Italian language translation thread (Upg 2026.09.12200

Version 2026.08.11704 --> 2026.08.11723 - template.xml file (and other languages).

Modify

From <S0256>Detected 'Do not allow compression on all NTFS volumes' policy or disabled NTFS compression on this machine. Mounting an image on such a machine is not supported by the OS. In order to proceed you will need to disable this policy or a setting and reboot the machine first.</S0256>

To <S0256>NTFS compression is unavailable on this volume. The update optimization step cannot run on an image kept here.</S0256>

From <S1760>Image operation aborted, an error has occurred.</S1760>

To <S1760>An error has occurred while processing an image file.</S1760>

From <S2506>Latest online updates</S2506>

To <S2506>Latest updates</S2506>

From <S0133>Please check the following and try again:

- Your PC time and date needs to be correct

- Make sure firewall is not blocking the connection</S0133>

To <S0133>Please check the following and try again:

- Your PC time, date and time zone need to be correct, within a minute of the real time

- If the time is set manually, start the Windows Time service and sync once, a drifted clock is rejected as untrusted

- Make sure firewall is not blocking the connection

- Make sure the internet connection is working</S0133>

From <S1376>Overwrite any existing unattended settings on the image with the ones set on this page. Off leaves the image's own settings intact.</S1376>

To <S1376>Enable overwrites any unattended settings the image already carries with the ones set on this page. Default leaves the image's own answer file intact. Remove takes it out without writing a new one.</S1376>

From <S0371>The existing unattended answer file will be deleted</S0371>

To <S0371>The image's own unattended answer file will be removed</S0371>

From <S1433>Windows Defender detected, it is recommended to disable it for a much faster processing.</S1433>

To <S1433>Detected antivirus, it is recommended to disable it or add these folders to its exclusion list, for a much faster processing:</S1433>

Add (New)

Post <S3873>

<S3917>Size at least</S3917>

Post <S3529>

<S3914>Mounting an image on such a machine is not supported by the OS.</S3914>

<S3915>Set this value to 0 and reboot, or choose a temporary directory on another volume.</S3915>

<S3916>NTFS compression requires a cluster size of 4 KB or smaller. Choose a temporary directory on a volume formatted with smaller clusters.</S3916>

Post <S3778>

<S3909>Send logs</S3909>

<S3910>Pack this session's logs and crash dumps into an NTLite_Logs_ zip in your Downloads folder, then open a support email to attach it to</S3910>

<S3911>No logs or crash dumps were found to pack.</S3911>

<S3912>Please attach the log package saved at the path below, and describe what went wrong:</S3912>

<S3913>Earlier log packages are still in your Downloads folder. Delete them before saving the new one?</S3913>

Post <S3887>

<S3902>This edit contains mounted images, they will be unloaded and their changes lost.</S3902>

<S3906>Continue skips this file and any further unreadable ones in this image. Cancel stops the operation.</S3906>

Post <S3419>

<S3918>The exported preset carries data that can identify you or this machine:

</S3918>

<S3919>Remove it from the exported file?

Names are replaced with placeholders, passwords and keys are emptied, paths keep only their last folder and file name.</S3919>

<S3920>private data removed</S3920>

Post <S3861>

<S3905>Enablement packages are not supported on LTSC, integrating one breaks future servicing with no rollback path</S3905>

Post <S3165>

<S3893>Load settings from an existing answer file, replacing the current content of this page. Settings this page does not cover are kept in the Other card and written back unchanged.</S3893>

<S3894>Select an answer file to import</S3894>

<S3895>The answer file only contains settings for a different processor architecture, so nothing was imported.</S3895>

<S3896>Replace the current unattended settings with the ones from this file?</S3896>

<S3897>Answer files</S3897>

<S3903>Settings this answer file carries which this page has no row for. They are shown as they were read, and written back to the answer file unchanged.</S3903>

<S3904>Word wrap</S3904>

Post <S3864>

<S3890>Windows S mode</S3890>

<S3891>Restricts the installation to Microsoft Store apps and Edge browsing, enforced by Code Integrity. Requires Secure Boot to be enabled.</S3891>

<S3892>Unsigned applications, drivers and post-setup scripts are blocked, this tool included. Exiting from inside Windows is a one-way Microsoft Store switch, while offline this setting can be turned off again.</S3892>

<S3898>Enabled from first boot</S3898>

<S3899>Enabled after post-setup</S3899>

<S3900>Enabling it after post-setup writes the lockdown as the last first-logon step, so applications, drivers and scripts still deploy normally, then one restart activates it. Capturing or generalizing the image before that logon drops the pending step.</S3900>

Post <S3867>

<S3907>Press No to continue regardless, Cancel to stop.</S3907>

<S3908>Continuing leaves Defender's protected files in place, so its removal will be partial.</S3908>

The Italian file is also aligned with 2026.08.11723

 

Attachments

Last edited:
Version 2026.08.11723 --> 2026.09.11904 - template.xml file (and other languages).


