15 ms·
“Reclaim Windows 10” Powershell Script
- becarefulyo 10y agoCareful, by default this disables the lock screen.
- CJefferson 10y agoI've had a number of friends who have had to do reinstalls after running these kinds of scripts. Easy to break lots of subtle things.
- maxt 10y agoIt's editable. There's a lot of stuff in there I had to remove. I still want Store functionality because I like the look and feel of the apps on there, especially the Twitter client.
- TranquilMarmot 10y agoYeah, my first Windows 10 install I did a lot of the things in this script (disable Cortana, Bing search, P2P updates, etc.) and my machine worked fine... for a time. Things slowly started to go REALLY downhill, to the point where I couldn't search the start menu and had to find the .exe for any application I wanted to open, I couldn't view any images with the default image viewer, the file explorer barely worked, and a whole bunch of other weird things. Eventually I gave up, reformatted the drive it was installed on, and re-installed. Everything's been pretty much fine since then.
- nhxu 10y agoNo it doesn't. At least on Anniversary Update but is anyone else running an earlier version of Windows? The NoLockScreen hack does not work in Anniversary Update. It's even described in the gist and the Anniversary workaround is commented out.
- kowdermeister 10y agoyup http://i.imgur.com/FXxoNpS.png http://i.imgur.com/FXxoNpS.png
- DanBC 10y ago> but is anyone else running an earlier version of Windows? Anyone who has one of the new netbooks that have 32 GB drives, because it's hard to get 16 GB free to install the update.
- TranquilMarmot 10y agoThe login screen where you input you password, or the lockscreen where you have to press spacebar to "slide up" the image to get to the login screen? For some reason Windows 10 has both even on desktop.
- danjc 10y agoDisabling the lock screen was about the only thing I wasn't sure about, I'd be pretty happy with the rest. Any idea why you would want the lock screen disabled?
- mnadkvlb 10y agoI had been a long time Windows user, at home (W10) and work(7/Server/Datacenter). Windows had been getting just more and more intrusive like a malware since the last couple years. I hope they do something to stop that. I have recently moved to Fedora and it is just awesome. Pretty much everything works like amazing. Its not a complete replacement if you are gaming, nvidia drivers are a bit painful to install but everything else just works. Its been stable even after an update to Fedora 24->25. I am so amazed at how far linux has come. I am so satisfied with it that i am not moving back to Windows for home usage. I hope Microsoft stops with auto-update, otherwise the alternatives are also catching up fast if you are not a gamer.
- douche 10y agoIf you can get ahold of the Windows 10 LTSB (Long-term servicing branch) distribution, it's actually really nice. Windows without the store, the cruft, the forced updates, and the telemetry. Unfortunately I believe you need MSDN or an enterprise volume licensing deal to have access to it.
- SteveNuts 10y agoIt's just so embarrassing to RDP to a windows server and see ads, news, and a store in the start menu. Why the hell anyone would want that on a server is beyond me.
- walterbell 10y agoIsn't W10 Enterprise available to individuals as a monthly subscription?
- druska 10y agoI recommend using Spybot Anti-Beacon [1], which is a safe way of disabling (or enabling) Windows 10 features. [1] https://www.safer-networking.org/spybot-anti-beacon/ https://www.safer-networking.org/spybot-anti-beacon/
- maxt 10y agoNice haven't tried that. I use Shutup10 https://www.oo-software.com/en/shutup10 https://www.oo-software.com/en/shutup10
- LeoPanthera 10y agoI also use Shutup10, which is essentially the same as the script only with a friendly GUI that lets you choose exactly what you want to do.
- wildrhythms 10y agoIs this open-source?
- maxt 10y agoNo that's the only caveat. I much prefer to use scripts, as these programs are a bit of a black box. But at least they're digitally signed and recommended by the wider Windows 'powertoy' community so you're allowed to trust them.
- jordic 10y agoIf isn't opensource You can't trust it.
- SippinLean 10y agoI can look at my network traffic though. It also tells you exactly what registry keys or HOSTS entries are being added, which you can verify.
- 10y ago
- tossedaway334 10y agoStuff like this is fundamentally unworkable when the people pushing software updates are your adversaries. They already do stuff like ignore DNS settings and firewall rules to send harvested data back to microsoft. They will almost certainly break anything this does in the future too...
