Turn Microsoft's official Windows 11 ISO into a small, clean, private one, with a graphical builder for the common options, or detailed command-line control.
With the built-in Default preset, it requests these changes to the resulting installation:
- remove planned bloat apps, Edge and OneDrive, and disable targeted AI/Widgets/advertising policies;
- send minimal telemetry;
- install without a Microsoft account or a network connection;
- skip the TPM / Secure Boot / CPU / RAM checks.
Default retains the Update, Defender and Store components; effective policy/runtime behavior depends on Windows edition/version and target testing.
This project is a fork of ntdevlabs/tiny11builder.
Its full history is kept on main, and the 2026 edition follows as regular commits on top.
It selectively adapts fixes from 20 community projects (see Credits and the branch comparison).
Important
The image patches target an offline Windows copy. Real builds temporarily attach media/hives and write project/work/output files:
- It mounts the image in a work folder and edits the image's offline registry
(temporarily loaded as
HKLM\z*), then writes a new ISO. - The registry helpers refuse any path outside those offline hives, and refuse to write at all unless an image hive is loaded.
- The only optional host-side change is Faster build (Defender exclusion). It is off by default and cleanup is attempted when the build ends. It is not authorized on this session's read-only host; see working notes.
Implementation reviewed at 2ae045d, 2026-10-05; version label remains 2026.09. Start with the documentation map, agent handoff, architecture/pipeline and verification matrix. Together they explain current behavior, constraints, history and unfinished validation from Markdown alone.
The latest app checks passed in PowerShell 5.1 and 7 (CI). Two earlier fresh Standard x64 Pro builds measured 9m18s / 14.75 GB uncompressed with cleanup skipped and 21m06s / 6.23 GB maximum with normal cleanup. These were at 7aa45d5, before later PR/reference safeguards. No latest-revision full ISO or VM installation is claimed. The historical final output is absent at its recorded path; source ISO and compact evidence remain. See PERFORMANCE.md.
- Current state and documentation
- Highlights
- Quick start
- The GUI
- Standard or Core
- Presets
- Command line
- What a build does
- After installing
- Customising
- Troubleshooting
- Project layout
- Development
- History and credits
| Build options in one window | A 7-tab GUI with a live log, step/overall progress and ETA. The build runs in a hidden child; Cancel attempts cleanup. |
| Current Windows | Readers/planners cover newer Windows release labels, x64/ARM64, WIM/ESD and language metadata. Full-build evidence is 26300.9457 Pro x64/en-US; other combinations need validation. |
| AI and ads off | Policies for Copilot, Recall, Click to Do, the Settings agent, generative AI in Paint, Notepad and Edge, Widgets, Bing search, Start recommendations and "finish setting up" nags. |
| No surprise reinstalls | Removed apps are deprovisioned, and the Outlook, Dev Home, Teams and Edge re-installers are blocked. |
| Your first boot, your way | A local admin account (or create one in OOBE), locale, time zone, computer name, a zero-touch install for VMs, a browser installed at first sign-in, and your own scripts. |
| Transparent | Every registry value is listed in docs/TWEAKS.md, every app in docs/APPS.md. Each ISO gets a .json manifest and a .sha256 file. |
| Safe by construction | Options are validated early. Offline registry guards protect live paths; failures stop and attempt cleanup, retaining files when dismount/state is unsafe. The downloaded oscdimg.exe is checksum-pinned. |
| Tested | About 1,900 core checks plus real media/export fixtures; PowerShell 5.1 and 7 CI. See the dated verification matrix for exact counts and limits. |
- Download a Windows 11 ISO from microsoft.com/software-download/windows11.
- Double-click
LAUNCH_TINY11.batand press 1 (graphical builder). It asks for administrator rights. - In Source, browse to the ISO and choose an edition, for example Windows 11 Pro. Its editions load automatically without mounting. For a typed path or existing drive, click Load editions.
- Optionally adjust the other tabs, then click Build ISO. Time depends on source/options/storage/CPU; the measured maximum run took 21 minutes. See the performance report.
- Write the ISO to a USB stick with Rufus (keep its default options) or attach it to a VM.
