mirror of
https://github.com/moons-14/dotfiles.git
synced 2026-10-05 23:18:11 +09:00
privact
This commit is contained in:
+69
-5
@@ -39,6 +39,11 @@ windows/
|
||||
│ ├── device-usage.dsc.yaml
|
||||
│ ├── explorer.dsc.yaml
|
||||
│ ├── ime.dsc.yaml
|
||||
│ ├── privacy/
|
||||
│ │ ├── configuration.dsc.yaml
|
||||
│ │ ├── machine.dsc.yaml
|
||||
│ │ ├── enhanced-search.json
|
||||
│ │ └── apply.ps1
|
||||
│ ├── advanced-settings/
|
||||
│ │ ├── configuration.dsc.yaml
|
||||
│ │ └── apply.ps1
|
||||
@@ -57,6 +62,10 @@ windows/
|
||||
│ ├── apply.ps1
|
||||
│ └── gitconfig
|
||||
│
|
||||
├── parsec/
|
||||
│ ├── apply.ps1
|
||||
│ └── installer.json
|
||||
│
|
||||
└── vscode/
|
||||
├── apply.ps1
|
||||
├── settings.json
|
||||
@@ -127,16 +136,19 @@ dsc config set --file .\configuration.dsc.yaml
|
||||
|
||||
& .\applications\chatgpt\apply.ps1
|
||||
& .\applications\git\apply.ps1
|
||||
& .\applications\parsec\apply.ps1
|
||||
& .\applications\vscode\apply.ps1
|
||||
& .\system\advanced-settings\apply.ps1
|
||||
& .\system\lock-screen\apply.ps1
|
||||
& .\system\power\apply.ps1
|
||||
& .\system\privacy\apply.ps1
|
||||
& .\system\wallpaper\apply.ps1
|
||||
```
|
||||
|
||||
The specialized scripts own the details of their own configuration. Only the
|
||||
advanced-settings script requests elevation, for the protected Explorer policy
|
||||
and machine-wide long-path setting; Scoop, DSC user settings, and application
|
||||
The specialized scripts own the details of their own configuration. The
|
||||
advanced-settings and privacy scripts request elevation for protected policies
|
||||
and machine-wide settings. The Parsec installer also requests elevation for its
|
||||
machine-wide installation; Scoop, other DSC user settings, and application
|
||||
configuration stay in the normal user process.
|
||||
|
||||
## Packages
|
||||
@@ -185,6 +197,17 @@ ChatGPT Classic (`9NT1R1C2HH7J`) is intentionally not installed.
|
||||
WinGet's `APPINSTALLER_CLI_ERROR_UPDATE_NOT_APPLICABLE` result is treated as
|
||||
success because it means the installed ChatGPT version is already current.
|
||||
|
||||
### Parsec
|
||||
|
||||
Parsec is installed by `applications/parsec/apply.ps1` instead of the WinGet
|
||||
DSC document. Parsec publishes mutable installer content at a stable URL, which
|
||||
can temporarily leave the WinGet manifest with a stale SHA256 and make the
|
||||
entire DSC run fail. The application-local declaration pins the verified file
|
||||
version, SHA256, and Authenticode signer thumbprint. The script downloads only
|
||||
when Parsec is absent, verifies all three values, then requests elevation and
|
||||
runs the official installer for all users. It never bypasses WinGet hash
|
||||
verification.
|
||||
|
||||
7-Zip is intentionally installed with its normal Windows installer through
|
||||
WinGet rather than as a portable Scoop package, because the normal installer
|
||||
provides Explorer shell integration.
|
||||
@@ -212,7 +235,7 @@ current image and only calls the API when the image differs.
|
||||
- recently added apps: on
|
||||
- recommended and recent files: off
|
||||
- recommendations for tips, shortcuts, and new apps: off
|
||||
- most used apps: on
|
||||
- app-launch tracking and most-used app personalization: off
|
||||
|
||||
### Device usage
|
||||
|
||||
@@ -220,6 +243,43 @@ current image and only calls the API when the image differs.
|
||||
for Development, Gaming, Family, Creativity, School, Entertainment, and
|
||||
Business.