- frik 10y agoExactly. Windows 10 has a hard coded whitelist of IPs and donain names in the kernel mode part of the OS (it's 64bit, it's signed, you can't modify it) - those IPs and domains will be ignored from your hosts file or firewall rules. Good luck with an hardware firewall attached to your Win10 notebook. ...unrealistic, so it's wise to stay with Win7 (minus some telemetry updates). I hope Android/Fuchsia, and other desktop OS come along until 2020, or MSFT CEO gets fired and they make a 180 degree u-turn.
- TwoNineA 10y agoI wonder what MS employees think when every week a new tool pops up disabling data mining in their OS.
- nol13 10y agoI'm guessing "lol you think the data mining is actually disabled now, Mr. Smith of St. Louis SSN 291-52-xxxx, who prefers to have taco night on wednesdays, and does most of his online shopping sunday mornings."
- Existential_Owl 10y agoJoke's on them. Microsoft probably just bought that info from my Android location history.
- maxt 10y agoI doubt it affects them that much, as there's always going to be powerusers. They get a lot of their telemetry from unsuspecting users / laymen buying those cheap Windows10 tablets you see everywhere now.
- my123 10y agoActually, a good part of the data collection is for having crashdumps to actually fix bugs. Not that many people write feedback.
- becarefulyo 10y agoI'm an enigneer on Windows. We actually use the crash dumps and the more the better so we can prioritize reliability bugs. Usage telemetry helps us prioritize work, like which settings to migrate from Control Panel to Settings first, or to see if design changes actually made things better for people.
- shostack 10y agoHow do engineers there feel about the fact that the data is encrypted so users don't even know what MS knows about them, and how those interested in privacy have to resort to something like this?
- maxt 10y agoIf you prefer a Batch script there's also Make Windows 10 Great Again: https://gist.github.com/IntergalacticApps/675339c2b805b4c9c6e9a442e0121b1d https://gist.github.com/IntergalacticApps/675339c2b805b4c9c6...
- Tempest1981 10y agoHas a nice list of IP addrs and hostnames... thanks!
- spapas82 10y agoHello, can anybody explain in simple words what this script does? How will it affect the behavior of my windows installation? Should I run it? Thanks !
- derEitel 10y agoIt will disable a lot of the Windows 10 telemetry features. Those are the features that send a bunch of data about your usage back to Microsoft. This includes Cortana and the Bing search tool in the normal windows search for example. If you want to run it you should read through it first, it says above every function what it is going to disable. I would go with a simple rule: If you don't understand it, don't disable it. Otherwise it contains code for enabling all features again in case you start to miss something. Edit: especially UI part seems to disable a lot of things by default that you might not want to disable!
- eli 10y agoIf telemetry really bothers you, I think you'd be better off with a different OS
- bostand 10y agoLike what? OSX and Ubuntu have this too.
- TwoNineA 10y agoIt can be turned off. Not in Windows, only toned down a bit.
- lloydde 10y agoWhich telemetry on macOS is not opt-in? Looking at this script there are seems like many more vectors on Windows then macOS and Ubuntu.
- morganvachon 10y agoUbuntu is not the only Linux distribution. Slackware is great if you want an OS that literally only does what you tell it to. Ditto OpenBSD if you're even more paranoid about telemetry. Granted, they aren't for beginners, but that's the sliding scale in action.
- KirinDave 10y agoWhich one? An essentially unsupported Linux distribution? Canonical does telemetry as well. Apple has been doing this for years an yet we still don't sweat wrathful spate of headlines over it. Oh and by the way, the logfiles from most package servers provide an accurate description of what you're doing with your machine and a weak concept of identity. So you'll need to avoid those. Browsers keep updating and the vast majority of websites collect telemetry as well. So no more internet. But yeah, the OS app level telemetry seems like a pretty big deal and we should stress out about it.
- my123 10y agoWindows has a standard logging infrastructure across all apps, ETW, which can also be used for telemetry.
- bostand 10y agoI don't consider win10 telemetry that bad. You can dial it down a lot until it's just sending crash data when thing go bad. Pretty much all OSes have this. What I really don't like however is Microsoft pushing garbage like candy crush to my machine without my consent.
- MrVitaliy 10y agoThat's not true. Install and run wireshark then dial all you want, there will always be traffic every other minute or so to one of Redmond's servers from just idling.
- UnoriginalGuy 10y agoI did just that, cannot reproduce. Did you actually try this or is this based on one of those articles about the open beta of Windows 10 that had a lot more telemetry you couldn't disable?
- MrVitaliy 10y agoThe only thing I didn't do is to block MS servers in System32\Drivers\etc\hosts file. This is useless in my opinion, MS can always change them or add new ones.