From an elevated PowerShell prompt, the same in one line:
.\tiny11maker.ps1 -ISO C:\iso\Win11_25H2_English_x64.iso -Edition Pro -YesThe ISO is written next to the scripts as tiny11.iso (tiny11core.iso for Core), with
tiny11.iso.json (what was built and how) and tiny11.iso.sha256. Logs go to logs\.
- Windows 10 or 11 (x64 or ARM64) and an administrator account.
- Windows PowerShell 5.1 (
powershell.exe, built into Windows) or PowerShell 7 (pwsh.exe, including the Microsoft Store build). Under PowerShell 7 the in-box DISM module fails on mounted images ("Class not registered"), so the builder loads it through the Windows PowerShell compatibility session automatically; nothing to configure. - About 25 GB free on an NTFS drive: 1.5 × the image size, at least 20 GB. The GUI shows the free space and warns before you start.
oscdimg.exeis taken from the Windows ADK if installed. Otherwise it is downloaded before image work and retained intools\oscdimg\2.56, from Microsoft's symbol server and verified against a pinned SHA-256.
tiny11gui.ps1 (option 1 of LAUNCH_TINY11.bat) exposes the common build choices. -WorkDirectory is currently CLI-only. Compression engine/effort/thread settings can be stored in profiles and forwarded, but do not have dedicated visible controls.
- It remembers your last settings in
gui-settings.json(never the password). - Save profile / Load profile stores a whole configuration, so you can rebuild it for every new Windows release in two clicks.
- Everything maps 1:1 to the command line; the Build tab shows the exact command.
| Tab | What you set |
|---|---|
| 1 Source | ISO file or drive; edition list with build, architecture, language and size; Standard or Core builder; output ISO; work drive (with free space); compression; quick test build; boot without "Press any key"; dry run |
| 2 Preset & features | Preset, plus each of its 22 flags as a checkbox (hover for details). Changed flags become a custom preset automatically. Load and save preset files. |
| 3 Apps | The full removal list by category (uncheck to keep an app), your own package prefixes, import/export of lists, the optional apps to keep, and "keep everything". |
| 4 Tweaks | All 28 registry tweak groups and what enables each. Uncheck to skip a group; check a greyed one to turn on its flag. Every value of the selected group is shown. |
| 5 Setup & account | Local admin and password, or create the account in OOBE. Language/keyboard, time zone, computer name, zero-touch install, custom answer file. Preview or save the generated autounattend.xml. |
| 6 Extras | .NET 3.5, a driver folder (the .inf files are counted), a browser, payload scripts, the low-RAM profile, no driver updates, and the Defender exclusion on the build PC. |
| 7 Build | Plan, checks and the equivalent command line. During the build: overall and current-step progress, elapsed time, rough total ETA and measured step ETA when enough progress is available, a colour-coded log, Cancel, logs and output buttons. Steps without a measurable percentage show an animated bar. |
![]() |
![]() |
![]() |
![]() |
![]() |
![]() |
The build runs as a hidden, non-interactive PowerShell process of the same edition as the
GUI (powershell.exe or pwsh.exe). Its arguments go through a
temporary file that is deleted immediately, so a password never appears on a command line.
Standard — tiny11maker.ps1 |
Core — tiny11Coremaker.ps1 |
|
|---|---|---|
| For | PCs, laptops, long-lived VMs | disposable VMs, test rigs, CI |
| Windows Update, language packs, features | keep working | impossible after the build |
| Defender | retained by Default; configurable offline policies | removed/disabled by Core choices |
| WinRE / "Reset this PC" | kept | removed |
| WinSxS | cleaned (/StartComponentCleanup /ResetBase) |
rebuilt with only the servicing stack |
| Edge WebView2 | kept (removed only with Minimal-VM) | removed |
| Default preset | Default | Minimal-VM |
A preset is a set of on/off flags (presets/*.json). The
tweak matrix shows which registry groups
each preset applies, and docs/APPS.md shows which apps depend
on the preset.