|
||||
|
||||
### Privacy, diagnostics, feedback, and search
|
||||
|
||||
`system/privacy/configuration.dsc.yaml` configures user-scoped preferences:
|
||||
|
||||
- advertising ID: off
|
||||
- website access to the language list: off
|
||||
- personalized offers and tailored experiences: off
|
||||
- Windows Spotlight, third-party content, Settings suggestions, tips, welcome
|
||||
experiences, device-setup suggestions, and suggested app installation: off
|
||||
- File Explorer sync-provider promotions: off
|
||||
- inking and typing diagnostics: off
|
||||
- feedback frequency and prompts: never
|
||||
- device search history and search highlights: off
|
||||
|
||||
`system/privacy/apply.ps1` requests elevation and applies both the user-scoped
|
||||
configuration above and `system/privacy/machine.dsc.yaml`, which configures:
|
||||
|
||||
- advertising ID and Windows consumer experiences: off by policy
|
||||
- diagnostic data: the lowest level supported by the installed Windows edition
|
||||
- feedback notifications and Diagnostic Data Viewer: off
|
||||
- diagnostic log and dump collection: limited
|
||||
- publishing and uploading activity history: off
|
||||
|
||||
The protected Windows Search key doesn't grant write access to administrators,
|
||||
so `apply.ps1` applies the desired value from the declarative
|
||||
`enhanced-search.json` as `SYSTEM` to set Find my files to Enhanced. It uses a
|
||||
uniquely named one-shot Scheduled Task and always unregisters it immediately
|
||||
afterward. It doesn't change the key's owner or access-control list and doesn't
|
||||
leave a persistent task behind.
|
||||
|
||||
Windows Pro still sends required diagnostic data even when `AllowTelemetry` is
|
||||
set to the Security value (`0`); only editions that support the Security level
|
||||
honor diagnostic data completely off. The configuration nevertheless disables
|
||||
optional diagnostic data and every related user-facing toggle. Enhanced search
|
||||
indexes the full user profile, so its initial indexing can temporarily use more
|
||||
CPU, battery, and storage.
|
||||
|
||||
### Taskbar
|
||||
|
||||
`system/taskbar.dsc.yaml` configures:
|
||||
@@ -434,10 +494,14 @@ system/start.dsc.yaml
|
||||
system/device-usage.dsc.yaml
|
||||
system/explorer.dsc.yaml
|
||||
system/ime.dsc.yaml
|
||||
system/privacy/configuration.dsc.yaml
|
||||
system/privacy/machine.dsc.yaml
|
||||
system/advanced-settings/configuration.dsc.yaml
|
||||
```
|
||||
|
||||
When adding a new DSC document, include it from `configuration.dsc.yaml`.
|
||||
Include ordinary user-scoped DSC documents from the root
|
||||
`configuration.dsc.yaml`. A protected or machine-wide document may instead be
|
||||
applied by its feature-local elevated script, as the privacy configuration is.
|
||||
|
||||
If a system feature cannot be expressed reliably with DSC and genuinely needs
|
||||
procedural setup, give that feature its own directory, following the wallpaper
|
||||
|
||||
@@ -0,0 +1,94 @@
|
||||
$ErrorActionPreference = "Stop"
|
||||
|
||||
function Test-ParsecInstalled {
|
||||
$candidatePaths = @(
|
||||
(Join-Path $env:ProgramFiles "Parsec\parsecd.exe")
|
||||
(Join-Path $env:LOCALAPPDATA "Parsec\parsecd.exe")
|
||||
(Join-Path $env:APPDATA "Parsec\parsecd.exe")
|
||||
)
|
||||
|
||||
if (${env:ProgramFiles(x86)}) {
|
||||
$candidatePaths += Join-Path ${env:ProgramFiles(x86)} "Parsec\parsecd.exe"
|
||||
}
|
||||
|
||||
if ($candidatePaths | Where-Object { Test-Path -LiteralPath $_ }) {
|
||||
return $true
|
||||
}
|
||||
|
||||
$uninstallRoots = @(
|
||||
"HKLM:\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\*"
|
||||
"HKLM:\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\*"
|
||||
"HKCU:\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\*"
|
||||
)
|
||||
|
||||
foreach ($root in $uninstallRoots) {
|
||||
$installedPackage = Get-ItemProperty -Path $root -ErrorAction SilentlyContinue |
|
||||
Where-Object { $_.DisplayName -like "Parsec*" } |
|
||||
Select-Object -First 1
|
||||
|
||||
if ($installedPackage) {
|
||||
return $true
|
||||
}
|
||||
}
|
||||
|
||||
return $false
|
||||
}
|
||||
|
||||
if (Test-ParsecInstalled) {
|
||||
Write-Host "Parsec is already installed."
