# Windows 11 S Mode Image

### Overview

This guide walks through creating a Windows 11 **Home** image with **S mode** enabled, adding the Manufacturing Mode key for Audit Mode customizations, removing the key, and preparing the image for deployment.

**Key rules**

- Use a **Windows 11 Home** image only.
- Never ship a device with the Manufacturing Mode key still present.
- Secure Boot must be enabled on the target hardware.

---

### 1. Prerequisites

- Windows Assessment and Deployment Kit (ADK) + WinPE add-on
- Official Windows 11 ISO → extract install.wim and full ISO
- Technician PC
- Reference PC (for Audit Mode)
- USB drive for WinPE (recommended)

---

### 2. Create the unattend.xml (Enable S Mode)

**Option A – Using Windows System Image Manager (recommended)**

1. Open **Windows System Image Manager**.
2. File → Select Windows Image → choose your install.wim → select **Windows 11 Home**.
3. Create the catalog when prompted.
4. File → New Answer File.
5. In the Windows Image pane, expand **Components**.
6. Right-click amd64\_Microsoft-Windows-CodeIntegrity → **Add Setting to Pass 2 offlineServicing**.
7. Set SkuPolicyRequired = **1**.
8. Save as unattend.xml.

**Option B – Manual XML (copy-paste ready)**

<div dir="auto" id="bkmrk-xml"><div data-testid="code-block"><div><div>XML <div><div>  
</div></div></div><div>  
</div></div></div></div>```
<?xml version="1.0" encoding="utf-8"?>
<unattend xmlns="urn:schemas-microsoft-com:unattend">
  <settings pass="offlineServicing">
    <component name="Microsoft-Windows-CodeIntegrity"
               processorArchitecture="amd64"
               publicKeyToken="31bf3856ad364e35"
               language="neutral"
               versionScope="nonSxS"
               xmlns:wcm="http://schemas.microsoft.com/WMIConfig/2002/State"
               xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance">
      <SkuPolicyRequired>1</SkuPolicyRequired>
    </component>
  </settings>
</unattend>
```

<div dir="auto" id="bkmrk--2"><div data-testid="code-block"><div><div>  
</div><div>  
</div></div><div>  
</div></div></div>---

### 3. Mount the Image and Enable S Mode + Manufacturing Mode

Open an elevated **Deployment and Imaging Tools Environment** (or Command Prompt).

<div dir="auto" id="bkmrk-cmd"><div data-testid="code-block"><div><div>cmd <div><div>  
</div></div></div><div>  
</div></div></div></div>```
:: Create mount folder
mkdir C:\mount\windows

:: Mount the image (use correct Index for Windows 11 Home)
DISM /Mount-Image /ImageFile:C:\path\to\install.wim /Index:1 /MountDir:C:\mount\windows

:: Create Panther folder and copy unattend.xml
mkdir C:\mount\windows\Windows\Panther
copy unattend.xml C:\mount\windows\Windows\Panther\unattend.xml

:: Apply unattend (enables S mode)
DISM /Image:C:\mount\windows /Apply-Unattend:C:\mount\windows\Windows\Panther\unattend.xml

:: Add Manufacturing Mode registry key
reg load HKLM\Windows10S C:\mount\windows\Windows\System32\config\SYSTEM
reg add HKLM\Windows10S\ControlSet001\Control\CI\Policy /v ManufacturingMode /t REG_DWORD /d 1 /f
reg unload HKLM\Windows10S
```

<div dir="auto" id="bkmrk--4"><div data-testid="code-block"><div><div>  
</div><div>  
</div></div><div>  
</div></div></div>---

### 4. (Optional) Add Drivers / Language Packs / UWP Apps

While the image is still mounted:  
cmd

```
:: Example – add drivers
DISM /Image:C:\mount\windows /Add-Driver /Driver:C:\Drivers /Recurse

:: Example – add language pack
DISM /Image:C:\mount\windows /Add-Package /PackagePath:C:\LanguagePacks\Microsoft-Windows-Client-Language-Pack_x64_de-de.cab
```

<div dir="auto" id="bkmrk--6"><div data-testid="code-block"><div><div>  
</div></div></div></div>Only use supported (signed / Store / MSIX) components.

