Italian language translation thread (Upg 2026.09.12311

Version 2026.08.11704 --> 2026.08.11723 - template.xml file (and other languages).

Modify​

From <S0256>Detected 'Do not allow compression on all NTFS volumes' policy or disabled NTFS compression on this machine. Mounting an image on such a machine is not supported by the OS. In order to proceed you will need to disable this policy or a setting and reboot the machine first.</S0256>​

To <S0256>NTFS compression is unavailable on this volume. The update optimization step cannot run on an image kept here.</S0256>​

​

From <S1760>Image operation aborted, an error has occurred.</S1760>​

To <S1760>An error has occurred while processing an image file.</S1760>​

​

From <S2506>Latest online updates</S2506>​

To <S2506>Latest updates</S2506>​

​

From <S0133>Please check the following and try again:​

- Your PC time and date needs to be correct​

- Make sure firewall is not blocking the connection</S0133>​

To <S0133>Please check the following and try again:​

- Your PC time, date and time zone need to be correct, within a minute of the real time​

- If the time is set manually, start the Windows Time service and sync once, a drifted clock is rejected as untrusted​

- Make sure firewall is not blocking the connection​

- Make sure the internet connection is working</S0133>​

​

From <S1376>Overwrite any existing unattended settings on the image with the ones set on this page. Off leaves the image's own settings intact.</S1376>​

To <S1376>Enable overwrites any unattended settings the image already carries with the ones set on this page. Default leaves the image's own answer file intact. Remove takes it out without writing a new one.</S1376>​

​

From <S0371>The existing unattended answer file will be deleted</S0371>​

To <S0371>The image's own unattended answer file will be removed</S0371>​

​

From <S1433>Windows Defender detected, it is recommended to disable it for a much faster processing.</S1433>​

To <S1433>Detected antivirus, it is recommended to disable it or add these folders to its exclusion list, for a much faster processing:</S1433>​

​

​

​

Add (New)​

Post <S3873>​

<S3917>Size at least</S3917>​

​

Post <S3529>​

<S3914>Mounting an image on such a machine is not supported by the OS.</S3914>​

<S3915>Set this value to 0 and reboot, or choose a temporary directory on another volume.</S3915>​

<S3916>NTFS compression requires a cluster size of 4 KB or smaller. Choose a temporary directory on a volume formatted with smaller clusters.</S3916>​

​

Post <S3778>​

<S3909>Send logs</S3909>​

<S3910>Pack this session's logs and crash dumps into an NTLite_Logs_ zip in your Downloads folder, then open a support email to attach it to</S3910>​

<S3911>No logs or crash dumps were found to pack.</S3911>​

<S3912>Please attach the log package saved at the path below, and describe what went wrong:</S3912>​

<S3913>Earlier log packages are still in your Downloads folder. Delete them before saving the new one?</S3913>​

​

Post <S3887>​

<S3902>This edit contains mounted images, they will be unloaded and their changes lost.</S3902>​

<S3906>Continue skips this file and any further unreadable ones in this image. Cancel stops the operation.</S3906>​

​

Post <S3419>​

<S3918>The exported preset carries data that can identify you or this machine:​

</S3918>​

<S3919>Remove it from the exported file?​

Names are replaced with placeholders, passwords and keys are emptied, paths keep only their last folder and file name.</S3919>​

<S3920>private data removed</S3920>​

​

Post <S3861>​

<S3905>Enablement packages are not supported on LTSC, integrating one breaks future servicing with no rollback path</S3905>​

​

Post <S3165>​

<S3893>Load settings from an existing answer file, replacing the current content of this page. Settings this page does not cover are kept in the Other card and written back unchanged.</S3893>​

<S3894>Select an answer file to import</S3894>​

<S3895>The answer file only contains settings for a different processor architecture, so nothing was imported.</S3895>​

<S3896>Replace the current unattended settings with the ones from this file?</S3896>​

<S3897>Answer files</S3897>​

<S3903>Settings this answer file carries which this page has no row for. They are shown as they were read, and written back to the answer file unchanged.</S3903>​

<S3904>Word wrap</S3904>​

​

Post <S3864>​

<S3890>Windows S mode</S3890>​

<S3891>Restricts the installation to Microsoft Store apps and Edge browsing, enforced by Code Integrity. Requires Secure Boot to be enabled.</S3891>​

<S3892>Unsigned applications, drivers and post-setup scripts are blocked, this tool included. Exiting from inside Windows is a one-way Microsoft Store switch, while offline this setting can be turned off again.</S3892>​

<S3898>Enabled from first boot</S3898>​

<S3899>Enabled after post-setup</S3899>​

<S3900>Enabling it after post-setup writes the lockdown as the last first-logon step, so applications, drivers and scripts still deploy normally, then one restart activates it. Capturing or generalizing the image before that logon drops the pending step.</S3900>​

​

Post <S3867>​

<S3907>Press No to continue regardless, Cancel to stop.</S3907>​

<S3908>Continuing leaves Defender's protected files in place, so its removal will be partial.</S3908>​

​

The Italian file is also aligned with 2026.08.11723​

 

Attachments

Last edited:
Version 2026.08.11723 --> 2026.09.11904 - template.xml file (and other languages).


Modify
From <S3862>Darker</S3862>
To <S3862>Black</S3862>

From <S3910>Pack this session's logs and crash dumps into an NTLite_Logs_ zip in your Downloads folder, then open a support email to attach it to</S3910>
To <S3910>Pick the logs, crash dumps and presets to pack into a support package, then open an email to attach it to</S3910>

From <S3913>Earlier log packages are still in your Downloads folder. Delete them before saving the new one?</S3913>
To <S3913>Delete earlier log packages</S3913>

From <S0512>Import external preset to the list</S0512>
To <S0512>Add external preset to the list</S0512>

From <S0789>Please BACKUP your activation by exporting the license.dat file.
Optionally also backup the settings.xml file which contains general tool settings and the license code.
Both files can be found in the installation directory of this application.</S0789>

To <S0789>Optionally use Export to keep a backup, in case this machine cannot reach the activation server later.</S0789>

From <S0889>more online activations available, after which the email-only activation is in effect.</S0889>
To <S0889>After that, activating another machine requires contacting support. Re-activating on this same machine does not spend one, even after reinstalling Windows or losing the license file.</S0889>

From <S3461>Import file</S3461>
To <S3461>This license is tied to the licensed user only, not to a machine. To move it, Export here and Import on the other machine along with your license code - that spends no online activation. Activate online there only if Import is not possible, and contact us for a reset if the online activations run out.</S3461>

From <S3462>Export backup</S3462>
To <S3462>Online activations remaining</S3462>

From <S1639>License file imported, please enter the correct license code and press OK.</S1639>
To <S1639>License file imported, enter its matching license code and press Activate.</S1639>