|
||||
return
|
||||
}
|
||||
|
||||
$declarationPath = Join-Path $PSScriptRoot "installer.json"
|
||||
$declaration = Get-Content -LiteralPath $declarationPath -Raw | ConvertFrom-Json
|
||||
$installerPath = Join-Path ([System.IO.Path]::GetTempPath()) (
|
||||
"parsec-{0}.exe" -f [guid]::NewGuid().ToString("N")
|
||||
)
|
||||
|
||||
try {
|
||||
Write-Host "Downloading the declared Parsec installer..."
|
||||
Invoke-WebRequest -Uri $declaration.url -OutFile $installerPath -UseBasicParsing
|
||||
|
||||
$actualHash = (Get-FileHash -LiteralPath $installerPath -Algorithm SHA256).Hash
|
||||
if ($actualHash -ne $declaration.sha256) {
|
||||
throw "Parsec installer SHA256 mismatch. Expected $($declaration.sha256), got $actualHash."
|
||||
}
|
||||
|
||||
$version = (Get-Item -LiteralPath $installerPath).VersionInfo.FileVersion
|
||||
if ($version -ne $declaration.version) {
|
||||
throw "Parsec installer version mismatch. Expected $($declaration.version), got $version."
|
||||
}
|
||||
|
||||
$signature = Get-AuthenticodeSignature -LiteralPath $installerPath
|
||||
if ($signature.Status -ne [System.Management.Automation.SignatureStatus]::Valid) {
|
||||
throw "Parsec installer signature is not valid: $($signature.StatusMessage)"
|
||||
}
|
||||
|
||||
if ($signature.SignerCertificate.Subject -ne $declaration.signerSubject) {
|
||||
throw "Parsec installer signer subject does not match the declaration."
|
||||
}
|
||||
|
||||
if ($signature.SignerCertificate.Thumbprint -ne $declaration.signerThumbprint) {
|
||||
throw "Parsec installer signer thumbprint does not match the declaration."
|
||||
}
|
||||
|
||||
Write-Host "Installing verified Parsec $version for all users..."
|
||||
$process = Start-Process -FilePath $installerPath `
|
||||
-ArgumentList $declaration.silentArguments `
|
||||
-Verb RunAs `
|
||||
-Wait `
|
||||
-PassThru
|
||||
|
||||
if ($process.ExitCode -notin @(0, 3010)) {
|
||||
throw "Parsec installer failed with exit code $($process.ExitCode)."
|
||||
}
|
||||
|
||||
if (-not (Test-ParsecInstalled)) {
|
||||
throw "Parsec installer completed, but the installation could not be verified."
|
||||
}
|
||||
|
||||
Write-Host "Parsec installation is present and verified."
