Windows 11 S Mode Image
Overview
This guide walks through creating a Windows 11 Home image with S mode enabled, adding the Manufacturing Mode key for Audit Mode customizations, removing the key, and preparing the image for deployment.
Key rules
- Use a Windows 11 Home image only.
- Never ship a device with the Manufacturing Mode key still present.
- Secure Boot must be enabled on the target hardware.
1. Prerequisites
- Windows Assessment and Deployment Kit (ADK) + WinPE add-on
- Official Windows 11 ISO → extract install.wim and full ISO
- Technician PC
- Reference PC (for Audit Mode)
- USB drive for WinPE (recommended)
2. Create the unattend.xml (Enable S Mode)
Option A – Using Windows System Image Manager (recommended)
- Open Windows System Image Manager.
- File → Select Windows Image → choose your install.wim → select Windows 11 Home.
- Create the catalog when prompted.
- File → New Answer File.
- In the Windows Image pane, expand Components.
- Right-click amd64_Microsoft-Windows-CodeIntegrity → Add Setting to Pass 2 offlineServicing.
- Set SkuPolicyRequired = 1.
- Save as unattend.xml.
Option B – Manual XML (copy-paste ready)
<?xml version="1.0" encoding="utf-8"?>
<unattend xmlns="urn:schemas-microsoft-com:unattend">
<settings pass="offlineServicing">
<component name="Microsoft-Windows-CodeIntegrity"
processorArchitecture="amd64"
publicKeyToken="31bf3856ad364e35"
language="neutral"
versionScope="nonSxS"
xmlns:wcm="http://schemas.microsoft.com/WMIConfig/2002/State"
xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance">
<SkuPolicyRequired>1</SkuPolicyRequired>
</component>
</settings>
</unattend>
3. Mount the Image and Enable S Mode + Manufacturing Mode
Open an elevated Deployment and Imaging Tools Environment (or Command Prompt).
:: Create mount folder
mkdir C:\mount\windows
:: Mount the image (use correct Index for Windows 11 Home)
DISM /Mount-Image /ImageFile:C:\path\to\install.wim /Index:1 /MountDir:C:\mount\windows
:: Create Panther folder and copy unattend.xml
mkdir C:\mount\windows\Windows\Panther
copy unattend.xml C:\mount\windows\Windows\Panther\unattend.xml
:: Apply unattend (enables S mode)
DISM /Image:C:\mount\windows /Apply-Unattend:C:\mount\windows\Windows\Panther\unattend.xml
:: Add Manufacturing Mode registry key
reg load HKLM\Windows10S C:\mount\windows\Windows\System32\config\SYSTEM
reg add HKLM\Windows10S\ControlSet001\Control\CI\Policy /v ManufacturingMode /t REG_DWORD /d 1 /f
reg unload HKLM\Windows10S
4. (Optional) Add Drivers / Language Packs / UWP Apps
While the image is still mounted:
cmd
:: Example – add drivers
DISM /Image:C:\mount\windows /Add-Driver /Driver:C:\Drivers /Recurse
:: Example – add language pack
DISM /Image:C:\mount\windows /Add-Package /PackagePath:C:\LanguagePacks\Microsoft-Windows-Client-Language-Pack_x64_de-de.cab
Only use supported (signed / Store / MSIX) components.
5. Unmount and Commit
DISM /Unmount-Image /MountDir:C:\mount\windows /Commit
6. Deploy Image to Reference PC and Boot into Audit Mode
- Boot the reference PC from WinPE.
How to Boot the Reference PC into WinPE
You need a bootable WinPE USB (created with the Windows ADK). Then force the reference PC to boot from that USB instead of the internal drive.
Part 1: Create a Bootable WinPE USB (on your Technician PC)
- Install the Windows ADK + Windows PE add-on (if you haven’t already).
- Open Deployment and Imaging Tools Environment as Administrator.
- Create the working files:
cmd
copype amd64 C:\WinPE_amd64(Use arm64 instead of amd64 if the reference PC is ARM-based.) - Plug in a USB drive (8 GB or larger is recommended). Warning: The next step will erase everything on the USB.
- Create the bootable USB:
cmd
MakeWinPEMedia /UFD C:\WinPE_amd64 X:- Replace X: with the actual drive letter of your USB stick.
- On newer ADK versions (December 2024+), you can add /bootex for the newer UEFI 2023 signing:
cmd
MakeWinPEMedia /UFD C:\WinPE_amd64 X: /bootex
- When finished, safely eject the USB. It is now bootable.
Optional – Multi-partition USB (recommended if you want to store large WIM files > 4 GB): Create a small FAT32 partition for WinPE and a larger NTFS partition for images. See Microsoft’s “Create a multipartition USB drive” documentation for the exact DiskPart commands.