Modify
From <S3862>Darker</S3862>
To <S3862>Black</S3862>

From <S3910>Pack this session's logs and crash dumps into an NTLite_Logs_ zip in your Downloads folder, then open a support email to attach it to</S3910>
To <S3910>Pick the logs, crash dumps and presets to pack into a support package, then open an email to attach it to</S3910>

From <S3913>Earlier log packages are still in your Downloads folder. Delete them before saving the new one?</S3913>
To <S3913>Delete earlier log packages</S3913>

From <S0512>Import external preset to the list</S0512>
To <S0512>Add external preset to the list</S0512>

From <S0789>Please BACKUP your activation by exporting the license.dat file.
Optionally also backup the settings.xml file which contains general tool settings and the license code.
Both files can be found in the installation directory of this application.</S0789>

To <S0789>Optionally use Export to keep a backup, in case this machine cannot reach the activation server later.</S0789>

From <S0889>more online activations available, after which the email-only activation is in effect.</S0889>
To <S0889>After that, activating another machine requires contacting support. Re-activating on this same machine does not spend one, even after reinstalling Windows or losing the license file.</S0889>

From <S3461>Import file</S3461>
To <S3461>This license is tied to the licensed user only, not to a machine. To move it, Export here and Import on the other machine along with your license code - that spends no online activation. Activate online there only if Import is not possible, and contact us for a reset if the online activations run out.</S3461>

From <S3462>Export backup</S3462>
To <S3462>Online activations remaining</S3462>

From <S1639>License file imported, please enter the correct license code and press OK.</S1639>
To <S1639>License file imported, enter its matching license code and press Activate.</S1639>

From <S0244>Desktop icon - Control Panel</S0244>
To <S0244>Control Panel</S0244>

From <S0245>Desktop icon - My Computer</S0245>
To <S0245>My Computer</S0245>

From <S0248>Desktop icon - User Files</S0248>
To <S0248>User Files</S0248

From <S1106>Taskbar - Combine buttons and hide labels</S1106>
To <S1106>Combine buttons and hide labels</S1106>

From <S1108>Taskbar - Show on all monitors</S1108>
To <S1108>Show on all monitors</S1108>

From <S1109>Taskbar - Show Store apps</S1109>
To <S1109>Show Store apps</S1109>

From <S1110>Taskbar - Small icons</S1110>
To <S1110>Small icons</S1110>

From <S1244>View - Show empty drives</S1244>
To <S1244>Show empty drives</S1244>

From <S1245>View - Show extensions for known file types</S1245>
To <S1245>Show extensions for known file types</S1245>

From <S1246>View - Show hidden files, folders and drives</S1246>
To <S1246>Show hidden files, folders and drives</S1246>

From <S1247>View - Show protected operating system files</S1247>
To <S1247>Show protected operating system files</S1247>

From <S2480>Allow apps access</S2480>
To <S2480>App permissions</S2480>

From <S3851>Disables DHCP/IPv4, IPv6 and DNS during the later stages of Windows Setup until after OOBE, then restores them automatically before the desktop appears, bypassing the pre-logon online update of Windows 11 setup. A pre-configured static IPv4 address is not affected.</S3851>
To <S3851>Disables DHCP/IPv4 and IPv6 during the later stages of Windows Setup until after OOBE, then restores them automatically before the desktop appears, bypassing the pre-logon online update of Windows 11 setup. A pre-configured static IPv4 address is not affected.</S3851>

From <S3424>Import host Start Menu layout</S3424>
To <S3424>Host Start Menu layout</S3424>

Add (New)

Post <<S3402>

<S3982>Active Setup Engine</S3982>

<S3983>Downloads and unpacks Internet Explorer components and ActiveX controls delivered as CAB files, then runs their INF setup directives.</S3983>

<S3984>Web Installer</S3984>

Post <S3425>

<S3992>File system filter class registration, not a driver itself. Third-party anti-virus, backup, encryption and virtualization tools install their file system minifilters into this class, and cannot install without it.</S3992>