|
||||
}
|
||||
finally {
|
||||
Remove-Item -LiteralPath $installerPath -Force -ErrorAction SilentlyContinue
|
||||
}
|
||||
@@ -0,0 +1,13 @@
|
||||
{
|
||||
"version": "150.104.1.0",
|
||||
"url": "https://builds.parsec.app/package/parsec-windows.exe",
|
||||
"sha256": "B8A9CD519010666DEF0EF6E119EB42B33B5B811216F34E4F6C8E2E25AC290FBC",
|
||||
"signerSubject": "CN=Unity Technologies SF, O=Unity Technologies SF, L=San Francisco, S=California, C=US",
|
||||
"signerThumbprint": "F83EAE671EDFDE1E819B41FF6F6A2ED611A651DF",
|
||||
"silentArguments": [
|
||||
"/silent",
|
||||
"/norun",
|
||||
"/nocleanuser",
|
||||
"/allusers"
|
||||
]
|
||||
}
|
||||
@@ -29,13 +29,6 @@ resources:
|
||||
source: winget
|
||||
useLatest: true
|
||||
|
||||
- name: Parsec
|
||||
type: Microsoft.WinGet/Package
|
||||
properties:
|
||||
id: Parsec.Parsec
|
||||
source: winget
|
||||
useLatest: true
|
||||
|
||||
- name: 7-Zip
|
||||
type: Microsoft.WinGet/Package
|
||||
properties:
|
||||
|
||||
@@ -0,0 +1,187 @@
|
||||
[CmdletBinding()]
|
||||
param(
|
||||
[string] $DscPath = (Get-Command dsc -ErrorAction Stop).Source,
|
||||
[string] $ResultPath
|
||||
)
|
||||
|
||||
$ErrorActionPreference = "Stop"
|
||||
|
||||
trap {
|
||||
if ($ResultPath) {
|
||||
$_ | Out-String | Set-Content `
|
||||
-LiteralPath $ResultPath `
|
||||
-Encoding UTF8
|
||||
}
|
||||
|
||||
break
|
||||
}
|
||||
|
||||
function Test-Administrator {
|
||||
$identity = [Security.Principal.WindowsIdentity]::GetCurrent()
|
||||
$principal = [Security.Principal.WindowsPrincipal]::new($identity)
|
||||
|
||||
return $principal.IsInRole(
|
||||
[Security.Principal.WindowsBuiltInRole]::Administrator
|
||||
)
|
||||
}
|
||||
|
||||
function Get-RegistryValueOrNull {
|
||||
param(
|
||||
[Parameter(Mandatory)]
|
||||
[string] $Path,
|
||||
|
||||
[Parameter(Mandatory)]
|
||||
[string] $Name
|
||||
)
|
||||
|
||||
if (-not (Test-Path -LiteralPath $Path)) {
|
||||
return $null
|
||||
}
|
||||
|
||||
$key = Get-Item -LiteralPath $Path
|
||||
|
||||
return $key.GetValue(
|
||||
$Name,
|
||||
$null,
|
||||
[Microsoft.Win32.RegistryValueOptions]::DoNotExpandEnvironmentNames
|
||||
)
|
||||
}
|
||||
|
||||
if (-not (Test-Administrator)) {
|
||||
$powershell = (Get-Process -Id $PID).Path
|
||||
$resultPath = Join-Path `
|
||||
$env:TEMP `
|
||||
"dotfiles-privacy-$([guid]::NewGuid().ToString('N')).log"
|
||||
$arguments = @(
|
||||
"-NoProfile"
|
||||
"-ExecutionPolicy"
|
||||
"Bypass"
|
||||
"-File"
|
||||
('"{0}"' -f $PSCommandPath)
|
||||
"-DscPath"
|
||||
('"{0}"' -f $DscPath)
|
||||
"-ResultPath"
|
||||
('"{0}"' -f $resultPath)
|
||||
)
|
||||
|
||||
try {
|
||||
$process = Start-Process `
|
||||
-FilePath $powershell `
|
||||
-ArgumentList $arguments `
|
||||
-Verb RunAs `
|
||||
-Wait `
|
||||
-PassThru
|
||||
|
||||
if ($process.ExitCode -ne 0) {
|
||||
$details = if (Test-Path -LiteralPath $resultPath) {
|
||||
Get-Content -Raw -LiteralPath $resultPath
|
||||
}
|
||||
else {
|
||||
"No detailed error was returned by the elevated process."
|
||||
}
|
||||
|
||||
throw "Elevated privacy settings failed with exit code $($process.ExitCode).`n$details"
|
||||
}
|
||||
}
|
||||
finally {
|
||||
Remove-Item `
|
||||
-LiteralPath $resultPath `
|
||||
-Force `
|
||||
-ErrorAction SilentlyContinue
|
||||
}
|
||||
|
||||
return
|
||||
}
|
||||
|
||||
$configurations = @(
|
||||
@{
|
||||
Name = "user privacy settings"
|
||||
Path = Join-Path $PSScriptRoot "configuration.dsc.yaml"
|
||||
}
|
||||
@{
|
||||
Name = "machine-wide privacy settings"
|
||||
Path = Join-Path $PSScriptRoot "machine.dsc.yaml"
|
||||
}
|
||||
)
|
||||
|
||||
foreach ($configuration in $configurations) {
|
||||
& $DscPath config set --file $configuration.Path
|
||||
|
||||
if ($LASTEXITCODE -ne 0) {
|
||||
throw "Failed to apply $($configuration.Name)."