- UnoriginalGuy 10y agoThat didn't answer my question at all. You said above: > That's not true. Install and run wireshark then dial all you want, there will always be traffic every other minute or so to one of Redmond's servers from just idling. I literally did exactly what you said. Shutdown all third party applications on a Windows 10 Pro machine, loaded Wireshark 2.2.3, filtered out all LAN traffic/broadcast traffic/etc and watched. Didn't see any traffic at all going to Microsoft nor anyone else, it is still running now and not a peep. Now I have no doubt that if I waited long enough I would, since I have Windows Update enabled, use Microsoft for time synchronisation, and a handful of other things. But it definitely isn't "every other minute." I cannot reproduce that.
- my123 10y agoI don't recommend anyone to use all the script. Dial telemetry down to Basic and then disable Cortana.
- ape4 10y agoI'd like PowerShell more if it wasn't MixedCase.
- gnaritas 10y agoIt's not, you can do everything in lowercase. Still sucks.
- airencracken 10y agoRather than continuing to struggle against these features which will continue to be added, why not use an operating system that respects your freedom?
- everyone 10y agotbh I mainly use windows cus of the great selection of pirate software available for it :p EDIT: ps. I know Linux has great, more or less equivalent, free or very cheap software available but I'm too lazy to learn that other software. EDIT2: I think perhaps a lot of windows users might fall into my category.
- Aldo_MX 10y agoI'd rather struggle with some Windows warts than reverse engineer my drivers. I'm not the kind of guy who would found a Free Software Foundation because of some Xerox printer drivers.
- eitland 10y ago> I'd rather struggle with some Windows warts than reverse engineer my drivers. I'd guess that any *nix user who reverse engineer their own drivers in 2017 does so because they want to and/or have a job that pays them to do so (most likely handsomely). For the rest of us at least mainstream Linux distros are almost as easy as Windows if not easier in some cases (until you come to MS Office, AutoCAD etc which is a whole different story, mostly unrelated to drivers IMO.)
- Aldo_MX 10y ago> have a job that pays them to do so (most likely handsomely). Nope, that's just fiction, the awesomely rewarded jobs are boring banking systems written in plain old Windows Forms (or WPF/Angular if you're lucky). Most jobs would send you with HR to have a serious talk if they found out you lost a week reverse engineering a display link docking station because your multi-monitor setup wouldn't run after installing Fedora in your job laptop. But that's none of my business. Kids are free to believe in Santa. > For the rest of us at least mainstream Linux distros are almost as easy as Windows if not easier in some cases. You usually install Linux because you enjoy working with the terminal, not because it's easy to use, but I certainly understand where do you come from. Ubuntu has done an amazing job to lower the barrier to start using Linux.
- airencracken 10y agoRather than continuing to struggle against these features which will continue to be added, why not use an operating system that respects your freedom?
- jmnicolas 10y agoWe shouldn't have to fight the OS, this is ridiculous. Before moving definitively to Linux I'm considering installing a proxy on my router, bloc all ports except one and just redirect Firefox and a few apps that need connectivity to this port. I'm not a network guy though, might be complicated.
- Tenoke 10y ago>We shouldn't have to fight the OS, this is ridiculous. I know what you mean, but as a Linux user, I feel like I'm spending a fair amount of time fighting the OS, too..
- alkonaut 10y agoYou'll either fight it because it doesn't manage power property on your new laptop or you'll fight it because it shows bing on your start menu or sends telemetry about what apps you run. I'm not going to argue which is "worse" but I sure prefer to switch a few reg keys to stay ahead of Microsoft, to scouring forums trying to figure out what well hidden lever I need to pull to just get the hardware working. You'll be fighting the OS either way - I'm picking this (easy) fight.
- agumonkey 10y agoA vast majority is Registry config values, could have avoided the powershell "version" here.
- cwyers 10y agoI seriously doubt that Windows 10 is doing anything so grave as to require you to run some arbitrary PowerShell script you found on the Internet with elevated privileges. If you do not understand every single command in this thing, you should avoid it, and if you understand every single command in this, you don't need it.
- eumoria 10y agoA good general one to rip out the bloatware is: Get-AppxPackage ** | Remove-AppxPackage Safe but sometimes you have to execute it restart and execute it again for seemingly no reason but it works and won't damage anything. Run powershell as admin. EDIT: A cursory glance of the script doesn't show anything dangerous. It may do thinks you don't want though but PowerShell's pretty decent to understand what's going on even if you don't know the commands specifically.
- ComputerGuru 10y agoBe careful, this breaks things. I ran this when I first switched to Windows 10, and I found that it killed search in the start menu, certain control panel applets that relied on the metro framework, and somehow, VSS.
