diff --git a/windows/README.md b/windows/README.md index 4cadb3c..01d3358 100644 --- a/windows/README.md +++ b/windows/README.md @@ -39,6 +39,11 @@ windows/ │ ├── device-usage.dsc.yaml │ ├── explorer.dsc.yaml │ ├── ime.dsc.yaml +│ ├── privacy/ +│ │ ├── configuration.dsc.yaml +│ │ ├── machine.dsc.yaml +│ │ ├── enhanced-search.json +│ │ └── apply.ps1 │ ├── advanced-settings/ │ │ ├── configuration.dsc.yaml │ │ └── apply.ps1 @@ -57,6 +62,10 @@ windows/ │ ├── apply.ps1 │ └── gitconfig │ + ├── parsec/ + │ ├── apply.ps1 + │ └── installer.json + │ └── vscode/ ├── apply.ps1 ├── settings.json @@ -127,16 +136,19 @@ dsc config set --file .\configuration.dsc.yaml & .\applications\chatgpt\apply.ps1 & .\applications\git\apply.ps1 +& .\applications\parsec\apply.ps1 & .\applications\vscode\apply.ps1 & .\system\advanced-settings\apply.ps1 & .\system\lock-screen\apply.ps1 & .\system\power\apply.ps1 +& .\system\privacy\apply.ps1 & .\system\wallpaper\apply.ps1 ``` -The specialized scripts own the details of their own configuration. Only the -advanced-settings script requests elevation, for the protected Explorer policy -and machine-wide long-path setting; Scoop, DSC user settings, and application +The specialized scripts own the details of their own configuration. The +advanced-settings and privacy scripts request elevation for protected policies +and machine-wide settings. The Parsec installer also requests elevation for its +machine-wide installation; Scoop, other DSC user settings, and application configuration stay in the normal user process. ## Packages @@ -185,6 +197,17 @@ ChatGPT Classic (`9NT1R1C2HH7J`) is intentionally not installed. WinGet's `APPINSTALLER_CLI_ERROR_UPDATE_NOT_APPLICABLE` result is treated as success because it means the installed ChatGPT version is already current. +### Parsec + +Parsec is installed by `applications/parsec/apply.ps1` instead of the WinGet +DSC document. Parsec publishes mutable installer content at a stable URL, which +can temporarily leave the WinGet manifest with a stale SHA256 and make the +entire DSC run fail. The application-local declaration pins the verified file +version, SHA256, and Authenticode signer thumbprint. The script downloads only +when Parsec is absent, verifies all three values, then requests elevation and +runs the official installer for all users. It never bypasses WinGet hash +verification. + 7-Zip is intentionally installed with its normal Windows installer through WinGet rather than as a portable Scoop package, because the normal installer provides Explorer shell integration. @@ -212,7 +235,7 @@ current image and only calls the API when the image differs. - recently added apps: on - recommended and recent files: off - recommendations for tips, shortcuts, and new apps: off -- most used apps: on +- app-launch tracking and most-used app personalization: off ### Device usage @@ -220,6 +243,43 @@ current image and only calls the API when the image differs. for Development, Gaming, Family, Creativity, School, Entertainment, and Business. +### Privacy, diagnostics, feedback, and search + +`system/privacy/configuration.dsc.yaml` configures user-scoped preferences: + +- advertising ID: off +- website access to the language list: off +- personalized offers and tailored experiences: off +- Windows Spotlight, third-party content, Settings suggestions, tips, welcome + experiences, device-setup suggestions, and suggested app installation: off +- File Explorer sync-provider promotions: off +- inking and typing diagnostics: off +- feedback frequency and prompts: never +- device search history and search highlights: off + +`system/privacy/apply.ps1` requests elevation and applies both the user-scoped +configuration above and `system/privacy/machine.dsc.yaml`, which configures: + +- advertising ID and Windows consumer experiences: off by policy +- diagnostic data: the lowest level supported by the installed Windows edition +- feedback notifications and Diagnostic Data Viewer: off +- diagnostic log and dump collection: limited +- publishing and uploading activity history: off + +The protected Windows Search key doesn't grant write access to administrators, +so `apply.ps1` applies the desired value from the declarative +`enhanced-search.json` as `SYSTEM` to set Find my files to Enhanced. It uses a +uniquely named one-shot Scheduled Task and always unregisters it immediately +afterward. It doesn't change the key's owner or access-control list and doesn't +leave a persistent task behind. + +Windows Pro still sends required diagnostic data even when `AllowTelemetry` is +set to the Security value (`0`); only editions that support the Security level +honor diagnostic data completely off. The configuration nevertheless disables +optional diagnostic data and every related user-facing toggle. Enhanced search +indexes the full user profile, so its initial indexing can temporarily use more +CPU, battery, and storage. + ### Taskbar `system/taskbar.dsc.yaml` configures: @@ -434,10 +494,14 @@ system/start.dsc.yaml system/device-usage.dsc.yaml system/explorer.dsc.yaml system/ime.dsc.yaml +system/privacy/configuration.dsc.yaml +system/privacy/machine.dsc.yaml system/advanced-settings/configuration.dsc.yaml ``` -When adding a new DSC document, include it from `configuration.dsc.yaml`. +Include ordinary user-scoped DSC documents from the root +`configuration.dsc.yaml`. A protected or machine-wide document may instead be +applied by its feature-local elevated script, as the privacy configuration is. If a system feature cannot be expressed reliably with DSC and genuinely needs procedural setup, give that feature its own directory, following the wallpaper diff --git a/windows/applications/parsec/apply.ps1 b/windows/applications/parsec/apply.ps1 new file mode 100644 index 0000000..133906e --- /dev/null +++ b/windows/applications/parsec/apply.ps1 @@ -0,0 +1,94 @@ +$ErrorActionPreference = "Stop" + +function Test-ParsecInstalled { + $candidatePaths = @( + (Join-Path $env:ProgramFiles "Parsec\parsecd.exe") + (Join-Path $env:LOCALAPPDATA "Parsec\parsecd.exe") + (Join-Path $env:APPDATA "Parsec\parsecd.exe") + ) + + if (${env:ProgramFiles(x86)}) { + $candidatePaths += Join-Path ${env:ProgramFiles(x86)} "Parsec\parsecd.exe" + } + + if ($candidatePaths | Where-Object { Test-Path -LiteralPath $_ }) { + return $true + } + + $uninstallRoots = @( + "HKLM:\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\*" + "HKLM:\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\*" + "HKCU:\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\*" + ) + + foreach ($root in $uninstallRoots) { + $installedPackage = Get-ItemProperty -Path $root -ErrorAction SilentlyContinue | + Where-Object { $_.DisplayName -like "Parsec*" } | + Select-Object -First 1 + + if ($installedPackage) { + return $true + } + } + + return $false +} + +if (Test-ParsecInstalled) { + Write-Host "Parsec is already installed." + return +} + +$declarationPath = Join-Path $PSScriptRoot "installer.json" +$declaration = Get-Content -LiteralPath $declarationPath -Raw | ConvertFrom-Json +$installerPath = Join-Path ([System.IO.Path]::GetTempPath()) ( + "parsec-{0}.exe" -f [guid]::NewGuid().ToString("N") +) + +try { + Write-Host "Downloading the declared Parsec installer..." + Invoke-WebRequest -Uri $declaration.url -OutFile $installerPath -UseBasicParsing + + $actualHash = (Get-FileHash -LiteralPath $installerPath -Algorithm SHA256).Hash + if ($actualHash -ne $declaration.sha256) { + throw "Parsec installer SHA256 mismatch. Expected $($declaration.sha256), got $actualHash." + } + + $version = (Get-Item -LiteralPath $installerPath).VersionInfo.FileVersion + if ($version -ne $declaration.version) { + throw "Parsec installer version mismatch. Expected $($declaration.version), got $version." + } + + $signature = Get-AuthenticodeSignature -LiteralPath $installerPath + if ($signature.Status -ne [System.Management.Automation.SignatureStatus]::Valid) { + throw "Parsec installer signature is not valid: $($signature.StatusMessage)" + } + + if ($signature.SignerCertificate.Subject -ne $declaration.signerSubject) { + throw "Parsec installer signer subject does not