From <S0244>Desktop icon - Control Panel</S0244>
To <S0244>Control Panel</S0244>

From <S0245>Desktop icon - My Computer</S0245>
To <S0245>My Computer</S0245>

From <S0248>Desktop icon - User Files</S0248>
To <S0248>User Files</S0248

From <S1106>Taskbar - Combine buttons and hide labels</S1106>
To <S1106>Combine buttons and hide labels</S1106>

From <S1108>Taskbar - Show on all monitors</S1108>
To <S1108>Show on all monitors</S1108>

From <S1109>Taskbar - Show Store apps</S1109>
To <S1109>Show Store apps</S1109>

From <S1110>Taskbar - Small icons</S1110>
To <S1110>Small icons</S1110>

From <S1244>View - Show empty drives</S1244>
To <S1244>Show empty drives</S1244>

From <S1245>View - Show extensions for known file types</S1245>
To <S1245>Show extensions for known file types</S1245>

From <S1246>View - Show hidden files, folders and drives</S1246>
To <S1246>Show hidden files, folders and drives</S1246>

From <S1247>View - Show protected operating system files</S1247>
To <S1247>Show protected operating system files</S1247>

From <S2480>Allow apps access</S2480>
To <S2480>App permissions</S2480>

From <S3851>Disables DHCP/IPv4, IPv6 and DNS during the later stages of Windows Setup until after OOBE, then restores them automatically before the desktop appears, bypassing the pre-logon online update of Windows 11 setup. A pre-configured static IPv4 address is not affected.</S3851>
To <S3851>Disables DHCP/IPv4 and IPv6 during the later stages of Windows Setup until after OOBE, then restores them automatically before the desktop appears, bypassing the pre-logon online update of Windows 11 setup. A pre-configured static IPv4 address is not affected.</S3851>

From <S3424>Import host Start Menu layout</S3424>
To <S3424>Host Start Menu layout</S3424>

Add (New)

Post <<S3402>​

<S3982>Active Setup Engine</S3982>​

<S3983>Downloads and unpacks Internet Explorer components and ActiveX controls delivered as CAB files, then runs their INF setup directives.</S3983>​

<S3984>Web Installer</S3984>​

​

Post <S3425>​

<S3992>File system filter class registration, not a driver itself. Third-party anti-virus, backup, encryption and virtualization tools install their file system minifilters into this class, and cannot install without it.</S3992>​

​

Post <S3839>
<S3976>Codecs</S3976>
<S3989>Windows AI Isolation Session</S3989>
<S3990>Isolation host for Windows AI features. Runs AI code in a contained session with its own view of files and the registry, kept separate from your user session.</S3990>
<S3994>Shared set of ahead-of-time compiled binaries, hard-linked into the apps that use them. Covers Start menu, Settings, account dialogs, app actions, AutoPlay, voice isolation and File Explorer parts.</S3994>
<S3995>App Overlay Platform</S3995>
<S3996>Runtime interface for apps that place an overlay window on top of another app.</S3996>

Post <S3917>
<S3972>Keeping</S3972>

Post <S3884>
<S3954>Expand</S3954>
<S3955>Collapse</S3955>
<S3991>Automatically save preset</S3991>


Post <S3916>
<S3969>Reset to preset: </S3969>
<S3970>Current values are replaced with those from this preset.</S3970>
<S3971>The whole page is replaced, not only the part named above.</S3971>

Post <S3913> [Modify]
<S3921>Pick what to include in the support package.</S3921>
<S3922>It can contain paths carrying your account name, and a preset can hold a product key or an auto-logon password. Nothing is sent automatically – you attach the file to the email yourself.</S3922>
<S3923>Remove private information</S3923>
<S3924>Left out of the package:</S3924>
<S3925>edited</S3925>
<S3926>Logs</S3926>
<S3927>Crash dumps</S3927>
<S3943>Account names in log paths are replaced with a placeholder, and presets are stripped of names, passwords and product keys the way an exported preset is.
This is best effort, so open the package and check it before you send it.</S3943>
<S3981>Compressing</S3981>

Post <S3905>
<S3986>Cancelling...</S3986>

Post <S3880>
<S3945>Removing apps requires briefly stopping the app repository service, which takes Remote Desktop down with it and will drop this connection.
The process keeps running, reconnect to this machine after about a minute.</S3945>

Post <S3868>
<S3977>Ignored while Windows Welcome is skipped.</S3977>
<S3978>This legacy option skips the per-user phase that runs after the account is created, and repeats for each new user: the first sign-in animation and profile setup. It skips none of the Windows Welcome prompts, which are already answered by then.</S3978>

Post <S3692>
<S3962>Machine serial is missing or unusable, enter a computer name</S3962>
<S3964>Computer name prompting needs a setup boot image, using an auto-generated name instead</S3964>
<S3966>Computer name entry was not found on the installation media. This boot image was prepared for different media, recreate the installation media instead of copying boot.wim onto it.</S3966>
<S3968>Computer name prompting needs Windows Script Host in the boot image, using an auto-generated name instead</S3968>

Post<S3900>
<S3928>Block clean-up of unused language packs</S3928>
<S3929>Stops the LPRemove task from deleting preinstalled language packs that no user on the machine has selected. Keeps an integrated language available and selectable after deployment, at the cost of the unused packs staying on disk.</S3929>
<S3930>Storage</S3930>
<S3932>Sharing</S3932>
<S3933>Folders</S3933>
<S3934>Icons</S3934>
<S3935>Folder options</S3935>
<S3936>Windows 11 24H2 and newer boot into the redesigned Setup. Legacy starts the classic setup.exe wizard instead, which still supports options the new one dropped, such as joining a domain during installation.</S3936>
<S3937>Telemetry</S3937>
<S3938>Typing and speech</S3938>
<S3939>Usage tracking</S3939>
<S3940>Bundled apps and suggestions</S3940>
<S3941>Sign-in</S3941>
<S3942>Automatic per-user installation of the consumer Teams chat client.</S3942>
<S3946>Microsoft Defender cloud protection (MAPS)</S3946>
<S3947>Sends information about suspicious files to Microsoft's cloud service, which also controls automatic sample submission. Has no effect while the antivirus is disabled.</S3947>
<S3948>App install control</S3948>
<S3949>Controls whether Windows warns about or blocks apps installed from outside the Microsoft Store. While Smart App Control is on it behaves as if set to Anywhere, whatever is chosen here.</S3949>
<S3950>Anywhere</S3950>
<S3951>Anywhere, notify of Store app</S3951>
<S3952>Anywhere, warn if not from Store</S3952>
<S3953>Microsoft Store only</S3953>
<S3956>CPU vulnerability mitigations (Spectre, Meltdown)</S3956>
<S3957>Turning these off can recover noticeable performance on older processors, and leaves those processor vulnerabilities open to exploit. Needs a restart, and does nothing on a system without the January 2018 or later updates. (FeatureSettingsOverride)</S3957>
<S3958>Microsoft vulnerable driver blocklist</S3958>
<S3959>Stops drivers Microsoft flagged as exploitable from loading, off a list that ships with Windows updates. Memory integrity, Smart App Control and S mode each force it back on and grey out its Windows Security switch. (VulnerableDriverBlocklistEnable)</S3959>
<S3960>Local Security Authority protection</S3960>
<S3961>Runs the credential process as protected, so tools that harvest passwords out of its memory cannot read it. Turning it on also arms a UEFI lock: on a machine that has already booted with it, turning it back off through the registry alone does nothing, and only an offline image or a clean install reverts it. Some older drivers and authentication add-ins stop loading under it. (RunAsPPL)</S3961>
<S3974>Updates during setup</S3974>
<S3975>Skips the Windows 11 setup screen offering the latest features and security updates, so setup continues to the logon screen. A fully unattended install may still attempt an update pass.</S3975>
<S3979>Privacy settings prompt on first sign-in</S3979>
<S3980>Windows asks each newly created account to choose privacy settings when it first signs in, and asks again after some upgrades. Disabled, those accounts keep the Windows defaults without being asked.</S3980>

