MDT for Windows 10 (Basic Functionality)
This assumes no knowledge of MDT and no prior installation and is one of many ways of configuration.
First of all, download the following:
ADK for Windows 10
https://msdn.microsoft.com/en-us/windows/hardware/dn913721.aspx#adkwin10
MDT 2013 Update 1
https://www.microsoft.com/en-us/download/details.aspx?id=48595
Windows 10 Pro/Edu/Ent ISO/DVD
https://www.microsoft.com/Licensing/servicecenter/default.aspx
ADK
On the server you have designated for MDT, install ADK for Windows 10 to a directory of your choosing, selecting No to the Participation for the Windows Kits. The main feature you want to install is the Deployment Tools and the Windows Preinstallation Environment (Windows PE), you can if you wish install other elements if you will be experimenting with them later.
MDT - Deployment Share Creation
Run the installer, select a directory of your choosing to install MDT. For the Customer Experience Improvement Program select 'I don't want to join the program at this time'.
Once MDT has installed, launch Deployment Workbench, right click and select New Deployment Share. When asked for a path, enter a path of X:\DeploymentShare (where X is a drive letter of plenty of space for storing the OS and any future drivers). For this instruction, it will be assumed you will have the Share name of DeploymentShare$.
You will be asked to customise the default behaviour for MDT. The settings I have chosen in this example with the reasons are as follows.
Ask if a computer backup should be performed. - No (As I will only be building or reinstalling PCs).
Ask for a product key - No (As I use KMS).
Ask to set the local Administrator password - No (As I will be setting this on the Task Sequence (shown later).
Ask if an image should be captured - No (As I will be deploying fresh installations of Windows from the media and then updating).
Ask if BitLocker should be enabled - No (As I can set BitLocker in the Task Sequence if required).
You can then finish the New Deployment Share Wizard.
MDT - Updating the Deployment Share Properties
Right click on the Deployment Share and select Properties.
If you wish to enable monitoring on the state of the builds, go to the Monitoring tab and select the Enable monitoring tick box.
If you won't be booting any computers off of a CD to connect to the network deployment share, go to the Windows PE tab and deselect the Generate a Lite Touch bootable ISO image. Change the Platform at the top and repeat the settings for the x64 image.
On the Rules tab, create a couple of new lines, then enter any custom settings you wish. The settings I use are below.
SkipLocaleSelection=YES UserLocale=en-GB SystemLocale=en-GB UIlanguage=en-US KeyboardLocale=0809:00000809 TimeZoneName=GMT Standard Time SkipTimeZone=YES SkipAppsOnUpgrade=YES SkipUserData=YES SkipSummary=YES WSUSServer=http://WIN-MS-01:8530 MachineObjectOU=OU=Workstations,DC=Horcrux,DC=Voldemort,DC=JKR,DC=Sch,DC=UK JoinDomain=Horcrux FinishAction=REBOOT
The top box of text sets the local to the UK. The second section of code disables screens such as the USMT as I won't be needing it. The third lot of settings specifies the WSUS server, the default location where I want to add computers and the domain name. Last but not least after a successful install, I want the PC to reboot so users can start using the machine (as I have a GPO with all the settings I want for the PC in the OU we are creating this in).
Click on the Bootstrap.ini button.
Under the [Default] header, enter the following:
KeyboardLocalePE=0809:00000809 SkipBDDWelcome=YES DeployRoot=\\DeploymentServer\DeploymentShare$
This sets the Windows PE keyboard to English UK (so the " and @ keys are mapped to the correct place!). Skips the first page welcoming you to Windows PE and immediately presents you with the username and password field. DeploymentRoot defines the location to pick up the Custom Settings file we updated in the previous section, the task sequences and the Operating Systems. Save the file and click ok.
Note: Whenever you change the Bootstrap.ini, add replace the Windows PE with one from an updated ADK or add new network or storage drivers, you will need to regenerate the WDS wim. This will be discussed later.
MDT - Adding the Operating System
In the Deployment Share section, right click on Operating Systems and select Import Operating System. Either mount the Windows 10 ISO image (double click in Server 2012) or put the DVD in the drive.
Select 'Full set of source files' and click Next (you could just select the WIM file, but I like to make sure I have all the files, just in case). Select the Drive letter the Windows 10 ISO/DVD is on and click Next.
Give the OS a relevant name or left with the default and click Next. On the Summary window, click Next and once Finished, click Finish.
MDT - Adding a Task Sequence
In the Deployment Share section, right click on Task Sequences and select New Task Sequence. Enter a Task sequence ID and name, for example ID: 10x64 Name: Windows 10 x64 and click Next. As this Task Sequence will be for building a new PC, select the Template 'Standard Client Task Sequence' and click Next.