---

### 5. Unmount and Commit

<div dir="auto" id="bkmrk-cmd-1"><div data-testid="code-block"><div><div>cmd <div><div>  
</div></div></div><div>  
</div></div></div></div>```
DISM /Unmount-Image /MountDir:C:\mount\windows /Commit
```

<div dir="auto" id="bkmrk--8"><div data-testid="code-block"><div><div>  
</div><div>  
</div></div><div>  
</div></div></div>---

### 6. Deploy Image to Reference PC and Boot into Audit Mode

1. Boot the reference PC from WinPE.

**How to Boot the Reference PC into WinPE**

You need a **bootable WinPE USB** (created with the Windows ADK). Then force the reference PC to boot from that USB instead of the internal drive.

---

### Part 1: Create a Bootable WinPE USB (on your Technician PC)

1. Install the **Windows ADK** + **Windows PE add-on** (if you haven’t already).
2. Open **Deployment and Imaging Tools Environment** as **Administrator**.
3. Create the working files: <div dir="auto"><div data-testid="code-block"><div><div>cmd <div><div>  
    </div></div></div><div>  
    </div></div></div></div>```
    copype amd64 C:\WinPE_amd64
    ```
    
    <div dir="auto"><div data-testid="code-block"><div><div>  
    </div><div>  
    </div></div><div>  
    </div></div></div>(Use arm64 instead of amd64 if the reference PC is ARM-based.)
4. Plug in a USB drive (8 GB or larger is recommended). **Warning**: The next step will erase everything on the USB.
5. Create the bootable USB: <div dir="auto"><div data-testid="code-block"><div><div>cmd <div><div>  
    </div></div></div><div>  
    </div></div></div></div>```
    MakeWinPEMedia /UFD C:\WinPE_amd64 X:
    ```
    
    <div dir="auto"><div data-testid="code-block"><div><div>  
    </div><div>  
    </div></div><div>  
    </div></div></div>
    - Replace X: with the actual drive letter of your USB stick.
    - On newer ADK versions (December 2024+), you can add /bootex for the newer UEFI 2023 signing: <div dir="auto"><div data-testid="code-block"><div><div>cmd <div><div>  
        </div></div></div><div>  
        </div></div></div></div>```
        MakeWinPEMedia /UFD C:\WinPE_amd64 X: /bootex
        ```
        
        <div dir="auto"><div data-testid="code-block"><div><div>  
        </div><div>  
        </div></div><div>  
        </div></div></div>
6. When finished, safely eject the USB. It is now bootable.

**Optional – Multi-partition USB** (recommended if you want to store large WIM files &gt; 4 GB): Create a small FAT32 partition for WinPE and a larger NTFS partition for images. See Microsoft’s “Create a multipartition USB drive” documentation for the exact DiskPart commands.

---

### Part 2: Boot the Reference PC into WinPE

1. Insert the WinPE USB into the **reference PC**.
2. Restart (or power on) the reference PC.
3. Immediately press the key that opens the **Boot Menu** (or Firmware/BIOS settings). Common keys: 
    - **F12**, **F10**, **F9**, **Esc**, or **Del**
    - The exact key depends on the manufacturer (Dell, HP, Lenovo, ASUS, etc.). It is usually shown briefly on the splash screen.
4. In the Boot Menu: 
    - Select the **USB drive**.
    - Prefer the **UEFI** entry if available (e.g. “UEFI: USB…” or “EFI USB Device”).
    - Avoid Legacy/CSM mode if possible (modern Windows 11 deployments use UEFI).
5. The PC should now boot into Windows PE. You will see a black command-prompt window. After a short delay, wpeinit runs automatically and initializes networking/drivers.

---

### Troubleshooting if it doesn’t boot

<div id="bkmrk-problem-solution-usb"><div><div><div dir="auto"><table dir="auto"><thead><tr><th data-col-size="md">Problem</th><th data-col-size="lg">Solution</th></tr></thead><tbody><tr><td data-col-size="md">USB not listed in boot menu</td><td data-col-size="lg">Try a different USB port (prefer USB 2.0 if available). Disable Secure Boot temporarily if needed.</td></tr><tr><td data-col-size="md">Boots to internal Windows instead</td><td data-col-size="lg">Change boot order in BIOS/UEFI so USB is first, or use the one-time Boot Menu every time.</td></tr><tr><td data-col-size="md">“No bootable device” or hangs</td><td data-col-size="lg">Recreate the USB with MakeWinPEMedia. Make sure you used the correct architecture (amd64 / arm64).</td></tr><tr><td data-col-size="md">UEFI vs Legacy</td><td data-col-size="lg">Force UEFI mode in the firmware. On some systems you may need to manually select \\EFI\\BOOT\\BOOTX64.EFI.</td></tr><tr><td data-col-size="md">Secure Boot blocks it</td><td data-col-size="lg">Temporarily disable Secure Boot, or use the /bootex option with a recent ADK.</td></tr></tbody></table>

</div></div></div></div>RESUME &gt;

1. Apply the image (example):

### Quick Tip

Once you are in WinPE you can type:

<div dir="auto" id="bkmrk-cmd-2"><div data-testid="code-block"><div><div>cmd <div><div>  
</div></div></div><div>  
</div></div></div></div>```
diskpart
list vol
```

completely wipe the disk and create clean partitions (UEFI example):

```
diskpart
select disk 0
clean
convert gpt
create partition efi size=100
format quick fs=fat32 label="System"
assign letter=S
create partition msr size=16
create partition primary
format quick fs=ntfs label="Windows_11S"
assign letter=C
exit
```

