Windows 10 Custom Image Build Tips & Tricks?

CheckThe Logs
CheckThe Logs used Ask the Experts™
Hello EE, I am starting to work on my gold image for Windows 10 Enterprise x64 (VM) and was hoping to get some help on any tips or tricks you all may have run into?

I am starting with SW_DVD5_WIN_ENT_10_1511.1_64BIT_English_MLF_X20-93758.iso and going to kick it up in a VM using VMware Workstation.

I would like to remove as much of the apps as possible without breaking the Microsoft Store if it was ever needed down the line.

I see some PowerShell scripts out there which seem to accomplish this, any solid ones you know working well for you?

Does this need to be done in Audit Mode or sign on with a local admin account okay to build the custom profile?

All I really want to do is install Office 2016 and run Windows Updates on it, get a good base to work with.

WSUS environment, not sure is it is even pushing out Windows 10 Updates yet, so would it be bad idea to update it direct over internet before capture and then use it in WSUS environment?

Reading about some nasty with the Anniversary Update for Windows 10 and WSUS.

Plan is to capture and deploy via MDT 2013 (I have version 6.2.5019.0 is this updated enough)?

Just hoping to get some insider scoop on anything to look out for, appreciate any feedback or insight.

Thank you,
Watch Question

Do more with

Expert Office
EXPERT OFFICE® is a registered trademark of EXPERTS EXCHANGE®
Distinguished Expert 2018
First, my bias. I am already a big fan of "thin" images. Given your environment and plans (as much as has been revealed anyways), I definitely would recommend that route.

In essence, don't customize the image (or do so only minimally.)  Now that Windows 10 uses cumulative updates, you are always one or two updates behind max.  Let MDT do that with a task sequence instead of embedding it in the image.

Same with Office. I install with a task sequence. This is true for MSI based installed or C2R, but either way, you either end up having to re-image often to make sure it is reasonably up-to-date, or end up having to install updates in the task sequence anyways. So why bother with a heavy image for something that requires a task sequence after the fact anyways.

I'd go ahead and use the AU as the base image.  As for "nasty" ...there are some isolated instances of people not being able to install the AU via WSUS, and >95% of those have been user error when I've been able to look at their setup. There is one rare instance where the update engine crashes, but again, this is only updating from 1511 to 1607, and is not a bug with 1607 itself, but with the update process. And was supposed to be fixed with the latest 1511 CU (which can only be negatively confirmed if the same crash occurs going forward.)

Regardless, not a reason to avoid starting with AU/1607.

Hope that answers your questions so far.
Distinguished Expert 2018
About the update problems: 1607 has received a cumulative update recently, that should have addressed the problem with WSUS. Before, on 1607, the update service was crashing regularly, when using it with WSUS during detection and/or download of cumulative updates, while other updates worked just fine. If the problem is really solved, we can only tell after the next patchday when another CU is offered.

App removal can be done using powershell, read


Hi Cliff Galiher and McKnife,

Thank you for the feedback. I guess I have always been a fan of trying to keep my image as thin as possible but yet at the same time having all the main software needs that I know all my users require, and have the image updated with Windows Updates as much as possible. My train of thought for this is that I want to eliminate the amount of time needed to deploy a image and with Task Sequences for the Windows Updates and software such as MS Office to me this seems like an added amount of time involved for each machine deployed, granted I have never had luck when attempting TS for Windows Updates, which is probably why I have gone this route.

C2R... I am not familiar with.

I will be working with Office 2016 and was reviewing this;

And this;

I would prefer to use the AU as the base, does this just require updating my base to the AU version, or is there a newer ISO I can grab somewhere?

Also, I am unable to verify if customizing the image requires Audit Mode or not? I have been seeing some really odd behavior when going into Audit Mode.

Windows Updates are saying fully up to date yet I can visibly tell I am not on AU 1607.

Edge and apps do not work, not a big deal for me yet as I want to keep it as lean as possible, just the Windows Updates and MS Office 2016.

It also appears that if I shutdown the VM when in Audit Mode, it will do some strange behavior like be in a startup repair loop, or it will have the administrator account disabled and I can no longer access the VM.

I will hopefully have more feedback on my experience with this over the weekend, and appreciate any and all feedback.

Thank you for your time and efforts.
Learn Ruby Fundamentals

This course will introduce you to Ruby, as well as teach you about classes, methods, variables, data structures, loops, enumerable methods, and finishing touches.

Distinguished Expert 2018

Office 2016 can come as an MSI or as C2R depending on the exact version you ran. And maintenance matters. C2R for example doesn't update via windows update at all.

There are 1607 ISOs available. I don't know your specific licensing (reimaging rights imare not universal) so I can't tell you where to find your ISOs based on your licensing model. But they are in all the usual places.

Again, I would not remove apps as part if the image creation process. Do So as a task during deployment of your image. In part, you can spend time removing apps just to have an update re-add them. Microsoft even has a blog post on this behavior.
Distinguished Expert 2018

Just a small comment on "Edge and apps do not work" - they do work. Your screenshot shows a message indicating that you test to run those as built-in administrator. Since that is the mightiest account there is and UAC is always off for it, disregarding the system's UAC setting, Microsoft has disabled apps for it by default. For normal users, those would work, normal behavior.


Hi Cliff Galiher & McKnife,

I have taken your advice not to customize the OS and use Task Sequences to apply customizations. I am just testing the waters here and followed this guide below;

Everything appears to work out okay, .wim is captured and VM shutsdown without error.

When I boot up the VM these are the errors\options I get;

The Startup Settings, non of these options seem to do anything, I have tried all 9 and it will just get me back to the error windowstrustedrt.sys error.

My best guess here is something to do with the partitions and how they were assigned but not sure.

I made sure to keep the VM in host -only mode for this process so it would not get out on the internet.

Thank you,
Distinguished Expert 2018

Fairly straightforward error. Drivers are missing. You need to include VMWare drivers in your task sequence (or not use VMWare Workstation to capture your image.)  I see a lot of problems with VMWare Workstation these days, so my inclination is to recommend Hyper-V (windows 10 has client Hyper-V after all) or at least VMWare ESX. Workstation just does too many funky things with drivers to make networking work.

Do more with

Expert Office
Submit tech questions to Ask the Experts™ at any time to receive solutions, advice, and new ideas from leading industry professionals.

Start 7-Day Free Trial