Post <S3839>
<S3976>Codecs</S3976>
<S3989>Windows AI Isolation Session</S3989>
<S3990>Isolation host for Windows AI features. Runs AI code in a contained session with its own view of files and the registry, kept separate from your user session.</S3990>
<S3994>Shared set of ahead-of-time compiled binaries, hard-linked into the apps that use them. Covers Start menu, Settings, account dialogs, app actions, AutoPlay, voice isolation and File Explorer parts.</S3994>
<S3995>App Overlay Platform</S3995>
<S3996>Runtime interface for apps that place an overlay window on top of another app.</S3996>

Post <S3917>
<S3972>Keeping</S3972>

Post <S3884>
<S3954>Expand</S3954>
<S3955>Collapse</S3955>
<S3991>Automatically save preset</S3991>


Post <S3916>
<S3969>Reset to preset: </S3969>
<S3970>Current values are replaced with those from this preset.</S3970>
<S3971>The whole page is replaced, not only the part named above.</S3971>

Post <S3913> [Modify]
<S3921>Pick what to include in the support package.</S3921>
<S3922>It can contain paths carrying your account name, and a preset can hold a product key or an auto-logon password. Nothing is sent automatically – you attach the file to the email yourself.</S3922>
<S3923>Remove private information</S3923>
<S3924>Left out of the package:</S3924>
<S3925>edited</S3925>
<S3926>Logs</S3926>
<S3927>Crash dumps</S3927>
<S3943>Account names in log paths are replaced with a placeholder, and presets are stripped of names, passwords and product keys the way an exported preset is.
This is best effort, so open the package and check it before you send it.</S3943>
<S3981>Compressing</S3981>

Post <S3905>
<S3986>Cancelling...</S3986>

Post <S3880>
<S3945>Removing apps requires briefly stopping the app repository service, which takes Remote Desktop down with it and will drop this connection.
The process keeps running, reconnect to this machine after about a minute.</S3945>

Post <S3868>
<S3977>Ignored while Windows Welcome is skipped.</S3977>
<S3978>This legacy option skips the per-user phase that runs after the account is created, and repeats for each new user: the first sign-in animation and profile setup. It skips none of the Windows Welcome prompts, which are already answered by then.</S3978>

Post <S3692>
<S3962>Machine serial is missing or unusable, enter a computer name</S3962>
<S3964>Computer name prompting needs a setup boot image, using an auto-generated name instead</S3964>
<S3966>Computer name entry was not found on the installation media. This boot image was prepared for different media, recreate the installation media instead of copying boot.wim onto it.</S3966>
<S3968>Computer name prompting needs Windows Script Host in the boot image, using an auto-generated name instead</S3968>

Post<S3900>
<S3928>Block clean-up of unused language packs</S3928>
<S3929>Stops the LPRemove task from deleting preinstalled language packs that no user on the machine has selected. Keeps an integrated language available and selectable after deployment, at the cost of the unused packs staying on disk.</S3929>
<S3930>Storage</S3930>
<S3932>Sharing</S3932>
<S3933>Folders</S3933>
<S3934>Icons</S3934>
<S3935>Folder options</S3935>
<S3936>Windows 11 24H2 and newer boot into the redesigned Setup. Legacy starts the classic setup.exe wizard instead, which still supports options the new one dropped, such as joining a domain during installation.</S3936>
<S3937>Telemetry</S3937>
<S3938>Typing and speech</S3938>
<S3939>Usage tracking</S3939>
<S3940>Bundled apps and suggestions</S3940>
<S3941>Sign-in</S3941>
<S3942>Automatic per-user installation of the consumer Teams chat client.</S3942>
<S3946>Microsoft Defender cloud protection (MAPS)</S3946>
<S3947>Sends information about suspicious files to Microsoft's cloud service, which also controls automatic sample submission. Has no effect while the antivirus is disabled.</S3947>
<S3948>App install control</S3948>
<S3949>Controls whether Windows warns about or blocks apps installed from outside the Microsoft Store. While Smart App Control is on it behaves as if set to Anywhere, whatever is chosen here.</S3949>
<S3950>Anywhere</S3950>
<S3951>Anywhere, notify of Store app</S3951>
<S3952>Anywhere, warn if not from Store</S3952>
<S3953>Microsoft Store only</S3953>
<S3956>CPU vulnerability mitigations (Spectre, Meltdown)</S3956>
<S3957>Turning these off can recover noticeable performance on older processors, and leaves those processor vulnerabilities open to exploit. Needs a restart, and does nothing on a system without the January 2018 or later updates. (FeatureSettingsOverride)</S3957>
<S3958>Microsoft vulnerable driver blocklist</S3958>
<S3959>Stops drivers Microsoft flagged as exploitable from loading, off a list that ships with Windows updates. Memory integrity, Smart App Control and S mode each force it back on and grey out its Windows Security switch. (VulnerableDriverBlocklistEnable)</S3959>
<S3960>Local Security Authority protection</S3960>
<S3961>Runs the credential process as protected, so tools that harvest passwords out of its memory cannot read it. Turning it on also arms a UEFI lock: on a machine that has already booted with it, turning it back off through the registry alone does nothing, and only an offline image or a clean install reverts it. Some older drivers and authentication add-ins stop loading under it. (RunAsPPL)</S3961>
<S3974>Updates during setup</S3974>
<S3975>Skips the Windows 11 setup screen offering the latest features and security updates, so setup continues to the logon screen. A fully unattended install may still attempt an update pass.</S3975>
<S3979>Privacy settings prompt on first sign-in</S3979>
<S3980>Windows asks each newly created account to choose privacy settings when it first signs in, and asks again after some upgrades. Disabled, those accounts keep the Windows defaults without being asked.</S3980>