Select the OS you wish to deploy and click Next. For the Product Key section, if you are using KMS to activate Windows, just select 'Do not specify a product key at this time' and click Next. For the full name and organisation, type your School/Business name, you can also customise the default Internet Explorer Home Page if you wish and click Next.
Enter a local Administrator account password you want on the machine and click Next. Click Next on the Summary and Finish on the Confirmation.
MDT - Updating the Task Sequence
Double click on the Task Sequence you have just created.
As we want this sequence to always format the machine, we are going to move a few tasks. Expand the Preinstall section, followed by the New Computer only section and move the Validate, Format and Partition Disk (BIOS), Format and Partition Disk (UEFI) and Copy scripts tasks up above the New Computer only section and underneath the Gather local only section.
As part of the build process, I want the machine to connect to our WSUS server to make sure it's up to date. To do this I will expand the State Restore section and click on the Windows Update (Pre-Application Installation) task, click on Options, and untick the 'Disable this step' and make sure 'Continue on error' is ticked. In case I decide to use MDT to deploy any applications in the future, I will also make these changes to the Windows Update (Post-Application Installation) task.
As part of the build process, I want to add Dot Net 3.5, as some of my applications require it. To do this I go to the Custom Tasks section and click 'Add', 'General', 'Run Command Line'. On the Properties tab I change the name of the task to Dot Net 3.5 and for the command line I type:
Dism /online /enable-feature /featurename:NetFX3 /All /Source:"\\DeploymentServer\DeploymentShare$\Operating Systems\Windows 10 Education VL 2015-11 x64\sources\sxs" /LimitAccess
As we have some PowerShell scripts which we like to run, I want to change the PowerShell execution policy. To do this I go to the Custom Tasks section and click 'Add', 'General', 'Run Command Line'. On the Properties tab I change the name of the task to Enable PowerShell Scripts and for the command line I type:
powershell.exe Set-ExecutionPolicy RemoteSigned
Note: If I want to I could also make a custom batch file in a folder on \\DeploymentServer\DeploymentShare$\Scripts and run this from a task sequence. if I want to refer to the scripts folder within a task sequence I can used the variable %SCRIPTROOT% (i.e. %SCRIPTROOT%\Custom\School.cmd).
Creating/Updating the Boot WIMs.
Right click on the Deployment Share and select Update Deployment Share. Select the option to Completely regenerate the boot images and click Next. Click Next on the Summary. Once the process is complete (it may take some time), click Finish.
Note: If you need to change Bootstrap.ini, add any Network Drivers or Storage Drivers to the drivers folder, you will need to follow the above so the Windows PE environment can access these devices or changes.
WDS - Setup
On your MDT server, add the Server Role of Windows Deployment Services, and accept the defaults. Once installed, launch Windows Deployment Services, right click on the Server object and click Configure Server. On the options, select Integrated with Active Directory, set the drive letter for the path to the same drive letter used for the MDT Deployment Share (i.e. X:\RemoteInstall instead of C:\RemoteInstall).
On the Proxy DHCP window, if you are running DHCP on the same server tick both boxes, if not untick them and click Next. Select Respond to all client computers (known and unknown) and click Next. Once the Service has installed, click Finish.
WDS - Boot Images
Under the Server, right click the Boot Images folder and select 'Add Boot Image...'. Select the file X:\DeploymentShare\Boot\LiteTouchPE_x86.wim and click Next, you can change the display name if you wish and click Next, Next and eventually Finish.
Repeat the above for the X:\DeploymentShare\Boot\LiteTouchPE_x64.wim file.
Installing your PC
To install your PC, enable network boot and start up your machine.
When prompted, press F12.
On some computers you may only see the x86 image or x64 boot wim files. Select one of the two files to continue.
Enter your build account (or admin account), username, password and domain to install and click OK.
Select the Windows version you want to install from fresh on your machine and click Next.
Change the computer name, and if you want the PC in a different OU, amend the OU details.
The PC will now install. If there are any errors you should get a report at the end.
Extras - Security
Once you are happy with everything, you can add some security features.
Using Part 2 - Steps 2 to 9 (excluding LABEL hardyubuntudesktop32 and below) from this guide, you can password protect before using the getting the Windows Deployment Services menu. This helps prevent users loading a command prompt or other tools in the Windows PE environment unless they know the password.
If you want to disable any interaction during the building process, you can add these two lines in the Custom Settings section.
DisableTaskMgr=YES
HideShell=YES
Extras - Multiple OUs
If you want to have a selection box of OUs to place the computer in, you can find a guide how to do this here: https://scriptimus.wordpress.com/2013/02/11/mdt-2012-domainous-list/
You will need to remove the line MachineObjectOU=... from your Custom Settings file for this to work.
Troubleshooting
If after entering your username password and domain in Windows PE, if it just hangs there, check to make sure that the DeploymentShare share permission has been set for the user.
Edited by DJ-1701





2 Comments
Recommended Comments
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now