Compare commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
a850b56a02 | ||
|
|
ac531db05e |
@@ -85,7 +85,8 @@ The generic SGU credential is rendered as a dedicated branded tile instead of
|
||||
being grouped below the anonymous **Other user** tile. Machine policy assigns
|
||||
the SGU CLSID as the default provider, hides the last signed-in identity, and
|
||||
disables local-user enumeration while retaining the built-in Microsoft password
|
||||
provider and its **Other user** recovery path. It enumerates one
|
||||
provider and its **Other user** recovery path. The computer GPO also applies
|
||||
Windows' native default account picture to named Windows accounts. It enumerates one
|
||||
`CPFT_TILE_IMAGE` and places the `CPFT_LARGE_TEXT` heading immediately after it
|
||||
with `CPFS_DISPLAY_IN_SELECTED_TILE`. LogonUI owns field typography and vertical
|
||||
tile order: on Windows 10 and 11, the account-name title used by **Other user**
|
||||
|
||||
@@ -61,15 +61,29 @@ elseif (-not $existingLinkEnabled -and
|
||||
|
||||
$dataCollectionKey = 'HKLM\Software\Policies\Microsoft\Windows\DataCollection'
|
||||
$powerPolicyRoot = 'HKLM\Software\Policies\Microsoft\Power\PowerSettings'
|
||||
$credentialProviderPolicyKey = 'HKLM\Software\Policies\Microsoft\Windows\System'
|
||||
$interactiveLogonPolicyKey = 'HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System'
|
||||
$accountPicturePolicyKey = 'HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer'
|
||||
$providerClassId = '{D789CFD8-5AD4-489F-9B83-7EB5D9D09335}'
|
||||
$policies = @(
|
||||
@{ Key = $dataCollectionKey; Name = 'AllowTelemetry'; Value = 0 },
|
||||
@{ Key = $dataCollectionKey; Name = 'DisableTelemetryOptInSettingsUx'; Value = 1 },
|
||||
@{ Key = $dataCollectionKey; Name = 'DisableTelemetryOptInChangeNotification'; Value = 1 },
|
||||
@{ Key = $dataCollectionKey; Name = 'DisableDiagnosticDataViewer'; Value = 1 },
|
||||
@{ Key = 'HKLM\Software\Policies\Microsoft\Windows\OOBE'; Name = 'DisablePrivacyExperience'; Value = 1 },
|
||||
@{ Key = 'HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System'; Name = 'EnableFirstLogonAnimation'; Value = 0 },
|
||||
@{ Key = 'HKLM\Software\Policies\Microsoft\Windows\LocationAndSensors'; Name = 'DisableLocation'; Value = 1 },
|
||||
@{ Key = 'HKLM\Software\Policies\Microsoft\Windows\AppPrivacy'; Name = 'LetAppsAccessLocation'; Value = 2 }
|
||||
@{ Key = $dataCollectionKey; Name = 'AllowTelemetry'; Type = 'DWord'; Value = 0 },
|
||||
@{ Key = $dataCollectionKey; Name = 'DisableTelemetryOptInSettingsUx'; Type = 'DWord'; Value = 1 },
|
||||
@{ Key = $dataCollectionKey; Name = 'DisableTelemetryOptInChangeNotification'; Type = 'DWord'; Value = 1 },
|
||||
@{ Key = $dataCollectionKey; Name = 'DisableDiagnosticDataViewer'; Type = 'DWord'; Value = 1 },
|
||||
@{ Key = 'HKLM\Software\Policies\Microsoft\Windows\OOBE'; Name = 'DisablePrivacyExperience'; Type = 'DWord'; Value = 1 },
|
||||
@{ Key = $interactiveLogonPolicyKey; Name = 'EnableFirstLogonAnimation'; Type = 'DWord'; Value = 0 },
|
||||
@{ Key = 'HKLM\Software\Policies\Microsoft\Windows\LocationAndSensors'; Name = 'DisableLocation'; Type = 'DWord'; Value = 1 },
|
||||
@{ Key = 'HKLM\Software\Policies\Microsoft\Windows\AppPrivacy'; Name = 'LetAppsAccessLocation'; Type = 'DWord'; Value = 2 },
|
||||
|
||||
# Enrollment selects the provider before domain join; this computer GPO
|
||||
# becomes the authoritative, self-healing configuration afterwards.
|
||||
@{ Key = $credentialProviderPolicyKey; Name = 'DefaultCredentialProvider'; Type = 'String'; Value = $providerClassId },
|
||||
@{ Key = $credentialProviderPolicyKey; Name = 'EnumerateLocalUsers'; Type = 'DWord'; Value = 0 },
|
||||
@{ Key = $interactiveLogonPolicyKey; Name = 'DontDisplayLastUserName'; Type = 'DWord'; Value = 1 },
