mirror of
https://github.com/moons-14/dotfiles.git
synced 2026-10-06 02:18:12 +09:00
privact
This commit is contained in:
+69
-5
@@ -39,6 +39,11 @@ windows/
|
|||||||
│ ├── device-usage.dsc.yaml
|
│ ├── device-usage.dsc.yaml
|
||||||
│ ├── explorer.dsc.yaml
|
│ ├── explorer.dsc.yaml
|
||||||
│ ├── ime.dsc.yaml
|
│ ├── ime.dsc.yaml
|
||||||
|
│ ├── privacy/
|
||||||
|
│ │ ├── configuration.dsc.yaml
|
||||||
|
│ │ ├── machine.dsc.yaml
|
||||||
|
│ │ ├── enhanced-search.json
|
||||||
|
│ │ └── apply.ps1
|
||||||
│ ├── advanced-settings/
|
│ ├── advanced-settings/
|
||||||
│ │ ├── configuration.dsc.yaml
|
│ │ ├── configuration.dsc.yaml
|
||||||
│ │ └── apply.ps1
|
│ │ └── apply.ps1
|
||||||
@@ -57,6 +62,10 @@ windows/
|
|||||||
│ ├── apply.ps1
|
│ ├── apply.ps1
|
||||||
│ └── gitconfig
|
│ └── gitconfig
|
||||||
│
|
│
|
||||||
|
├── parsec/
|
||||||
|
│ ├── apply.ps1
|
||||||
|
│ └── installer.json
|
||||||
|
│
|
||||||
└── vscode/
|
└── vscode/
|
||||||
├── apply.ps1
|
├── apply.ps1
|
||||||
├── settings.json
|
├── settings.json
|
||||||
@@ -127,16 +136,19 @@ dsc config set --file .\configuration.dsc.yaml
|
|||||||
|
|
||||||
& .\applications\chatgpt\apply.ps1
|
& .\applications\chatgpt\apply.ps1
|
||||||
& .\applications\git\apply.ps1
|
& .\applications\git\apply.ps1
|
||||||
|
& .\applications\parsec\apply.ps1
|
||||||
& .\applications\vscode\apply.ps1
|
& .\applications\vscode\apply.ps1
|
||||||
& .\system\advanced-settings\apply.ps1
|
& .\system\advanced-settings\apply.ps1
|
||||||
& .\system\lock-screen\apply.ps1
|
& .\system\lock-screen\apply.ps1
|
||||||
& .\system\power\apply.ps1
|
& .\system\power\apply.ps1
|
||||||
|
& .\system\privacy\apply.ps1
|
||||||
& .\system\wallpaper\apply.ps1
|
& .\system\wallpaper\apply.ps1
|
||||||
```
|
```
|
||||||
|
|
||||||
The specialized scripts own the details of their own configuration. Only the
|
The specialized scripts own the details of their own configuration. The
|
||||||
advanced-settings script requests elevation, for the protected Explorer policy
|
advanced-settings and privacy scripts request elevation for protected policies
|
||||||
and machine-wide long-path setting; Scoop, DSC user settings, and application
|
and machine-wide settings. The Parsec installer also requests elevation for its
|
||||||
|
machine-wide installation; Scoop, other DSC user settings, and application
|
||||||
configuration stay in the normal user process.
|
configuration stay in the normal user process.
|
||||||
|
|
||||||
## Packages
|
## Packages
|
||||||
@@ -185,6 +197,17 @@ ChatGPT Classic (`9NT1R1C2HH7J`) is intentionally not installed.
|
|||||||
WinGet's `APPINSTALLER_CLI_ERROR_UPDATE_NOT_APPLICABLE` result is treated as
|
WinGet's `APPINSTALLER_CLI_ERROR_UPDATE_NOT_APPLICABLE` result is treated as
|
||||||
success because it means the installed ChatGPT version is already current.
|
success because it means the installed ChatGPT version is already current.
|
||||||
|
|
||||||
|
### Parsec
|
||||||
|
|
||||||
|
Parsec is installed by `applications/parsec/apply.ps1` instead of the WinGet
|
||||||
|
DSC document. Parsec publishes mutable installer content at a stable URL, which
|
||||||
|
can temporarily leave the WinGet manifest with a stale SHA256 and make the
|
||||||
|
entire DSC run fail. The application-local declaration pins the verified file
|
||||||
|
version, SHA256, and Authenticode signer thumbprint. The script downloads only
|
||||||
|
when Parsec is absent, verifies all three values, then requests elevation and
|
||||||
|
runs the official installer for all users. It never bypasses WinGet hash
|
||||||
|
verification.
|
||||||
|
|
||||||
7-Zip is intentionally installed with its normal Windows installer through
|
7-Zip is intentionally installed with its normal Windows installer through
|
||||||
WinGet rather than as a portable Scoop package, because the normal installer
|
WinGet rather than as a portable Scoop package, because the normal installer
|
||||||
provides Explorer shell integration.
|
provides Explorer shell integration.
|
||||||
@@ -212,7 +235,7 @@ current image and only calls the API when the image differs.
