This commit is contained in:
2026-07-29 09:52:32 +09:00
parent e474c38aff
commit e23e0058bd
10 changed files with 669 additions and 14 deletions
+187
View File
@@ -0,0 +1,187 @@
[CmdletBinding()]
param(
[string] $DscPath = (Get-Command dsc -ErrorAction Stop).Source,
[string] $ResultPath
)
$ErrorActionPreference = "Stop"
trap {
if ($ResultPath) {
$_ | Out-String | Set-Content `
-LiteralPath $ResultPath `
-Encoding UTF8
}
break
}
function Test-Administrator {
$identity = [Security.Principal.WindowsIdentity]::GetCurrent()
$principal = [Security.Principal.WindowsPrincipal]::new($identity)
return $principal.IsInRole(
[Security.Principal.WindowsBuiltInRole]::Administrator
)
}
function Get-RegistryValueOrNull {
param(
[Parameter(Mandatory)]
[string] $Path,
[Parameter(Mandatory)]
[string] $Name
)
if (-not (Test-Path -LiteralPath $Path)) {
return $null
}
$key = Get-Item -LiteralPath $Path
return $key.GetValue(
$Name,
$null,
[Microsoft.Win32.RegistryValueOptions]::DoNotExpandEnvironmentNames
)
}
if (-not (Test-Administrator)) {
$powershell = (Get-Process -Id $PID).Path
$resultPath = Join-Path `
$env:TEMP `
"dotfiles-privacy-$([guid]::NewGuid().ToString('N')).log"
$arguments = @(
"-NoProfile"
"-ExecutionPolicy"
"Bypass"
"-File"
('"{0}"' -f $PSCommandPath)
"-DscPath"
('"{0}"' -f $DscPath)
"-ResultPath"
('"{0}"' -f $resultPath)
)
try {
$process = Start-Process `
-FilePath $powershell `
-ArgumentList $arguments `
-Verb RunAs `
-Wait `
-PassThru
if ($process.ExitCode -ne 0) {
$details = if (Test-Path -LiteralPath $resultPath) {
Get-Content -Raw -LiteralPath $resultPath
}
else {
"No detailed error was returned by the elevated process."
}
throw "Elevated privacy settings failed with exit code $($process.ExitCode).`n$details"
}
}
finally {
Remove-Item `
-LiteralPath $resultPath `
-Force `
-ErrorAction SilentlyContinue
}
return
}
$configurations = @(
@{
Name = "user privacy settings"
Path = Join-Path $PSScriptRoot "configuration.dsc.yaml"
}
@{
Name = "machine-wide privacy settings"
Path = Join-Path $PSScriptRoot "machine.dsc.yaml"
}
)
foreach ($configuration in $configurations) {
& $DscPath config set --file $configuration.Path
if ($LASTEXITCODE -ne 0) {
throw "Failed to apply $($configuration.Name)."
}
}
$searchConfiguration = Get-Content `
-Raw `
-LiteralPath (Join-Path $PSScriptRoot "enhanced-search.json") |
ConvertFrom-Json
$searchKey = $searchConfiguration.keyPath -replace '^HKLM\\', 'HKLM:\'
$searchValueName = $searchConfiguration.valueName
$enhancedSearch = Get-RegistryValueOrNull `
-Path $searchKey `
-Name $searchValueName
if ($enhancedSearch -ne $searchConfiguration.valueData) {
$taskName = "Dotfiles-EnhancedSearch-$([guid]::NewGuid().ToString('N'))"
$reg = Join-Path $env:SystemRoot "System32\reg.exe"
$regArguments = 'add "{0}" /v "{1}" /t {2} /d {3} /f' -f @(
$searchConfiguration.keyPath
$searchConfiguration.valueName
$searchConfiguration.valueType
$searchConfiguration.valueData
)
$action = New-ScheduledTaskAction `
-Execute $reg `
-Argument $regArguments
$principal = New-ScheduledTaskPrincipal `
-UserId "SYSTEM" `
-LogonType ServiceAccount `
-RunLevel Highest
$taskDefinition = New-ScheduledTask `
-Action $action `
-Principal $principal
$startedAt = Get-Date
try {
Register-ScheduledTask `
-TaskName $taskName `
-InputObject $taskDefinition `
-Force | Out-Null
Start-ScheduledTask -TaskName $taskName
$deadline = (Get-Date).AddSeconds(30)
do {
Start-Sleep -Milliseconds 200
$task = Get-ScheduledTask -TaskName $taskName
$taskInfo = Get-ScheduledTaskInfo -TaskName $taskName
$hasRun = $taskInfo.LastRunTime -ge $startedAt.AddSeconds(-1)
} while (
(Get-Date) -lt $deadline -and
(-not $hasRun -or $task.State -eq "Running")
)
if (-not $hasRun -or $task.State -eq "Running") {
throw "Timed out while enabling enhanced file search."
