Secret Admin Passwords

Microsoft MVP – Windows Expert - IT Pro
[email protected]
Unattend.xml
Administrator password
Unattend.xml
Unattend.xml
x
Unattend.xml
Deployment Server
WDS & MDT & ConfigMgr
Deployment Server
WDS & MDT & ConfigMgr
Unattend.xml
Deployment Server
WDS & MDT & ConfigMgr
Unattend.xml
Deployment Server
WDS & MDT & ConfigMgr
\\server\REMINST
\\server\deploymentshare$
Unattend.xml
Deployment Server
WDS & MDT & ConfigMgr
Unattend.xml
WinPE
Deployment Server
WDS & MDT & ConfigMgr
F8 or Shift-F10
opens cmd.exe
Unattend.xml
WinPE
Unattend.xml
Unattend.xml
Deployment Server
WDS & MDT & ConfigMgr
Unattend.xml
WinPE
Unattend.xml
Unattend.xml
Deployment Server
WDS & MDT & ConfigMgr
Unattend.xml
WinPE
Unattend.xml
Unattend.xml
Deployment Server
WDS & MDT & ConfigMgr
Unattend.xml
WinPE
Disable cmd.exe from all WIM-files (WinPE and install.wim)
 Manually mounting wim and make file:
Deployment Server
WDS & MDT & ConfigMgr
 mount\Windows\Setup\Scripts\DisableCMDRequest.TAG
 ConfigMgr 2012
Unattend.xml
 MDT
WinPE
Search unsensored unattend files and delete them
 Check your computers for unattend.xml files
 dir /S C:\*unattend.xml
Deployment Server
WDS & MDT & ConfigMgr
Unattend.xml
 Run cleanup script in the end of OS Deployment
 C:\Windows\Setup\Scripts\SetupComplete.cmd
WinPE
dc01.yoda.local
Active Directory
%USERDNSDOMAIN%\SYSVOL\
client01.yoda.local
DNS
DHCP
WDS
MDT
Hyper-V
running 3 VMs
ubuntu (.yoda.local)
Unattend.xml
”Base64-encrypting”
DomainJoinCredentials
clear-text
Deployment Server
WDS & MDT & ConfigMgr
Unattend.xml
Check share rights
\\srv\REMINST
\\srv\deploymentshare$
Active Directory
GPO & GPP
WinPE
Disable cmd
Unattend.xml
GUI, BootstrapNoSF8,
DisableCMDRequest.TAG
Thank you!
Slides: www.petripaavola.fi
[email protected]