You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何通过Wix Toolset打包需交互的PowerShell脚本为MSI用于OEM镜像部署?

How to Package a User-Interactive PowerShell Script into an MSI with WiX (for OEM MDT Deployments)

Awesome question—this is a super common scenario for OEM deployments, and WiX is absolutely up to the task. The biggest gotcha here is session 0 isolation (Windows Installer runs in a non-interactive session by default), but we can work around that to make your user prompts pop up exactly when you need them. Let’s break this down step by step:

First: Embed Your PowerShell Script in the MSI

First, we’ll add your script as a binary resource inside the WiX project. This keeps everything self-contained in the MSI:

<Wix xmlns="http://schemas.microsoft.com/wix/2006/wi">
  <Product Name="OEM Setup Tool" Id="*" Language="1033" Version="1.0.0.0" Manufacturer="Your Company" UpgradeCode="YOUR-UPGRADE-GUID-HERE">
    <!-- Your standard WiX product config goes here -->
    
    <!-- Embed the PowerShell script as a binary resource -->
    <Binary Id="OemSetupScript.ps1" SourceFile=".\path\to\your\OemSetupScript.ps1" />
  </Product>
</Wix>

Second: Choose When to Run the Script (Critical for User Interaction)

Since you want the prompt to appear after the first reboot post-deployment, we need to avoid running the script directly during the MDT installation (which runs as the SYSTEM account in session 0, no desktop access). The most reliable approach is to trigger it on the first user login:

Option 1: Use RunOnce to Trigger the Script on First Login

This ensures the script runs in a user session (with access to the desktop) so prompts work correctly. Here’s how to set it up:

  1. Extract the script to a persistent location during installation (since the MSI’s binary resources are temporary):

    <CustomAction Id="ExtractScript"
                  BinaryKey="OemSetupScript.ps1"
                  ExeCommand="cmd.exe /c copy &quot;[#OemSetupScript.ps1]&quot; &quot;[CommonAppData]\OEMTools\OemSetupScript.ps1&quot;"
                  Return="check"
                  Execute="deferred" />
    
  2. Add a RunOnce registry entry to trigger the script on first login:

    <DirectoryRef Id="TARGETDIR">
      <Component Id="RunOnceEntry" Guid="YOUR-COMPONENT-GUID-HERE">
        <RegistryKey Root="HKLM" Key="Software\Microsoft\Windows\CurrentVersion\RunOnce">
          <RegistryValue Name="OEMPostSetup"
                         Value="powershell.exe -ExecutionPolicy Bypass -File &quot;[CommonAppData]\OEMTools\OemSetupScript.ps1&quot;"
                         Type="string" KeyPath="yes" />
        </RegistryKey>
      </Component>
    </DirectoryRef>
    
  3. Link everything together in your feature and install sequence:

    <Feature Id="MainFeature" Title="OEM Setup" Level="1">
      <ComponentRef Id="RunOnceEntry" />
    </Feature>
    
    <InstallExecuteSequence>
      <Custom Action="ExtractScript" After="InstallFinalize">NOT Installed</Custom>
    </InstallExecuteSequence>
    

Option 2: Run the Script During Interactive MSI Installation (If MDT Uses a User Context)

If your MDT deployment runs the MSI as an interactive user (not SYSTEM), you can run the script directly during installation with user impersonation:

<CustomAction Id="RunSetupScript"
              BinaryKey="OemSetupScript.ps1"
              ExeCommand="powershell.exe -ExecutionPolicy Bypass -File [TempFolder]OemSetupScript.ps1"
              Return="check"
              Impersonate="yes"
              Execute="immediate" />

<InstallExecuteSequence>
  <Custom Action="RunSetupScript" After="InstallInitialize">NOT Installed</Custom>
</InstallExecuteSequence>

But note: This won’t work if MDT uses the SYSTEM account (which is standard for most deployments), so Option 1 is safer for your OEM scenario.

Third: Ensure PowerShell Allows the Script to Run

Always include the -ExecutionPolicy Bypass parameter when calling PowerShell—this skips the default script execution policy that would block your script. If you want to make this permanent for the deployment image, you can set the system execution policy via MDT beforehand:

Set-ExecutionPolicy RemoteSigned -Force

Fourth: Test the Workflow

  1. Package your WiX project into an MSI.
  2. Add it to your MDT task sequence without silent install parameters (no /qn or /qb flags).
  3. Deploy the image: After the initial installation/reboot, the first user login will trigger your script, and the prompts will pop up as expected.
  4. Don’t forget to add logic in your PowerShell script to delete the RunOnce entry after it runs (so it doesn’t trigger again on next login):
    Remove-ItemProperty -Path "HKLM:\Software\Microsoft\Windows\CurrentVersion\RunOnce" -Name "OEMPostSetup" -ErrorAction SilentlyContinue
    

Key Takeaways

  • WiX is 100% capable of handling this scenario.
  • Session 0 isolation is the main hurdle—using RunOnce ensures your script runs in an interactive user session.
  • Keep the script self-contained in the MSI with the <Binary> element for easy deployment via MDT.

内容的提问来源于stack exchange,提问作者adam humphrey

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.15 08:31:13