}
if ($taskInfo.LastTaskResult -ne 0) {
throw "Failed to enable enhanced file search (task result $($taskInfo.LastTaskResult))."
}
}
finally {
if (Get-ScheduledTask -TaskName $taskName -ErrorAction SilentlyContinue) {
Unregister-ScheduledTask -TaskName $taskName -Confirm:$false
}
}
}
$enhancedSearch = Get-RegistryValueOrNull `
-Path $searchKey `
-Name $searchValueName
if ($enhancedSearch -ne $searchConfiguration.valueData) {
throw "Failed to verify enhanced file search."
}
@@ -0,0 +1,200 @@
$schema: https://aka.ms/dsc/schemas/v3/bundled/config/document.json
resources:
- name: Disable advertising ID
type: Microsoft.Windows/Registry
properties:
keyPath: HKCU\Software\Microsoft\Windows\CurrentVersion\AdvertisingInfo
valueName: Enabled
valueData:
DWord: 0
_exist: true
- name: Do not share the language list with websites
type: Microsoft.Windows/Registry
properties:
keyPath: HKCU\Control Panel\International\User Profile
valueName: HttpAcceptLanguageOptOut
valueData:
DWord: 1
_exist: true
- name: Disable personalized offers
type: Microsoft.Windows/Registry
properties:
keyPath: HKCU\Software\Microsoft\Windows\CurrentVersion\Privacy
valueName: TailoredExperiencesWithDiagnosticDataEnabled
valueData:
DWord: 0
_exist: true
- name: Disable tailored experiences by policy
type: Microsoft.Windows/Registry
properties:
keyPath: HKCU\Software\Policies\Microsoft\Windows\CloudContent
valueName: DisableTailoredExperiencesWithDiagnosticData
valueData:
DWord: 1
_exist: true
- name: Disable all Windows Spotlight suggestions
type: Microsoft.Windows/Registry
properties:
keyPath: HKCU\Software\Policies\Microsoft\Windows\CloudContent
valueName: DisableWindowsSpotlightFeatures
valueData:
DWord: 1
_exist: true
- name: Disable third-party Spotlight suggestions
type: Microsoft.Windows/Registry
properties:
keyPath: HKCU\Software\Policies\Microsoft\Windows\CloudContent
valueName: DisableThirdPartySuggestions
valueData:
DWord: 1
_exist: true
- name: Disable suggested content in Settings
type: Microsoft.Windows/Registry
properties:
keyPath: HKCU\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager
valueName: SubscribedContent-338393Enabled
valueData:
DWord: 0
_exist: true
- name: Disable Settings suggestions
type: Microsoft.Windows/Registry
properties:
keyPath: HKCU\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager
valueName: SystemPaneSuggestionsEnabled
valueData:
DWord: 0
_exist: true
- name: Disable Settings account suggestions
type: Microsoft.Windows/Registry
properties:
keyPath: HKCU\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager
valueName: SubscribedContent-353694Enabled
valueData:
DWord: 0
_exist: true
- name: Disable Settings app suggestions
type: Microsoft.Windows/Registry
properties:
keyPath: HKCU\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager
valueName: SubscribedContent-353696Enabled
valueData:
DWord: 0
_exist: true
- name: Disable tips about Windows
type: Microsoft.Windows/Registry
properties:
keyPath: HKCU\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager
valueName: SubscribedContent-338389Enabled
valueData:
DWord: 0
_exist: true
- name: Disable Windows welcome experience
type: Microsoft.Windows/Registry
properties:
keyPath: HKCU\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager
valueName: SubscribedContent-310093Enabled
valueData:
DWord: 0
_exist: true
- name: Disable suggested apps
type: Microsoft.Windows/Registry
properties:
keyPath: HKCU\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager
valueName: SubscribedContent-338388Enabled
valueData:
DWord: 0
_exist: true
- name: Disable soft-landing tips
type: Microsoft.Windows/Registry
properties:
keyPath: HKCU\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager
valueName: SoftLandingEnabled
valueData:
DWord: 0
_exist: true
- name: Disable automatic suggested app installation
type: Microsoft.Windows/Registry
properties:
keyPath: HKCU\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager
valueName: SilentInstalledAppsEnabled