|
|||||||
- recently added apps: on
|
- recently added apps: on
|
||||||
- recommended and recent files: off
|
- recommended and recent files: off
|
||||||
- recommendations for tips, shortcuts, and new apps: off
|
- recommendations for tips, shortcuts, and new apps: off
|
||||||
- most used apps: on
|
- app-launch tracking and most-used app personalization: off
|
||||||
|
|
||||||
### Device usage
|
### Device usage
|
||||||
|
|
||||||
@@ -220,6 +243,43 @@ current image and only calls the API when the image differs.
|
|||||||
for Development, Gaming, Family, Creativity, School, Entertainment, and
|
for Development, Gaming, Family, Creativity, School, Entertainment, and
|
||||||
Business.
|
Business.
|
||||||
|
|
||||||
|
### Privacy, diagnostics, feedback, and search
|
||||||
|
|
||||||
|
`system/privacy/configuration.dsc.yaml` configures user-scoped preferences:
|
||||||
|
|
||||||
|
- advertising ID: off
|
||||||
|
- website access to the language list: off
|
||||||
|
- personalized offers and tailored experiences: off
|
||||||
|
- Windows Spotlight, third-party content, Settings suggestions, tips, welcome
|
||||||
|
experiences, device-setup suggestions, and suggested app installation: off
|
||||||
|
- File Explorer sync-provider promotions: off
|
||||||
|
- inking and typing diagnostics: off
|
||||||
|
- feedback frequency and prompts: never
|
||||||
|
- device search history and search highlights: off
|
||||||
|
|
||||||
|
`system/privacy/apply.ps1` requests elevation and applies both the user-scoped
|
||||||
|
configuration above and `system/privacy/machine.dsc.yaml`, which configures:
|
||||||
|
|
||||||
|
- advertising ID and Windows consumer experiences: off by policy
|
||||||
|
- diagnostic data: the lowest level supported by the installed Windows edition
|
||||||
|
- feedback notifications and Diagnostic Data Viewer: off
|
||||||
|
- diagnostic log and dump collection: limited
|
||||||
|
- publishing and uploading activity history: off
|
||||||
|
|
||||||
|
The protected Windows Search key doesn't grant write access to administrators,
|
||||||
|
so `apply.ps1` applies the desired value from the declarative
|
||||||
|
`enhanced-search.json` as `SYSTEM` to set Find my files to Enhanced. It uses a
|
||||||
|
uniquely named one-shot Scheduled Task and always unregisters it immediately
|
||||||
|
afterward. It doesn't change the key's owner or access-control list and doesn't
|
||||||
|
leave a persistent task behind.
|
||||||
|
|
||||||
|
Windows Pro still sends required diagnostic data even when `AllowTelemetry` is
|
||||||
|
set to the Security value (`0`); only editions that support the Security level
|
||||||
|
honor diagnostic data completely off. The configuration nevertheless disables
|
||||||
|
optional diagnostic data and every related user-facing toggle. Enhanced search
|
||||||
|
indexes the full user profile, so its initial indexing can temporarily use more
|
||||||
|
CPU, battery, and storage.
|
||||||
|
|
||||||
### Taskbar
|
### Taskbar
|
||||||
|
|
||||||
`system/taskbar.dsc.yaml` configures:
|
`system/taskbar.dsc.yaml` configures:
|
||||||
@@ -434,10 +494,14 @@ system/start.dsc.yaml
|
|||||||
system/device-usage.dsc.yaml
|
system/device-usage.dsc.yaml
|
||||||
system/explorer.dsc.yaml
|
system/explorer.dsc.yaml
|
||||||
system/ime.dsc.yaml
|
system/ime.dsc.yaml
|
||||||
|
system/privacy/configuration.dsc.yaml
|
||||||
|
system/privacy/machine.dsc.yaml
|
||||||
system/advanced-settings/configuration.dsc.yaml
|
system/advanced-settings/configuration.dsc.yaml
|
||||||
```
|
```
|
||||||
|
|
||||||
When adding a new DSC document, include it from `configuration.dsc.yaml`.
|
Include ordinary user-scoped DSC documents from the root
|
||||||
|
`configuration.dsc.yaml`. A protected or machine-wide document may instead be
|
||||||
|
applied by its feature-local elevated script, as the privacy configuration is.
|
||||||
|
|
||||||
If a system feature cannot be expressed reliably with DSC and genuinely needs
|
If a system feature cannot be expressed reliably with DSC and genuinely needs
|
||||||
procedural setup, give that feature its own directory, following the wallpaper
|
procedural setup, give that feature its own directory, following the wallpaper
|
||||||
|
|||||||
@@ -0,0 +1,94 @@
|
|||||||
|
$ErrorActionPreference = "Stop"
|
||||||
|
|
||||||
|
function Test-ParsecInstalled {
|
||||||
|
$candidatePaths = @(
|
||||||
|
(Join-Path $env:ProgramFiles "Parsec\parsecd.exe")
|
||||||
|
(Join-Path $env:LOCALAPPDATA "Parsec\parsecd.exe")
|
||||||
|
(Join-Path $env:APPDATA "Parsec\parsecd.exe")
|
||||||
|
)
|
||||||
|
|
||||||
|
if (${env:ProgramFiles(x86)}) {
|
||||||
|
$candidatePaths += Join-Path ${env:ProgramFiles(x86)} "Parsec\parsecd.exe"
|
||||||
|
}
|
||||||
|
|
||||||
|
if ($candidatePaths | Where-Object { Test-Path -LiteralPath $_ }) {
|
||||||
|
return $true
|
||||||
|
}
|
||||||
|
|
||||||
|
$uninstallRoots = @(
|
||||||
|
"HKLM:\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\*"
|
||||||
|
"HKLM:\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\*"
|
||||||
|
"HKCU:\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\*"
|
||||||
|
)
|
||||||
|
|
||||||
|
foreach ($root in $uninstallRoots) {
|
||||||
|
$installedPackage = Get-ItemProperty -Path $root -ErrorAction SilentlyContinue |
|
||||||
|
Where-Object { $_.DisplayName -like "Parsec*" } |
|
||||||
|
Select-Object -First 1
|
||||||
|
|
||||||
|
if ($installedPackage) {
|
||||||
|
return $true
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
return $false
|
||||||
|
}
|
||||||
|
|
||||||
|
if (Test-ParsecInstalled) {
|
||||||
|
Write-Host "Parsec is already installed."