|
||||
}
|
||||
}
|
||||
|
||||
$searchConfiguration = Get-Content `
|
||||
-Raw `
|
||||
-LiteralPath (Join-Path $PSScriptRoot "enhanced-search.json") |
|
||||
ConvertFrom-Json
|
||||
$searchKey = $searchConfiguration.keyPath -replace '^HKLM\\', 'HKLM:\'
|
||||
$searchValueName = $searchConfiguration.valueName
|
||||
$enhancedSearch = Get-RegistryValueOrNull `
|
||||
-Path $searchKey `
|
||||
-Name $searchValueName
|
||||
|
||||
if ($enhancedSearch -ne $searchConfiguration.valueData) {
|
||||
$taskName = "Dotfiles-EnhancedSearch-$([guid]::NewGuid().ToString('N'))"
|
||||
$reg = Join-Path $env:SystemRoot "System32\reg.exe"
|
||||
$regArguments = 'add "{0}" /v "{1}" /t {2} /d {3} /f' -f @(
|
||||
$searchConfiguration.keyPath
|
||||
$searchConfiguration.valueName
|
||||
$searchConfiguration.valueType
|
||||
$searchConfiguration.valueData
|
||||
)
|
||||
$action = New-ScheduledTaskAction `
|
||||
-Execute $reg `
|
||||
-Argument $regArguments
|
||||
$principal = New-ScheduledTaskPrincipal `
|
||||
-UserId "SYSTEM" `
|
||||
-LogonType ServiceAccount `
|
||||
-RunLevel Highest
|
||||
$taskDefinition = New-ScheduledTask `
|
||||
-Action $action `
|
||||
-Principal $principal
|
||||
$startedAt = Get-Date
|
||||
|
||||
try {
|
||||
Register-ScheduledTask `
|
||||
-TaskName $taskName `
|
||||
-InputObject $taskDefinition `
|
||||
-Force | Out-Null
|
||||
|
||||
Start-ScheduledTask -TaskName $taskName
|
||||
|
||||
$deadline = (Get-Date).AddSeconds(30)
|
||||
|
||||
do {
|
||||
Start-Sleep -Milliseconds 200
|
||||
$task = Get-ScheduledTask -TaskName $taskName
|
||||
$taskInfo = Get-ScheduledTaskInfo -TaskName $taskName
|
||||
$hasRun = $taskInfo.LastRunTime -ge $startedAt.AddSeconds(-1)
|
||||
} while (
|
||||
(Get-Date) -lt $deadline -and
|
||||
(-not $hasRun -or $task.State -eq "Running")
|
||||
)
|
||||
|
||||
if (-not $hasRun -or $task.State -eq "Running") {
|
||||
throw "Timed out while enabling enhanced file search."
|
||||
}
|
||||
|
||||
if ($taskInfo.LastTaskResult -ne 0) {
|
||||
throw "Failed to enable enhanced file search (task result $($taskInfo.LastTaskResult))."
|
||||
}
|
||||
}
|
||||
finally {
|
||||
if (Get-ScheduledTask -TaskName $taskName -ErrorAction SilentlyContinue) {
|
||||
Unregister-ScheduledTask -TaskName $taskName -Confirm:$false
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
$enhancedSearch = Get-RegistryValueOrNull `
|
||||
-Path $searchKey `
|
||||
-Name $searchValueName
|
||||
|
||||
if ($enhancedSearch -ne $searchConfiguration.valueData) {
|
||||
throw "Failed to verify enhanced file search."