valueData:
DWord: 0
_exist: true
- name: Disable device setup suggestions
type: Microsoft.Windows/Registry
properties:
keyPath: HKCU\Software\Microsoft\Windows\CurrentVersion\UserProfileEngagement
valueName: ScoobeSystemSettingEnabled
valueData:
DWord: 0
_exist: true
- name: Disable File Explorer sync-provider promotions
type: Microsoft.Windows/Registry
properties:
keyPath: HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced
valueName: ShowSyncProviderNotifications
valueData:
DWord: 0
_exist: true
- name: Disable inking and typing diagnostics
type: Microsoft.Windows/Registry
properties:
keyPath: HKCU\Software\Microsoft\Input\TIPC
valueName: Enabled
valueData:
DWord: 0
_exist: true
- name: Set feedback frequency period to never
type: Microsoft.Windows/Registry
properties:
keyPath: HKCU\Software\Microsoft\Siuf\Rules
valueName: PeriodInNanoSeconds
valueData:
DWord: 0
_exist: true
- name: Set feedback prompts to never
type: Microsoft.Windows/Registry
properties:
keyPath: HKCU\Software\Microsoft\Siuf\Rules
valueName: NumberOfSIUFInPeriod
valueData:
DWord: 0
_exist: true
- name: Disable device search history
type: Microsoft.Windows/Registry
properties:
keyPath: HKCU\Software\Microsoft\Windows\CurrentVersion\SearchSettings
valueName: IsDeviceSearchHistoryEnabled
valueData:
DWord: 0
_exist: true
- name: Disable search highlights
type: Microsoft.Windows/Registry
properties:
keyPath: HKCU\Software\Microsoft\Windows\CurrentVersion\SearchSettings
valueName: IsDynamicSearchBoxEnabled
valueData:
DWord: 0
_exist: true
@@ -0,0 +1,6 @@
{
"keyPath": "HKLM\\SOFTWARE\\Microsoft\\Windows Search\\Gather\\Windows\\SystemIndex",
"valueName": "EnableFindMyFiles",
"valueType": "REG_DWORD",
"valueData": 1
}
+92
View File
@@ -0,0 +1,92 @@
$schema: https://aka.ms/dsc/schemas/v3/bundled/config/document.json
resources:
- name: Disable advertising ID by policy
type: Microsoft.Windows/Registry
properties:
keyPath: HKLM\Software\Policies\Microsoft\Windows\AdvertisingInfo
valueName: DisabledByGroupPolicy
valueData:
DWord: 1
_exist: true
- name: Disable Windows consumer experiences
type: Microsoft.Windows/Registry
properties:
keyPath: HKLM\Software\Policies\Microsoft\Windows\CloudContent
valueName: DisableWindowsConsumerFeatures
valueData:
DWord: 1
_exist: true
- name: Set diagnostic data to the lowest available level
type: Microsoft.Windows/Registry
properties:
keyPath: HKLM\Software\Policies\Microsoft\Windows\DataCollection
valueName: AllowTelemetry
valueData:
DWord: 0
_exist: true
- name: Disable feedback notifications
type: Microsoft.Windows/Registry
properties:
keyPath: HKLM\Software\Policies\Microsoft\Windows\DataCollection
valueName: DoNotShowFeedbackNotifications
valueData:
DWord: 1
_exist: true
- name: Disable Diagnostic Data Viewer
type: Microsoft.Windows/Registry
properties:
keyPath: HKLM\Software\Policies\Microsoft\Windows\DataCollection
valueName: DisableDiagnosticDataViewer
valueData:
DWord: 1
_exist: true
- name: Limit diagnostic log collection
type: Microsoft.Windows/Registry
properties:
keyPath: HKLM\Software\Policies\Microsoft\Windows\DataCollection
valueName: LimitDiagnosticLogCollection
valueData:
DWord: 1
_exist: true
- name: Limit diagnostic dump collection
type: Microsoft.Windows/Registry
properties:
keyPath: HKLM\Software\Policies\Microsoft\Windows\DataCollection
valueName: LimitDumpCollection
valueData:
DWord: 1
_exist: true
- name: Disable activity feed
type: Microsoft.Windows/Registry
properties:
keyPath: HKLM\Software\Policies\Microsoft\Windows\System
valueName: EnableActivityFeed
valueData:
DWord: 0
_exist: true
- name: Disable publishing user activity
type: Microsoft.Windows/Registry
properties:
keyPath: HKLM\Software\Policies\Microsoft\Windows\System
valueName: PublishUserActivities
valueData:
DWord: 0
_exist: true
- name: Disable uploading user activity
type: Microsoft.Windows/Registry
properties:
keyPath: HKLM\Software\Policies\Microsoft\Windows\System
valueName: UploadUserActivities
valueData:
DWord: 0
_exist: true