match the declaration." + } + + if ($signature.SignerCertificate.Thumbprint -ne $declaration.signerThumbprint) { + throw "Parsec installer signer thumbprint does not match the declaration." + } + + Write-Host "Installing verified Parsec $version for all users..." + $process = Start-Process -FilePath $installerPath ` + -ArgumentList $declaration.silentArguments ` + -Verb RunAs ` + -Wait ` + -PassThru + + if ($process.ExitCode -notin @(0, 3010)) { + throw "Parsec installer failed with exit code $($process.ExitCode)." + } + + if (-not (Test-ParsecInstalled)) { + throw "Parsec installer completed, but the installation could not be verified." + } + + Write-Host "Parsec installation is present and verified." +} +finally { + Remove-Item -LiteralPath $installerPath -Force -ErrorAction SilentlyContinue +} diff --git a/windows/applications/parsec/installer.json b/windows/applications/parsec/installer.json new file mode 100644 index 0000000..7ceed4b --- /dev/null +++ b/windows/applications/parsec/installer.json @@ -0,0 +1,13 @@ +{ + "version": "150.104.1.0", + "url": "https://builds.parsec.app/package/parsec-windows.exe", + "sha256": "B8A9CD519010666DEF0EF6E119EB42B33B5B811216F34E4F6C8E2E25AC290FBC", + "signerSubject": "CN=Unity Technologies SF, O=Unity Technologies SF, L=San Francisco, S=California, C=US", + "signerThumbprint": "F83EAE671EDFDE1E819B41FF6F6A2ED611A651DF", + "silentArguments": [ + "/silent", + "/norun", + "/nocleanuser", + "/allusers" + ] +} diff --git a/windows/packages/winget.dsc.yaml b/windows/packages/winget.dsc.yaml index 3005204..87d1dc3 100644 --- a/windows/packages/winget.dsc.yaml +++ b/windows/packages/winget.dsc.yaml @@ -29,13 +29,6 @@ resources: source: winget useLatest: true - - name: Parsec - type: Microsoft.WinGet/Package - properties: - id: Parsec.Parsec - source: winget - useLatest: true - - name: 7-Zip type: Microsoft.WinGet/Package properties: diff --git a/windows/system/privacy/apply.ps1 b/windows/system/privacy/apply.ps1 new file mode 100644 index 0000000..19a2cf6 --- /dev/null +++ b/windows/system/privacy/apply.ps1 @@ -0,0 +1,187 @@ +[CmdletBinding()] +param( + [string] $DscPath = (Get-Command dsc -ErrorAction Stop).Source, + [string] $ResultPath +) + +$ErrorActionPreference = "Stop" + +trap { + if ($ResultPath) { + $_ | Out-String | Set-Content ` + -LiteralPath $ResultPath ` + -Encoding UTF8 + } + + break +} + +function Test-Administrator { + $identity = [Security.Principal.WindowsIdentity]::GetCurrent() + $principal = [Security.Principal.WindowsPrincipal]::new($identity) + + return $principal.IsInRole( + [Security.Principal.WindowsBuiltInRole]::Administrator + ) +} + +function Get-RegistryValueOrNull { + param( + [Parameter(Mandatory)] + [string] $Path, + + [Parameter(Mandatory)] + [string] $Name + ) + + if (-not (Test-Path -LiteralPath $Path)) { + return $null + } + + $key = Get-Item -LiteralPath $Path + + return $key.GetValue( + $Name, + $null, + [Microsoft.Win32.RegistryValueOptions]::DoNotExpandEnvironmentNames + ) +} + +if (-not (Test-Administrator)) { + $powershell = (Get-Process -Id $PID).Path + $resultPath = Join-Path ` + $env:TEMP ` + "dotfiles-privacy-$([guid]::NewGuid().ToString('N')).log" + $arguments = @( + "-NoProfile" + "-ExecutionPolicy" + "Bypass" + "-File" + ('"{0}"' -f $PSCommandPath) + "-DscPath" + ('"{0}"' -f $DscPath) + "-ResultPath" + ('"{0}"' -f $resultPath) + ) + + try { + $process = Start-Process ` + -FilePath $powershell ` + -ArgumentList $arguments ` + -Verb RunAs ` + -Wait ` + -PassThru + + if ($process.ExitCode -ne 0) { + $details = if (Test-Path -LiteralPath $resultPath) { + Get-Content -Raw -LiteralPath $resultPath + } + else { + "No detailed error was returned by the elevated process." + } + + throw "Elevated privacy settings failed with exit code $($process.ExitCode).