Post <S3908>
<S3965>Image edition unavailable</S3965>

Post <S3847>
<S3963>Ready-made settings this page already carries. Appends to the current choices, does not reset.</S3963>

Post <S3403>
<S3973>Startup</S3973>


Delete
<S3496>Checked</S3496>
<S3497>Unchecked</S3497>
<S0246>Desktop icon - Network</S0246>
<S0247>Desktop icon - Recycle Bin</S0247>
<S1107>Taskbar notifications</S1107>
<S1733>Power Control</S1733>
<S3578>Icon cache</S3578>
<S3579>Maximum number of icons Explorer keeps cached. Windows uses 500 when unset; a higher value reduces icon re-fetching and flicker.</S3579>
<S1067>State</S1067>

The Italian file is also aligned with 2026.09.11904

 

Attachments

Version 2026.09.11904 --> 2026.09.12200 - template.xml file (and other languages).

Delete
<S3309>A command line tool used to transfer data to and from a server.</S3309>
<S3310>Various scripts</S3310>
<S2522>Trim</S2522>
<S3747>Sort mounted images first</S3747>
<S3848>Monthly</S3848>
<S3566>Some characters are invalid and will be removed on commit (max 32).</S3566>
<S2528>External</S2528>
<S3651>Certificate deployment complete (0x4000); all deployable bits cleared.</S3651>
<S3679>Apply the certificate update before the 2011 certificates expire (June/October 2026), or this PC may stop booting updated media.</S3679>
<S3703>Stuck at KEK step: the OEM-signed KEK is missing (event 1803). Needs an OEM firmware or virtualization-platform update.</S3703>
<S3465>App Catalog</S3465>
<S3466>Browse and select apps from winget for automated installation</S3466>
<S3469>Online</S3469>
<S3470>Offline</S3470>
<S3471>Download Selected</S3471>
<S3472>Open Cache</S3472>
<S3473>Reloads and caches the latest online catalog entries</S3473>
<S0434>Free (limited, non-commercial)</S0434>
<S1392>Home (single-seat, non-commercial)</S1392>
<S1393>Professional (single-seat, commercial)</S1393>
<S1394>Business (single-seat, commercial)</S1394>
<S1395>Enterprise (multi-seat, commercial)</S1395>
<S0245>My Computer</S0245>
<S1399>At least one Metro App needs to be kept so that Windows 10 Start Menu gets installed properly.</S1399>
<S3907>Press No to continue regardless, Cancel to stop.</S3907>
<S3908>Continuing leaves Defender's protected files in place, so its removal will be partial.</S3908>

Add
Post <S3836>
<S4147>A command line tool used to create, list and extract archives, including tar, tar.gz, zip and 7z. Accepts the same options as tar on Linux and macOS, so existing scripts and habits carry over.</S4147>
<S4148>A command line tool used to transfer data to and from a server. Batch scripts and app installers call it to download files, since it ships with Windows.</S4148>
<S4174>Dashboard for the device's protection and health: virus and threat protection, firewall, account protection, app and browser control, device security. Includes its tray icon and the Security Center service, which reports the state of the installed antivirus and firewall.</S4174>
Post <S3991> modify
<S3997>Expand on title click</S3997>
<S3998>Clicking a card or parent title expands or collapses it.
When off, only the arrow does, and a title click selects the row.</S3998>
<S4022>ESD compression threads</S4022>
<S4023>Maximum number of CPU threads for ESD compression, capped by the Threads setting. Automatic leaves part of the CPU unused, as higher counts can cause crashes on some systems.</S4023>
<S4113>Modified rows</S4113>
<S4114>How rows that differ from the image default are marked.</S4114>
<S4115>Edge bar</S4115>
<S4116>Bold text</S4116>
<S4127>Early release of next month's non-security fixes and improvements. Includes the same month's Security Update.</S4127>
<S4186>Links</S4186>

