- `Invoke-WinUtilISOScript.ps1`: Prepares setup media and customizations
- Stages AppX removal (19 bloatware packages) into `autounattend.xml` for first logon
- Applies 50+ registry tweaks during Windows Setup and first logon; removes scheduled tasks at first logon
- Triggers OneDrive uninstall during first logon
- Stages setup script fallbacks to `sources\$OEM$\$$\Setup\Scripts\`
- Pins selected edition in `autounattend.xml` and writes `sources\ei.cfg`
- Injects eligible current system drivers into WIM images if enabled (WIM mount is only used for driver servicing)
### Win11 Creator Data Flow
@@ -169,18 +179,19 @@ User optionally enables the Driver Injection checkbox
↓
Invoke-WinUtilISOModify (runs in background runspace)
├─ Create work directory: ~WinUtil_Win11ISO_[timestamp]
├─ Copy ISO contents to disk (~5-6 GB)
├─ Mount install.wim at selected edition/index
├─ Copy ISO contents to disk via robocopy (~5-6 GB)
├─ Invoke-WinUtilISOScript:
│ ├─ Remove 40+ bloat AppX packages
│ ├─ Export and inject drivers (if enabled)
│ ├─ Remove OneDrive setup
│ ├─ Load offline registry hives
│ ├─ Apply 50+ registry tweaks (hardware bypass, privacy, telemetry, OOBE, etc.)
│ ├─ Delete telemetry scheduled task files
│ ├─ Pre-stage setup scripts from autounattend.xml to C:\Windows\Setup\Scripts\
│ └─ Unload registry hives
├─ Dismount and save the modified install.wim (~10+ minutes, slowest step)
│ ├─ Generate autounattend.xml with Windows PE and specialize safeguards
│ ├─ Add first-logon script (19 AppX removals, registry tweaks, OneDrive uninstall)
│ ├─ Pin selected edition index in autounattend.xml (/IMAGE/INDEX)
│ ├─ Stage setup script fallbacks to sources\$OEM$\$$\Setup\Scripts\
│ ├─ Write sources\ei.cfg and remove stale sources\PID.txt
│ └─ If driver injection enabled:
│ ├─ Require install.wim; install.esd cannot accept driver injection
│ ├─ Export current system drivers via DISM
│ ├─ Exclude stale duplicate packages
│ ├─ Inject storage drivers into boot.wim index 2 and eligible drivers into install.wim
│ └─ Validate WIM metadata before and after injection
├─ Dismount source ISO
└─ Report completion, enable export options
↓
@@ -191,12 +202,15 @@ Invoke-WinUtilISOExport (user chooses output)
│
└─ Option 2: Write to USB
├─ Format USB as GPT
├─ Create 512 MB EFI partition
├─ Copy modified ISO contents
├─ Create single FAT32 partition (capped at 32 GB)
├─ Split install.wim into .swm files if > 3.8 GB
├─ Reject install.esd files of 4 GB or more
├─ Copy files via robocopy
└─ Output: Bootable USB (minimum 8 GB)
↓
Invoke-WinUtilISOCleanAndReset (optional)
└─ Delete temp working directory (~10-15 GB)
├─ Dismount any open WIM mounts with discard
├─ Delete temp working directory (~10-15 GB)
└─ Reset UI to initial state
```
@@ -208,20 +222,30 @@ Invoke-WinUtilISOCleanAndReset (optional)
- Checks image metadata for "Windows 11" string
- Rejects custom, modified, or non-Windows 11 ISOs
**WIM Metadata Validation**:
- During driver injection, `Assert-WinUtilISOWimMetadata` validates critical fields (`Languages`, `Installation`, `Edition`, `ProductSuite`, `ProductType`) before and after WIM servicing
- Driver injection stops before export if the required metadata is missing or changes
- Without driver injection, WinUtil preserves the original installation image and skips WIM metadata validation
**Edition Pinning & Setup Fallback**:
- Writes `sources\ei.cfg` and removes `sources\PID.txt` so setup does not use mismatched OEM product keys
- Pins the selected edition index in `autounattend.xml` (`/IMAGE/INDEX`)
- Stages fallback setup scripts under `sources\$OEM$\$$\Setup\Scripts\` with `UseConfigurationSet` enabled
**Work Session Recovery**:
- Auto-detects incomplete work from previous sessions
- Allows resuming the export step without re-running selection and modification
- Prevents redundant modifications
**Modification Safety**:
- All registry changes are documented in a script (reversible)
- Windows PE and specialize set hardware bypass and setup safeguards; `WinUtil-PostInstall.ps1` applies additional registry changes at first logon
- Original ISO never modified; only working copy
- Logged to `WinUtil_Win11ISO.log` for debugging
- DISM handles image dismount with automatic cleanup on error
- Logged to the WinUtil session log and the live UI status panel
- DISM handles image dismount with automatic cleanup and discard on error
### Win11 Creator Registry Tweaks
The `Invoke-WinUtilISOScript` function applies **50+ offline registry tweaks**:
The `Invoke-WinUtilISOScript` function applies **50+ registry tweaks** during setup and first logon:
**Hardware Bypass**:
- TPM 2.0 check bypass
+14 -6
View File
@@ -45,8 +45,8 @@ Once the ISO is verified, WinUtil moves to this step and shows the mounted drive
Then click **Run Windows ISO Modification and Creator** to start the customization process. WinUtil will:
**App & Component Removal:**
- **Remove 40+ bloat apps** — Clipchamp, Teams, Copilot, Dev Home, new Outlook, Bing apps, Solitaire, and more
- **Delete OneDrive setup** from the image
- **Remove 19 bloat apps** — Clipchamp, Teams, Dev Home, new Outlook, Bing apps, Solitaire, and more
- **Uninstall OneDrive** during first logon
**System Customization:**
- **Bypass hardware checks** — removes TPM, Secure Boot, CPU, RAM, and storage requirement enforcement so the ISO installs on unsupported hardware
@@ -69,7 +69,11 @@ Then click **Run Windows ISO Modification and Creator** to start the customizati
**Optional: Driver Injection**
- If enabled, WinUtil exports the drivers from your current system, injects boot-storage drivers into `boot.wim` (Windows Setup, index 2), and injects eligible packages into the selected `install.wim` image. Stale duplicate packages are excluded before injection. Each remaining package is added separately, so one incompatible package does not stop the others. If a package fails, WinUtil discards the partial mount and retries the remaining packages against the original image. Check the live log for warnings: if every package fails, WinUtil keeps the original `install.wim` and still produces the ISO.
A live log shows progress as each step completes. This stage usually takes **10–30 minutes** depending on disk speed. The WIM dismount near the end is the slowest part, so do not close WinUtil while it is running.
:::note
Driver injection requires `sources\install.wim`. If the ISO uses `sources\install.esd`, leave this option off.
:::
A live log shows progress as each step completes. Without driver injection, WinUtil writes the setup changes in a few seconds after the ISO copy. With driver injection, this stage usually takes **10–20 minutes**, depending on hardware. Keep WinUtil open until the log reports completion.
:::note
The resulting ISO is close to the size of the source ISO. WinUtil does not remove the unused editions from `install.wim`; it selects your edition through `sources\ei.cfg` and `autounattend.xml` so Windows Setup installs the right one.
@@ -95,7 +99,11 @@ Once the modification is complete, choose how to save your image:
1. Click **Write Directly to a USB Drive**.
2. Select your USB drive from the dropdown (click **Refresh** if it doesn't appear).
3. Click **Erase & Write to USB** and confirm the warning — **all data on the drive will be permanently erased**.
4. WinUtil formats the drive as GPT with a 512 MB EFI partition and copies the modified Windows files.
4. WinUtil formats the drive as GPT with a single FAT32 partition (capped at 32 GB, splitting `install.wim` into `.swm` files if larger than 3.8 GB) and copies the modified Windows files.
:::note
WinUtil cannot split `install.esd`. If that file is 4 GB or larger, save an ISO instead of writing a FAT32 USB drive.
:::
:::danger
Double-check you have selected the correct drive before confirming. This operation cannot be undone.
@@ -130,10 +138,10 @@ When you install Windows 11 from your modified ISO:
| Problem | Fix |
|---------|-----|
| "install.wim not found" | Not a valid Windows 11 ISO — download a fresh one from Microsoft |
| "install.wim / install.esd was not found" | The ISO has no Windows installation image — download a fresh official ISO from Microsoft |
| "oscdimg.exe not found" | Run `winget install -e --id Microsoft.OSCDIMG` then retry |
| USB drive not showing up | Plug it in, wait a few seconds, then click **Refresh** |
| Modification seems stuck | The WIM dismount step is slow — wait at least 10 minutes before assuming it's frozen |
| Driver injection seems stuck | WIM servicing can pause at a mount or commit. Allow 10–20 minutes depending on hardware, and check the live log before closing WinUtil |
| "Access Denied" error | Make sure WinUtil is running as Administrator |
| Driver injection warning | Review the live log for the named package. Other compatible packages continue; if none succeed, the ISO is created with the original `install.wim` |
| "Setup has failed to validate the product key" | Recreate the ISO with the latest WinUtil. The creator now removes stale `PID.txt`, writes `sources\ei.cfg`, and pins the selected image in `autounattend.xml` so setup does not use an embedded OEM key for a different edition |