|
||||||
|
return
|
||||||
|
}
|
||||||
|
|
||||||
|
$declarationPath = Join-Path $PSScriptRoot "installer.json"
|
||||||
|
$declaration = Get-Content -LiteralPath $declarationPath -Raw | ConvertFrom-Json
|
||||||
|
$installerPath = Join-Path ([System.IO.Path]::GetTempPath()) (
|
||||||
|
"parsec-{0}.exe" -f [guid]::NewGuid().ToString("N")
|
||||||
|
)
|
||||||
|
|
||||||
|
try {
|
||||||
|
Write-Host "Downloading the declared Parsec installer..."
|
||||||
|
Invoke-WebRequest -Uri $declaration.url -OutFile $installerPath -UseBasicParsing
|
||||||
|
|
||||||
|
$actualHash = (Get-FileHash -LiteralPath $installerPath -Algorithm SHA256).Hash
|
||||||
|
if ($actualHash -ne $declaration.sha256) {
|
||||||
|
throw "Parsec installer SHA256 mismatch. Expected $($declaration.sha256), got $actualHash."
|
||||||
|
}
|
||||||
|
|
||||||
|
$version = (Get-Item -LiteralPath $installerPath).VersionInfo.FileVersion
|
||||||
|
if ($version -ne $declaration.version) {
|
||||||
|
throw "Parsec installer version mismatch. Expected $($declaration.version), got $version."
|
||||||
|
}
|
||||||
|
|
||||||
|
$signature = Get-AuthenticodeSignature -LiteralPath $installerPath
|
||||||
|
if ($signature.Status -ne [System.Management.Automation.SignatureStatus]::Valid) {
|
||||||
|
throw "Parsec installer signature is not valid: $($signature.StatusMessage)"
|
||||||
|
}
|
||||||
|
|
||||||
|
if ($signature.SignerCertificate.Subject -ne $declaration.signerSubject) {
|
||||||
|
throw "Parsec installer signer subject does not match the declaration."
|
||||||
|
}
|
||||||
|
|
||||||
|
if ($signature.SignerCertificate.Thumbprint -ne $declaration.signerThumbprint) {
|
||||||
|
throw "Parsec installer signer thumbprint does not match the declaration."
|
||||||
|
}
|
||||||
|
|
||||||
|
Write-Host "Installing verified Parsec $version for all users..."
|
||||||
|
$process = Start-Process -FilePath $installerPath `
|
||||||
|
-ArgumentList $declaration.silentArguments `
|
||||||
|
-Verb RunAs `
|
||||||
|
-Wait `
|
||||||
|
-PassThru
|
||||||
|
|
||||||
|
if ($process.ExitCode -notin @(0, 3010)) {
|
||||||
|
throw "Parsec installer failed with exit code $($process.ExitCode)."
|
||||||
|
}
|
||||||
|
|
||||||
|
if (-not (Test-ParsecInstalled)) {
|
||||||
|
throw "Parsec installer completed, but the installation could not be verified."
|
||||||
|
}
|
||||||
|
|
||||||
|
Write-Host "Parsec installation is present and verified."