<div dir="auto" id="bkmrk-cmd-3"><div data-testid="code-block"><div>  
</div><div>cmd <div><div>  
</div></div></div><div>  
</div></div></div>```
DISM /Apply-Image /ImageFile:D:\Images\Windows11S.wim /Index:1 /ApplyDir:W:\
W:\Windows\System32\bcdboot W:\Windows /s S:
```

<div dir="auto" id="bkmrk--13"><div data-testid="code-block"><div><div>  
</div><div>  
</div></div><div>  
</div></div></div>3. Restart the PC. It will boot into **Audit Mode** because of the Manufacturing Mode key (and if you configured Sysprep to Audit earlier, or force it).

---

### 7. Customize in Audit Mode

You can now freely:

- Install drivers
- Install supported apps
- Run scripts
- Use cmd / PowerShell / regedit

**Do all customizations now.**

---

### 8. Remove the Manufacturing Mode Key (Critical)

While still in Audit Mode, open an elevated Command Prompt:

<div dir="auto" id="bkmrk-cmd-4"><div data-testid="code-block"><div><div>cmd <div><div>  
</div></div></div><div>  
</div></div></div></div>```
reg delete HKLM\SYSTEM\ControlSet001\Control\CI\Policy /v ManufacturingMode /f
```

<div dir="auto" id="bkmrk--16"><div data-testid="code-block"><div><div>  
</div><div>  
</div></div><div>  
</div></div></div>Verify it is gone:

<div dir="auto" id="bkmrk-cmd-5"><div data-testid="code-block"><div><div>cmd <div><div>  
</div></div></div><div>  
</div></div></div></div>```
reg query HKLM\SYSTEM\ControlSet001\Control\CI\Policy
```

<div dir="auto" id="bkmrk--17"><div data-testid="code-block"><div><div>  
</div><div>  
</div></div><div>  
</div></div></div>---

### 9. Sysprep and Capture

Still in Audit Mode:

<div dir="auto" id="bkmrk-cmd-6"><div data-testid="code-block"><div><div>cmd <div><div>  
</div></div></div><div>  
</div></div></div></div>```
:: Generalize and prepare for OOBE
%windir%\System32\Sysprep\sysprep.exe /oobe /generalize /shutdown
```

<div dir="auto" id="bkmrk--19"><div data-testid="code-block"><div><div>  
</div><div>  
</div></div><div>  
</div></div></div>After the PC shuts down, boot back into WinPE and capture the image:

<div dir="auto" id="bkmrk-cmd-7"><div data-testid="code-block"><div><div>cmd <div><div>  
</div></div></div><div>  
</div></div></div></div>```
DISM /Capture-Image /ImageFile:D:\Images\Windows11S-Final.wim /CaptureDir:C:\ /Name:"Windows 11 Home S Mode"
```

<div dir="auto" id="bkmrk--20"><div data-testid="code-block"><div><div>you do not need to capture the image if you are only going to use it on this same machine.</div><div>  
</div></div><div>  
</div></div></div>---

### 10. Recovery Exclusion (Recommended) &lt; I didn't do this

Create ExcludeManufacturingMode.xml:

<div dir="auto" id="bkmrk-xml-1"><div data-testid="code-block"><div><div>XML <div><div>  
</div></div></div><div>  
</div></div></div></div>```
<?xml version="1.0" encoding="UTF-8"?>
<migration urlid="https://www.microsoft.com/migration/1.0/migxmlext/ExcludeManufacturingMode">
  <component type="System">
    <displayName>Exclude manufacturing regkey</displayName>
    <role role="Settings">
      <rules context="System">
        <unconditionalExclude>
          <objectSet>
            <pattern type="Registry">HKLM\SYSTEM\CurrentControlSet\Control\CI\Policy [ManufacturingMode]</pattern>
          </objectSet>
        </unconditionalExclude>
      </rules>
    </role>
  </component>
</migration>
```

<div dir="auto" id="bkmrk--22"><div data-testid="code-block"><div>  
</div></div></div>Use this file with ScanState when creating the recovery package.

---

### Quick Reference Commands

<div id="bkmrk-action-command-mount"><div><div><div dir="auto"><table dir="auto"><thead><tr><th data-col-size="md">Action</th><th data-col-size="lg">Command</th></tr></thead><tbody><tr><td data-col-size="md">Mount image</td><td data-col-size="lg">DISM /Mount-Image /ImageFile:... /Index:1 /MountDir:C:\\mount\\windows</td></tr><tr><td data-col-size="md">Apply unattend (S mode)</td><td data-col-size="lg">DISM /Image:C:\\mount\\windows /Apply-Unattend:...</td></tr><tr><td data-col-size="md">Add Manufacturing Mode</td><td data-col-size="lg">reg add HKLM\\Windows10S\\ControlSet001\\Control\\CI\\Policy /v ManufacturingMode /t REG\_DWORD /d 1 /f</td></tr><tr><td data-col-size="md">Remove Manufacturing Mode</td><td data-col-size="lg">reg delete HKLM\\SYSTEM\\ControlSet001\\Control\\CI\\Policy /v ManufacturingMode /f</td></tr><tr><td data-col-size="md">Unmount + commit</td><td data-col-size="lg">DISM /Unmount-Image /MountDir:C:\\mount\\windows /Commit</td></tr><tr><td data-col-size="md">Sysprep</td><td data-col-size="lg">sysprep /oobe /generalize /shutdown</td></tr></tbody></table>

</div></div><div><div>  
</div></div></div><div>  
</div></div>---

**End of Guide**

Robbert Tromp © 2026