`n$details" + } + } + finally { + Remove-Item ` + -LiteralPath $resultPath ` + -Force ` + -ErrorAction SilentlyContinue + } + + return +} + +$configurations = @( + @{ + Name = "user privacy settings" + Path = Join-Path $PSScriptRoot "configuration.dsc.yaml" + } + @{ + Name = "machine-wide privacy settings" + Path = Join-Path $PSScriptRoot "machine.dsc.yaml" + } +) + +foreach ($configuration in $configurations) { + & $DscPath config set --file $configuration.Path + + if ($LASTEXITCODE -ne 0) { + throw "Failed to apply $($configuration.Name)." + } +} + +$searchConfiguration = Get-Content ` + -Raw ` + -LiteralPath (Join-Path $PSScriptRoot "enhanced-search.json") | + ConvertFrom-Json +$searchKey = $searchConfiguration.keyPath -replace '^HKLM\\', 'HKLM:\' +$searchValueName = $searchConfiguration.valueName +$enhancedSearch = Get-RegistryValueOrNull ` + -Path $searchKey ` + -Name $searchValueName + +if ($enhancedSearch -ne $searchConfiguration.valueData) { + $taskName = "Dotfiles-EnhancedSearch-$([guid]::NewGuid().ToString('N'))" + $reg = Join-Path $env:SystemRoot "System32\reg.exe" + $regArguments = 'add "{0}" /v "{1}" /t {2} /d {3} /f' -f @( + $searchConfiguration.keyPath + $searchConfiguration.valueName + $searchConfiguration.valueType + $searchConfiguration.valueData + ) + $action = New-ScheduledTaskAction ` + -Execute $reg ` + -Argument $regArguments + $principal = New-ScheduledTaskPrincipal ` + -UserId "SYSTEM" ` + -LogonType ServiceAccount ` + -RunLevel Highest + $taskDefinition = New-ScheduledTask ` + -Action $action ` + -Principal $principal + $startedAt = Get-Date + + try { + Register-ScheduledTask ` + -TaskName $taskName ` + -InputObject $taskDefinition ` + -Force | Out-Null + + Start-ScheduledTask -TaskName $taskName + + $deadline = (Get-Date).AddSeconds(30) + + do { + Start-Sleep -Milliseconds 200 + $task = Get-ScheduledTask -TaskName $taskName + $taskInfo = Get-ScheduledTaskInfo -TaskName $taskName + $hasRun = $taskInfo.LastRunTime -ge $startedAt.AddSeconds(-1) + } while ( + (Get-Date) -lt $deadline -and + (-not $hasRun -or $task.State -eq "Running") + ) + + if (-not $hasRun -or $task.State -eq "Running") { + throw "Timed out while enabling enhanced file search." + } + + if ($taskInfo.LastTaskResult -ne 0) { + throw "Failed to enable enhanced file search (task result $($taskInfo.LastTaskResult))." + } + } + finally { + if (Get-ScheduledTask -TaskName $taskName -ErrorAction SilentlyContinue) { + Unregister-ScheduledTask -TaskName $taskName -Confirm:$false + } + } +} + +$enhancedSearch = Get-RegistryValueOrNull ` + -Path $searchKey ` + -Name $searchValueName + +if ($enhancedSearch -ne $searchConfiguration.valueData) { + throw "Failed to verify enhanced file search." +} diff --git a/windows/system/privacy/configuration.dsc.yaml b/windows/system/privacy/configuration.dsc.yaml new file mode 100644 index 0000000..5aafce3 --- /dev/null +++ b/windows/system/privacy/configuration.dsc.yaml @@ -0,0 +1,200 @@ +$schema: https://aka.ms/dsc/schemas/v3/bundled/config/document.json + +resources: + - name: Disable advertising ID + type: Microsoft.Windows/Registry + properties: + keyPath: HKCU\Software\Microsoft\Windows\CurrentVersion\AdvertisingInfo + valueName: Enabled + valueData: + DWord: 0 + _exist: true + + - name: Do not share the language list with websites + type: Microsoft.Windows/Registry + properties: + keyPath: HKCU\Control Panel\International\User Profile + valueName: HttpAcceptLanguageOptOut + valueData: + DWord: 1 + _exist: true + + - name: Disable personalized offers + type: Microsoft.Windows/Registry + properties: + keyPath: HKCU\Software\Microsoft\Windows\CurrentVersion\Privacy + valueName: TailoredExperiencesWithDiagnosticDataEnabled + valueData: + DWord: 0 + _exist: true + + - name: Disable tailored experiences by policy + type: Microsoft.Windows/Registry + properties: + keyPath: HKCU\Software\Policies\Microsoft\Windows\CloudContent + valueName: DisableTailoredExperiencesWithDiagnosticData + valueData: + DWord: 1 + _exist: true + + - name: Disable all Windows Spotlight suggestions + type: Microsoft.Windows/Registry + properties: + keyPath: HKCU\Software\Policies\Microsoft\Windows\CloudContent + valueName: DisableWindowsSpotlightFeatures + valueData: + DWord: 1 + _exist: true + + - name: Disable third-party Spotlight suggestions + type: Microsoft.Windows/Registry + properties: + keyPath: HKCU\Software\Policies\Microsoft\Windows\CloudContent + valueName: DisableThirdPartySuggestions + valueData: + DWord: 1 + _exist: true + + - name: Disable suggested content in Settings + type: Microsoft.Windows/Registry + properties: + keyPath: HKCU\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager + valueName: SubscribedContent-338393Enabled + valueData: + DWord: 0 + _exist: true + + - name: Disable Settings suggestions + type: Microsoft.Windows/Registry + properties: + keyPath: HKCU\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager + valueName: SystemPaneSuggestionsEnabled + valueData: + DWord: 0 + _exist: true + + - name: Disable Settings account suggestions + type: Microsoft.Windows/Registry + properties: + keyPath: HKCU\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager + valueName: SubscribedContent-353694Enabled + valueData: + DWord: 0 + _exist: true + + - name: Disable Settings app suggestions + type: Microsoft.Windows/Registry + properties: + keyPath: HKCU\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager + valueName: SubscribedContent-353696Enabled + valueData: + DWord: 0 + _exist: true + + - name: Disable tips about Windows + type: Microsoft.Windows/Registry + properties: + keyPath: HKCU\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager + valueName: SubscribedContent-338389Enabled + valueData: + DWord: 0 + _exist: true + + - name: Disable Windows welcome experience + type: Microsoft.Windows/Registry + properties: + keyPath: HKCU\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager + valueName: SubscribedContent-310093Enabled + valueData: + DWord: 0 + _exist: true + + - name: Disable suggested apps + type: Microsoft.Windows/Registry + properties: + keyPath: HKCU\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager + valueName: SubscribedContent-338388Enabled + valueData: + DWord: 0 + _exist: true + + - name: Disable soft-landing tips + type: Microsoft.Windows/Registry + properties: + keyPath: HKCU\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager + valueName: SoftLandingEnabled + valueData: + DWord: 0 + _exist: true + + - name: Disable automatic suggested app installation + type: Microsoft.Windows/Registry + properties: + keyPath: HKCU\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager + valueName: SilentInstalledAppsEnabled + valueData: + DWord: 0 + _exist: true + + - name: Disable device setup suggestions + type: Microsoft.Windows/Registry + properties: + keyPath: HKCU\Software\Microsoft\Windows\CurrentVersion\UserProfileEngagement + valueName: ScoobeSystemSettingEnabled + valueData: + DWord: 0 + _exist: true + + - name: Disable File Explorer sync-provider promotions + type: Microsoft.Windows/Registry + properties: + keyPath: HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced + valueName: ShowSyncProviderNotifications + valueData: + DWord: 0 + _exist: true + + - name: Disable inking and typing diagnostics + type: Microsoft.Windows/Registry + properties: + keyPath: HKCU\Software\Microsoft\Input\TIPC + valueName: Enabled + valueData: + DWord: 0 + _exist: true + + - name: Set feedback frequency period to never + type: Microsoft.Windows/Registry + properties: + keyPath: HKCU\Software\Microsoft\Siuf\Rules + valueName: PeriodInNanoSeconds + valueData: + DWord: 0 + _exist: true + + - name: Set feedback prompts to never + type: Microsoft.Windows/Registry + properties: + keyPath: HKCU\Software\Microsoft\Siuf\Rules + valueName: NumberOfSIUFInPeriod + valueData: + DWord: 0 + _exist: true + + - name: Disable device search history + type: Microsoft.Windows/Registry + properties: + keyPath: HKCU\Software\Microsoft\Windows\CurrentVersion\SearchSettings + valueName: IsDeviceSearchHistoryEnabled + valueData: + DWord: 0 + _exist: true + + - name: Disable search highlights + type: Microsoft.Windows/Registry + properties: + keyPath: HKCU\Software\Microsoft\Windows\CurrentVersion\SearchSettings + valueName: IsDynamicSearchBoxEnabled + valueData: + DWord: 0 + _exist: true diff --git a/windows/system/privacy/enhanced-search.json