Post <S3971>
<S4055>The running operation is being cancelled. Wait for its cancel notice before closing this message - the image being written may be incomplete.</S4055>
<S4056>NTLite closed unexpectedly last time and the crash report was not shown.</S4056>

Post <S3981>
<S4033>EULA</S4033>
<S4034>Readme</S4034>
<S4035>Documentation</S4035>
<S4077>Third-party notices</S4077>

Post <S3906>
<S4159>Install the Windows ADK Deployment Tools, or copy oscdimg.exe next to NTLite.exe, to create ISO images without it.</S4159>
<S4160>all editions</S4160>
<S4161>editions</S4161>
<S4182>Exported</S4182>
<S4187>Recovery/Setup</S4187>

Post <S3920>
<S4139>Saved from the selected image</S4139>

Post <S3842>
<S4068>These characters are not allowed:</S4068>
<S4069>Maximum length reached.</S4069>
<S4183>Editions</S4183>

Post <S3986>
<S4000>Update compression library was not updated as signature could not be verified, report if unexpected</S4000>
<S4050>Article</S4050>
<S4054>Unlisted</S4054>
<S4128>non-ESU</S4128>
<S4129>Out-of-band</S4129>
<S4130>.NET Framework 3.5 and 4.8.1</S4130>
<S4131>.NET Framework 3.5 and 4.8</S4131>
<S4134>Later cumulative updates are built on this one, so it is added with them when the image does not have it yet.</S4134>
<S4136>Enablement package</S4136>
<S4149>Duplicates</S4149>
<S4151>Delete superseded files from the update cache</S4151>
<S4152>Delete extra copies from the update cache, keeping one of each update</S4152>
<S4155>To install the language packs offline, get the Features on Demand ISO</S4155>
<S4158>To install the language packs offline, get the Language Pack DVD</S4158>
<S4180>Offline</S4180>

Post <S3989>
<S4057>Feature Update</S4057>

Post <S3874>
<S4059>2011 only</S4059>
<S4060>2023 trusted</S4060>
<S4061>Lockout</S4061>
<S4062>2023 upgrade</S4062>
<S4063>Certificate updates unavailable</S4063>
<S4064>Vendor firmware update needed</S4064>
<S4065>The firmware already carries the vendor-signed 2023 KEK; deploy when ready.</S4065>
<S4066>The boot manager and db steps work on any UEFI; whether the vendor shipped a 2023 KEK shows after the first deployment run.</S4066>
<S4071>Boot revocation list</S4071>
<S4072>older than the image</S4072>
<S4073>Media</S4073>
<S4074>The media's boot revocation list (boot.stl) is older than the one inside the boot image, so a machine may refuse to boot this media with error 0xC0430001. Updating the boot manager or integrating an update into the boot image refreshes it.</S4074>
<S4075>Boot manager below the image's anti-rollback floor</S4075>
<S4076>The boot manager on this media has a lower Secure Boot version number than the floor this image's update publishes. A PC that has installed that update, or this image once it applies it, refuses to boot the media with error 0xC0430001. Update the boot manager, or let the cumulative update service the boot image.</S4076>
<S4078>Not offered: the boot manager this PC starts from has a lower Secure Boot version number than the floor this step would set, so the PC could refuse its own boot manager with error 0xC0430001. Install the latest cumulative update first, then stage this step.</S4078>
<S4081>Load this media's install.wim to update the boot manager.</S4081>

Post <S3945>
<S4079>Hide cmd window</S4079>
<S4080>Hides the main command window of the scripts.
A command that waits for input then waits with nothing on screen.
Security products can flag the 'conhost.exe --headless' launch it writes, as some malware is known for it.
Before logon, the Unattended and SetupComplete.cmd modes are hidden by design.</S4080>
<S4142>The downloaded file is damaged or not signed by Microsoft, so it was not kept.</S4142>
<S4173>Removing Defender on a running Windows is a two-stage job. This run disabled it and removed part of it. Re-run NTLite and remove Defender again to clear the rest.</S4173>
<S4176>Individual</S4176>
<S4177>Editions that carry the same WinRE share one row. It is serviced once, and the result is written into each of them.</S4177>
<S4178>Every edition's WinRE has a row of its own and is serviced on its own.</S4178>
<S4179>Open with popup</S4179>

