无法通过Unattended XML自动配置Windows 10隐私相关设置
解决Windows 10自动化安装中的隐私设置弹窗问题
一、修改Unattended.xml的隐私配置节点
将以下配置添加到unattended.xml的oobeSystem阶段对应组件中,覆盖原有相关设置:
禁用位置服务
在Microsoft-Windows-LocationAndSensors组件中添加:<EnableLocation>false</EnableLocation>关闭查找我的设备
在Microsoft-Windows-Shell-Setup组件的FindMyDevice节点设置:<FindMyDevice>Off</FindMyDevice>设置诊断数据为最低级别
在Microsoft-Windows-DiagTrack-Service组件中添加:<AllowTelemetry>0</AllowTelemetry>禁用墨迹书写和键入数据收集
在Microsoft-Windows-TabletPC-InputService组件中添加:<EnableHandwritingDataCollection>false</EnableHandwritingDataCollection>关闭个性化体验
在Microsoft-Windows-DiagTrack-Service组件中添加:<ConfigureTelemetryOptInSettings>0</ConfigureTelemetryOptInSettings>禁用广告ID
在Microsoft-Windows-Shell-Setup组件的Privacy节点下添加:<AdvertisingId>false</AdvertisingId>
二、通过DISM修改离线WIM镜像(XML配置失效时)
如果XML配置仍无法跳过弹窗,可直接修改WIM镜像的注册表项:
挂载WIM镜像:
dism /Mount-Wim /WimFile:C:\install.wim /Index:1 /MountDir:C:\mount导入以下注册表设置(可保存为
.reg文件后导入):Windows Registry Editor Version 5.00 ; 禁用位置服务 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\ConsentStore\location] "Value"="Deny" ; 关闭查找我的设备 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\FindMyDevice] "Enabled"=dword:00000000 ; 设置诊断数据为安全级别 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\DataCollection] "AllowTelemetry"=dword:00000000 "DisableTelemetry"=dword:00000001 ; 禁用墨迹书写和键入数据收集 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\InputPersonalization] "RestrictImplicitInkCollection"=dword:00000001 "RestrictImplicitTextCollection"=dword:00000001 ; 关闭个性化体验 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\InputPersonalization\TrainedDataStore] "AllowImplicitCollection"=dword:00000000 ; 禁用广告ID [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\AdvertisingInfo] "Enabled"=dword:00000000卸载并提交镜像修改:
dism /Unmount-Wim /MountDir:C:\mount /Commit
三、OOBE阶段运行PowerShell脚本兜底
若上述方法仍无效,可在Unattended.xml中配置首次登录命令,执行脚本完成隐私设置:
创建PowerShell脚本
PrivacySettings.ps1:# 禁用位置服务 Set-ItemProperty -Path "HKLM:\Software\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\ConsentStore\location" -Name "Value" -Type String -Value "Deny" # 关闭查找我的设备 Set-ItemProperty -Path "HKLM:\SOFTWARE\Microsoft\FindMyDevice" -Name "Enabled" -Type DWord -Value 0 # 设置诊断数据级别 Set-ItemProperty -Path "HKLM:\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\DataCollection" -Name "AllowTelemetry" -Type DWord -Value 0 Set-ItemProperty -Path "HKLM:\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\DataCollection" -Name "DisableTelemetry" -Type DWord -Value 1 # 禁用墨迹数据收集 Set-ItemProperty -Path "HKLM:\SOFTWARE\Microsoft\InputPersonalization" -Name "RestrictImplicitInkCollection" -Type DWord -Value 1 Set-ItemProperty -Path "HKLM:\SOFTWARE\Microsoft\InputPersonalization" -Name "RestrictImplicitTextCollection" -Type DWord -Value 1 # 关闭个性化体验 Set-ItemProperty -Path "HKLM:\SOFTWARE\Microsoft\InputPersonalization\TrainedDataStore" -Name "AllowImplicitCollection" -Type DWord -Value 0 # 禁用广告ID Set-ItemProperty -Path "HKLM:\SOFTWARE\Microsoft\Windows\CurrentVersion\AdvertisingInfo" -Name "Enabled" -Type DWord -Value 0将脚本添加到WIM镜像的
C:\Scripts目录(需提前创建),然后在Unattended.xml的oobeSystem阶段添加:<FirstLogonCommands> <SynchronousCommand wcm:action="add"> <CommandLine>powershell.exe -ExecutionPolicy Bypass -File C:\Scripts\PrivacySettings.ps1</CommandLine> <Order>1</Order> <Description>Apply Privacy Settings</Description> </SynchronousCommand> </FirstLogonCommands>
内容的提问来源于stack exchange,提问作者SammyJ
相关产品推荐
相关产品推荐