|
||||||
|
}
|
||||||
|
finally {
|
||||||
|
Remove-Item -LiteralPath $installerPath -Force -ErrorAction SilentlyContinue
|
||||||
|
}
|
||||||
@@ -0,0 +1,13 @@
|
|||||||
|
{
|
||||||
|
"version": "150.104.1.0",
|
||||||
|
"url": "https://builds.parsec.app/package/parsec-windows.exe",
|
||||||
|
"sha256": "B8A9CD519010666DEF0EF6E119EB42B33B5B811216F34E4F6C8E2E25AC290FBC",
|
||||||
|
"signerSubject": "CN=Unity Technologies SF, O=Unity Technologies SF, L=San Francisco, S=California, C=US",
|
||||||
|
"signerThumbprint": "F83EAE671EDFDE1E819B41FF6F6A2ED611A651DF",
|
||||||
|
"silentArguments": [
|
||||||
|
"/silent",
|
||||||
|
"/norun",
|
||||||
|
"/nocleanuser",
|
||||||
|
"/allusers"
|
||||||
|
]
|
||||||
|
}
|
||||||
@@ -29,13 +29,6 @@ resources:
|
|||||||
source: winget
|
source: winget
|
||||||
useLatest: true
|
useLatest: true
|
||||||
|
|
||||||
- name: Parsec
|
|
||||||
type: Microsoft.WinGet/Package
|
|
||||||
properties:
|
|
||||||
id: Parsec.Parsec
|
|
||||||
source: winget
|
|
||||||
useLatest: true
|
|
||||||
|
|
||||||
- name: 7-Zip
|
- name: 7-Zip
|
||||||
type: Microsoft.WinGet/Package
|
type: Microsoft.WinGet/Package
|
||||||
properties:
|
properties:
|
||||||
|
|||||||
@@ -0,0 +1,187 @@
|
|||||||
|
[CmdletBinding()]
|
||||||
|
param(
|
||||||
|
[string] $DscPath = (Get-Command dsc -ErrorAction Stop).Source,
|
||||||
|
[string] $ResultPath
|
||||||
|
)
|
||||||
|
|
||||||
|
$ErrorActionPreference = "Stop"
|
||||||
|
|
||||||
|
trap {
|
||||||
|
if ($ResultPath) {
|
||||||
|
$_ | Out-String | Set-Content `
|
||||||
|
-LiteralPath $ResultPath `
|
||||||
|
-Encoding UTF8
|
||||||
|
}
|
||||||
|
|
||||||
|
break
|
||||||
|
}
|
||||||
|
|
||||||
|
function Test-Administrator {
|
||||||
|
$identity = [Security.Principal.WindowsIdentity]::GetCurrent()
|
||||||
|
$principal = [Security.Principal.WindowsPrincipal]::new($identity)
|
||||||
|
|
||||||
|
return $principal.IsInRole(
|
||||||
|
[Security.Principal.WindowsBuiltInRole]::Administrator
|
||||||
|
)
|
||||||
|
}
|
||||||
|
|
||||||
|
function Get-RegistryValueOrNull {
|
||||||
|
param(
|
||||||
|
[Parameter(Mandatory)]
|
||||||
|
[string] $Path,
|
||||||
|
|
||||||
|
[Parameter(Mandatory)]
|
||||||
|
[string] $Name
|
||||||
|
)
|
||||||
|
|
||||||
|
if (-not (Test-Path -LiteralPath $Path)) {
|
||||||
|
return $null
|
||||||
|
}
|
||||||
|
|
||||||
|
$key = Get-Item -LiteralPath $Path
|
||||||
|
|
||||||
|
return $key.GetValue(
|
||||||
|
$Name,
|
||||||
|
$null,
|
||||||
|
[Microsoft.Win32.RegistryValueOptions]::DoNotExpandEnvironmentNames
|
||||||
|
)
|
||||||
|
}
|
||||||
|
|
||||||
|
if (-not (Test-Administrator)) {
|
||||||
|
$powershell = (Get-Process -Id $PID).Path
|
||||||
|
$resultPath = Join-Path `
|
||||||
|
$env:TEMP `
|
||||||
|
"dotfiles-privacy-$([guid]::NewGuid().ToString('N')).log"
|
||||||
|
$arguments = @(
|
||||||
|
"-NoProfile"
|
||||||
|
"-ExecutionPolicy"
|
||||||
|
"Bypass"
|
||||||
|
"-File"
|
||||||
|
('"{0}"' -f $PSCommandPath)
|
||||||
|
"-DscPath"
|
||||||
|
('"{0}"' -f $DscPath)
|
||||||
|
"-ResultPath"
|
||||||
|
('"{0}"' -f $resultPath)
|
||||||
|
)
|
||||||
|
|
||||||
|
try {
|
||||||
|
$process = Start-Process `
|
||||||
|
-FilePath $powershell `
|
||||||
|
-ArgumentList $arguments `
|
||||||
|
-Verb RunAs `
|
||||||
|
-Wait `
|
||||||
|
-PassThru
|
||||||
|
|
||||||
|
if ($process.ExitCode -ne 0) {
|
||||||
|
$details = if (Test-Path -LiteralPath $resultPath) {
|
||||||
|
Get-Content -Raw -LiteralPath $resultPath
|
||||||
|
}
|
||||||
|
else {
|
||||||
|
"No detailed error was returned by the elevated process."
|
||||||
|
}
|
||||||
|
|
||||||
|
throw "Elevated privacy settings failed with exit code $($process.ExitCode).`n$details"
|
||||||
|
}
|
||||||
|
}
|
||||||
|
finally {
|
||||||
|
Remove-Item `
|
||||||
|
-LiteralPath $resultPath `
|
||||||
|
-Force `
|
||||||
|
-ErrorAction SilentlyContinue
|
||||||
|
}
|
||||||
|
|
||||||
|
return
|
||||||
|
}
|
||||||
|
|
||||||
|
$configurations = @(
|
||||||
|
@{
|
||||||
|
Name = "user privacy settings"
|
||||||
|
Path = Join-Path $PSScriptRoot "configuration.dsc.yaml"
|
||||||
|
}
|
||||||
|
@{
|
||||||
|
Name = "machine-wide privacy settings"
|
||||||
|
Path = Join-Path $PSScriptRoot "machine.dsc.yaml"
|
||||||
|
}
|
||||||
|
)
|
||||||
|
|
||||||
|
foreach ($configuration in $configurations) {
|
||||||
|
& $DscPath config set --file $configuration.Path
|
||||||
|
|
||||||
|
if ($LASTEXITCODE -ne 0) {
|
||||||
|
throw "Failed to apply $($configuration.Name)."