|
||||
}
|
||||
@@ -0,0 +1,200 @@
|
||||
$schema: https://aka.ms/dsc/schemas/v3/bundled/config/document.json
|
||||
|
||||
resources:
|
||||
- name: Disable advertising ID
|
||||
type: Microsoft.Windows/Registry
|
||||
properties:
|
||||
keyPath: HKCU\Software\Microsoft\Windows\CurrentVersion\AdvertisingInfo
|
||||
valueName: Enabled
|
||||
valueData:
|
||||
DWord: 0
|
||||
_exist: true
|
||||
|
||||
- name: Do not share the language list with websites
|
||||
type: Microsoft.Windows/Registry
|
||||
properties:
|
||||
keyPath: HKCU\Control Panel\International\User Profile
|
||||
valueName: HttpAcceptLanguageOptOut
|
||||
valueData:
|
||||
DWord: 1
|
||||
_exist: true
|
||||
|
||||
- name: Disable personalized offers
|
||||
type: Microsoft.Windows/Registry
|
||||
properties:
|
||||
keyPath: HKCU\Software\Microsoft\Windows\CurrentVersion\Privacy
|
||||
valueName: TailoredExperiencesWithDiagnosticDataEnabled
|
||||
valueData:
|
||||
DWord: 0
|
||||
_exist: true
|
||||
|
||||
- name: Disable tailored experiences by policy
|
||||
type: Microsoft.Windows/Registry
|
||||
properties:
|
||||
keyPath: HKCU\Software\Policies\Microsoft\Windows\CloudContent
|
||||
valueName: DisableTailoredExperiencesWithDiagnosticData
|
||||
valueData:
|
||||
DWord: 1
|
||||
_exist: true
|
||||
|
||||
- name: Disable all Windows Spotlight suggestions
|
||||
type: Microsoft.Windows/Registry
|
||||
properties:
|
||||
keyPath: HKCU\Software\Policies\Microsoft\Windows\CloudContent
|
||||
valueName: DisableWindowsSpotlightFeatures
|
||||
valueData:
|
||||
DWord: 1
|
||||
_exist: true
|
||||
|
||||
- name: Disable third-party Spotlight suggestions
|
||||
type: Microsoft.Windows/Registry
|
||||
properties:
|
||||
keyPath: HKCU\Software\Policies\Microsoft\Windows\CloudContent
|
||||
valueName: DisableThirdPartySuggestions
|
||||
valueData:
|
||||
DWord: 1
|
||||
_exist: true
|
||||
|
||||
- name: Disable suggested content in Settings
|
||||
type: Microsoft.Windows/Registry
|
||||
properties:
|
||||
keyPath: HKCU\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager
|
||||
valueName: SubscribedContent-338393Enabled
|
||||
valueData:
|
||||
DWord: 0
|
||||
_exist: true
|
||||
|
||||
- name: Disable Settings suggestions
|
||||
type: Microsoft.Windows/Registry
|
||||
properties:
|
||||
keyPath: HKCU\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager
|
||||
valueName: SystemPaneSuggestionsEnabled
|
||||
valueData:
|
||||
DWord: 0
|
||||
_exist: true
|
||||
|
||||
- name: Disable Settings account suggestions
|
||||
type: Microsoft.Windows/Registry
|
||||
properties:
|
||||
keyPath: HKCU\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager
|
||||
valueName: SubscribedContent-353694Enabled
|
||||
valueData:
|
||||
DWord: 0
|
||||
_exist: true
|
||||
|
||||
- name: Disable Settings app suggestions
|
||||
type: Microsoft.Windows/Registry
|
||||
properties:
|
||||
keyPath: HKCU\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager
|
||||
valueName: SubscribedContent-353696Enabled
|
||||
valueData:
|
||||
DWord: 0
|
||||
_exist: true
|
||||
|
||||
- name: Disable tips about Windows
|
||||
type: Microsoft.Windows/Registry
|
||||
properties:
|
||||
keyPath: HKCU\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager
|
||||
valueName: SubscribedContent-338389Enabled
|
||||
valueData:
|
||||
DWord: 0
|
||||
_exist: true
|
||||
|
||||
- name: Disable Windows welcome experience
|
||||
type: Microsoft.Windows/Registry
|
||||
properties:
|
||||
keyPath: HKCU\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager
|
