A comprehensive collection of PowerShell scripts designed to automate Windows post-installation customization, debloating, privacy hardening, and system optimization. This toolkit transforms a fresh Windows installation into a streamlined, privacy-focused, and performance-optimized system with minimal manual intervention.
This repository addresses common pain points with fresh Windows installations by providing:
- Automated debloating - Removes unwanted pre-installed applications and services
- Privacy hardening - Disables telemetry, advertising, and data collection features
- Performance optimization - Applies system tweaks for better responsiveness
- Security enhancements - Configures Windows Defender, BitLocker, and security policies
- User experience improvements - Customizes Explorer, taskbar, and system behaviors
- Enterprise-ready configuration - Suitable for both home users and enterprise environments
CRITICAL: These scripts make extensive system modifications. Before running:
- Create a system backup or use a virtual machine for testing
- Review all scripts in the
includes/directory to understand changes - Test on non-production systems first
- Run PowerShell as Administrator for proper execution
- Understand rollback procedures - system restore points are created but have limitations
Open PowerShell as Administrator and execute:
Set-ExecutionPolicy Bypass -Scope Process -Force; `
iwr -useb https://raw.githubusercontent.com/ShaheedFazal/customize-windows-setup/main/download-repo.ps1 | iex; `
& "C:\Temp\customize-windows-setup\customize-windows-setup-main\customize-windows-client.ps1"For machines that need to keep Microsoft Account and OneDrive functionality, use this variant:
Set-ExecutionPolicy Bypass -Scope Process -Force; `
iwr -useb https://raw.githubusercontent.com/ShaheedFazal/customize-windows-setup/main/download-repo.ps1 | iex; `
& "C:\Temp\customize-windows-setup\customize-windows-setup-main\customize-windows-client-with-microsoft.ps1"This variant skips the following scripts:
ZZ-Disable-MicrosoftAccount.ps1- Keeps Microsoft Account sign-in enabledUninstall-OneDrive.ps1- Keeps OneDrive installed and functional
Use this variant for:
- Machines requiring cloud sync and backup
- Users who rely on Microsoft 365 integration
- Environments using OneDrive for Business
- Systems that need Microsoft Account authentication
- Download and run
download-repo.ps1to extract the repository toC:\Temp - Navigate to the extracted folder
- Execute
customize-windows-client.ps1as Administrator
customize-windows-setup/
βββ customize-windows-client.ps1 # Main orchestrator script (full debloating)
βββ customize-windows-client-with-microsoft.ps1 # Variant keeping Microsoft Account & OneDrive
βββ download-repo.ps1 # Repository downloader utility
βββ includes/ # Modular customization scripts
β βββ Shared-Functions.ps1 # Common utility functions
β βββ [Feature Scripts] # Individual customization modules
β βββ disabled/ # Scripts excluded from execution
βββ wallpaper/ # Custom wallpaper assets
βββ HKCU-to-HKLM-Migration.md # Policy migration documentation
βββ AGENTS.md # Development guidelines
- Initialization: Creates system restore point, sets up logging
- Registry Backup: Backs up critical registry hives (HKLM, HKCR, HKU)
- Script Discovery: Loads all
.ps1files fromincludes/(excludingdisabled/) - Sequential Execution: Runs scripts alphabetically, with
ZZZ-prefixed scripts last - Multi-User Application: Applies changes to current user, all loaded profiles, and default template
- Error Handling: Logs failures and continues execution where possible
- Telemetry Removal: Disables Windows diagnostic data collection
- Advertising Removal: Blocks Microsoft advertising and consumer features
- Cortana Disable: Turns off voice assistant and data collection
- Search Hardening: Removes Bing integration from Windows Search
- Feedback Suppression: Prevents Windows feedback prompts
Note: Location services are NOT disabled by default to preserve automatic time zone detection and time sync functionality. A disabled script exists in
includes/disabled/if needed.
- App Removal: Uninstalls pre-installed Microsoft Store apps
- Service Optimization: Disables unnecessary Windows services
- Startup Cleanup: Removes unwanted startup programs
- OneDrive Removal: Complete OneDrive uninstallation (optional)
- Power Management: Sets High Performance power plan with integrated 30-minute screen lock
- Fast Startup: Disables problematic Fast Startup feature
- Hibernation: Disables hibernation to save disk space
- Visual Effects: Optimizes animations and visual effects
- Explorer Tweaks: Shows file extensions, optimizes folder views
- Taskbar Customization: Hides unwanted buttons and icons
- Desktop Cleanup: Removes unnecessary desktop icons
- Custom Wallpaper: Applies consistent wallpaper across all users
- Automatic Screen Lock: 30-minute display timeout with password protection
- Windows Defender: Optimizes antivirus settings
- BitLocker: Enables drive encryption (where supported)
- Account Security: Configures user account policies
- Network Security: Hardens network and firewall settings
- Wake on LAN: Configures network adapters for remote wake capability (with multi-language support)
Configure-Clipboard.ps1- Clipboard history and cross-device syncDisable-FastStartup.ps1- Removes Fast Startup for stabilityDisable-Hibernation.ps1- Disables hibernation modeSet-PowerManagement-HighPerformance.ps1- High Performance power plan with 30-minute screen lock
Disable-Cortana.ps1- Removes voice assistant featuresDisable-Bing-Search.ps1- Removes web search integrationStrengthen-Privacy.ps1- Comprehensive privacy hardening
Hide-People-Icon-Taskbar.ps1- Removes People iconHide-Widgets-Icon.ps1- Removes Widgets buttonShow-Known-File-Extensions.ps1- Shows file extensionsSet-Control-Panel-View-to-Small-Icons.ps1- Optimizes Control Panel
Uninstall-Default-Software-Packages.ps1- Removes bloatwareUninstall-OneDrive.ps1- Complete OneDrive removal
Enable-WakeOnLan.ps1- Configures Wake on LAN with international language support
ZZZ-Set-Wallpaper.ps1- Applies custom wallpaper system-wide
Note: Screen lock functionality is integrated into Set-PowerManagement-HighPerformance.ps1 rather than using a separate screensaver script, providing a consolidated approach to power management and security.