b/windows/system/privacy/enhanced-search.json new file mode 100644 index 0000000..4a5a1f3 --- /dev/null +++ b/windows/system/privacy/enhanced-search.json @@ -0,0 +1,6 @@ +{ + "keyPath": "HKLM\\SOFTWARE\\Microsoft\\Windows Search\\Gather\\Windows\\SystemIndex", + "valueName": "EnableFindMyFiles", + "valueType": "REG_DWORD", + "valueData": 1 +} diff --git a/windows/system/privacy/machine.dsc.yaml b/windows/system/privacy/machine.dsc.yaml new file mode 100644 index 0000000..6cf88d0 --- /dev/null +++ b/windows/system/privacy/machine.dsc.yaml @@ -0,0 +1,92 @@ +$schema: https://aka.ms/dsc/schemas/v3/bundled/config/document.json + +resources: + - name: Disable advertising ID by policy + type: Microsoft.Windows/Registry + properties: + keyPath: HKLM\Software\Policies\Microsoft\Windows\AdvertisingInfo + valueName: DisabledByGroupPolicy + valueData: + DWord: 1 + _exist: true + + - name: Disable Windows consumer experiences + type: Microsoft.Windows/Registry + properties: + keyPath: HKLM\Software\Policies\Microsoft\Windows\CloudContent + valueName: DisableWindowsConsumerFeatures + valueData: + DWord: 1 + _exist: true + + - name: Set diagnostic data to the lowest available level + type: Microsoft.Windows/Registry + properties: + keyPath: HKLM\Software\Policies\Microsoft\Windows\DataCollection + valueName: AllowTelemetry + valueData: + DWord: 0 + _exist: true + + - name: Disable feedback notifications + type: Microsoft.Windows/Registry + properties: + keyPath: HKLM\Software\Policies\Microsoft\Windows\DataCollection + valueName: DoNotShowFeedbackNotifications + valueData: + DWord: 1 + _exist: true + + - name: Disable Diagnostic Data Viewer + type: Microsoft.Windows/Registry + properties: + keyPath: HKLM\Software\Policies\Microsoft\Windows\DataCollection + valueName: DisableDiagnosticDataViewer + valueData: + DWord: 1 + _exist: true + + - name: Limit diagnostic log collection + type: Microsoft.Windows/Registry + properties: + keyPath: HKLM\Software\Policies\Microsoft\Windows\DataCollection + valueName: LimitDiagnosticLogCollection + valueData: + DWord: 1 + _exist: true + + - name: Limit diagnostic dump collection + type: Microsoft.Windows/Registry + properties: + keyPath: HKLM\Software\Policies\Microsoft\Windows\DataCollection + valueName: LimitDumpCollection + valueData: + DWord: 1 + _exist: true + + - name: Disable activity feed + type: Microsoft.Windows/Registry + properties: + keyPath: HKLM\Software\Policies\Microsoft\Windows\System + valueName: EnableActivityFeed + valueData: + DWord: 0 + _exist: true + + - name: Disable publishing user activity + type: Microsoft.Windows/Registry + properties: + keyPath: HKLM\Software\Policies\Microsoft\Windows\System + valueName: PublishUserActivities + valueData: + DWord: 0 + _exist: true + + - name: Disable uploading user activity + type: Microsoft.Windows/Registry + properties: + keyPath: HKLM\Software\Policies\Microsoft\Windows\System + valueName: UploadUserActivities + valueData: + DWord: 0 + _exist: true diff --git a/windows/system/start.dsc.yaml b/windows/system/start.dsc.yaml index 39bdcd6..3b82ff3 100644 --- a/windows/system/start.dsc.yaml +++ b/windows/system/start.dsc.yaml @@ -28,11 +28,11 @@ resources: DWord: 0 _exist: true - - name: Show most used apps + - name: Disable app launch tracking type: Microsoft.Windows/Registry properties: keyPath: HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced valueName: Start_TrackProgs valueData: - DWord: 1 + DWord: 0 _exist: true diff --git a/windows/update.ps1 b/windows/update.ps1 index 6f7ddbc..1a76ec3 100644 --- a/windows/update.ps1 +++ b/windows/update.ps1 @@ -9,12 +9,18 @@ try { dsc config set --file .\configuration.dsc.yaml + if ($LASTEXITCODE -ne 0) { + throw "Failed to apply the main DSC configuration." + } + & .\applications\chatgpt\apply.ps1 & .\applications\git\apply.ps1 + & .\applications\parsec\apply.ps1 & .\applications\vscode\apply.ps1 & .\system\advanced-settings\apply.ps1 & .\system\lock-screen\apply.ps1 & .\system\power\apply.ps1 + & .\system\privacy\apply.ps1 & .\system\wallpaper\apply.ps1 } finally {