|
||||
|
||||
# Use Windows' native default account image for named user tiles. LogonUI
|
||||
# retains ownership of the anonymous Other user tile and its circular mask.
|
||||
@{ Key = $accountPicturePolicyKey; Name = 'UseDefaultTile'; Type = 'DWord'; Value = 1 }
|
||||
)
|
||||
|
||||
$powerSettingIds = @(
|
||||
@@ -80,8 +94,8 @@ $powerSettingIds = @(
|
||||
)
|
||||
foreach ($settingId in $powerSettingIds) {
|
||||
$settingKey = "$powerPolicyRoot\$settingId"
|
||||
$policies += @{ Key = $settingKey; Name = 'ACSettingIndex'; Value = 0 }
|
||||
$policies += @{ Key = $settingKey; Name = 'DCSettingIndex'; Value = 0 }
|
||||
$policies += @{ Key = $settingKey; Name = 'ACSettingIndex'; Type = 'DWord'; Value = 0 }
|
||||
$policies += @{ Key = $settingKey; Name = 'DCSettingIndex'; Type = 'DWord'; Value = 0 }
|
||||
}
|
||||
|
||||
foreach ($policy in $policies) {
|
||||
@@ -92,7 +106,7 @@ foreach ($policy in $policies) {
|
||||
-Server $DomainController `
|
||||
-Key $policy.Key `
|
||||
-ValueName $policy.Name `
|
||||
-Type DWord `
|
||||
-Type $policy.Type `
|
||||
-Value $policy.Value | Out-Null
|
||||
}
|
||||
}
|
||||
@@ -105,7 +119,7 @@ foreach ($policy in $policies) {
|
||||
-Server $DomainController `
|
||||
-Key $policy.Key `
|
||||
-ValueName $policy.Name
|
||||
$configuredPolicies[$policy.Name + '@' + $policy.Key] = [int]$configured.Value
|
||||
$configuredPolicies[$policy.Name + '@' + $policy.Key] = $configured.Value
|
||||
}
|
||||
$link = @(Get-GPInheritance -Target $TargetOuDn -Domain $domainName -Server $DomainController).GpoLinks |
|
||||
Where-Object DisplayName -eq $GpoName |
|
||||
|
||||
@@ -10,6 +10,7 @@ $ErrorActionPreference = 'Stop'
|
||||
$policyKey = 'HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System'
|
||||
$policyValueName = 'DisableLockWorkstation'
|
||||
$desktopPolicyKey = 'HKCU\Software\Policies\Microsoft\Windows\Control Panel\Desktop'
|
||||
$themeKey = 'HKCU\Software\Microsoft\Windows\CurrentVersion\Themes\Personalize'
|
||||
|
||||
$identity = [Security.Principal.WindowsIdentity]::GetCurrent()
|
||||
$principal = [Security.Principal.WindowsPrincipal]::new($identity)
|
||||
@@ -83,6 +84,19 @@ if ($PSCmdlet.ShouldProcess($GpoName, 'Prevent SGU users from manually locking w
|
||||
-Type String `
|
||||
-Value '0' | Out-Null
|
||||
|
||||
# Apply the native Windows dark theme at user logon. Both values are required:
|
||||
# one controls the shell and the other controls supported applications.
|
||||
foreach ($themeValueName in 'AppsUseLightTheme', 'SystemUsesLightTheme') {
|
||||
Set-GPRegistryValue `
|
||||
-Name $GpoName `
|
||||
-Domain $domainName `
|
||||
-Server $DomainController `
|
||||
-Key $themeKey `
|
||||
-ValueName $themeValueName `
|
||||
-Type DWord `
|
||||
-Value 0 | Out-Null
|
||||
}
|
||||
|
||||
if ($WallpaperPath) {
|
||||
Set-GPRegistryValue `
|
||||
-Name $GpoName `
|
||||
@@ -115,6 +129,18 @@ $screenSaverValue = Get-GPRegistryValue `
|
||||
-Server $DomainController `
|
||||
-Key $desktopPolicyKey `
|
||||
-ValueName 'ScreenSaveActive'
|
||||
$appsThemeValue = Get-GPRegistryValue `
|
||||
-Name $GpoName `
|
||||
-Domain $domainName `
|
||||
-Server $DomainController `
|
||||
-Key $themeKey `
|
||||
-ValueName 'AppsUseLightTheme'
|
||||
$systemThemeValue = Get-GPRegistryValue `
|
||||
-Name $GpoName `
|
||||
-Domain $domainName `
|
||||
-Server $DomainController `
|
||||
-Key $themeKey `
|
||||
-ValueName 'SystemUsesLightTheme'
|
||||
$link = @(Get-GPInheritance -Target $TargetOuDn -Domain $domainName -Server $DomainController).GpoLinks |
|
||||
Where-Object DisplayName -eq $GpoName |
|
||||
Select-Object -First 1
|
||||
@@ -138,5 +164,6 @@ if ($WallpaperPath) {
|
||||
LinkEnabled = [bool]$linkEnabled
|
||||
DisableLockWorkstation = [int]$configuredValue.Value
|
||||
ScreenSaverDisabled = [string]$screenSaverValue.Value -eq '0'
|
||||
DarkMode = ([int]$appsThemeValue.Value -eq 0) -and ([int]$systemThemeValue.Value -eq 0)
|
||||
Wallpaper = $configuredWallpaper
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user