Jump to content

Sign in to follow this  

How can I automate the deployment of Windows 10 (Creators Update) using MDT and PowerShell ?

Recommended Posts


This script has been written to allow you to automate the deployment Windows 10 version 1703 (Creators Update) using the latest available software including:

  • Windows 10 x64 (version 1703, MSDN media)
  • Microsoft Deployment Toolkit (MDT) build 8443
  • Latest available 2017 drivers for the Surface Pro 4
  • Windows 10 ADK (version 1703)
  • Windows Server 2016

Note: This is fully automated, and as this does install a Windows Deployment Services server role hosting a boot image, you should modify the script accordingly and test it thoroughly in a lab first. As ADK 1703 has an issue with Secure Boot, you must temporarily disable Secure Boot on your Windows Server 2016 prior to running this script, I will amend this post if ADK 1703 is re-released.

This script is tailored for one thing only, deploying Windows 10 x64 to the Microsoft Surface Pro 4 with all drivers loaded and MDT 2013 pre-configured. Download it and customize it to suit your needs for other hardware if you wish because what it does is pretty cool.

This script performs the following actions:-

  • Downloads and then Installs Windows ADK 10 (version 1703) if you have not done so already
  • Downloads and then Installs MDT, if you have not done so already
  • Downloads all required drivers for Microsoft Surface Pro 4 if you have not done so already
  • Imports the Windows 10 x64 (version 1703) operating system into MDT
  • Imports the Microsoft Surface Pro 4 drivers into MDT
  • Creates Selection Profiles for Microsoft Surface Pro 4 and WinPE x64
  • Creates a Deploy Windows 10 x64 - Surface Pro 4 task sequence
  • Edits the Deploy Windows 10 x64 - Surface Pro 4 task sequence and adds an inject drivers step for Microsoft Surface Pro 4
  • Sets a WMI query for hardware detection for the Surface Pro 4 on the corresponding driver step
  • Injects the Microsoft Surface Pro 4 network drivers into the LiteTouchPE_x64.wim
  • Creates custom CustomSettings.ini and BootStrap.ini files
  • Disables the X86 boot wim (as it is not needed for Surface Pro 4)
  • Changes the Selection Profile for the X64 boot wim to use the WinPE x64 selection profile
  • Installs the Windows Deployment Service role
  • Configures the WDS role and adds the previously created LiteTouchPE_x64.wim
  • Starts the WDS service so that you can PXE boot (UEFI network boot).

All you have to do is download the script below, modify some variables, then place certain files in the right place such as the Windows 10 x64 Enterprise (version 1703) media. Please ensure you have a working DHCP scope on your Active Directory domain controller, then PXE boot a Microsoft Surface Pro 4 and sit back and enjoy the show.

Step 1. Download the script

The PowerShell script will do all the hard work for you, it is in the Downloads section at the end of this guide, download it, unzip it and place it on a server that is designated to be the MDT server.

Note: If you use this on Windows Server 2016 then you'll need to temporarily disable secure boot to allow ADK 1703 to install otherwise it will fail due to driver signing. Hopefully this will be fixed in an upcoming release of ADK 10 version 1703.

Step 2. Configure the variables in the script

Once you have downloaded and extracted the script, you need to configure certain variables interspersed throughout the script. I'll highlight the ones you need to edit.

The most important of them is the $SourcePath variable (line 61) as this decides where to get the content from and where to store it. This variable should point to a valid drive letter, the folder name will be created if it does not exist.


The $FolderPath variable (line 242) specifies the MDT Deployment share root folder for example E:\MDTDeploy.


There are other variables to configure, for joining the Domain (lines 320-322)

domain join.png

and then you need to configure how you actually connect to the MDT server from WinPE (lines 393-397)

connect to mdt.png

Step 3. Copy the Windows 10 x64 (version 1703) operating system files

Mount a Microsoft Windows 10 x64 Enterprise (version 1703) ISO and copy the contents to $SourcePath\Operating Systems\Windows 10 x64\1703 as shown below

1703 files.png

Step 4. Optionally copy MDT, ADK 10, Surface Pro 4 drivers

This is an optional step. If you've already downloaded the above files then place them in the source folder, otherwise the script will download them for you.

