In this article, I’ll show you the new Windows Imaging and Configuration Designer (ICD) and how it can help with Windows 10 provisioning without having to reimage devices or use the Microsoft Deployment Toolkit (MDT) or System Center Configuration Manager.

Kyle Beckman

Kyle Beckman works as a systems administrator in Atlanta, GA supporting Office 365 in higher education. He has 17+ years of systems administration experience.

With Windows 10, Microsoft has released a new tool to allow organizations to rapidly provision or configure both corporate and personally owned Windows 10 devices. The release of Windows 10 on July 29, 2015, also requires updates to the tools that organizations use to deploy the OS, such as the Microsoft Deployment Toolkit (MDT) and System Center Configuration Manager. In addition to the updates to these products, a new tool—Imaging and Configuration Designer (ICD)—is now available to customize Windows 10 installs without the need to reimage the device.

Windows Imaging and Configuration Designer in the ADK Setup
Windows Imaging and Configuration Designer in the Windows Assessment and Deployment (ADK) Setup

Imaging and Configuration Designer allows an IT admin to create provisioning packages that can customize both the mobile and computer versions of Windows 10. These provisioning packages (that have the PPKG file extension) can be used during the OS first run experience or after the OS has been set up to perform tasks such as connecting to WiFi networks, adding certificates, connecting to Active Directory, enrolling a device in MDM, and even upgrading editions—all without the need to format the drive and reinstall Windows. I can think of two scenarios where ICD will be useful: configuration of BYOD devices and automated configuration of OEM images.

Windows Imaging and Configuration Designer
Windows Imaging and Configuration Designer

Configuration of personally owned BYOD devices ^

If your organization supports BYOD, how do you handle setting up your users’ personally owned devices? User devices need to be set up with WiFi, VPN profiles, certificates, applications, etc. At my organization, we publish online FAQs, but many end users still need extra help with some of the more complex configurations. If your organization allows users to bring their devices to a Help Desk or to their IT person, a lot of manual configuration still has to be performed on the devices. What if you could automate all this work?

With ICD, you can build a PPKG file that contains your company’s root certificate, WiFi settings, VPN settings, line of business applications, enrollment in MDM (Mobile Device Management), etc. This PPKG file can then be distributed via USB thumb drive, URL, or even email attachment to any users needing to configure their devices. The user double-clicks the file, accepts a UAC prompt, and then is asked to allow the provisioning package installation. Their device reboots if necessary and configuration is complete with very little manual effort.

Provisioning package installation from a PPKG file
Provisioning package installation from a PPKG file

Automated configuration of OEM OS loads ^

Most large organizations tend to wipe new computers when they are received so IT can install their own custom image and software with MDT, Configuration Manager, or some other OS deployment solution. The primary reason for needing to reload the device is that the Enterprise Edition of Windows doesn’t come preinstalled by OEMs. New devices typically come with the Professional SKU preinstalled unless your organization has an agreement with the OEM to have a custom image installed.

Setting up and maintaining an OS deployment solution can be a lot work for a small (or even a one-person) IT shop that only images a handful of machines on a regular basis, so this is something for small- and medium-sized organizations to consider.

ICD allows you to build a PPKG file that, like the BYOD scenario, can configure certificates, WiFi, VPN, etc. It can also add the computer to Active Directory, set the computer name, and even upgrade the edition of Windows 10 from Professional to Enterprise with only a reboot or two as a requirement.

The PPKG file can also be used to remove preinstalled universal applications or Win32 applications via a script if you know which applications are preinstalled on the system. The PPKG file can either be installed after the computer is set up or during the first run experience by pressing the Windows key five times. This allows you to completely configure a new device without having to perform the steps manually as soon as you pull the computer out of the box.

Setting up a new Windows 10 device with a PPKG file by pressing the Windows key five times
Setting up a new Windows 10 device with a PPKG file by pressing the Windows key five times

What can be configured with a PPKG? ^

You can use ICD to create PPKG provisioning files that can perform the initial setup of a device, upgrade the Windows 10 edition, add a device to MDM/Active Directory/Azure Active Directory, configure WiFi, configure VPN, install certificates, install Universal Windows apps, install Win32 apps, run scripts, copy offline content to the device, configure browser settings, customize the Start Menu, configure Assigned Access, and configure a number of other Enterprise policies such as power and security settings.

Do I need Windows Imaging and Configuration Designer?

If you support BYOD, want to use factory OEM images, or want to automate configurations that you’re currently performing manually, I would definitely check out ICD. ICD only works with Windows 10 and won’t completely replace tools such as your MDM solution, System Center Configuration Manager, or Group Policy; however, it does give you a great way to automate manual work with very little time investment and no infrastructure investment.

Are you an IT pro? Apply for membership!

Your question was not answered? Ask in the forum!

0
Share
4 Comments
  1. daven 4 years ago

    This sounds like exactly what i want for the surface. Prepping an image for desktops and laptops is easy for me now that MDT is set up. However, the surface is a little more work and we don't buy them very often [they are 20 of the 200 pcs we have] so i only tried imaging 2 or 3 of them. I didn't get everything working exactly like I wanted, however.

    0

    • Author
      Kyle Beckman 4 years ago

      I agree completely. The Surface is a great example of a system that IT may not want to touch because of the custom setup involved. I don't see this tool replacing any existing tools today, but it is definitely a good supplement to further automate things that you may be doing by hand today.

      0

  2. Bennie Murphy 4 years ago

    how do you setup application to install?

    1+

  3. Manikanta 1 year ago

    This blog gives me an idea and underrunde of icd how it will works.

    Could you please share examples or links to create and understand more on this concept.

    Can I call this after os install in MDT ?

    0

Leave a reply

Your email address will not be published. Required fields are marked *

*

© 4sysops 2006 - 2019

CONTACT US

Please ask IT administration questions in the forums. Any other messages are welcome.

Sending

Log in with your credentials

or    

Forgot your details?

Create Account