Files
Workstation-Setup/PHASE-4-WINDOWS-CONFIGURATION.md
2026-09-09 11:11:06 -07:00

19 KiB

PHASE 4: WINDOWS CONFIGURATION BY PROFILE

Operating System Hardening, Optimization & Profile-Specific Settings

Phase Start Date: 2026-09-09
Scope: Design reversible, logged, profile-specific Windows configuration
Outcomes: Windows configuration per profile with detection, planning, application, and rollback


4.1 CONFIGURATION PRINCIPLES

Design Requirements

  1. Detect: Identify current state before making changes
  2. Plan: Show what will change, expected impact
  3. Apply: Execute changes with logging
  4. Verify: Confirm changes took effect
  5. Rollback: Reverse changes if needed (where technically practical)
  6. Document: Log all changes with rationale and recovery info
  7. Safe: No changes that cannot be detected/recovered from

Implementation Pattern

function Set-WindowsConfiguration {
    param(
        [Parameter(Mandatory)][ValidateSet('Detect', 'Plan', 'Apply', 'Verify', 'Rollback')]
        [string]$Mode
    )
    
    $current = Get-CurrentSetting
    $desired = $DesiredConfiguration[$Profile]
    
    if ($Mode -eq 'Detect') {
        return $current
    }
    elseif ($Mode -eq 'Plan') {
        return Compare-Configuration -Current $current -Desired $desired
    }
    elseif ($Mode -eq 'Apply') {
        Set-SettingValue -Value $desired.Value
        Verify-SettingChanged
    }
    elseif ($Mode -eq 'Verify') {
        return Test-SettingValue -Expected $desired.Value
    }
    elseif ($Mode -eq 'Rollback') {
        Set-SettingValue -Value $current.Value
        Verify-SettingChanged
    }
}

4.2 CONFIGURATION AREAS

4.2.1 Power Management

Rationale: Automotive diagnostics require consistent power. Sleeping/hibernating mid-operation causes failures.

Setting: Hibernation

  • Detection: powercfg.exe /query SCHEME_CURRENT SUB_SLEEP HIBERNATEFILE
  • DailyTech: Disabled (must stay powered for long tuning sessions)
  • ODIS & XENTRY: Disabled (diagnostic sessions must not sleep)
  • PIWIS & ISTA: Disabled (diagnostic sessions must not sleep)
  • Application:
    powercfg.exe /hibernate off
    
  • Rollback: powercfg.exe /hibernate on
  • Status: ✅ Already implemented in current script

Setting: USB Selective Suspend

  • Rationale: Prevents USB diagnostic interfaces from powering down mid-operation
  • DailyTech: Disabled (critical for interfaces)
  • ODIS & XENTRY: Disabled (critical for J2534)
  • PIWIS & ISTA: Disabled (critical for J2534)
  • Application:
    powercfg.exe /setacvalueindex SCHEME_CURRENT SUB_USB USBSELECTIVE 0  # AC Power
    powercfg.exe /setdcvalueindex SCHEME_CURRENT SUB_USB USBSELECTIVE 0  # Battery
    powercfg.exe /setactive SCHEME_CURRENT
    
  • Detection:
    $acValue = powercfg.exe /query SCHEME_CURRENT SUB_USB USBSELECTIVE | Select-String "AC Power Setting"
    
  • Status: ✅ Already implemented in current script

Setting: Power Plan

  • DailyTech: High Performance
    • Rationale: Full CPU/GPU for long-running analysis tasks
  • ODIS & XENTRY: Balanced
    • Rationale: Diagnostic tool requirements vary; balanced is safer
  • PIWIS & ISTA: Balanced
    • Rationale: Diagnostic tool requirements vary
  • Application:
    powercfg.exe /setactive SCHEME_GUID
    
  • Detection:
    (Get-CimInstance -ClassName Win32_PowerPlan -Namespace root\cimv2\power | 
      Where-Object IsActive -eq $true).ElementName
    