||||
valueName: SubscribedContent-310093Enabled
|
||||
valueData:
|
||||
DWord: 0
|
||||
_exist: true
|
||||
|
||||
- name: Disable suggested apps
|
||||
type: Microsoft.Windows/Registry
|
||||
properties:
|
||||
keyPath: HKCU\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager
|
||||
valueName: SubscribedContent-338388Enabled
|
||||
valueData:
|
||||
DWord: 0
|
||||
_exist: true
|
||||
|
||||
- name: Disable soft-landing tips
|
||||
type: Microsoft.Windows/Registry
|
||||
properties:
|
||||
keyPath: HKCU\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager
|
||||
valueName: SoftLandingEnabled
|
||||
valueData:
|
||||
DWord: 0
|
||||
_exist: true
|
||||
|
||||
- name: Disable automatic suggested app installation
|
||||
type: Microsoft.Windows/Registry
|
||||
properties:
|
||||
keyPath: HKCU\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager
|
||||
valueName: SilentInstalledAppsEnabled
|
||||
valueData:
|
||||
DWord: 0
|
||||
_exist: true
|
||||
|
||||
- name: Disable device setup suggestions
|
||||
type: Microsoft.Windows/Registry
|
||||
properties:
|
||||
keyPath: HKCU\Software\Microsoft\Windows\CurrentVersion\UserProfileEngagement
|
||||
valueName: ScoobeSystemSettingEnabled
|
||||
valueData:
|
||||
DWord: 0
|
||||
_exist: true
|
||||
|
||||
- name: Disable File Explorer sync-provider promotions
|
||||
type: Microsoft.Windows/Registry
|
||||
properties:
|
||||
keyPath: HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced
|
||||
valueName: ShowSyncProviderNotifications
|
||||
valueData:
|
||||
DWord: 0
|
||||
_exist: true
|
||||
|
||||
- name: Disable inking and typing diagnostics
|
||||
type: Microsoft.Windows/Registry
|
||||
properties:
|
||||
keyPath: HKCU\Software\Microsoft\Input\TIPC
|
||||
valueName: Enabled
|
||||
valueData:
|
||||
DWord: 0
|
||||
_exist: true
|
||||
|
||||
- name: Set feedback frequency period to never
|
||||
type: Microsoft.Windows/Registry
|
||||
properties:
|
||||
keyPath: HKCU\Software\Microsoft\Siuf\Rules
|
||||
valueName: PeriodInNanoSeconds
|
||||
valueData:
|
||||
DWord: 0
|
||||
_exist: true
|
||||
|
||||
- name: Set feedback prompts to never
|
||||
type: Microsoft.Windows/Registry
|
||||
properties:
|
||||
keyPath: HKCU\Software\Microsoft\Siuf\Rules
|
||||
valueName: NumberOfSIUFInPeriod
|
||||
valueData:
|
||||
DWord: 0
|
||||
_exist: true
|
||||
|
||||
- name: Disable device search history
|
||||
type: Microsoft.Windows/Registry
|
||||
properties:
|
||||
keyPath: HKCU\Software\Microsoft\Windows\CurrentVersion\SearchSettings
|
||||
valueName: IsDeviceSearchHistoryEnabled
|
||||
valueData:
|
||||
DWord: 0
|
||||
_exist: true
|
||||
|
||||
- name: Disable search highlights
|
||||
type: Microsoft.Windows/Registry
|
||||
properties:
|
||||
keyPath: HKCU\Software\Microsoft\Windows\CurrentVersion\SearchSettings
|
||||
valueName: IsDynamicSearchBoxEnabled
|
||||
valueData:
|
||||
DWord: 0
|
||||
_exist: true
|
||||
@@ -0,0 +1,6 @@
|
||||
{
|
||||
"keyPath": "HKLM\\SOFTWARE\\Microsoft\\Windows Search\\Gather\\Windows\\SystemIndex",
|
||||
"valueName": "EnableFindMyFiles",
|
||||
"valueType": "REG_DWORD",
|
||||
"valueData": 1
|
||||
}
|
||||
@@ -0,0 +1,92 @@
|
||||
$schema: https://aka.ms/dsc/schemas/v3/bundled/config/document.json
|
||||
|
||||
resources:
|
||||
- name: Disable advertising ID by policy
|
||||
type: Microsoft.Windows/Registry
|
||||
properties:
|
||||
keyPath: HKLM\Software\Policies\Microsoft\Windows\AdvertisingInfo
|
||||
valueName: DisabledByGroupPolicy
|
||||
valueData:
|
||||
DWord: 1
|
||||
_exist: true
|
||||
|