Post <S3390>
<S4024>limited, non-commercial</S4024>
<S4025>single-seat, non-commercial</S4025>
<S4026>single-seat, commercial</S4026>
<S4027>multi-seat, commercial</S4027>
<S4028>Include boot.wim updates by default</S4028>
<S4029>Queuing a cumulative or dynamic update also ticks the boot.wim 'Windows Setup' Updates row. The Secure Boot 'Update boot manager' task ticks it regardless.</S4029>

Post <S3980>
<S3999>Lists</S3999>
<S4001>Printer sharing</S4001>
<S4002>Connect over RPC named pipes</S4002>
<S4003>Windows 11 22H2 and later connect to shared printers over RPC over TCP only. Older Windows expects RPC over named pipes and the connection fails with error 0x00000709.</S4003>
<S4004>Accept incoming RPC over</S4004>
<S4005>Protocols the Print Spooler listens on for other PCs. Windows 11 22H2 and later listen on RPC over TCP only, so older Windows cannot reach the shared printer (error 0x00000709).</S4005>
<S4006>Apply on the PC sharing the printer and on the PC connecting to it, then restart the Print Spooler service or reboot.</S4006>
<S4007>Require Kerberos for incoming RPC</S4007>
<S4008>Accepts only Kerberos-authenticated connections, which needs every PC domain-joined. Disabled = Negotiate, which uses Kerberos when available and NTLM otherwise, so workgroup and older Windows clients can still connect.</S4008>
<S4009>RPC over TCP port</S4009>
<S4010>Fixed port for incoming and outgoing RPC over TCP instead of a dynamic one (49152-65535), for firewall rules. 0 = dynamic, the default.</S4010>
<S4011>RPC packet privacy</S4011>
<S4012>Encrypts and authenticates every packet on the print spooler RPC interface (CVE-2021-1678, enforced since the September 2021 updates). Clients without that update fail with error 0x0000011b; disabling it lets them connect at the cost of that protection. Set on the PC sharing the printer.</S4012>
<S4013>RPC over named pipes</S4013>
<S4014>RPC over TCP</S4014>
<S4015>RPC over named pipes and TCP</S4015>
<S4016>Point and Print - warn and elevate on driver install</S4016>
<S4017>Since the August 2021 updates (PrintNightmare, CVE-2021-34527) installing a driver from a shared printer shows a warning and asks for administrator credentials. Disabling the prompt lets any user connect to a shared printer, but a malicious print server could then install code without asking.</S4017>
<S4018>Point and Print - driver update prompt</S4018>
<S4019>Show warning and elevation prompt</S4019>
<S4020>Show warning only</S4020>
<S4021>Do not show warning or elevation prompt</S4021>
<S4036>Microsoft defaults</S4036>
<S4037>All forced on</S4037>
<S4038>Intel, Hyper-Threading enabled</S4038>
<S4039>Intel, Hyper-Threading disabled</S4039>
<S4040>Administrator protection</S4040>
<S4041>Runs each elevated action through a temporary system-managed administrator account instead of the signed-in one, and asks for Windows Hello or a password every time. Off by default, and inert with User Account Control switched off. Microsoft advises against it on machines that need Hyper-V or Windows Subsystem for Linux, network drives are unreachable from elevated apps, and some installers fail, often reading as an app that cannot write to its own data folder. Windows 11 24H2 and newer with recent updates, desktop editions only. Needs a restart.</S4041>
<S4042>Outgoing NTLM authentication</S4042>
<S4043>NTLM hands a reusable credential to whatever server asks for it, which is what relay and coercion attacks collect.</S4043>
<S4044>Audit only</S4044>
<S4045>Blocked</S4045>
<S4046>NetBIOS name resolution broadcasts</S4046>
<S4047>When DNS has no answer, Windows shouts the name at the whole subnet, and any machine on it can answer with its own address to harvest credentials. Disabled switches to point-to-point mode, so names resolve through DNS or a WINS server only. Devices that answer to NetBIOS broadcasts alone, mostly old file shares and printers, stop being reachable by name.</S4047>
<S4048>Windows Script Host</S4048>