| Preset | For | Compared with Default |
|---|---|---|
| Default | everyone | Removes bloat apps, Edge, OneDrive and AI features; telemetry off. Keeps the Store, Defender, WebView2 and Mark-of-the-Web. |
| Gaming | gaming PCs | Keeps the Xbox app, Game Bar and Xbox sign-in. Adds the Ultimate Performance power plan, raw mouse input, fast shutdown and firewall rules that block telemetry. |
| PrivacyPlus | privacy first | Adds firewall rules that block telemetry and fast shutdown. Defender stays on but sends no cloud reports or samples. |
| Minimal-VM | lab VMs | Also removes the Store, WebView2 and Defender (no antivirus), and turns off Mark-of-the-Web. |
To make your own preset, change the checkboxes in the GUI and click Save as preset, or
copy a JSON file. Then use it with -Preset .\my-preset.json. Missing flags inherit from
Default.
Both builders share the main options. -LowRam, -DisableDriverUpdates and
-Custom are Standard-only CLI parameters; Core does not accept them. Core asks about .NET 3.5 when run interactively. Run Get-Help .\tiny11maker.ps1 -Full
for the built-in help.
# Check everything first, build nothing
.\tiny11maker.ps1 -ISO C:\iso\Win11.iso -Edition Pro -DryRun
# Gaming preset, keep Paint and Snipping Tool, install Firefox at first sign-in
.\tiny11maker.ps1 -ISO E -Edition Pro -Preset Gaming -Keep Paint,SnippingTool -Browser Firefox -Yes
# Unattended VM install that WIPES DISK 0, with a UK locale and a named account
.\tiny11maker.ps1 -ISO E -Edition Pro -ZeroTouch -User Alice -Password "S3cret!" `
-Locale en-GB -TimeZone "GMT Standard Time" -ComputerName TINY11-VM -Yes
# Smallest possible image for throw-away VMs
.\tiny11Coremaker.ps1 -ISO E -Edition Pro -YesSource and output
| Option | Meaning |
|---|---|
-ISO <path|letter> |
A Windows 11 .iso file, or the drive letter of a mounted ISO or USB stick |
-Edition <name> / -Index <n> |
The edition to build, e.g. Pro, Home, "Windows 11 Pro N" (the exact name or its last word), or its index |
-SCRATCH <letter> |
NTFS drive for the legacy root work folders (default: the scripts' drive) |
-WorkDirectory <absolute folder> |
CLI-only isolated work root; new or empty local NTFS folder. Overrides work-root placement, but shared hive aliases still require one build at a time. |
-OutputIso <path> |
Where to write the ISO |
-Compress maximum|balanced|fast|none |
maximum (default) writes install.esd, the smallest ISO; the others write install.wim |
-CompressionEngine Auto|Wimlib|Dism |
Auto prefers the portable pinned wimlib compressor; DISM is available as a fallback |
-CompressionLevel <1-200> |
wimlib compression effort; 100 (high) by default |
-CompressionThreads <n> |
Zero (default) chooses threads based on CPU and memory; no host priority settings are changed |
-Fast |
Fast compression and no component cleanup (quick test builds) |
-NoPrompt |
The ISO boots straight into Setup without "Press any key" (implied by -ZeroTouch) |
maximum means solid LZMS compression; balanced means LZX. The old recovery
and max spellings remain accepted for existing commands and saved profiles.
DISM's API still requires those historical names internally. Maximum compression
is applied once, at the end. The initial edition export reuses ordinary WIM
compressed resources where possible; solid ESD sources are converted to a
standard WIM for servicing. See performance measurements and dependency audit.
The build bug investigation records reproduced failures,
upstream size/Setup regressions, safeguards and the limits of current verification.