- eumoria 10y agoIt rips out all the metro apps. It does nothing to cortana so that's confusing. VSS?
- deleted 10y ago[deleted]
- cwyers 10y agoIt doesn't have to be malicious to be dangerous, it can just be wrong. Nobody's running a test suite on these things whenever a Windows update comes down, nobody's testing them on a wide array of Windows configurations, and from the ones I've seen before, they can cause problems with your PC.
- BigChiefSmokem 10y agoUseless unless it also includes a way to prevent your privacy from being invaded my Google, Amazon, et al. Just more fear mongering from the ye old anti-Microsoft camp, (founded 1995).
- russellbeattie 10y agoI have something like this for macOS turning off iCloud and killing .DS_store files, among other annoyances. I wouldn't recommend running this as is (neither does the author) but it's a nice list to pick and choose options from.
- pjmlp 10y agoPity he missed the related shell scripts for the Apple and Google operating systems.
- raffapen 10y agoBeing heavily involved in setting up standard developer workstations, I consider this to be the only practical approach. It's way beyond any specific config item (including telemetry). This is a sure way to get to a stable and consistent configuration. A few comments: - It is better to split such a mega-script into a set of named scripts, so admins can mix-and-match their own configuration set. - The configuration set scripts should be re-entrant, that is, one can run it few times in a row, achieving the same stable result. This is an important principle because those scripts evolve over time until they are are stable, so the re-entrancy enabled the re-configuration game. - Some configuration items are system-based while other are user-account-based. This means that the latter should be invoked automatically once a new user account is created. - VM is your friend. Wash, rinse, repeat. - It is not always wise to replace automation (PowerShell) invocations with direct registry modifications. Tradeoffs should be obvious. - MDT setups should avoid direct system configuration wherever possible, and rely on configuration scripts instead. - One of the features still not possible to script is setting the policy startup/shutdown/login/logout scripts. One can provide this manually in a base workstation image. - Esp. on Windows systems prior to Windows 10: make sure PowerShell is stable - version and module-wise.
- anton_gogolev 10y agoI believe the word you're looking for in your very first list item is "idempotent", not "re-entrant".
- raffapen 10y agoRight. One should ensure that simply re-invoking the script will not break anything by itself. The end result between invocations may be different if scripts are modified between invocations, as getting configuration right is a tricky business.
- qplex 10y agoThis script is a good start. I would also change the default policy in Windows Firewall to drop all outgoing traffic, and then enable access on application basis, and for basic things such as DNS and DHCP. Windows 10 will still spam the DNS server for telemetry hostnames, and there seems to be nothing that you can do about that. And really, if you can, you should switch to a better OS that doesnt require you to work against it.
- vocatus_gate 10y agoThis reminds me of the Tron project https://reddit.com/r/TronScript https://reddit.com/r/TronScript
- novaleaf 10y agoWarning: i tried turning Cortana off by following some powershell scripts (not this one though). ended up she's still on, but now my search functionality is broken. Nothing I did could fix it. Guess I need to reinstall windows if I ever want to get that back.
- alkonaut 10y agoIs it possible to disable the screen magnifier? I press it several times a day by accident and it's really tricky to switch off...
- nzubair 10y ago- Launch "Ease of Access Center", either from control panel or search in start menu. - Click Make the computer easier to see. - Uncheck the option Turn on Magnifier and click on Save
- aceperry 10y agoI seem to remember a few other apps and scripts that do the same thing, but I also heard that they get out of date pretty quickly. Don't know if this is going to keep up with the updates, but it shows that this is an ongoing problem with Windows10.
- saghm 10y ago> Restrict Windows Update P2P only to local network I find this interesting as a security choice rather than completely disabling P2P updates, as I'd guess that a substantial number of users aren't in control of all machines on their network, and if the other computers on the network got their updates from peers outside the network, then you'll still end up getting the updates from those peers. Is completely disabling P2P updates not an option?
- mjevans 10y agoIt's a real question of how well it detects your /local/ network versus being on that over a third party VPN. For desktops local network is fine. For laptops it should be a no-go.
- MichaelMoser123 10y agothe script changes some registry settings - did you check that it really stops snooping if you just set the registry settings and reboot? What if another update just enables the snooping back regardless of the registry setting?
- MichaelMoser123 10y agoanybody knows why Microsoft joined in with the data gathering? this move might alienate their corporate customers and that's the real cash cow, don't they make enough money out of licensing? They say that Mr. Nadella is such a smart guy, but this really looks like a way to loose existing business.