Post <S3908>
<S3965>Image edition unavailable</S3965>

Post <S3847>
<S3963>Ready-made settings this page already carries. Appends to the current choices, does not reset.</S3963>

Post <S3403>
<S3973>Startup</S3973>


Delete
<S3496>Checked</S3496>
<S3497>Unchecked</S3497>
<S0246>Desktop icon - Network</S0246>
<S0247>Desktop icon - Recycle Bin</S0247>
<S1107>Taskbar notifications</S1107>
<S1733>Power Control</S1733>
<S3578>Icon cache</S3578>
<S3579>Maximum number of icons Explorer keeps cached. Windows uses 500 when unset; a higher value reduces icon re-fetching and flicker.</S3579>
<S1067>State</S1067>

The Italian file is also aligned with 2026.09.11904​

 

Attachments

Version 2026.09.11904 --> 2026.09.12209 - template.xml file (and other languages).

Delete
<S3309>A command line tool used to transfer data to and from a server.</S3309>
<S3310>Various scripts</S3310>
<S2522>Trim</S2522>
<S3747>Sort mounted images first</S3747>
<S3848>Monthly</S3848>
<S3566>Some characters are invalid and will be removed on commit (max 32).</S3566>
<S2528>External</S2528>
<S3651>Certificate deployment complete (0x4000); all deployable bits cleared.</S3651>
<S3679>Apply the certificate update before the 2011 certificates expire (June/October 2026), or this PC may stop booting updated media.</S3679>
<S3703>Stuck at KEK step: the OEM-signed KEK is missing (event 1803). Needs an OEM firmware or virtualization-platform update.</S3703>
<S3465>App Catalog</S3465>
<S3466>Browse and select apps from winget for automated installation</S3466>
<S3469>Online</S3469>
<S3470>Offline</S3470>
<S3471>Download Selected</S3471>
<S3472>Open Cache</S3472>
<S3473>Reloads and caches the latest online catalog entries</S3473>
<S0434>Free (limited, non-commercial)</S0434>
<S1392>Home (single-seat, non-commercial)</S1392>
<S1393>Professional (single-seat, commercial)</S1393>
<S1394>Business (single-seat, commercial)</S1394>
<S1395>Enterprise (multi-seat, commercial)</S1395>
<S0245>My Computer</S0245>
<S1399>At least one Metro App needs to be kept so that Windows 10 Start Menu gets installed properly.</S1399>
<S3907>Press No to continue regardless, Cancel to stop.</S3907>
<S3908>Continuing leaves Defender's protected files in place, so its removal will be partial.</S3908>

Add
Post <S3836>
<S4147>A command line tool used to create, list and extract archives, including tar, tar.gz, zip and 7z. Accepts the same options as tar on Linux and macOS, so existing scripts and habits carry over.</S4147>
<S4148>A command line tool used to transfer data to and from a server. Batch scripts and app installers call it to download files, since it ships with Windows.</S4148>
<S4174>Dashboard for the device's protection and health: virus and threat protection, firewall, account protection, app and browser control, device security. Includes its tray icon and the Security Center service, which reports the state of the installed antivirus and firewall.</S4174>
Post <S3991> modify
<S3997>Expand on title click</S3997>
<S3998>Clicking a card or parent title expands or collapses it.
When off, only the arrow does, and a title click selects the row.</S3998>
<S4022>ESD compression threads</S4022>
<S4023>Maximum number of CPU threads for ESD compression, capped by the Threads setting. Automatic leaves part of the CPU unused, as higher counts can cause crashes on some systems.</S4023>
<S4113>Modified rows</S4113>
<S4114>How rows that differ from the image default are marked.</S4114>
<S4115>Edge bar</S4115>
<S4116>Bold text</S4116>
<S4127>Early release of next month's non-security fixes and improvements. Includes the same month's Security Update.</S4127>
<S4186>Links</S4186>

Post <S3971>
<S4055>The running operation is being cancelled. Wait for its cancel notice before closing this message - the image being written may be incomplete.</S4055>
<S4056>NTLite closed unexpectedly last time and the crash report was not shown.</S4056>

Post <S3981>
<S4033>EULA</S4033>
<S4034>Readme</S4034>
<S4035>Documentation</S4035>
<S4077>Third-party notices</S4077>

Post <S3906>
<S4159>Install the Windows ADK Deployment Tools, or copy oscdimg.exe next to NTLite.exe, to create ISO images without it.</S4159>
<S4160>all editions</S4160>
<S4161>editions</S4161>
<S4182>Exported</S4182>
<S4187>Recovery/Setup</S4187>

Post <S3920>
<S4139>Saved from the selected image</S4139>

Post <S3842>
<S4068>These characters are not allowed:</S4068>
<S4069>Maximum length reached.</S4069>
<S4183>Editions</S4183>

Post <S3986>
<S4000>Update compression library was not updated as signature could not be verified, report if unexpected</S4000>
<S4050>Article</S4050>
<S4054>Unlisted</S4054>
<S4128>non-ESU</S4128>
<S4129>Out-of-band</S4129>
<S4130>.NET Framework 3.5 and 4.8.1</S4130>
<S4131>.NET Framework 3.5 and 4.8</S4131>
<S4134>Later cumulative updates are built on this one, so it is added with them when the image does not have it yet.</S4134>
<S4136>Enablement package</S4136>
<S4149>Duplicates</S4149>
<S4151>Delete superseded files from the update cache</S4151>
<S4152>Delete extra copies from the update cache, keeping one of each update</S4152>
<S4155>To install the language packs offline, get the Features on Demand ISO</S4155>
<S4158>To install the language packs offline, get the Language Pack DVD</S4158>
<S4180>Offline</S4180>