||||
- name: Disable Windows consumer experiences
|
||||
type: Microsoft.Windows/Registry
|
||||
properties:
|
||||
keyPath: HKLM\Software\Policies\Microsoft\Windows\CloudContent
|
||||
valueName: DisableWindowsConsumerFeatures
|
||||
valueData:
|
||||
DWord: 1
|
||||
_exist: true
|
||||
|
||||
- name: Set diagnostic data to the lowest available level
|
||||
type: Microsoft.Windows/Registry
|
||||
properties:
|
||||
keyPath: HKLM\Software\Policies\Microsoft\Windows\DataCollection
|
||||
valueName: AllowTelemetry
|
||||
valueData:
|
||||
DWord: 0
|
||||
_exist: true
|
||||
|
||||
- name: Disable feedback notifications
|
||||
type: Microsoft.Windows/Registry
|
||||
properties:
|
||||
keyPath: HKLM\Software\Policies\Microsoft\Windows\DataCollection
|
||||
valueName: DoNotShowFeedbackNotifications
|
||||
valueData:
|
||||
DWord: 1
|
||||
_exist: true
|
||||
|
||||
- name: Disable Diagnostic Data Viewer
|
||||
type: Microsoft.Windows/Registry
|
||||
properties:
|
||||
keyPath: HKLM\Software\Policies\Microsoft\Windows\DataCollection
|
||||
valueName: DisableDiagnosticDataViewer
|
||||
valueData:
|
||||
DWord: 1
|
||||
_exist: true
|
||||
|
||||
- name: Limit diagnostic log collection
|
||||
type: Microsoft.Windows/Registry
|
||||
properties:
|
||||
keyPath: HKLM\Software\Policies\Microsoft\Windows\DataCollection
|
||||
valueName: LimitDiagnosticLogCollection
|
||||
valueData:
|
||||
DWord: 1
|
||||
_exist: true
|
||||
|
||||
- name: Limit diagnostic dump collection
|
||||
type: Microsoft.Windows/Registry
|
||||
properties:
|
||||
keyPath: HKLM\Software\Policies\Microsoft\Windows\DataCollection
|
||||
valueName: LimitDumpCollection
|
||||
valueData:
|
||||
DWord: 1
|
||||
_exist: true
|
||||
|
||||
- name: Disable activity feed
|
||||
type: Microsoft.Windows/Registry
|
||||
properties:
|
||||
keyPath: HKLM\Software\Policies\Microsoft\Windows\System
|
||||
valueName: EnableActivityFeed
|
||||
valueData:
|
||||
DWord: 0
|
||||
_exist: true
|
||||
|
||||
- name: Disable publishing user activity
|
||||
type: Microsoft.Windows/Registry
|
||||
properties:
|
||||
keyPath: HKLM\Software\Policies\Microsoft\Windows\System
|
||||
valueName: PublishUserActivities
|
||||
valueData:
|
||||
DWord: 0
|
||||
_exist: true
|
||||
|
||||
- name: Disable uploading user activity
|
||||
type: Microsoft.Windows/Registry
|
||||
properties:
|
||||
keyPath: HKLM\Software\Policies\Microsoft\Windows\System
|
||||
valueName: UploadUserActivities
|
||||
valueData:
|
||||
DWord: 0
|
||||
_exist: true
|
||||
@@ -28,11 +28,11 @@ resources:
|
||||
DWord: 0
|
||||
_exist: true
|
||||
|
||||
- name: Show most used apps
|
||||
- name: Disable app launch tracking
|
||||
type: Microsoft.Windows/Registry
|
||||
properties:
|
||||
keyPath: HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced
|
||||
valueName: Start_TrackProgs
|
||||
valueData:
|
||||
DWord: 1
|
||||
DWord: 0
|
||||
_exist: true
|
||||
|
||||
@@ -9,12 +9,18 @@ try {
|
||||
|
||||
dsc config set --file .\configuration.dsc.yaml
|
||||
|
||||
if ($LASTEXITCODE -ne 0) {
|
||||
throw "Failed to apply the main DSC configuration."
|
||||
}
|
||||
|
||||
& .\applications\chatgpt\apply.ps1
|
||||
& .\applications\git\apply.ps1
|
||||
& .\applications\parsec\apply.ps1
|
||||
& .\applications\vscode\apply.ps1
|
||||
& .\system\advanced-settings\apply.ps1
|
||||
& .\system\lock-screen\apply.ps1
|
||||
& .\system\power\apply.ps1
|
||||
& .\system\privacy\apply.ps1
|
||||
& .\system\wallpaper\apply.ps1
|
||||
}
|
||||
finally {
|
||||
|
||||
Reference in New Issue
Block a user