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
$searchConfiguration = Get-Content `
|
||||||
|
-Raw `
|
||||||
|
-LiteralPath (Join-Path $PSScriptRoot "enhanced-search.json") |
|
||||||
|
ConvertFrom-Json
|
||||||
|
$searchKey = $searchConfiguration.keyPath -replace '^HKLM\\', 'HKLM:\'
|
||||||
|
$searchValueName = $searchConfiguration.valueName
|
||||||
|
$enhancedSearch = Get-RegistryValueOrNull `
|
||||||
|
-Path $searchKey `
|
||||||
|
-Name $searchValueName
|
||||||
|
|
||||||
|
if ($enhancedSearch -ne $searchConfiguration.valueData) {
|
||||||
|
$taskName = "Dotfiles-EnhancedSearch-$([guid]::NewGuid().ToString('N'))"
|
||||||
|
$reg = Join-Path $env:SystemRoot "System32\reg.exe"
|
||||||
|
$regArguments = 'add "{0}" /v "{1}" /t {2} /d {3} /f' -f @(
|
||||||
|
$searchConfiguration.keyPath
|
||||||
|
$searchConfiguration.valueName
|
||||||
|
$searchConfiguration.valueType
|
||||||
|
$searchConfiguration.valueData
|
||||||
|
)
|
||||||
|
$action = New-ScheduledTaskAction `
|
||||||
|
-Execute $reg `
|
||||||
|
-Argument $regArguments
|
||||||
|
$principal = New-ScheduledTaskPrincipal `
|
||||||
|
-UserId "SYSTEM" `
|
||||||
|
-LogonType ServiceAccount `
|
||||||
|
-RunLevel Highest
|
||||||
|
$taskDefinition = New-ScheduledTask `
|
||||||
|
-Action $action `
|
||||||
|
-Principal $principal
|
||||||
|
$startedAt = Get-Date
|
||||||
|
|
||||||
|
try {
|
||||||
|
Register-ScheduledTask `
|
||||||
|
-TaskName $taskName `
|
||||||
|
-InputObject $taskDefinition `
|
||||||
|
-Force | Out-Null
|
||||||
|
|
||||||
|
Start-ScheduledTask -TaskName $taskName
|
||||||
|
|
||||||
|
$deadline = (Get-Date).AddSeconds(30)
|
||||||
|
|
||||||
|
do {
|
||||||
|
Start-Sleep -Milliseconds 200
|
||||||
|
$task = Get-ScheduledTask -TaskName $taskName
|
||||||
|
$taskInfo = Get-ScheduledTaskInfo -TaskName $taskName
|
||||||
|
$hasRun = $taskInfo.LastRunTime -ge $startedAt.AddSeconds(-1)
|
||||||
|
} while (
|
||||||
|
(Get-Date) -lt $deadline -and
|
||||||
|
(-not $hasRun -or $task.State -eq "Running")
|
||||||
|
)
|
||||||
|
|
||||||
|
if (-not $hasRun -or $task.State -eq "Running") {
|
||||||
|
throw "Timed out while enabling enhanced file search."
|
||||||
|
}
|
||||||
|
|
||||||
|
if ($taskInfo.LastTaskResult -ne 0) {
|
||||||
|
throw "Failed to enable enhanced file search (task result $($taskInfo.LastTaskResult))."
|
||||||
|
}
|
||||||
|
}
|
||||||
|
finally {
|
||||||
|
if (Get-ScheduledTask -TaskName $taskName -ErrorAction SilentlyContinue) {
|
||||||
|
Unregister-ScheduledTask -TaskName $taskName -Confirm:$false
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
$enhancedSearch = Get-RegistryValueOrNull `
|
||||||
|
-Path $searchKey `
|
||||||
|
-Name $searchValueName
|
||||||
|
|
||||||
|
if ($enhancedSearch -ne $searchConfiguration.valueData) {
|
||||||
|
throw "Failed to verify enhanced file search."