What is removed
| Option | Meaning |
|---|---|
-Preset <name|file.json> |
Default, Gaming, PrivacyPlus, Minimal-VM, or your own JSON file |
-Keep a,b / -Remove a,b |
Optional apps: Terminal, Calculator, Notepad, Photos, Paint, Camera, SoundRecorder, StickyNotes, Clock, MediaPlayer, MoviesTV, SnippingTool |
-KeepApps |
Remove no provisioned app at all |
-PackageList <file> |
Your own list instead of removePackage.txt |
-Custom |
Pick the apps to remove interactively in the console (and decide on Edge and OneDrive) |
-SkipTweak Id1,Id2 |
Leave out tweak groups; the ids are in docs/TWEAKS.md |
-LowRam |
Extra trimming for 1–2 GB PCs (Windows Update and Defender untouched) |
-DisableDriverUpdates |
Windows Update will not install drivers |
What is added
| Option | Meaning |
|---|---|
-EnableNetFx3 |
Enable .NET Framework 3.5 from the ISO |
-DriverPath <folder> |
Inject .inf drivers into Windows and into Setup (e.g. Intel RST/VMD, so Setup can see the disk) |
-Browser Firefox|Chrome |
Silent install at the first sign-in; waits for the network |
-Payload |
Run your scripts from payload\packages at the end of Setup (details) |
Installation and first start (built into the ISO's answer file)
| Option | Default | Meaning |
|---|---|---|
-User / -Password |
User / empty |
Local administrator created by Setup, signed in automatically once. The password is stored Base64-obfuscated, and the answer files are deleted after the first sign-in. |
-InteractiveOobe |
off | Create no account; Windows asks for a local user name instead |
-Locale xx-YY |
ask in OOBE | Language, region and keyboard (e.g. de-DE); skips those setup pages |
-TimeZone <id> |
UTC |
Any id from tzutil /l, e.g. "W. Europe Standard Time" |
-ComputerName <name> |
random | 1–15 letters, digits or - |
-ZeroTouch |
off | Wipes disk 0 and installs with no questions (UEFI/GPT). For VMs and test PCs. |
-UnattendFile <xml> |
— | Your own answer file; its image index is pointed at the exported edition |
Build behaviour
| Option | Meaning |
|---|---|
-DryRun |
Validate and print the plan without image patch/export/mastering. Writes logs and may attach/release the source; legacy stale-state cleanup can occur without WorkDirectory. |
-Yes |
Never prompt. Needs -ISO, and -Edition/-Index for multi-edition ISOs |
-DefenderExclusion |
Temporarily exclude the work folders from this PC's Defender scan; removed at the end |
In PowerShell, lists work as -Keep Paint,Camera; from cmd, write -Keep "Paint,Camera".
- Normalizes/validates options and loads the servicing prerequisites. A real build prepares the ISO writer early, before long image work; a dry run skips its download.
- Resolves the source, selects the actual edition and records source metadata. Source/work-tree overlap is rejected. Prefer a fresh isolated
-WorkDirectoryfor manual runs; legacy root layout includes stale-state recovery and is not safe alongside another writer. - Tests a disposable offline hive before copying/mounting, copies setup media excluding the original install image, and exports only the chosen source edition. Ordinary WIM resources can be reused without re-encoding; solid ESD becomes a mountable WIM.
- Mounts the image and performs planned app/capability/Edge/OneDrive changes and optional .NET/driver injection. Core also reduces component packages, WinRE and WinSxS.
- Loads owned offline hives, applies the tweak catalog and removes offline telemetry tasks. SYSTEM template paths follow the image's
Select\Default; denied DWORDs receive verified file-only repair after unload. - Stages generated/custom answer files and SetupComplete/FirstLogon hooks, applies normal component cleanup unless skipped, then commits/unmounts.
- Exports the final selected compression format once and validates actual source edition/language/product metadata. Only missing source-derived fields may be restored via supported wimlib operations; conflicts fail.
- Patches small Setup hive files without a boot mount where supported; driver/fallback servicing uses a separate boot mount. Writes the final answer file.
- Refuses duplicate/intermediate installation images, masters the ISO with the prepared Oscdimg path, hashes it and writes JSON/SHA sidecars. Releases owned attachments and cleans safe work folders.
Failure and GUI Cancel attempt cleanup. If dismount fails or mount state is unknown, image files are retained. Check the actual state before any replacement; cleanup is not guaranteed, separate folders are not a global concurrency lock, and counted warnings need inspection. See PROJECT_GUIDE.md for the complete mechanism and BUILD_BUG_REPORT.md for unresolved failures.
