Documentation

autounattend.xml: Unattended Windows Installs

An answer file lets Windows Setup run without a human clicking through it: disk layout, locale, user accounts, OOBE screens and first-logon commands all come from XML. Here is the minimum you need to understand before generating one.

Where the file goes

Name it autounattend.xml and place it in the root of the installation media (or on a separate USB stick / floppy image). Windows Setup searches a fixed list of locations and picks it up automatically - no key press, no /unattend switch. For an already-deployed image the same XML is applied as unattend.xml under C:\Windows\Panther.

The passes you will actually touch

  • windowsPE - language of Setup itself, product key, disk configuration and the image to install. Everything destructive lives here.
  • specialize - computer name, time zone, machine-scoped registry writes, domain join. Runs after the image is applied.
  • oobeSystem - the out-of-box experience: EULA, region screens, network requirement, local accounts, auto-logon and FirstLogonCommands.

Two other passes (offlineServicing, auditUser) exist and are rarely needed outside enterprise imaging.

A minimal skeleton

<unattend xmlns="urn:schemas-microsoft-com:unattend">
  <settings pass="oobeSystem">
    <component name="Microsoft-Windows-Shell-Setup" ...>
      <OOBE>
        <HideEULAPage>true</HideEULAPage>
        <HideOnlineAccountScreens>true</HideOnlineAccountScreens>
        <ProtectYourPC>3</ProtectYourPC>
      </OOBE>
      <UserAccounts>...</UserAccounts>
    </component>
  </settings>
</unattend>

The component elements need their full processorArchitecture, publicKeyToken and language attributes; that boilerplate is why almost nobody writes these by hand. Use a generator and review the output - the field-by-field walkthrough is in the autounattend guide.

Windows 11 hardware and account requirements

Windows 11 Setup checks TPM, Secure Boot and CPU support, and pushes a Microsoft account during OOBE. An answer file can create a local account and skip the online account screens; the hardware checks are bypassed with registry writes during windowsPE (the LabConfig keys) on unsupported test machines. Whether to do that is a decision about support and updates, not just a technical one - read the guide before shipping it into production media.

Disk configuration erases data

A windowsPE DiskConfiguration block with WillWipeDisk set to true destroys the target disk without a prompt - that is the point of an unattended install. Test in a VM first, every time.

Building the media

An answer file usually travels with a prepared ISO: drivers injected, unwanted packages removed, scripts staged. WIMUtil covers that side - sourcing the ISO, adding the XML, adding drivers and writing the stick. Combined with a .winhance configuration file applied at first logon, a fresh machine can arrive debloated and configured without a single manual step, following the same choices described in the debloat guide.

Frequently asked questions

Where do I put autounattend.xml?

In the root of the installation media. Windows Setup finds it automatically; no command-line switch is required.

Can autounattend.xml create a local account on Windows 11?

Yes. The oobeSystem pass can add a local account and hide the online account screens, which skips the Microsoft account requirement during setup.

Related reading