<S4049>Blocks .vbs, .js and .wsf files from running through wscript and cscript, one of the oldest malware delivery routes still in use. Written for both the 64-bit and the 32-bit script host. Some installers and logon scripts need it, and the failure reads as a broken installer rather than a blocked script.</S4049>
<S4067>Legacy compatibility</S4067>
<S4082>Not configured</S4082>
<S4083>Execution policy - All users</S4083>
<S4084>Whether Windows PowerShell runs script files, and which ones. A plain choice is the local machine preference: what Set-ExecutionPolicy writes when no scope is named, written for both the 64-bit and the 32-bit PowerShell, and the lowest ranking scope. Left unset it means Restricted on desktop editions and RemoteSigned on Server. A (Policy) choice sets the machine policy instead: it overrides every other scope, and while it is set Set-ExecutionPolicy cannot change the policy at all.</S4084>
<S4085>Local machine preference</S4085>
<S4086>What Set-ExecutionPolicy writes when no scope is named. Lowest ranking scope, so any of the three above it wins. Written for both the 64-bit and the 32-bit PowerShell. Left unset it means Restricted on desktop editions and RemoteSigned on Server.</S4086>
<S4087>Execution policy - Per user</S4087>
<S4088>The same choice for each user. A plain choice is the current user preference, what Set-ExecutionPolicy -Scope CurrentUser writes, and it outranks the all-users preference. A (Policy) choice sets the user policy instead: it ranks below only the machine policy, and locks out Set-ExecutionPolicy the same way.</S4088>
<S4089>Current user preference</S4089>
<S4090>What Set-ExecutionPolicy -Scope CurrentUser writes. Ranks above the local machine preference and below both policies.</S4090>
<S4091>Script block logging</S4091>
<S4092>Records every block of PowerShell code into the event log as it runs, including code decoded or built at runtime, which is what obfuscated scripts hide behind. Verbose on a busy machine, and the log ends up holding whatever the script handled, passwords included.</S4092>
<S4093>Module logging</S4093>
<S4094>Records the pipeline of every PowerShell module command into the event log, with the arguments it was called with. Enabled here covers all modules.</S4094>
<S4095>Transcription</S4095>
<S4096>Writes a text transcript of every PowerShell session, input and output, into a file in the user's Documents folder. Readable by whoever ran the session, and the files grow without limit.</S4096>
<S4097>blocks every script file, and is what produces the 'running scripts is disabled on this system' error</S4097>
<S4098>runs only scripts signed by a publisher the machine trusts</S4098>
<S4099>runs local scripts, and needs a trusted signature only on downloaded ones</S4099>
<S4100>runs everything, warning once per downloaded script</S4100>
<S4101>runs everything, never blocking or warning</S4101>
<S4102>Certificate revocation check wait</S4102>
<S4103>How long Windows waits for a certificate authority to answer whether a signature is revoked. An unreachable authority means the full wait is spent for nothing, which is why installers stall for minutes offline. A shorter wait still checks, but abandons a slow authority, so a revoked certificate can slip through. Windows default is 15 seconds per address, 20 total.</S4103>
<S4104>1 second per address, 1.3 total</S4104>
<S4105>Applies to every user account.</S4105>
<S4106>Applies to each user account separately.</S4106>
<S4107>logs what would be blocked, without blocking anything, so it shows what would break first</S4107>
<S4108>stops logins to servers reached by IP address, older network drives and anything else that cannot use Kerberos</S4108>
<S4109>leaves several mitigations off, and more of them on Server images</S4109>
<S4110>closes that gap, at a performance cost</S4110>
<S4111>recovers noticeable performance on older processors, and leaves those processor vulnerabilities open to exploit</S4111>
<S4112>Windows watches how the machine is used, then turns it on or off by itself</S4112>
<S4137>TPM / Secure Boot (anti-cheat)</S4137>
<S4175>Not enforced</S4175>
<S4181>Empty folder</S4181>
<S4184>3 seconds per address, 4 total</S4184>
<S4185>6 seconds per address, 8 total</S4185>