Post <S3989>
<S4057>Feature Update</S4057>

Post <S3874>
<S4059>2011 only</S4059>
<S4060>2023 trusted</S4060>
<S4061>Lockout</S4061>
<S4062>2023 upgrade</S4062>
<S4063>Certificate updates unavailable</S4063>
<S4064>Vendor firmware update needed</S4064>
<S4065>The firmware already carries the vendor-signed 2023 KEK; deploy when ready.</S4065>
<S4066>The boot manager and db steps work on any UEFI; whether the vendor shipped a 2023 KEK shows after the first deployment run.</S4066>
<S4071>Boot revocation list</S4071>
<S4072>older than the image</S4072>
<S4073>Media</S4073>
<S4074>The media's boot revocation list (boot.stl) is older than the one inside the boot image, so a machine may refuse to boot this media with error 0xC0430001. Updating the boot manager or integrating an update into the boot image refreshes it.</S4074>
<S4075>Boot manager below the image's anti-rollback floor</S4075>
<S4076>The boot manager on this media has a lower Secure Boot version number than the floor this image's update publishes. A PC that has installed that update, or this image once it applies it, refuses to boot the media with error 0xC0430001. Update the boot manager, or let the cumulative update service the boot image.</S4076>
<S4078>Not offered: the boot manager this PC starts from has a lower Secure Boot version number than the floor this step would set, so the PC could refuse its own boot manager with error 0xC0430001. Install the latest cumulative update first, then stage this step.</S4078>
<S4081>Load this media's install.wim to update the boot manager.</S4081>

Post <S3945>
<S4079>Hide cmd window</S4079>
<S4080>Hides the main command window of the scripts.
A command that waits for input then waits with nothing on screen.
Security products can flag the 'conhost.exe --headless' launch it writes, as some malware is known for it.
Before logon, the Unattended and SetupComplete.cmd modes are hidden by design.</S4080>
<S4142>The downloaded file is damaged or not signed by Microsoft, so it was not kept.</S4142>
<S4173>Removing Defender on a running Windows is a two-stage job. This run disabled it and removed part of it. Re-run NTLite and remove Defender again to clear the rest.</S4173>
<S4176>Individual</S4176>
<S4177>Editions that carry the same WinRE share one row. It is serviced once, and the result is written into each of them.</S4177>
<S4178>Every edition's WinRE has a row of its own and is serviced on its own.</S4178>
<S4179>Open with popup</S4179>

Post <S3390>
<S4024>limited, non-commercial</S4024>
<S4025>single-seat, non-commercial</S4025>
<S4026>single-seat, commercial</S4026>
<S4027>multi-seat, commercial</S4027>
<S4028>Include boot.wim updates by default</S4028>
<S4029>Queuing a cumulative or dynamic update also ticks the boot.wim 'Windows Setup' Updates row. The Secure Boot 'Update boot manager' task ticks it regardless.</S4029>

Post <S3980>
<S3999>Lists</S3999>
<S4001>Printer sharing</S4001>
<S4002>Connect over RPC named pipes</S4002>
<S4003>Windows 11 22H2 and later connect to shared printers over RPC over TCP only. Older Windows expects RPC over named pipes and the connection fails with error 0x00000709.</S4003>
<S4004>Accept incoming RPC over</S4004>
<S4005>Protocols the Print Spooler listens on for other PCs. Windows 11 22H2 and later listen on RPC over TCP only, so older Windows cannot reach the shared printer (error 0x00000709).</S4005>
<S4006>Apply on the PC sharing the printer and on the PC connecting to it, then restart the Print Spooler service or reboot.</S4006>
<S4007>Require Kerberos for incoming RPC</S4007>
<S4008>Accepts only Kerberos-authenticated connections, which needs every PC domain-joined. Disabled = Negotiate, which uses Kerberos when available and NTLM otherwise, so workgroup and older Windows clients can still connect.</S4008>
<S4009>RPC over TCP port</S4009>
<S4010>Fixed port for incoming and outgoing RPC over TCP instead of a dynamic one (49152-65535), for firewall rules. 0 = dynamic, the default.</S4010>
<S4011>RPC packet privacy</S4011>
<S4012>Encrypts and authenticates every packet on the print spooler RPC interface (CVE-2021-1678, enforced since the September 2021 updates). Clients without that update fail with error 0x0000011b; disabling it lets them connect at the cost of that protection. Set on the PC sharing the printer.</S4012>
<S4013>RPC over named pipes</S4013>
<S4014>RPC over TCP</S4014>
<S4015>RPC over named pipes and TCP</S4015>
<S4016>Point and Print - warn and elevate on driver install</S4016>
<S4017>Since the August 2021 updates (PrintNightmare, CVE-2021-34527) installing a driver from a shared printer shows a warning and asks for administrator credentials. Disabling the prompt lets any user connect to a shared printer, but a malicious print server could then install code without asking.</S4017>
<S4018>Point and Print - driver update prompt</S4018>
<S4019>Show warning and elevation prompt</S4019>
<S4020>Show warning only</S4020>
<S4021>Do not show warning or elevation prompt</S4021>
<S4036>Microsoft defaults</S4036>
<S4037>All forced on</S4037>
<S4038>Intel, Hyper-Threading enabled</S4038>
<S4039>Intel, Hyper-Threading disabled</S4039>
<S4040>Administrator protection</S4040>
<S4041>Runs each elevated action through a temporary system-managed administrator account instead of the signed-in one, and asks for Windows Hello or a password every time. Off by default, and inert with User Account Control switched off. Microsoft advises against it on machines that need Hyper-V or Windows Subsystem for Linux, network drives are unreachable from elevated apps, and some installers fail, often reading as an app that cannot write to its own data folder. Windows 11 24H2 and newer with recent updates, desktop editions only. Needs a restart.</S4041>
<S4042>Outgoing NTLM authentication</S4042>
<S4043>NTLM hands a reusable credential to whatever server asks for it, which is what relay and coercion attacks collect.</S4043>
<S4044>Audit only</S4044>
<S4045>Blocked</S4045>
<S4046>NetBIOS name resolution broadcasts</S4046>
<S4047>When DNS has no answer, Windows shouts the name at the whole subnet, and any machine on it can answer with its own address to harvest credentials. Disabled switches to point-to-point mode, so names resolve through DNS or a WINS server only. Devices that answer to NetBIOS broadcasts alone, mostly old file shares and printers, stop being reachable by name.</S4047>
<S4048>Windows Script Host</S4048>
<S4049>Blocks .vbs, .js and .wsf files from running through wscript and cscript, one of the oldest malware delivery routes still in use. Written for both the 64-bit and the 32-bit script host. Some installers and logon scripts need it, and the failure reads as a broken installer rather than a blocked script.</S4049>
<S4067>Legacy compatibility</S4067>
<S4082>Not configured</S4082>
<S4083>Execution policy - All users</S4083>
<S4084>Whether Windows PowerShell runs script files, and which ones. A plain choice is the local machine preference: what Set-ExecutionPolicy writes when no scope is named, written for both the 64-bit and the 32-bit PowerShell, and the lowest ranking scope. Left unset it means Restricted on desktop editions and RemoteSigned on Server. A (Policy) choice sets the machine policy instead: it overrides every other scope, and while it is set Set-ExecutionPolicy cannot change the policy at all.</S4084>
<S4085>Local machine preference</S4085>
<S4086>What Set-ExecutionPolicy writes when no scope is named. Lowest ranking scope, so any of the three above it wins. Written for both the 64-bit and the 32-bit PowerShell. Left unset it means Restricted on desktop editions and RemoteSigned on Server.</S4086>
<S4087>Execution policy - Per user</S4087>
<S4088>The same choice for each user. A plain choice is the current user preference, what Set-ExecutionPolicy -Scope CurrentUser writes, and it outranks the all-users preference. A (Policy) choice sets the user policy instead: it ranks below only the machine policy, and locks out Set-ExecutionPolicy the same way.</S4088>
<S4089>Current user preference</S4089>
<S4090>What Set-ExecutionPolicy -Scope CurrentUser writes. Ranks above the local machine preference and below both policies.</S4090>
<S4091>Script block logging</S4091>
<S4092>Records every block of PowerShell code into the event log as it runs, including code decoded or built at runtime, which is what obfuscated scripts hide behind. Verbose on a busy machine, and the log ends up holding whatever the script handled, passwords included.</S4092>
<S4093>Module logging</S4093>
<S4094>Records the pipeline of every PowerShell module command into the event log, with the arguments it was called with. Enabled here covers all modules.</S4094>
<S4095>Transcription</S4095>
<S4096>Writes a text transcript of every PowerShell session, input and output, into a file in the user's Documents folder. Readable by whoever ran the session, and the files grow without limit.</S4096>
<S4097>blocks every script file, and is what produces the 'running scripts is disabled on this system' error</S4097>
<S4098>runs only scripts signed by a publisher the machine trusts</S4098>
<S4099>runs local scripts, and needs a trusted signature only on downloaded ones</S4099>
<S4100>runs everything, warning once per downloaded script</S4100>
<S4101>runs everything, never blocking or warning</S4101>
<S4102>Certificate revocation check wait</S4102>
<S4103>How long Windows waits for a certificate authority to answer whether a signature is revoked. An unreachable authority means the full wait is spent for nothing, which is why installers stall for minutes offline. A shorter wait still checks, but abandons a slow authority, so a revoked certificate can slip through. Windows default is 15 seconds per address, 20 total.</S4103>
<S4104>1 second per address, 1.3 total</S4104>
<S4105>Applies to every user account.</S4105>
<S4106>Applies to each user account separately.</S4106>
<S4107>logs what would be blocked, without blocking anything, so it shows what would break first</S4107>
<S4108>stops logins to servers reached by IP address, older network drives and anything else that cannot use Kerberos</S4108>
<S4109>leaves several mitigations off, and more of them on Server images</S4109>
<S4110>closes that gap, at a performance cost</S4110>
<S4111>recovers noticeable performance on older processors, and leaves those processor vulnerabilities open to exploit</S4111>
<S4112>Windows watches how the machine is used, then turns it on or off by itself</S4112>
<S4137>TPM / Secure Boot (anti-cheat)</S4137>
<S4175>Not enforced</S4175>
<S4181>Empty folder</S4181>
<S4184>3 seconds per address, 4 total</S4184>
<S4185>6 seconds per address, 8 total</S4185>