- Setup creates your account and signs in once automatically, unless you chose to create the account in OOBE.
- Software:
winget(App Installer) is always kept, e.g.winget install Mozilla.Firefox 7zip.7zip VideoLAN.VLC. - Logs on the installed system:
C:\Windows\Setup\Tiny11\setupcomplete.logandfirstlogon.log. - Undoing a tweak: every value is listed in docs/TWEAKS.md. Most are
policies under
HKLM\SOFTWARE\Policies; delete the value to restore the Windows default. - Getting Edge back: delete
HKLM\SOFTWARE\Policies\Microsoft\EdgeUpdate, then runwinget install Microsoft.Edge.
| What | Where |
|---|---|
| Apps removed by default | removePackage.txt, one package-name prefix per line (or the Apps tab) |
| Optional apps and their defaults | Get-OptionalUtilities in lib/tiny11utils.psm1 |
| Registry tweaks | data/tweaks.psd1: add a value to a group, or a new group with a When flag |
| Presets | presets/*.json, or Save as preset in the GUI |
| Scripts run after Setup | payload/packages/ with -Payload |
| Browser installers | Browsers/ |
After editing the catalog, the presets or the answer-file generator, run
.\scripts\update-generated.ps1. It refreshes docs/TWEAKS.md, docs/APPS.md, the reference
answer files and the module manifests.
| Symptom | Fix |
|---|---|
| Hive unload / commit failure | Stop the owned writer and close handles into the offline work folder. Verify owned mounts/hives before retrying; preserve image files if dismount/state is unsafe. See the bug report. |
| "Filename or extension is too long" during hive load | A 33-character path still failed in controlled tests; CIM launching succeeded, but the Windows cause is unresolved. The early hive preflight detects it. See the launch-context investigation; do not change host security settings. |
| Slow build / apparently stalled percentage | Consult stage logs and PERFORMANCE.md. Maximum LZMS dominated the measured run; overall percentage/ETA is approximate. Do not overlap DISM writers or change this session's host settings. |
| "Load editions" fails | The ISO must contain sources\install.wim or install.esd. Editions are read through the bundled UDF/ISO9660 reader, without elevation, mounting, downloads or cached guesses. Malformed, encrypted or split images need suitable source media. |
| Setup rejects product-key/edition validation | Verify the chosen edition, source-derived final XML and any custom answer file. A successful build alone cannot rule out the upstream metadata failure. Firmware keys/activation depend on the target and matching edition. |
| Setup cannot see the disk (Intel VMD/RST laptops) | Point the drivers folder at the extracted Intel RST "F6" drivers. |
| The ISO does not boot on an old BIOS PC | x64 ISOs boot on BIOS, but zero-touch partitions for UEFI/GPT. Install interactively instead. |
| Anything else | Run a dry run, then read the log in logs\. It records every value written. |
LAUNCH_TINY11.bat Menu launcher (GUI / Standard / Core), elevates itself
Run.bat Runs tiny11maker.ps1 with your arguments
tiny11gui.ps1 Graphical builder (every option, live build log)
tiny11maker.ps1 Standard (serviceable) builder
tiny11Coremaker.ps1 Core (minimal, non-serviceable) builder
tiny11LegacyProfile.ps1 Compatibility shim for the old low-RAM profile
removePackage.txt Apps removed by default
autounattend*.xml Reference answer files (generated)
data/tweaks.psd1 Registry tweak catalog, the single source of truth
presets/*.json Build presets
lib/tiny11utils.psm1 Build library: DISM/registry helpers, catalog engine, answer-file
generator, removal planning, shared build stages, ISO creation
lib/tiny11gui.psm1 Windows Forms window, state -> builder arguments, build runner
lib/tiny11media.psm1 Read-only bundled optical/WIM metadata reader
lib/OfflineRegistry.cs File-only protected image-hive DWORD repair
data/reference-repos.json Exact reference URLs and branches
payload/ Your post-install scripts (-Payload)
Browsers/ Browser installers run at the first sign-in (-Browser)
docs/ Handoff/architecture/verification and detailed reports; generated catalogs
docs/verification/ Compact dated measurement/audit evidence
scripts/ Tests, parse check, linter, generators, test fixtures
repos/ Reference forks (git-ignored, for study only)
.\scripts\parse-check.ps1 # every file parses, every command resolves
.\scripts\test-core-helpers.ps1 # ~1,900 checks, no admin rights and no ISO needed
.\scripts\test-media-progress.ps1 # real ISO metadata/progress fixtures
.\scripts\test-export-pipeline.ps1 # real small WIM/ESD fixtures
.\scripts\update-generated.ps1 # docs, reference answer files, manifests (-Check fails if stale)
.\scripts\linter.ps1 # PSScriptAnalyzer, high-signal rules
.\scripts\update-screenshots.ps1 # re-render docs\gui-*.png (window-only rendering)The tests cover:
- every catalog entry and the presets;
- the generated and reference answer files, checked against an allow-list of real unattend settings (one unknown element makes Windows Setup abort);
- app, capability and package removal planning;
- the build stages, run against mocked DISM and registry functions;
- the GUI logic, the build launcher, and the whole window driven end to end with a fake builder that never touches the system.