|
||||||
|
}
|
||||||
@@ -0,0 +1,200 @@
|
|||||||
|
$schema: https://aka.ms/dsc/schemas/v3/bundled/config/document.json
|
||||||
|
|
||||||
|
resources:
|
||||||
|
- name: Disable advertising ID
|
||||||
|
type: Microsoft.Windows/Registry
|
||||||
|
properties:
|
||||||
|
keyPath: HKCU\Software\Microsoft\Windows\CurrentVersion\AdvertisingInfo
|
||||||
|
valueName: Enabled
|
||||||
|
valueData:
|
||||||
|
DWord: 0
|
||||||
|
_exist: true
|
||||||
|
|
||||||
|
- name: Do not share the language list with websites
|
||||||
|
type: Microsoft.Windows/Registry
|
||||||
|
properties:
|
||||||
|
keyPath: HKCU\Control Panel\International\User Profile
|
||||||
|
valueName: HttpAcceptLanguageOptOut
|
||||||
|
valueData:
|
||||||
|
DWord: 1
|
||||||
|
_exist: true
|
||||||
|
|
||||||
|
- name: Disable personalized offers
|
||||||
|
type: Microsoft.Windows/Registry
|
||||||
|
properties:
|
||||||
|
keyPath: HKCU\Software\Microsoft\Windows\CurrentVersion\Privacy
|
||||||
|
valueName: TailoredExperiencesWithDiagnosticDataEnabled
|
||||||
|
valueData:
|
||||||
|
DWord: 0
|
||||||
|
_exist: true
|
||||||
|
|
||||||
|
- name: Disable tailored experiences by policy
|
||||||
|
type: Microsoft.Windows/Registry
|
||||||
|
properties:
|
||||||
|
keyPath: HKCU\Software\Policies\Microsoft\Windows\CloudContent
|
||||||
|
valueName: DisableTailoredExperiencesWithDiagnosticData
|
||||||
|
valueData:
|
||||||
|
DWord: 1
|
||||||
|
_exist: true
|
||||||
|
|
||||||
|
- name: Disable all Windows Spotlight suggestions
|
||||||
|
type: Microsoft.Windows/Registry
|
||||||
|
properties:
|
||||||
|
keyPath: HKCU\Software\Policies\Microsoft\Windows\CloudContent
|
||||||
|
valueName: DisableWindowsSpotlightFeatures
|
||||||
|
valueData:
|
||||||
|
DWord: 1
|
||||||
|
_exist: true
|
||||||
|
|
||||||
|
- name: Disable third-party Spotlight suggestions
|
||||||
|
type: Microsoft.Windows/Registry
|
||||||
|
properties:
|
||||||
|
keyPath: HKCU\Software\Policies\Microsoft\Windows\CloudContent
|
||||||
|
valueName: DisableThirdPartySuggestions
|
||||||
|
valueData:
|
||||||
|
DWord: 1
|
||||||
|
_exist: true
|
||||||
|
|
||||||
|
- name: Disable suggested content in Settings
|
||||||
|
type: Microsoft.Windows/Registry
|
||||||
|
properties:
|
||||||
|
keyPath: HKCU\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager
|
||||||
|
valueName: SubscribedContent-338393Enabled
|
||||||
|
valueData:
|
||||||
|
DWord: 0
|
||||||
|
_exist: true
|
||||||
|
|
||||||
|
- name: Disable Settings suggestions
|
||||||
|
type: Microsoft.Windows/Registry
|
||||||
|
properties:
|
||||||
|
keyPath: HKCU\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager
|
||||||
|
valueName: SystemPaneSuggestionsEnabled
|
||||||
|
valueData:
|
||||||
|
DWord: 0
|
||||||
|
_exist: true
|
||||||
|
|
||||||
|
- name: Disable Settings account suggestions
|
||||||
|
type: Microsoft.Windows/Registry
|
||||||
|
properties:
|
||||||
|
keyPath: HKCU\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager
|
||||||
|
valueName: SubscribedContent-353694Enabled
|
||||||
|
valueData:
|
||||||
|
DWord: 0
|
||||||
|
_exist: true
|
||||||
|
|
||||||
|
- name: Disable Settings app suggestions
|
||||||
|
type: Microsoft.Windows/Registry
|
||||||
|
properties:
|
||||||
|
keyPath: HKCU\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager
|
||||||
|
valueName: SubscribedContent-353696Enabled
|
||||||
|
valueData:
|
||||||
|
DWord: 0
|
||||||
|
_exist: true
|
||||||
|
|
||||||
|
- name: Disable tips about Windows
|
||||||
|
type: Microsoft.Windows/Registry
|
||||||
|
properties:
|
||||||
|
keyPath: HKCU\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager
|
||||||
|
valueName: SubscribedContent-338389Enabled
|
||||||
|
valueData:
|
||||||
|
DWord: 0
|
||||||
|
_exist: true
|
||||||
|
|
||||||
|
- name: Disable Windows welcome experience
|
||||||
|
type: Microsoft.Windows/Registry
|
||||||
|
properties:
|
||||||
|
keyPath: HKCU\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager
|
||||||
|
valueName: SubscribedContent-310093Enabled
|
||||||
|
valueData:
|
||||||
|
DWord: 0
|
||||||
|
_exist: true
|
||||||
|
|
||||||
|
- name: Disable suggested apps