Post <S3105>
<S4117>The ISO destination drive is not available. Reconnect it or select another destination.</S4117>
<S4118>Skipped, pending operations detected</S4118>
<S4121>DISM update cleanup fails on such an image, so updates are cleaned with the Custom method instead.</S4121>
<S4122>Skipped, an earlier removal trimmed the component store</S4122>
<S4123>DISM's servicing host crashed while working on this image.</S4123>
<S4125>An earlier apply removed components from this image with servicing stack compatibility disabled.</S4125>
<S4126>Enabling a Windows feature fails if that removal deleted files the feature needs.</S4126>
<S4135>Added language packs and Features on Demand stay out of date until a cumulative update is applied after them.</S4135>
<S4138>Adding language packs and Features on Demand to this image needs the checkpoint cumulative update queued</S4138>

Post <S3965>
<S4162>Ignore the steps above</S4162>
<S4163>Steps to run before applying</S4163>
<S4164>Turn off Tamper protection</S4164>
<S4165>Switch Tamper protection off in Windows Security, then return here.</S4165>
<S4166>Turn off Real-time protection</S4166>
<S4167>NTLite switches this off to speed up processing. No reboot needed.</S4167>
<S4169>Turn off its real-time protection, or add these folders to its exclusion list, for faster processing.</S4169>
<S4170>Show folders to exclude</S4170>
<S4171>Open Windows Security</S4171>
<S4172>Turn off now</S4172>

Post <S3403>
<S4051>The free version is limited to one capability or language per image.</S4051>
<S4052>Replace with</S4052>
<S4053>Enable feature</S4053>
<S4058>Download the CAB packages the enabled capabilities need, from the Microsoft Features on Demand ISO into the update cache. Available once a capability is enabled and its packages are not cached yet.</S4058>
<S4120>A firewall or proxy may be blocking NTLite from reaching the Microsoft download server. Allow the connection, then try again.</S4120>
<S4124>Features on Demand could not be downloaded.</S4124>
<S4146>WMIC is removed by Windows updates for this version, so it can no longer be added.</S4146>
<S4153>Not installed</S4153>
<S4154>To install Features on Demand offline, get the Features on Demand ISO</S4154>
<S4156>Extract it whole into this folder</S4156>
<S4157>To install Features on Demand offline, extract the Features on Demand ISO whole into this folder</S4157>


end part 1
 
Last edited:
continue part 2

Modify
<S3984>DirectX Web Installer</S3984>
<S0602>Load last session</S0602>
<S2524>Delete unlisted files from the update cache</S2524>
<S3420>Keep history in overwritten presets</S3420>
<S3828>Compact 'Last change' dates</S3828>
<S3830>Log at debug level</S3830>
<S3849>Optional Update</S3849>
<S3869>Show actions on hover</S3869>
<S3870>Reveal actions when passing a mouse over an item, e.g. image actions over the title.
When off, card actions such as Image or Presets stay permanently visible.
Note that the options are always accessible in the right-click menu and toolbar on selection.</S3870>
<S3883>Use larger fonts</S3883>
<S3991>Save last session as</S3991>
<S3910>Pack the logs, crash dumps and presets you pick into a support package, ready to email to support.</S3910>
<S3943>Account names in log paths are replaced with a placeholder. Presets are stripped of names, passwords and product keys and their file paths are shortened, the same way an exported preset is. Crash dumps are packed as they are.
This is best effort, so open the package and check it before you send it.</S3943>
<S0228>Current image will be replaced after conversion, backup or create 'New edit' before this operation.</S0228>
<S0801>Please unload any mounted editions from this image file before retrying.</S0801>
<S1145>Missing Windows component</S1145>
<S3123>Disconnect</S3123>
<S3124>Replace reference</S3124>
<S1802>Save image</S1802>
<S2937>Servicing Stack Update</S2937>
<S3668>Unreadable</S3668>
<S3686>This image is ready for 2023 Secure Boot.</S3686>
<S3968>Computer name prompting needs Windows Script Host and VBScript in the boot image, using an auto-generated name instead</S3968>
<S2887>Feature update safeguard (Upgrade block)</S2887>
<S3059>On supported updated OS versions enables RPC_C_AUTHN_LEVEL_PKT_INTEGRITY on DCOM by default.</S3059>
<S3932>File sharing</S3932>
<S3957>Default does not mean every protection is on. Pick a forced option by the processor the image will run on, not the one building it. Needs a restart, and does nothing on a system without the January 2018 or later updates.</S3957>
<S3959>Stops drivers Microsoft flagged as exploitable from loading, off a list that ships with Windows updates. Memory integrity, Smart App Control and S mode each force it back on and grey out its Windows Security switch.</S3959>
<S3961>Runs the credential process as protected, so tools that harvest passwords out of its memory cannot read it. Turning it on also arms a UEFI lock: on a machine that has already booted with it, turning it back off through the registry alone does nothing, and only an offline image or a clean install reverts it. Some older drivers and authentication add-ins stop loading under it.</S3961>
<S0074>Back up preset and log on the edited image</S0074>
<S1071>Stop before saving the loaded and install images, boot and recovery still save</S1071>
<S3866>This PC cannot run the image's servicing stack. Integrate updates and features on a PC of the image's architecture</S3866>
<S2640>NTLite cannot download Features on Demand for this image, as Microsoft publishes no download link for its Features on Demand ISO.</S2640>