Note: You do not have to do this as the script will download the content for you if it's not found.

optional files.png

Step 5. Optionally copy your Applications to the respective folders

This is an optional step. If you have apps like Office 365, copy them to their respective folders under Applications. If you do add any applications, you'll need to edit the corresponding section within the script for the CustomSettings.ini and replace the GUID for the App

as shown here (line 362)

app guid.png

Step 6. Run the script

On the server that will become your MDT server, start PowerShell ISE as Administrator. Click on the green triangle to run the script. Below you can see the script in action:

script running.png


After the script is complete, you are ready to test deploying Windows 10 Creators Update to a Microsoft Surface Pro 4. You can see that Windows Deployment Services is installed and that the ADK 1703 version of the MDT LiteTouch_X64 boot wim is already imported. This boot image also has the Surface Pro 4 network drivers added.

wds boot image server 2016.png

After opening the Deployment Workbench, you can see the Deploy Windows 10 x64 version 1703 task sequence is created

ts created.png

The Surface Pro 4 Inject drivers step is pre-configured for you and the WMI query for the hardware is also added on the options tab

inject drivers step.png

and drivers specific to the Surface Pro 4 for are imported into MDT

surface drivers.png

and custom selection profiles for the Surface Pro 4 are created

custom  selection profiles.png


Step 7. Sit back and watch the deployment

Take a properly shutdown Surface Pro 4, and power it on using the following sequence. Hold the down volume key and then press the power button while continuing to hold down the volume key, it should PXE boot. Press enter when prompted

wds boot manager.png

and then it will load the MDT LitetouchPE_X64 boot wim.

loading boot wim.png

before prompting you for a computer name, note that it's currently set to SurfacePro4 in CustomSettings.ini contained within the script,

prompt for computername.png

If you have optional apps they'll be listed here along with the mandatory Office 365 ProPlus

office 365.png

you can change that behavior in the UI itself (CustomSettings.ini on the Properties/Rules of the DeploymentShare) or automate it via the many methods available such as those that Mikael describes here

click Next and off it goes,

running lite touch installation.png

and finally it's all complete, Windows 10 Creators Update installed fully automated !



If the script has issues starting WDS (and you see the error below)

An error occurred while trying to execute the command.
Error Code: 0x41D
Error Description: The service did not respond to the start or control request in a timely fashion.


then restart the server, as you were asked to do at the end of the script ;-).

If you cannot PXE boot, because WDS is not accepting connections (revealed by the PXE Response tab in WDS properties), then look for the following error in the scripts output:

An error occurred while trying to execute the command.
Error Code: 0x5
Error Description: Access is denied.

If you see that error, then the user you are logged in as does not have sufficient permissions to configure WDS.

To grant permissions to approve a pending computer

  1. Open Active Directory Users and Computers.
  2. Right-click the OU where you are creating prestaged computer accounts, and then select Delegate Control.
  3. On the first screen of the wizard, click Next.
  4. Change the object type to include computers.
  5. Add the computer object of the Windows Deployment Services server, and then click Next.
  6. Select Create a Custom task to delegate.
  7. Select Only the following objects in the folder. Then select the Computer Objects check box, select Create selected objects in this folder, and click Next.
  8. In the Permissions box, select the Write all Properties check box, and click Finish.

full control of computer objects.png


You can test whether the permission change works by issuing the following after the script is complete:

WDSUTIL /Set-Server /AnswerClients:All

To perform these procedures, you must be a member of the Account Operators group or the Domain Administrators group, or you must have been delegated the appropriate user rights.

For deployment issues, you can review the logs found in the following locations depending on what part of the OSD process you are in:-

In WinPE

  • X:\Windows\Temp\SMSTSLOG

In Windows

  • C:\Windows\Temp\DeploymentLogs
  • C:\Users\Administrator\Appdata\Local\temp\SMSTSLog


Automating the deployment of Windows 10 Creators Update to the Microsoft Surface Pro 4 using PowerShell and MDT is easy when you know how.


Download the PowerShell script contained in the ZIP file. Deploy Windows 10 Creators Update to Microsoft Surface Pro 4 with MDT - April 2017.zip


Share this post

Link to post
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now
Sign in to follow this