|
||||||
|
type: Microsoft.Windows/Registry
|
||||||
|
properties:
|
||||||
|
keyPath: HKCU\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager
|
||||||
|
valueName: SubscribedContent-338388Enabled
|
||||||
|
valueData:
|
||||||
|
DWord: 0
|
||||||
|
_exist: true
|
||||||
|
|
||||||
|
- name: Disable soft-landing tips
|
||||||
|
type: Microsoft.Windows/Registry
|
||||||
|
properties:
|
||||||
|
keyPath: HKCU\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager
|
||||||
|
valueName: SoftLandingEnabled
|
||||||
|
valueData:
|
||||||
|
DWord: 0
|
||||||
|
_exist: true
|
||||||
|
|
||||||
|
- name: Disable automatic suggested app installation
|
||||||
|
type: Microsoft.Windows/Registry
|
||||||
|
properties:
|
||||||
|
keyPath: HKCU\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager
|
||||||
|
valueName: SilentInstalledAppsEnabled
|
||||||
|
valueData:
|
||||||
|
DWord: 0
|
||||||
|
_exist: true
|
||||||
|
|
||||||
|
- name: Disable device setup suggestions
|
||||||
|
type: Microsoft.Windows/Registry
|
||||||
|
properties:
|
||||||
|
keyPath: HKCU\Software\Microsoft\Windows\CurrentVersion\UserProfileEngagement
|
||||||
|
valueName: ScoobeSystemSettingEnabled
|
||||||
|
valueData:
|
||||||
|
DWord: 0
|
||||||
|
_exist: true
|
||||||
|
|
||||||
|
- name: Disable File Explorer sync-provider promotions
|
||||||
|
type: Microsoft.Windows/Registry
|
||||||
|
properties:
|
||||||
|
keyPath: HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced
|
||||||
|
valueName: ShowSyncProviderNotifications
|
||||||
|
valueData:
|
||||||
|
DWord: 0
|
||||||
|
_exist: true
|
||||||
|
|
||||||
|
- name: Disable inking and typing diagnostics
|
||||||
|
type: Microsoft.Windows/Registry
|
||||||
|
properties:
|
||||||
|
keyPath: HKCU\Software\Microsoft\Input\TIPC
|
||||||
|
valueName: Enabled
|
||||||
|
valueData:
|
||||||
|
DWord: 0
|
||||||
|
_exist: true
|
||||||
|
|
||||||
|
- name: Set feedback frequency period to never
|
||||||
|
type: Microsoft.Windows/Registry
|
||||||
|
properties:
|
||||||
|
keyPath: HKCU\Software\Microsoft\Siuf\Rules
|
||||||
|
valueName: PeriodInNanoSeconds
|
||||||
|
valueData:
|
||||||
|
DWord: 0
|
||||||
|
_exist: true
|
||||||
|
|
||||||
|
- name: Set feedback prompts to never
|
||||||
|
type: Microsoft.Windows/Registry
|
||||||
|
properties:
|
||||||
|
keyPath: HKCU\Software\Microsoft\Siuf\Rules
|
||||||
|
valueName: NumberOfSIUFInPeriod
|
||||||
|
valueData:
|
||||||
|
DWord: 0
|
||||||
|
_exist: true
|
||||||
|
|
||||||
|
- name: Disable device search history
|
||||||
|
type: Microsoft.Windows/Registry
|
||||||
|
properties:
|
||||||
|
keyPath: HKCU\Software\Microsoft\Windows\CurrentVersion\SearchSettings
|
||||||
|
valueName: IsDeviceSearchHistoryEnabled
|
||||||
|
valueData:
|
||||||
|
DWord: 0
|
||||||
|
_exist: true
|
||||||
|
|
||||||
|
- name: Disable search highlights
|
||||||
|
type: Microsoft.Windows/Registry
|
||||||
|
properties:
|
||||||
|
keyPath: HKCU\Software\Microsoft\Windows\CurrentVersion\SearchSettings
|
||||||
|
valueName: IsDynamicSearchBoxEnabled
|
||||||
|
valueData:
|
||||||
|
DWord: 0
|
||||||
|
_exist: true
|
||||||
@@ -0,0 +1,6 @@
|
|||||||
|
{
|
||||||
|
"keyPath": "HKLM\\SOFTWARE\\Microsoft\\Windows Search\\Gather\\Windows\\SystemIndex",
|
||||||
|
"valueName": "EnableFindMyFiles",
|
||||||
|
"valueType": "REG_DWORD",
|
||||||
|
"valueData": 1
|
||||||
|
}
|
||||||
@@ -0,0 +1,92 @@
|
|||||||
|
$schema: https://aka.ms/dsc/schemas/v3/bundled/config/document.json
|
||||||
|
|
||||||
|
resources:
|
||||||
|
- name: Disable advertising ID by policy
|
||||||
|
type: Microsoft.Windows/Registry
|
||||||
|
properties:
|
||||||
|
keyPath: HKLM\Software\Policies\Microsoft\Windows\AdvertisingInfo
|
||||||
|
valueName: DisabledByGroupPolicy
|
||||||
|
valueData:
|
||||||
|
DWord: 1
|
||||||
|
_exist: true
|
||||||
|
|
||||||
|
- name: Disable Windows consumer experiences
|
||||||
|
type: Microsoft.Windows/Registry
|
||||||
|
properties:
|
||||||
|
keyPath: HKLM\Software\Policies\Microsoft\Windows\CloudContent
|
||||||
|
valueName: DisableWindowsConsumerFeatures
|
||||||
|
valueData:
|
||||||
|
DWord: 1
|
||||||
|
_exist: true