CI checks both Windows PowerShell 5.1 and PowerShell 7. A real ISO build needs admin rights and a Windows ISO: test those changes in a VM (dry run first) and mention the build you used in the pull request. See CONTRIBUTING.md and CHANGELOG.md.
main holds the complete history of ntdevlabs/tiny11builder
(100 commits), followed by the 2026 edition as regular commits, so every change can be traced
back to the original with git log / git blame.
Ideas and fixes were studied in these projects and selectively adapted (code is downloaded under repos/).
The tracked reference list, refresh script and
comparison report record all 21 checkouts, exact branches and revisions:
| Project | Ideas used |
|---|---|
| ntdevlabs/tiny11builder | The original: offline debloat, hardware bypass, answer file |
| chrisGrando/tiny11maker-reforged | GUI, launcher, ISO auto-mount, final install.esd export |
| vinisebold/tiny11builder-revamped | Shared module, TaskCache ACL takeover, cleanup trap, app selector |
| zPoche/tiny11builder-v2 | Pre-flight checks, dry run, quick builds, ARM64, the mount-folder fix |
| YmlyZA/tiny11builder | Tests, linter, build summary, keep/remove utilities, zero-touch |
| namnguyen97x/tiny-auto-builder | Presets, driver injection, retrying dismount/unload |
| bluecloud122/tiny11builder | Low-RAM profile, ISO sanity checks |
| MOPELotus/tiny11builder | Payload / SetupComplete design, OOBE page tweaks, stale-state recovery |
| SamHimmy/tiny11builder | 24H2/25H2 AI, Recall and Widgets policies |
| keepitupkitty/tiny11builder | Paint/Notepad AI policies, Edge and OneDrive leftovers |
| user129233/tiny11builder | Specialize-pass commands, answer-file cleanup after sign-in |
| DFveloper/DFwindows11_builder | Browser installers, language-independent ACL handling |
| prismatecas-ui/tiny11builder | GUI option ideas, installed-apps inventory |
| bedlaj/tiny11builder | ADK lookup through the registry |
| AhmedLolyProductions/Loly11 | Package-list entries |
| u0reo/tiny11builder, feature/25h2-patch | Cloud-search policy; broader removals/raw XML repair reviewed selectively |
| luyingwei80/tiny11builder, Tony-patch-multi | Multiple-edition deployment reference; retain our single-edition default |
| pi0n00r/tiny11builder, deployment/2026-26h2 | Offline default control-set selection and source/workspace separation |
| 391546581/tiny11builder | CI workflows studied; original builder code unchanged |
| icis-org/tiny11builder | Build workflow studied; original builder code unchanged |
| lexp-hub/tiny11builder.sh | Linux/macOS port studied; file-only boot-update idea already covered |
MIT, see LICENSE. Windows is a trademark of Microsoft. This project ships no Microsoft files; you supply your own ISO.






