在AWS通过Packer构建Windows Server2016时,PowerShell禁用IE增强安全配置失败
Let’s break down why you’re hitting this error and walk through practical fixes:
Why the Error Occurs
Windows Server 2016 doesn’t launch Explorer.exe by default in non-interactive sessions—which is exactly the context Packer uses to run provisioners in the background. Since there’s no Explorer process running during the provisioning step, Stop-Process -Name Explorer -Force throws the "cannot find process" error.
Fix 1: Add Error Guardrails to the Stop-Process Command
First, avoid the error entirely by checking if the process exists before attempting to stop it, or suppress errors directly:
# Option 1: Check for Explorer first, then stop if (Get-Process -Name Explorer -ErrorAction SilentlyContinue) { Stop-Process -Name Explorer -Force } # Option 2: Suppress errors explicitly Stop-Process -Name Explorer -Force -ErrorAction SilentlyContinue
Fix 2: Apply IE ESC Changes Without Restarting Explorer
If your core goal is to disable IE Enhanced Security Configuration (ESC), you don’t actually need to restart Explorer. Use this full script to disable ESC for both admins and users, with immediate application:
# Disable IE ESC for Administrators Set-ItemProperty -Path "HKLM:\SOFTWARE\Microsoft\Active Setup\Installed Components\{A509B1A7-37EF-4b3f-8CFC-4F3A74704073}" -Name "IsInstalled" -Value 0 -Force # Disable IE ESC for Regular Users Set-ItemProperty -Path "HKLM:\SOFTWARE\Microsoft\Active Setup\Installed Components\{A509B1A8-37EF-4b3f-8CFC-4F3A74704073}" -Name "IsInstalled" -Value 0 -Force # Force Active Setup to apply changes immediately (no Explorer restart needed) Rundll32.exe advpack.dll,LaunchINFSection C:\Windows\inf\ie.inf,IE_Server_Custom,,3,N
The Rundll32 command triggers Windows to apply the registry changes right away, so you skip the need to interact with Explorer entirely.
Fix 3: Launch Explorer Temporarily (If You Must)
If you have a specific reason to restart Explorer (e.g., other UI-related configs), launch it first before stopping:
# Start Explorer if it's not running if (-not (Get-Process -Name Explorer -ErrorAction SilentlyContinue)) { Start-Process Explorer.exe # Give it a moment to initialize Start-Sleep -Seconds 2 } # Now stop the process Stop-Process -Name Explorer -Force
Quick Note About Server Manager
When you remote into the server and open Server Manager, you trigger an interactive session—which automatically launches Explorer.exe. That’s why you see the process running after logging in, even though it wasn’t present during Packer’s provisioning step.
内容的提问来源于stack exchange,提问作者SignalRichard