|
||||||
|
|
||||||
|
- name: Set diagnostic data to the lowest available level
|
||||||
|
type: Microsoft.Windows/Registry
|
||||||
|
properties:
|
||||||
|
keyPath: HKLM\Software\Policies\Microsoft\Windows\DataCollection
|
||||||
|
valueName: AllowTelemetry
|
||||||
|
valueData:
|
||||||
|
DWord: 0
|
||||||
|
_exist: true
|
||||||
|
|
||||||
|
- name: Disable feedback notifications
|
||||||
|
type: Microsoft.Windows/Registry
|
||||||
|
properties:
|
||||||
|
keyPath: HKLM\Software\Policies\Microsoft\Windows\DataCollection
|
||||||
|
valueName: DoNotShowFeedbackNotifications
|
||||||
|
valueData:
|
||||||
|
DWord: 1
|
||||||
|
_exist: true
|
||||||
|
|
||||||
|
- name: Disable Diagnostic Data Viewer
|
||||||
|
type: Microsoft.Windows/Registry
|
||||||
|
properties:
|
||||||
|
keyPath: HKLM\Software\Policies\Microsoft\Windows\DataCollection
|
||||||
|
valueName: DisableDiagnosticDataViewer
|
||||||
|
valueData:
|
||||||
|
DWord: 1
|
||||||
|
_exist: true
|
||||||
|
|
||||||
|
- name: Limit diagnostic log collection
|
||||||
|
type: Microsoft.Windows/Registry
|
||||||
|
properties:
|
||||||
|
keyPath: HKLM\Software\Policies\Microsoft\Windows\DataCollection
|
||||||
|
valueName: LimitDiagnosticLogCollection
|
||||||
|
valueData:
|
||||||
|
DWord: 1
|
||||||
|
_exist: true
|
||||||
|
|
||||||
|
- name: Limit diagnostic dump collection
|
||||||
|
type: Microsoft.Windows/Registry
|
||||||
|
properties:
|
||||||
|
keyPath: HKLM\Software\Policies\Microsoft\Windows\DataCollection
|
||||||
|
valueName: LimitDumpCollection
|
||||||
|
valueData:
|
||||||
|
DWord: 1
|
||||||
|
_exist: true
|
||||||
|
|
||||||
|
- name: Disable activity feed
|
||||||
|
type: Microsoft.Windows/Registry
|
||||||
|
properties:
|
||||||
|
keyPath: HKLM\Software\Policies\Microsoft\Windows\System
|
||||||
|
valueName: EnableActivityFeed
|
||||||
|
valueData:
|
||||||
|
DWord: 0
|
||||||
|
_exist: true
|
||||||
|
|
||||||
|
- name: Disable publishing user activity
|
||||||
|
type: Microsoft.Windows/Registry
|
||||||
|
properties:
|
||||||
|
keyPath: HKLM\Software\Policies\Microsoft\Windows\System
|
||||||
|
valueName: PublishUserActivities
|
||||||
|
valueData:
|
||||||
|
DWord: 0
|
||||||
|
_exist: true
|
||||||
|
|
||||||
|
- name: Disable uploading user activity
|
||||||
|
type: Microsoft.Windows/Registry
|
||||||
|
properties:
|
||||||
|
keyPath: HKLM\Software\Policies\Microsoft\Windows\System
|
||||||
|
valueName: UploadUserActivities
|
||||||
|
valueData:
|
||||||
|
DWord: 0
|
||||||
|
_exist: true
|
||||||
@@ -28,11 +28,11 @@ resources:
|
|||||||
DWord: 0
|
DWord: 0
|
||||||
_exist: true
|
_exist: true
|
||||||
|
|
||||||
- name: Show most used apps
|
- name: Disable app launch tracking
|
||||||
type: Microsoft.Windows/Registry
|
type: Microsoft.Windows/Registry
|
||||||
properties:
|
properties:
|
||||||
keyPath: HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced
|
keyPath: HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced
|
||||||
valueName: Start_TrackProgs
|
valueName: Start_TrackProgs
|
||||||
valueData:
|
valueData:
|
||||||
DWord: 1
|
DWord: 0
|
||||||
_exist: true
|
_exist: true
|
||||||
|
|||||||
@@ -9,12 +9,18 @@ try {
|
|||||||
|
|
||||||
dsc config set --file .\configuration.dsc.yaml
|
dsc config set --file .\configuration.dsc.yaml
|
||||||
|
|
||||||
|
if ($LASTEXITCODE -ne 0) {
|
||||||
|
throw "Failed to apply the main DSC configuration."
|
||||||
|
}
|
||||||
|
|
||||||
& .\applications\chatgpt\apply.ps1
|
& .\applications\chatgpt\apply.ps1
|
||||||
& .\applications\git\apply.ps1
|
& .\applications\git\apply.ps1
|
||||||
|
& .\applications\parsec\apply.ps1
|
||||||
& .\applications\vscode\apply.ps1
|
& .\applications\vscode\apply.ps1
|
||||||
& .\system\advanced-settings\apply.ps1
|
& .\system\advanced-settings\apply.ps1
|
||||||
& .\system\lock-screen\apply.ps1
|
& .\system\lock-screen\apply.ps1
|
||||||
& .\system\power\apply.ps1
|
& .\system\power\apply.ps1
|
||||||
|
& .\system\privacy\apply.ps1
|
||||||
& .\system\wallpaper\apply.ps1
|
& .\system\wallpaper\apply.ps1
|
||||||
}
|
}
|
||||||
finally {
|
finally {
|
||||||
|
|||||||
Reference in New Issue
Block a user