The Italian file is also aligned with 2026.09.12209​

 

Attachments

Last edited:
Version 2026.09.11209 --> 2026.09.12311 Major update Part A

Move
Section <Updates>  </Updates> moved in the template and now comes after Drivers.

Delete
<S1260>Before proceeding with component removal, if planning to remove more than just Apps in DISM mode, please read this carefully.</S1260>
<S1261>Removing Windows components is an irreversible process and can cause unforeseen consequences.</S1261>
<S1262>In case of an image (offline) modification, you should test the edited image in a virtual environment before deploying it to a real machine.</S1262>
<S1263>In case of an already deployed (online) modification, you should have a backup ready before applying any changes.</S1263>
<S1264>Due to the nature of Windows package installation - if you remove components, some updates (hotfix, language pack, etc.) and Features later might not install.</S1264>
<S1265>Updates expect files being updated to be present. Due to partial package removal (removing a component in the package) you can run into a situation where especially bigger cumulative updates or language packs will not be able to find what needs to be updated and thus fail installing.</S1265>
<S1266>If you remove components from Windows, you should be prepared to reinstall at any point, be it because you want to install a failing update, or to return some component back.</S1266>
<S1281>Windows component removal warning</S1281>
<S1541>On Windows 10 and 11, it is possible to reconfigure kept components, and update without Windows Update, using the Host Refresh wizard without reinstallation.</S1541>
<S1959>Make sure to report such preset and update combination.</S1959>
<S2546>To trigger a deeper removal mode, without Windows Update compatibility, also disable Servicing Stack compatibility in the same session.</S2546>
<S2643>Newer Windows 10 and 11 cumulative updates return removed component pieces if updated after deployment - there is a single-click cleanup option in the #Image - Tools - Remove Reinstalls. Alternatively update via the Host Refresh method.</S2643>
<S3079>App removal</S3079>
<S3080>Applies only to apps, DISM is normal mode, Custom adds extra steps on top of it, removing support for the app in some cases.</S3080>
<S2702>Most used apps</S2702>
<S2709>Recently opened items in Jump Lists</S2709>
<S4082>Not configured</S4082>
<S4085>Local machine preference</S4085>
<S4086>What Set-ExecutionPolicy writes when no scope is named. Lowest ranking scope, so any of the three above it wins. Written for both the 64-bit and the 32-bit PowerShell. Left unset it means Restricted on desktop editions and RemoteSigned on Server.</S4086>
<S4089>Current user preference</S4089>
<S4090>What Set-ExecutionPolicy -Scope CurrentUser writes. Ranks above the local machine preference and below both policies.</S4090>