  • Rollback: Switch back to previous plan

Setting: Monitor Sleep

  • DailyTech: Disable (no sleep during long tuning)
  • ODIS & XENTRY: 30 minutes (reasonable for diagnostics)
  • PIWIS & ISTA: 30 minutes
  • Application:
    powercfg.exe /change monitor-timeout-ac 0  # DailyTech
    powercfg.exe /change monitor-timeout-ac 30 # ODIS/PIWIS
    
  • Rollback: Restore previous timeout value

Setting: Disk Sleep

  • All Profiles: Disable (avoid mid-operation failures)
  • Application:
    powercfg.exe /change disk-timeout-ac 0
    

Setting: System Sleep

  • DailyTech: Disable
  • ODIS & XENTRY: 60 minutes
  • PIWIS & ISTA: 60 minutes
  • Application:
    powercfg.exe /change standby-timeout-ac 0  # or value in minutes
    

4.2.2 Windows Update

Setting: Active Hours

  • All Profiles: Set to business hours to prevent mid-operation restarts
    • Start: 08:00 (8 AM)
    • End: 17:00 (5 PM)
  • Application:
    $path = "HKLM:\SOFTWARE\Microsoft\WindowsUpdate\UX\Settings"
    Set-ItemProperty -Path $path -Name ActiveHoursStart -Value 8
    Set-ItemProperty -Path $path -Name ActiveHoursEnd -Value 17
    
  • Detection:
    Get-ItemProperty -Path $path -Name ActiveHoursStart, ActiveHoursEnd
    

Setting: Automatic Restart

  • DailyTech: Manual (user decides when to restart)
  • ODIS & XENTRY: Manual (during breaks)
  • PIWIS & ISTA: Manual (during breaks)
  • Application:
    # Set to "Notify for scheduled restart" instead of auto-restart
    Set-ItemProperty -Path "HKLM:\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU" `
      -Name NoAutoRebootWithLoggedOnUsers -Value 1
    
  • Detection:
    Get-ItemProperty -Path "HKLM:\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU" `
      -Name NoAutoRebootWithLoggedOnUsers
    

4.2.3 Fast Startup

Setting: Enable Fast Startup

  • DailyTech: Enabled (faster boot)
  • ODIS & XENTRY: Enabled
  • PIWIS & ISTA: Enabled
  • Rationale: Faster access to diagnostic tools
  • Application:
    $path = "HKLM:\SYSTEM\CurrentControlSet\Control\Session Manager\Power"
    Set-ItemProperty -Path $path -Name HibernationBootOptimization -Value 1
    
  • Detection:
    Get-ItemProperty -Path $path -Name HibernationBootOptimization
    

4.2.4 File System

Setting: Long Path Support (Windows 10 1607+)

  • All Profiles: Enabled (ECU projects may have deep folder structures)
  • Application:
    # Registry key for long path support
    $path = "HKLM:\SYSTEM\CurrentControlSet\Control\FileSystem"
    Set-ItemProperty -Path $path -Name LongPathsEnabled -Value 1
    
  • Detection:
    (Get-ItemProperty -Path $path -Name LongPathsEnabled).LongPathsEnabled
    

Setting: File Extension Visibility

  • All Profiles: Show all file extensions (critical for .hex, .bin, .eep)
  • Application:
    # HKCU: Hide extensions for known file types = 0 (show)
    $path = "HKCU:\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced"
    Set-ItemProperty -Path $path -Name HideFileExt -Value 0
    
  • Rollback: Set HideFileExt to 1

Setting: Hidden Files Visibility

  • All Profiles: Show hidden files (for debugging/admin tools)
  • Application:
    Set-ItemProperty -Path $path -Name Hidden -Value 1  # 1 = show
    

Setting: Page File Management

  • DailyTech: System Managed (default; allow automatic sizing)
  • ODIS & XENTRY: System Managed
  • PIWIS & ISTA: System Managed
  • Rationale: Page file helps with large EEPROM/binary analysis
  • Detection:
    Get-CimInstance -ClassName Win32_PageFileUsage
    

4.2.5 Storage Health

Setting: Storage Sense

  • All Profiles: Enabled (automatic cleanup)
  • Application:
    $path = "HKCU:\Software\Microsoft\Windows\CurrentVersion\StorageSense\Parameters\StoragePolicy"
    Set-ItemProperty -Path $path -Name `01` -Value 1
    