The toolkit uses HKLM (Local Machine) policies instead of HKCU (Current User) settings to ensure:
- System-wide application across all user accounts
- Resistance to user-level changes
- Consistent behavior for new user accounts
- Enterprise policy compliance
- Automatic Backups: Creates registry backups before modifications
- System Restore Points: Creates restoration checkpoints
- Error Logging: Comprehensive logging for troubleshooting
- Rollback Documentation: Clear instructions for reversing changes
- Move scripts to
includes/disabled/to skip execution - Modify
customize-windows-client.ps1variables for different configurations - Edit individual scripts for custom behaviors
disabled/ folder require careful review before enabling. These scripts may contain:
- Outdated or untested functionality
- Settings that conflict with active scripts
- Enterprise-specific configurations not suitable for all environments
- Features that have been disabled for compatibility reasons
Always test disabled scripts in a virtual machine or isolated environment before moving them to the active includes/ folder.
- Create new
.ps1script inincludes/ - Use
Shared-Functions.ps1utilities for consistency - Follow existing naming conventions
- Test thoroughly before deployment
Key variables in customize-windows-client.ps1:
$DRIVELABELSYS = "OS" # System drive label
$POWERMANAGEMENT = "High performance" # Power plan
$OFFICESUITE = "Google" # Default office suite preferenceThe toolkit includes specific logic for Windows Server environments:
- Detects Windows Server editions
- Applies server-appropriate configurations
- Excludes client-only features
- Supports Server 2016, 2019, and newer versions
- Main Log:
C:\Temp\customize-windows-client-[timestamp].log - Registry Backups:
C:\Install\registry-backup-* - Shared Log:
C:\Temp\Customization.log(via shared functions)
- Non-blocking errors allow script continuation
- Comprehensive error reporting
- Exit codes indicate overall success/failure
- Detailed error messages for troubleshooting
- System Restore Points (limited by Windows frequency settings)
- Registry backups for manual restoration
- Service restoration utilities
- Use Windows System Restore
- Import registry backups from
C:\Install\ - Re-enable services using Windows Services console
- Manually adjust specific settings as documented
- Scripts work in both workgroup and domain environments
- Some policies may conflict with Group Policy
- Test in isolated environments first
- Document any Group Policy interactions
- All modifications use documented Windows features
- No third-party tools or unsigned binaries
- BSD 3-Clause license allows commercial use
- Audit trail through comprehensive logging
- No automated testing framework (by design)
- Manual testing on multiple Windows versions required
- PowerShell version compatibility checking only
- Virtual machine testing recommended
- Use shared functions from
Shared-Functions.ps1 - Implement proper error handling
- Include descriptive comments
- Follow existing naming conventions
- Fork the repository
- Create feature branches
- Test on multiple Windows versions
- Submit pull requests with detailed descriptions
- Follow existing code style and patterns
- Clean up manufacturer bloatware
- Improve system performance
- Enhance privacy protection
- Streamline user interface
- Standardize workstation configurations
- Automate post-imaging customization
- Implement corporate security policies
- Reduce manual configuration time
- Prepare systems for delivery
- Apply consistent configurations
- Remove unwanted software
- Optimize performance settings
- Startup Time: 20-40% faster boot times
- Memory Usage: 10-30% reduction in RAM utilization
- Disk Space: 2-5GB freed from app removal
- Network Usage: Reduced background data consumption
- Task Manager for memory/CPU monitoring
- Resource Monitor for detailed analysis
- PowerShell performance counters
- Windows Performance Analyzer (advanced)
- Execution Policy Errors: Use
Set-ExecutionPolicy Bypass - Permission Denied: Run PowerShell as Administrator
- Script Not Found: Verify repository extraction path
- Registry Access: Ensure administrative privileges
- Check PowerShell version (
$PSVersionTable) - Verify administrator privileges
- Review log files in
C:\Temp\ - Test individual scripts in isolation
This toolkit is actively maintained with regular updates for:
- New Windows versions compatibility
- Security policy updates
- Performance optimizations
- Bug fixes and improvements
- Original Repository
- Current Fork
- Issue tracking via GitHub Issues
- Community discussions in repository discussions
Contributions welcome for:
- New customization modules
- Bug fixes and improvements
- Documentation enhancements
- Testing on different Windows versions
This project is licensed under the BSD 3-Clause License, which permits:
- Commercial and non-commercial use
- Modification and redistribution
- Private use and distribution
This software is provided "as is" without any warranties. Users assume all risks associated with system modifications. Always backup systems before use.
This toolkit serves as an excellent learning resource for:
- PowerShell scripting techniques
- Windows registry manipulation
- System administration automation
- Security policy implementation
- Enterprise configuration management