<S0097>Block Level Backup Service Engine</S0097>
<S1005>Shared Protection Point (SPP)</S1005>
<S1980>Isolated user mode (IUM)</S1980>
<S3314>During cumulative update integration, update boot manager files as well.</S3314>
<S0012>Accessories</S0012>
<S0136>Checkpoint, F5, Juniper and SonicWALL built-in VPN support.</S0136>
<S1256>VPN plugins</S1256>
<S1608>Terminal Services USB redirector</S1608>
<S1331>XPS Writer and Services</S1331>
<S0109>Brokers connections that allow Windows Store Apps to receive notifications from the internet.</S0109>
<S0110>Browser Choice backend</S0110>
<S1335>You can use the Browser Choice update to select and install the web browser you want to use on your PC.</S1335>
<S1891>Non-Windows applications push notifications API</S1891>
<S1922>Windows PDF Engine</S1922>
<S1923>Used in Reader and Edge to display PDFs.</S1923>
<S2964>C++ Runtime framework package for Desktop Bridge</S2964>
<S2982>Camera Barcode Scanner Preview</S2982>
<S2983>Desktop App Web Viewer</S2983>
<S2985>Support for eye-tracking hardware.</S2985>
<S3048>Windows Apps</S3048>
<S3060>Phone Link</S3060>
<S0140>Chinese</S0140>
<S1300>Windows Media Center update</S1300>
<S1195>Uncheck all</S1195>
<S3026>Overlay</S3026>
<S1594>Windows boot</S1594>
<S3803>Hover</S3803>
<S0293>Driver Export</S0293>
<S0872>Reboot</S0872>
<S1450>Needed for Windows 10 networking.</S1450>
<S1504>Automate</S1504>
<S2410>Skip all</S2410>
<S0949>Saving general settings failed.</S0949>
<S0880>Register</S0880>
<S1642>Website</S1642>
<S3927>Crash dumps</S3927>
<S4034>Readme</S4034>
<S2598>Exit after processing</S2598>
<S2599>Type 0 to disable, or 1 to enable this functionality</S2599>
<S0093>64 bit</S0093>
<S0346>Enter part size:</S0346>
<S0384>Export all</S0384>
<S0432>Found and using oscdimg in the application root.</S0432>
<S0654>Minimum split size warning</S0654>
<S0727>Note: this is not the currently loaded image, to apply any changes with this tool, you must load the image first.</S0727>
<S0865>Read registry.</S0865>
<S0898>Removal on this Windows version not supported.</S0898>
<S0996>Do you want to set the size to</S0996>
<S1054>Split image is not officially supported by Microsoft on Windows 8 and newer.
However it is known to work if the part size is big enough.
Minimum recommended split part size for Windows 8 and newer is half of the final image size.
If this image installation gets stuck on boot asking for a product key or a Windows license even if you provided a valid one, convert back to WIM and try a bigger split part size.</S1054>
<S1057>Split the selected WIM image into multiple SWM parts?</S1057>
<S1154>To apply any changes with this tool, use the Apply page on the left instead.</S1154>
<S1179>Type a label for the ISO image:</S1179>
<S0501>Image directory</S0501>
<S0661>Missing preset</S0661>
<S1745>Open Host Refresh wizard instead?</S1745>
<S1748>Copy to temporary location before editing</S1748>
<S1772>Select which image tasks to automate during the process. Currently loaded image and its pending changes are the reference.</S1772>
<S3565>File exists - will be overwritten</S3565>
<S3582>SWM images cannot be re-saved in place. Select a different destination.</S3582>
<S3584>Re-splitting an SWM into smaller parts is not yet supported. Keep the part size at or above the source's current part size, or export to WIM or ESD instead.</S3584>
<Other> 2030
<S0006>Abort</S0006>
<S0161>Closing DISM</S0161>
<S0226>Crucial files are being already used by another process.</S0226>
<S0396>Extract</S0396>
<S0668>Mount directory seems to be in use. This tool is about to close all DISM sessions on your machine, make sure that you do not have any other DISM operation in progress before continuing.
If you know what is keeping it open, press Cancel after closing it.</S0668>
<S1626>or</S1626>
<S2864>Run 'Remove Reinstalls' after a reboot?</S2864>
<S2884>Servicing stack compatibility option is disabled, deep removal mode is enabled. Updating this image will require a Host Refresh or reinstall.</S2884> ADD
<S2927>Express Update</S2927>
<S0765>Package files</S0765>
<S2495>Compatible</S2495>
<S2515>Last checked</S2515>
<S3587>Signed</S3587>
<S0592>License code</S0592>
<S1333>You already have the latest version.</S1333>
<S3474>Last updated</S3474>
<S0594>Licensed</S0594>
<S3031>Renewal</S3031>
<S3032>Paste renewal license code</S3032>
<S0732>OEM SetupComplete</S0732>
<S1192>Unattended mode</S1192>
<S0303>Driver files</S0303>
<S1112>TCP/IP</S1112>
<S1293>Windows Installer</S1293>
<S1342>Reset Value</S1342>
<S1970>Shell Folders</S1970>
<S2689>Folder</S2689>
<S3141>Animation effects</S3141>
<S3531>Extras</S3531>
<S0611>Local Machine</S0611>
<Toolbar>
<S0953>Scope</S0953>
</Toolbar>
<S0130>Change and run</S0130>
<S0189>Configure features</S0189>
<S0530>Install packages</S0530>
<S0538>Integrate drivers</S0538>
<S0539>Integrate packages</S0539>
<S0574>Keep only</S0574>
<S0900>Remove components</S0900>
<S1777>Install drivers</S1777>
<S0150>Cleaning empty directories</S0150>
<S0823>Preparing integration</S0823>
<S1435>Cannot automatically disable Windows Defender, please manually disable Real-time protection in its settings.</S1435>
<S1436>Press Yes to open Windows Defender Settings.</S1436>
<S0809>Image post-processing</S0809>
<S0944>Save changes and unmount</S0944>
<S0955>Seal features</S0955>
<S0956>Remove Windows 7 Features obsolete updates, reducing size much more. Windows Features (CPanel-&gt;Programs-&gt;Features) states will not be changeable after this operation, so make sure to setup final Features page states when using this option. </S0956>
<S1053>Split</S1053>
<S1345>Passive</S1345>
<S0368>Execution queue</S0368>
<S3919>Remove it from the exported file?
Names are replaced with placeholders, passwords and keys are emptied, paths keep only their last folder and file name.</S3919>
<S3841>Select file</S3841>
<S2514>Selected</S2514>
<S1641>File successfully copied.</S1641>

End Part A
 
Version 2026.09.11209 --> 2026.09.12311 Major update Part B

Add
Post <S1194>
<S4193>Removal mode</S4193>
<S4194>Update support</S4194>
<S4196>Next</S4196>
<S4197>Choose a removal mode. It controls which components are shown and which are protected.</S4197>
<S4198>Fully supported Windows operations only.
Lists Apps, Features, third-party drivers and ISO files that are safe to remove.</S4198>
<S4199>Lists every component.
Uses Native removal where possible and Custom removal for the rest.</S4199>
<S4201>Cumulative updates may bring back parts of removed components. Image - Tools - Remove Reinstalls cleans them up.</S4201>
<S4202>Off: updates can no longer be installed.</S4202>
<S4203>Removal goes deeper, for a smaller image.</S4203>
<S4204>Use the Host Refresh wizard instead.</S4204>
<S4205>Removed components cannot be restored in place.</S4205>
<S4206>Test an edited image in a virtual machine first.</S4206>
<S4207>SFC compatibility</S4207>
<S4208>I understand the risks of this mode</S4208>
<S4212>Keeps Windows servicing, so updates, language packs and Features can still be installed. Best effort, some may fail.</S4212>
<S4213>Keeps WinSxS for the components you keep, so an SFC scan can still repair them. The image stays larger.</S4213>
<S4214>Native</S4214>
<S4215>Custom app cleanup</S4215>
<S4216>Also removes what each removed app leaves behind in the system. Leave it off to reinstall apps later.
System Apps always get Custom removal, as Native cannot remove them.</S4216>
<S4217>Native keeps components you unchecked and checks them again:</S4217>
<S4218>Back up this system before applying.</S4218>
<S4219>The Host Refresh wizard brings most of them back, from an image that still has them.</S4219>
<S4220>The image stays larger: key components and the WinSxS copies updates use are kept.</S4220>
<S4221>Earlier edits to this image lock some choices. Start from a fresh image to change them.</S4221>

Post <S3481>
<S4188>Default language</S4188>
<S4189>Language pack queued for integration</S4189>
<S4190>Needed on Windows 10 and later</S4190>
<S4191>Needed to boot</S4191>
<S4192>Needed for the Unattended computer name prompt</S4192>

Post <S4179>
<S4222>This Windows has the recommended secure connection protocols (TLS 1.2 and newer) turned off, and NTLite needs them to reach its server and downloads. Turn them on now? Older protocols stay on for the programs that still use them.</S4222>
<S4223>Windows also needs the Microsoft update KB3140245, Yes opens its page.</S4223>
<S4224>Answer No to open the Microsoft page and do it manually.</S4224>
<S4225>This Windows version cannot use TLS 1.2 for secure connections, and NTLite needs it to reach its server and downloads. A newer Windows version is needed.</S4225>

Post <S4185>
<S4226>Turns this protocol on or off for everything that uses the Windows secure connection stack: Remote Desktop, IIS, and the programs built on WinHTTP, WinINet or .NET. Default leaves the Windows default. Disabled for incoming only turns it off for connections this machine accepts, and keeps it for the ones it makes.</S4226>
<S4227>Disabled for incoming only</S4227>
<S4228>TLS 1.2 by default</S4228>
<S4229>Lets programs built on WinHTTP, many installers and updaters among them, connect with TLS 1.2. Windows 7 and Server 2012 leave it off for them even where TLS 1.2 itself is on, and need the Microsoft update KB3140245 before this setting does anything. Older protocols stay on.</S4229>
<S4230>Use Windows TLS settings</S4230>
<S4231>Lets .NET Framework programs use the protocols Windows offers, TLS 1.2 included, instead of the shorter list built into the framework. Older protocols stay available. .NET Framework 3.5 needs its TLS 1.2 update installed for this to work.</S4231>
<S4232>Strong cryptography</S4232>
<S4233>Limits .NET Framework programs to TLS 1.2 and newer, and drops weak ciphers such as RC4. A .NET program that talks to a server which only speaks an older protocol stops reaching it.</S4233>