  • Features to Enable:
    • Delete temporary files when storage is low
    • Delete OneDrive cloud files if not accessed > 30 days (disable for this workstation)

Setting: Free Space Threshold

  • All Profiles: Alert if < 10% free space
  • Application: Implement in HealthCheck function
  • Detection: Compare SizeRemaining / Size ratio

Setting: Disk Defragmentation

  • All Profiles: Automatic weekly (SSDs exempt via WinGet settings)
  • Application:
    $defragSchedule = "defrag C: /U /V"  # Schedule weekly
    

4.2.6 Windows Defender & Security

Setting: Defender Status

  • DailyTech: Enabled (monitor for threats)
    • Note: May flag legitimate tools (binary analysis, reverse engineering)
    • Recommendation: Exclude project folders as needed
  • ODIS & XENTRY: Enabled
  • PIWIS & ISTA: Enabled
  • Detection:
    Get-MpPreference | Select-Object DisableRealtimeMonitoring
    
  • Rationale: Do not disable antivirus globally (defeats security)

Setting: Controlled Folder Access

  • DailyTech: Disabled (tools may access system folders)
  • ODIS & XENTRY: Disabled
  • PIWIS & ISTA: Disabled
  • Rationale: Diagnostic/OEM tools need broad access; manually add exclusions only if required
  • Application:
    Set-MpPreference -EnableControlledFolderAccess Disabled
    

Setting: Firewall

  • All Profiles: Enabled (monitor for unauthorized access)
  • Custom Rules: Allow VPN, remote SSH if needed
  • Detection:
    Get-NetFirewallProfile | Select-Object Name, Enabled
    
  • Rationale: Firewall should remain on; add exceptions only for known services

Setting: Windows Defender Exclusions

  • Pattern: Exclude project folders (if user opts in; NOT automatic)
  • Rationale: Some binary analysis tools trigger false positives
  • Manual Configuration: User should set C:\Automotive\Projects\* exclusions after setup
  • Application: Provide PowerShell snippet for user to run manually

Setting: Device Driver Signature Policy

  • All Profiles: Enforce (require signed drivers)
  • Exception: Only for well-known automotive interfaces (PCAN, J2534, etc.)
  • Rationale: Prevent malicious unsigned drivers; approve needed ones
  • Detection:
    bcdedit /enum | Select-String "nointegritychecks"
    

4.2.7 Network Configuration

Setting: Network Profile

  • All Profiles: Private network (more permissive firewall rules)
  • Rationale: These are isolated workstations, not on corporate networks
  • Application:
    Set-NetConnectionProfile -NetworkCategory Private
    
  • Detection:
    Get-NetConnectionProfile | Select-Object Name, NetworkCategory
    

Setting: Time Synchronization

  • All Profiles: Enabled (critical for logs/diagnostics timestamps)
  • Application:
    # Ensure time sync service is running
    Start-Service -Name W32Time
    Set-Service -Name W32Time -StartupType Automatic
    

Setting: Timezone

  • Detection: Get-TimeZone
  • Note: User should set timezone manually during Windows install
  • Rationale: Timezone affects EEPROM dates, logs, diagnostic records

4.2.8 Optional Features

Feature: Hyper-V

  • DailyTech: Optional (for VM testing)
    • Installation: Enable-WindowsOptionalFeature -FeatureName Microsoft-Hyper-V -Online -NoRestart
  • ODIS & XENTRY: Not recommended (conflicts with other virtualization)
  • PIWIS & ISTA: Not recommended
  • Rationale: Hyper-V conflicts with VirtualBox; choose one

Feature: Windows Sandbox

  • DailyTech: Optional (for sandboxed app testing)
    • Installation: Enable-WindowsOptionalFeature -FeatureName Containers-DisposableContainers -Online
  • ODIS & XENTRY: Optional
  • PIWIS & ISTA: Optional
  • Rationale: Useful for safe testing; adds minimal overhead

Feature: Windows Subsystem for Linux (WSL)

