Docs / Remove / Components

Components

Remove Windows components with dependency analysis and safety warnings.

This page contains a list of detected removable Windows components for the loaded image. To queue a component for removal, uncheck the checkbox on the left.

Most components are color-coded, indicating a member of the template in the menu.

Removal Mode

The Mode button on the toolbar decides how deep removal goes: which components the page lists, and which it protects. With no mode chosen yet, the Removal mode dialog opens by itself on the first visit to the page.

  • Native - fully supported Windows operations only. The page lists just apps, features, third-party drivers and the ISO files that are safe to remove; everything else is hidden and kept. The safe choice when the image must stay exactly as serviceable as Microsoft ships it.
  • Custom - lists every component. Native removal is used where it can be, and Custom removal for the rest. Removed components cannot be restored in place - the Host Refresh wizard brings most of them back from an image that still has them - so Custom asks you to tick I understand the risks of this mode before it continues.

Level

A Level slider trades image size against what the result can still do. Dragging it sets the options below, and changing an option moves the slider:

  • Native - Native mode.
  • Default - Custom, with Update support on.
  • Default+ - Default, plus Custom app cleanup.
  • Deep - Update support off, SFC compatibility kept.
  • Max - Update support and SFC compatibility both off, the smallest image.

Custom Options

  • Update support - keeps Windows servicing, so updates, language packs and features can still be installed later. The image stays larger. Turned off, updates can no longer be installed (use Host Refresh instead), and removal goes deeper; it asks for its own confirmation, and unchecks Windows Update and the other servicing rows for you.
  • Custom app cleanup - offered while Update support is on. Also removes what each removed app leaves behind in the system. Leave it off to reinstall apps later. System apps always get Custom removal, since Native cannot remove them.
  • SFC compatibility - offered while Update support is off. Keeps what an SFC scan needs to repair the components you keep, at the cost of a larger image.

An image edited before can lock some of these choices, since a removal already made cannot be undone by picking a gentler level. Start from a fresh image to change them.

The level a new session starts on is set by Default removal level in the app's Settings: Prompt (the default, opening the dialog on the first visit) or a fixed level. A loaded preset sets its own.

Categories

Components sit in categories that sort alphabetically, with the user-facing groups first and the system and critical ones last. Two landmarks moved: Enterprise is now Organizations, and Command-Line Utilities is grouped under Productivity. Apps are no longer a separate list either, each one sits in the category it belongs to.

An app with more than one version in the image lists each version as its own row, and each architecture too where both ship, so an old leftover version can go while the current one stays. In Native mode a version Windows does not have provisioned stays locked, as only Custom mode can remove it.

Show Filter

The Show drop-down on the filter row narrows the tree to one view, alongside whatever the search box is matching:

  • All - the full tree, the default.
  • Keeping / Removing - what is kept, or what is queued for removal.
  • Preset (All) / Preset (Modified) - the rows a loaded preset sets, or only those it changes. Offered while a preset is loaded.
  • Apps (User) / Apps (System) - only apps, each still under its own category.
  • Drivers (Exportable) - only the drivers you can export.
  • Template (Privacy), Template (General), Template (Lite) - what each template would target, so a template can be reviewed before it is applied.
  • Size at least... - asks for a size in MB and lists the components at least that big.

A view expands the categories holding a match, so nothing stays buried under a collapsed parent, and the active view shows as a tag on the filter row. Clicking that tag returns to All and restores your own collapse state, rather than leaving the tree fully expanded.

While the search box has text, a Descriptions checkbox beside it decides whether descriptions are searched too; untick it to match names only. Copy name on the right-click menu copies a component's name.

Hover Card

Hovering a component shows its description and size, and a Links part listing what is tied to it elsewhere in the app - features, services, scheduled tasks, settings and drivers - so the reach of a removal is visible before you make it.

Templates

Menu in the toolbar, unchecks sets of components for each level (Privacy → General → Lite), with Lite removing the most. The Windows Lite ISO guide walks through a full build on top of these templates.

Component checkbox color labels reflect each template:

  • Green - Privacy template
  • Blue - General template
  • Yellow - Lite template
  • Red - Not recommended to remove

Compatibility

Opened from the toolbar, these options help you protect the needed components from removal for a given feature set. The button is hidden in Native mode, which protects everything it does not list anyway.

Enable those that you want protected; that will automatically lock the tied components from unchecking, and thus removal. Especially useful in combination with Templates.

Protection reaches the tied services as well, not only the components: with an option enabled, the service rows that feature depends on are locked on the Settings page too, so a protected feature cannot be broken from the other side. Turning the option back off releases both.

  • Recommended - on by default. Protects every component rated not recommended to remove, the file-system filter classes that antivirus, backup and encryption tools install into among them.
  • Windows Security - on by default, covering the whole security surface: the Windows Security app, Defender, Code Integrity, Smart App Control, virtualization-based security, Device Guard and their supporting pieces. Untick it only if removing the security stack is what you are after.
  • TPM / Secure Boot (anti-cheat) - on by default for new presets. Keeps what anti-cheat systems check for: the TPM and its tools, the boot manager and Secure Boot updates. Game-specific options such as EA Javelin Anti-Cheat sit in the Apps group.

The servicing options - Windows Update, the servicing stack and SFC - no longer show here. The Removal mode level holds them, so they follow Update support and SFC compatibility.

Security Components

Windows Security is the app, with Microsoft Defender Antivirus under it as a separate row, so the antivirus engine can go while the app stays. In the Security & Identity category, Code Integrity (CI) carries Smart App Control (SAC) and Virtualization-based security (VBS) under it, with Device Guard under VBS. Removing Hyper-V keeps VBS.

Code Integrity here is the application-control side of it, the policy surface that Smart App Control and WDAC rules run on. The signature checking Windows needs in order to boot is not part of what a removal takes.

Removing Defender

On a live system, queuing Defender for removal opens a checklist of the steps to run before applying, each marked done or not: Turn off Tamper protection and Turn off Real-time protection, each with a link that does it. When only the Windows Security app went missing, the list offers Repair Windows Security to reinstall it. Continue waits until the steps are done or you tick to ignore them.

Removal and Tied Settings

A queued component removal takes its dependent settings with it. The tweak, visual-effect and event rows that only exist because of that component leave the Settings page and the Apply page as soon as the component is unchecked, and their off value is applied along with the removal, so nothing the component left behind stays switched on. Services and scheduled tasks tied to it stay listed instead, greyed and reading Removing, since they go with the component rather than being settings you still choose.

Order no longer matters. Changing a setting first and queuing its component for removal afterwards used to leave a setting on the Apply page that could not apply, and now the setting leaves with the component either way.