Post <S3996
<S4268>Perception Simulation</S4268>
<S4269>Simulates head, hand and controller input and manages virtual cameras for mixed reality development, such as the HoloLens Emulator.</S4269>

Post <S4221>
<S4240>Default+</S4240>
<S4241>Deep</S4241>
<S4242>Max</S4242>
<S4244>Removal level</S4244>
<S4263>Default removal level</S4263>
<S4264>The removal level an image gets when no preset sets one. Prompt opens the Removal mode dialog on the first visit to Components.</S4264>
<S4265>Prompt</S4265>

Post <S4192>
<S4259>Not provisioned, removable in Custom mode only</S4259>
<S4260>Provisioned</S4260>
<S4261>Unprovisioned</S4261>
<S4262>Windows Input Experience</S4262>

Post <S4233>
<S4246>Copilot and AI</S4246>
<S4247>Ask Copilot in taskbar search</S4247>
<S4248>Copilot key</S4248>
<S4249>Save snapshots</S4249>
<S4250>Settings agentic search</S4250>
<S4251>Agent connectors</S4251>
<S4252>System AI models</S4252>
<S4253>AI features</S4253>
<S4254>Sidebar</S4254>
<S4257>Services that depend on a disabled service will not start.</S4257>
<S4258>Remove the dependency so they can start</S4258>
<S4266>Phone-PC linking</S4266>
<S4267>Lets this PC link to phones, for Phone Link, Mobile devices and Continue on PC. Disabled unlinks every phone. Takes effect after a restart.</S4267>

Post <S4172>
<S4234>Repair Windows Security</S4234>
<S4235>The Windows Security app is missing, so its Defender settings cannot open. NTLite installs it again from Microsoft's Windows Security update.</S4235>
<S4236>Repair now</S4236>
<S4237>Installing Windows Security, this can take a few minutes...</S4237>
<S4238>Missing Sources\SxS package.</S4238>
<S4239>Enable .NET Framework 3.5 on the Features page, Features on Demand tab, instead.</S4239>
<S4243>Exporting from an ISO needs these, missing on this Windows:</S4243>
<S4245>Browse</S4245>
<S4255>Windows Security cannot be repaired</S4255>
<S4256>The Windows Security app and its Security Health service were both removed. Microsoft's Windows Security update does not include the service, so its Defender settings cannot open on this system.</S4256>

Post <S4269>
<S4293>Camera Class Extension</S4293>
<S4294>Kernel framework used by newer camera drivers.</S4294>

Post <S4187>
<S4271>Download Image</S4271>
<S4272>Edition set</S4272>
<S4273>Consumer</S4273>
<S4274>Skip</S4274>
<S4275>Scanning existing local images</S4275>
<S4276>Could not read the download list from Microsoft.</S4276>
<S4277>Microsoft refused the request. Many downloads in a short time, a VPN or a proxy can cause it. Try again later or from another network.</S4277>
<S4278>The downloaded file does not match the checksum Microsoft publishes for it, so it was deleted.</S4278>
<S4279>Not enough free space for this download</S4279>
<S4281>Locate</S4281>
<S4282>Business</S4282>
<S4283>Microsoft no longer serves this file. Pick another release.</S4283>
<S4284>Another format to try</S4284>
<S4296>Convert to ISO</S4296>

Post <S3872>
<S4270>Download a Windows image from Microsoft and add it to the list</S4270>

Post <S4139>
<S4295>Keep it in the exported file?
No removes it: names are replaced with placeholders, passwords and keys are emptied, paths keep only their last folder and file name.</S4295>

Post <S4183>
<S4285>Select destination</S4285>
<S4286>Include setup files</S4286>
<S4287>Writes the Windows setup files and boot.wim along with the ticked editions, laid out as installation media. Untick to export the ticked editions alone.</S4287>
<S4289>Builds an ISO of the setup files and the ticked editions beside the ESD, then deletes the ESD.</S4289>
<S4290>Convert image</S4290>
<S4291>Rewrites the image in the chosen format, then deletes the original file.</S4291>
<S4292>Packed</S4292>

Post <S4057>
<S4297>Stop</S4297>
<S4298>Stopping...</S4298>
<S4299>Are you sure you want to stop?</S4299>

Post <S4267>
<S4280>Dependent services</S4280>

Post <S4186>
<S4302>Custom scratch (extract) directory</S4302>
<S4303>Custom update cache for extracted updates</S4303>

Post <S4295> [modify]
<S4300>It is removed from the exported file: names are replaced with placeholders, passwords and keys are emptied, paths keep only their last folder and file name.</S4300>

Post <S4138> [modify]
<S4304>Skipped as expected</S4304>

Post <S3963>
<S4301>Custom theme</S4301>



Modify
<S1981>Uses hardware virtualization features to create and isolate a secure region of memory from the normal operating system. When Credential Guard is enabled, Local Security Authority Subsystem Service (lsass.exe) runs sensitive code in an Isolated user mode process (LsaIso.exe) to help protect data from malware. Memory integrity, Credential Guard, Windows Hello Enhanced Sign-in Security, Recall and hotpatch updates need it.</S1981>
<S4226>Turns this protocol on or off for everything that uses the Windows secure connection stack: Remote Desktop, IIS, and the programs built on WinHTTP, WinINet or .NET. Client covers the connections this machine makes, Server the ones it accepts. Default leaves the Windows default. Opt-in only keeps it off unless a program asks for this protocol by name.</S4226>
<S4227>Opt-in only</S4227>
<S1340>Needs the full Windows setup media (an ISO or a copy of the USB setup files), not a single image file.</S1340>
<S4103>How long Windows waits for a certificate authority to answer whether a signature is revoked. A shorter wait still checks, but abandons a slow or unresponsive authority sooner, so a revoked certificate can slip through. Windows default is 15 seconds per address, 20 total.</S4103>
<S4258>Remove the dependency so they might start</S4258>
<S4267>Lets this PC link to phones, for Phone Link, Mobile devices and Continue on PC. Disabled unlinks every phone.</S4267>
<S4244>Level</S4244>
<S3138>Throws away every change made in this edit and makes it match its reference image again, copying or deleting only what differs.</S3138>
<S4295>Keep private data</S4295>
<S4135>Cumulative update at the image's version or newer</S4135>
<S4138>Added language packs and Features on Demand need</S4138>


The Italian file is also aligned with 2026.09.12311​

 

Attachments

Back
Top