  • DailyTech: Optional (for Linux tool support)
  • ODIS & XENTRY: Not recommended
  • PIWIS & ISTA: Not recommended
  • Rationale: Adds complexity; not necessary for automotive diagnostics

Feature: VirtualBox Support

  • All Profiles: Keep VirtualBox as WinGet optional package (user chooses)
  • Note: Cannot use Hyper-V and VirtualBox together
  • Recommendation: If user enables Hyper-V, warn about VirtualBox incompatibility

4.2.9 Services

Core Services (Always Running)

  • TermService — Remote Desktop (optional; disable if not needed)
  • Bits — Background Intelligent Transfer Service (keep for updates)
  • WinDefend — Windows Defender (keep enabled for security)
  • W32Time — Time sync (critical for logs)
  • AudioSrv — Audio (needed for some diagnostic tools)

Services to Disable (Reduce Attack Surface)

  • DiagTrack — Connected User Experiences and Telemetry
  • dmwappushservice — Update Orchestrator Service (handle via Group Policy)
  • AppVClient — App-V client (if not using App-V)
  • RemoteRegistry — Remote Registry (disable if not doing remote management)

Configuration per Profile

  • DailyTech: Minimal restrictions (user may need various services)
    • Disable: DiagTrack, dmwappushservice
  • ODIS & XENTRY: Minimal restrictions
    • Disable: DiagTrack, dmwappushservice
  • PIWIS & ISTA: Minimal restrictions
    • Disable: DiagTrack, dmwappushservice

Application:

$servicesToDisable = @('DiagTrack', 'dmwappushservice')
foreach ($service in $servicesToDisable) {
    Set-Service -Name $service -StartupType Disabled -ErrorAction SilentlyContinue
    Stop-Service -Name $service -Force -ErrorAction SilentlyContinue
}

Detection:

Get-Service -Name $servicesToDisable | Select-Object Name, StartType, Status

4.2.10 Event Logging & Crash Dumps

Setting: System Event Log

  • All Profiles: Enabled (critical for troubleshooting)
  • Size: 20MB minimum (allow system to keep 30 days of logs)
  • Application:
    $eventLog = Get-WmiObject Win32_NTEventLogFile -Filter "LogFileName='System'"
    $eventLog.MaxFileSize = 20971520  # 20 MB
    $eventLog.Put()
    

Setting: Application Event Log

  • All Profiles: Enabled
  • Size: 20MB minimum

Setting: Crash Dumps

  • All Profiles: Enabled (system memory dump)
  • Rationale: Helps diagnose system crashes/BSODs
  • Application:
    $path = "HKLM:\SYSTEM\CurrentControlSet\Control\CrashControl"
    Set-ItemProperty -Path $path -Name CrashDumpEnabled -Value 1  # Full dump
    

Setting: PowerShell Script Logging

  • All Profiles: Enable for security + debugging
  • Application:
    $path = "HKLM:\Software\Policies\Microsoft\Windows\PowerShell\ScriptBlockLogging"
    New-Item -Path $path -Force
    Set-ItemProperty -Path $path -Name EnableScriptBlockLogging -Value 1
    

4.2.11 BitLocker & Encryption

Setting: BitLocker Status

  • All Profiles: Check status (do not auto-enable)
  • Rationale: User's choice; may conflict with forensic recovery needs
  • Detection:
    manage-bde -status C:
    
  • Recommendation: User should configure if needed

4.2.12 System Restore & Recovery

Setting: System Protection

  • All Profiles: Enabled (allow system restore points)
  • Rationale: Allows rollback if OS-level changes break diagnostics
  • Application:
    Enable-ComputerRestore -Drive "C:\"
    
  • Detection:
    Get-ComputerRestorePoint | Select-Object -Last 1
    

Setting: Shadow Copy (Volume Shadow Copy)

  • All Profiles: Enabled (for file version history)
  • Application:
    # Enable on C: drive
    Get-WmiObject -List -Namespace root\cimv2 | Where-Object Name -eq Win32_ShadowCopy
    