Post <S3105>
<S4117>The ISO destination drive is not available. Reconnect it or select another destination.</S4117>
<S4118>Skipped, pending operations detected</S4118>
<S4121>DISM update cleanup fails on such an image, so updates are cleaned with the Custom method instead.</S4121>
<S4122>Skipped, an earlier removal trimmed the component store</S4122>
<S4123>DISM's servicing host crashed while working on this image.</S4123>
<S4125>An earlier apply removed components from this image with servicing stack compatibility disabled.</S4125>
<S4126>Enabling a Windows feature fails if that removal deleted files the feature needs.</S4126>
<S4135>Added language packs and Features on Demand stay out of date until a cumulative update is applied after them.</S4135>
<S4138>Adding language packs and Features on Demand to this image needs the checkpoint cumulative update queued</S4138>

Post <S3965>
<S4162>Ignore the steps above</S4162>
<S4163>Steps to run before applying</S4163>
<S4164>Turn off Tamper protection</S4164>
<S4165>Switch Tamper protection off in Windows Security, then return here.</S4165>
<S4166>Turn off Real-time protection</S4166>
<S4167>NTLite switches this off to speed up processing. No reboot needed.</S4167>
<S4169>Turn off its real-time protection, or add these folders to its exclusion list, for faster processing.</S4169>
<S4170>Show folders to exclude</S4170>
<S4171>Open Windows Security</S4171>
<S4172>Turn off now</S4172>

Post <S3403>
<S4051>The free version is limited to one capability or language per image.</S4051>
<S4052>Replace with</S4052>
<S4053>Enable feature</S4053>
<S4058>Download the CAB packages the enabled capabilities need, from the Microsoft Features on Demand ISO into the update cache. Available once a capability is enabled and its packages are not cached yet.</S4058>
<S4120>A firewall or proxy may be blocking NTLite from reaching the Microsoft download server. Allow the connection, then try again.</S4120>
<S4124>Features on Demand could not be downloaded.</S4124>
<S4146>WMIC is removed by Windows updates for this version, so it can no longer be added.</S4146>
<S4153>Not installed</S4153>
<S4154>To install Features on Demand offline, get the Features on Demand ISO</S4154>
<S4156>Extract it whole into this folder</S4156>
<S4157>To install Features on Demand offline, extract the Features on Demand ISO whole into this folder</S4157>


end part 1
 
continue part 2

Modify
<S3984>DirectX Web Installer</S3984>
<S0602>Load last session</S0602>
<S2524>Delete unlisted files from the update cache</S2524>
<S3420>Keep history in overwritten presets</S3420>
<S3828>Compact 'Last change' dates</S3828>
<S3830>Log at debug level</S3830>
<S3849>Optional Update</S3849>
<S3869>Show actions on hover</S3869>
<S3870>Reveal actions when passing a mouse over an item, e.g. image actions over the title.
When off, card actions such as Image or Presets stay permanently visible.
Note that the options are always accessible in the right-click menu and toolbar on selection.</S3870>
<S3883>Use larger fonts</S3883>
<S3991>Save last session as</S3991>
<S3910>Pack the logs, crash dumps and presets you pick into a support package, ready to email to support.</S3910>
<S3943>Account names in log paths are replaced with a placeholder. Presets are stripped of names, passwords and product keys and their file paths are shortened, the same way an exported preset is. Crash dumps are packed as they are.
This is best effort, so open the package and check it before you send it.</S3943>
<S0228>Current image will be replaced after conversion, backup or create 'New edit' before this operation.</S0228>
<S0801>Please unload any mounted editions from this image file before retrying.</S0801>
<S1145>Missing Windows component</S1145>
<S3123>Disconnect</S3123>
<S3124>Replace reference</S3124>
<S1802>Save image</S1802>
<S2937>Servicing Stack Update</S2937>
<S3668>Unreadable</S3668>
<S3686>This image is ready for 2023 Secure Boot.</S3686>
<S3968>Computer name prompting needs Windows Script Host and VBScript in the boot image, using an auto-generated name instead</S3968>
<S2887>Feature update safeguard (Upgrade block)</S2887>
<S3059>On supported updated OS versions enables RPC_C_AUTHN_LEVEL_PKT_INTEGRITY on DCOM by default.</S3059>
<S3932>File sharing</S3932>
<S3957>Default does not mean every protection is on. Pick a forced option by the processor the image will run on, not the one building it. Needs a restart, and does nothing on a system without the January 2018 or later updates.</S3957>
<S3959>Stops drivers Microsoft flagged as exploitable from loading, off a list that ships with Windows updates. Memory integrity, Smart App Control and S mode each force it back on and grey out its Windows Security switch.</S3959>
<S3961>Runs the credential process as protected, so tools that harvest passwords out of its memory cannot read it. Turning it on also arms a UEFI lock: on a machine that has already booted with it, turning it back off through the registry alone does nothing, and only an offline image or a clean install reverts it. Some older drivers and authentication add-ins stop loading under it.</S3961>
<S0074>Back up preset and log on the edited image</S0074>
<S1071>Stop before saving the loaded and install images, boot and recovery still save</S1071>
<S3866>This PC cannot run the image's servicing stack. Integrate updates and features on a PC of the image's architecture</S3866>
<S2640>NTLite cannot download Features on Demand for this image, as Microsoft publishes no download link for its Features on Demand ISO.</S2640>

The Italian file is also aligned with 2026.09.12200

 

Attachments

Back
Top