Part 2: Boot the Reference PC into WinPE
- Insert the WinPE USB into the reference PC.
- Restart (or power on) the reference PC.
- Immediately press the key that opens the Boot Menu (or Firmware/BIOS settings). Common keys:
- F12, F10, F9, Esc, or Del
- The exact key depends on the manufacturer (Dell, HP, Lenovo, ASUS, etc.). It is usually shown briefly on the splash screen.
- In the Boot Menu:
- Select the USB drive.
- Prefer the UEFI entry if available (e.g. “UEFI: USB…” or “EFI USB Device”).
- Avoid Legacy/CSM mode if possible (modern Windows 11 deployments use UEFI).
- The PC should now boot into Windows PE. You will see a black command-prompt window. After a short delay, wpeinit runs automatically and initializes networking/drivers.
Troubleshooting if it doesn’t boot
| Problem | Solution |
|---|---|
| USB not listed in boot menu | Try a different USB port (prefer USB 2.0 if available). Disable Secure Boot temporarily if needed. |
| Boots to internal Windows instead | Change boot order in BIOS/UEFI so USB is first, or use the one-time Boot Menu every time. |
| “No bootable device” or hangs | Recreate the USB with MakeWinPEMedia. Make sure you used the correct architecture (amd64 / arm64). |
| UEFI vs Legacy | Force UEFI mode in the firmware. On some systems you may need to manually select \EFI\BOOT\BOOTX64.EFI. |
| Secure Boot blocks it | Temporarily disable Secure Boot, or use the /bootex option with a recent ADK. |
RESUME >
- Apply the image (example):
Quick Tip
Once you are in WinPE you can type:
diskpart
list vol
completely wipe the disk and create clean partitions (UEFI example):
diskpart
select disk 0
clean
convert gpt
create partition efi size=100
format quick fs=fat32 label="System"
assign letter=S
create partition msr size=16
create partition primary
format quick fs=ntfs label="Windows_11S"
assign letter=C
exit
DISM /Apply-Image /ImageFile:D:\Images\Windows11S.wim /Index:1 /ApplyDir:W:\
W:\Windows\System32\bcdboot W:\Windows /s S:
- Restart the PC. It will boot into Audit Mode because of the Manufacturing Mode key (and if you configured Sysprep to Audit earlier, or force it).
7. Customize in Audit Mode
You can now freely:
- Install drivers
- Install supported apps
- Run scripts
- Use cmd / PowerShell / regedit
Do all customizations now.
8. Remove the Manufacturing Mode Key (Critical)
While still in Audit Mode, open an elevated Command Prompt:
reg delete HKLM\SYSTEM\ControlSet001\Control\CI\Policy /v ManufacturingMode /f
Verify it is gone:
reg query HKLM\SYSTEM\ControlSet001\Control\CI\Policy
9. Sysprep and Capture
Still in Audit Mode:
:: Generalize and prepare for OOBE
%windir%\System32\Sysprep\sysprep.exe /oobe /generalize /shutdown
After the PC shuts down, boot back into WinPE and capture the image:
DISM /Capture-Image /ImageFile:D:\Images\Windows11S-Final.wim /CaptureDir:C:\ /Name:"Windows 11 Home S Mode"
10. Recovery Exclusion (Recommended) < I didn't do this
Create ExcludeManufacturingMode.xml:
<?xml version="1.0" encoding="UTF-8"?>
<migration urlid="https://www.microsoft.com/migration/1.0/migxmlext/ExcludeManufacturingMode">
<component type="System">
<displayName>Exclude manufacturing regkey</displayName>
<role role="Settings">
<rules context="System">
<unconditionalExclude>
<objectSet>
<pattern type="Registry">HKLM\SYSTEM\CurrentControlSet\Control\CI\Policy [ManufacturingMode]</pattern>
</objectSet>
</unconditionalExclude>
</rules>
</role>
</component>
</migration>
Use this file with ScanState when creating the recovery package.
Quick Reference Commands
| Action | Command |
|---|---|
| Mount image | DISM /Mount-Image /ImageFile:... /Index:1 /MountDir:C:\mount\windows |
| Apply unattend (S mode) | DISM /Image:C:\mount\windows /Apply-Unattend:... |
| Add Manufacturing Mode | reg add HKLM\Windows10S\ControlSet001\Control\CI\Policy /v ManufacturingMode /t REG_DWORD /d 1 /f |
| Remove Manufacturing Mode | reg delete HKLM\SYSTEM\ControlSet001\Control\CI\Policy /v ManufacturingMode /f |
| Unmount + commit | DISM /Unmount-Image /MountDir:C:\mount\windows /Commit |
| Sysprep | sysprep /oobe /generalize /shutdown |
End of Guide
Robbert Tromp © 2026
No comments to display
No comments to display