4.3 WINDOWS CONFIGURATION JSON SCHEMA

{
  "WindowsSettings": {
    "DailyTech-Tuning": {
      "PowerManagement": {
        "Hibernation": {
          "Value": "Disabled",
          "Registry": "N/A",
          "Command": "powercfg.exe /hibernate off",
          "Detect": "powercfg /query",
          "Rollback": "powercfg.exe /hibernate on",
          "Critical": true
        },
        "USBSelectiveSuspend": {
          "Value": "Disabled",
          "ACValue": 0,
          "DCValue": 0,
          "Critical": true
        },
        "PowerPlan": {
          "Value": "High Performance",
          "Guid": "SCHEME_MIN",
          "Rationale": "Full CPU for long analysis tasks",
          "Critical": false
        },
        "MonitorSleep": {
          "Value": "Never",
          "Minutes": 0,
          "Critical": true
        },
        "DiskSleep": {
          "Value": "Never",
          "Minutes": 0,
          "Critical": true
        },
        "SystemSleep": {
          "Value": "Never",
          "Minutes": 0,
          "Critical": true
        }
      },
      "WindowsUpdate": {
        "ActiveHoursStart": 8,
        "ActiveHoursEnd": 17,
        "AutomaticRestart": "Disabled",
        "RestartNotification": "User Configurable"
      },
      "Security": {
        "Defender": "Enabled",
        "ControlledFolderAccess": "Disabled",
        "Firewall": "Enabled",
        "DriverSignaturePolicy": "Enforce"
      },
      "FileSystem": {
        "LongPathSupport": "Enabled",
        "ShowFileExtensions": "Enabled",
        "ShowHiddenFiles": "Enabled"
      },
      "Services": {
        "Disable": ["DiagTrack", "dmwappushservice"],
        "Enable": ["W32Time", "AudioSrv"]
      }
    },
    "ODIS-XENTRY": {
      // Similar structure, but:
      "PowerManagement": {
        "PowerPlan": {
          "Value": "Balanced",
          "Rationale": "OEM diagnostic tool requirements"
        },
        "MonitorSleep": {
          "Minutes": 30
        }
      }
    },
    "PIWIS-ISTA": {
      // Similar structure to ODIS-XENTRY
    }
  }
}

4.4 CONFIGURATION IMPLEMENTATION FUNCTIONS

New PowerShell Functions to Create

  1. Detect-WindowsConfiguration — Scan current OS state
  2. Plan-WindowsConfiguration — Show proposed changes
  3. Set-WindowsConfiguration — Apply settings per profile
  4. Verify-WindowsConfiguration — Confirm changes took effect
  5. Rollback-WindowsConfiguration — Revert to pre-setup state
  6. Get-PowerPlanGUID — Resolve power plan names to GUIDs
  7. Detect-PendingRestart — Check for pending restart
  8. Test-PowerPlan — Verify active power plan
  9. Test-USBSelectiveSuspend — Verify USB policy
  10. Test-RegistrySetting — Generic registry test

4.5 SAFETY GATES

Before Applying Configuration

  1. ✅ Admin check: Must be elevated
  2. ✅ Backup state: Save current config to JSON
  3. ✅ Conflict check: Warn if Hyper-V + VirtualBox selected
  4. ✅ System impact: Warn about pending restart scenarios
  5. ✅ Manual override: Allow -SkipWindowsConfiguration flag

After Applying Configuration

  1. ✅ Verification: Run Verify functions
  2. ✅ Report: Export configuration state to CSV/JSON
  3. ✅ Recovery: Save rollback instructions

4.6 CONFIGURATION MATRIX SUMMARY

Setting DailyTech ODIS/XENTRY PIWIS/ISTA Reason
Hibernation Off Off Off Critical for diagnostics
USB Suspend Off Off Off Critical for interfaces
Power Plan High Perf Balanced Balanced Workload optimization
Defender On On On Security
CFA Off Off Off Tool flexibility
Fast Startup On On On Boot speed
Long Paths On On On Project depth
Show Extensions On On On Critical for .hex, .bin
Services Min removal Min removal Min removal Reduce telemetry

NEXT STEPS

Phase 5 will build on this foundation to create Workspace Templates for each profile, including automated folder structures and project initialization.