Building A Windows 10 1903 May 2019 Update (19H1) Reference Image with MDT

Current Known Issue: With the Windows 10 1903 ADK on 64-bit, the Windows System Image Manager (WSIM) will fail to generate a catalogue. Microsoft has issued a fix which you can download here. The fix contains two updated files, ImageCat.exe and ImgMgr.exe which need to be copied to the location the ADK is installed. By default the location is: C:\Program Files (x86)\Windows Kits\10\Assessment and Deployment Kit\Deployment Tools\WSIM. After installation you will still not be able to access the WSIM through MDT, but launching WSIM manually and then opening the install.wim file for the Operation System you wish to change, and the XML answer file which will be located in \\server\share\Control\Task-Sequence-ID\Unattend.xml. Many thanks to reader Mark Stenglein for letting me know about this in the comments!


Important note: If you are using Enterprise or Education editions of Windows 10, from 1809 onwards, the xx09 versions of Windows 10 get 30 months of support, over the usual 18 months that the xx03 versions get. So you may wish to reconsider if you deploy the xx03 version at all and just wait for the xx09 update. Here’s some official information from Microsoft here.


This post will walk through installing and configuring Microsoft Deployment Toolkit to build a reference image of Windows 10 1903 (May 2019 Update) using a Hyper-V Virtual Machine. It is assumed that you have a Server or PC ready to install MDT onto and create an file share for MDT to build the image with. I’ll focusing on the Enterprise edition of Windows 10.

Here are the links to the software we’ll be using:

Additional software which may be useful to you:


Installing Microsoft Deployment Toolkit and Dependencies

  1. First we’ll install the Windows 10 1903 ADK. During setup additional files will need to be downloaded, so it may take some time depending on your internet connection.
  2. On the Select the features you want to install screen select:
  • Deployment Tools
  • Imaging And Configuration Designer (ICD)
  • Configuration Designer
  • User State Migration Tool (USMT)
  1. WinPE is now a separate install. Install the WinPE add-on by running the adkwinpesetup.exe, there is no specific configuration during the install wizard.
  2. Now install MDT by running the setup file downloaded earlier. There is no specific configuration during the install wizard.


Creating the Deployment Share

  1. Open the Deployment Workbench from the Start Menu.
  2. Right click on Deployment Shares.
  3. Select New Deployment Share.
  4. Enter the path for the Deployment Share: E:\Build.
  5. Enter the Share nameBuild$.
  6. Give the share a description.
  7. On the Options screen, accept the defaults as you can change them later.
  8. Complete the wizard to create the share.
  9. By default, the share permissions are set the local administrators group. We’ll revisit this later.


Adding an Operating System

  1. Mount the Windows 10 1903 ISO in File Explorer.
  2. Go to Deployment WorkbenchOperating Systems.
  3. Right click and select New Folder.
  4. Enter the name Windows 10 1903 x64 and click through the wizard to create the folder.
  5. Right click again and select Import Operating System.
  6. In the wizard, select Full set of source files and then enter the root of the mounted ISO as the Source directory.
  7. For the destination directory name enter Windows 10 1903 x64 and complete the wizard.
  8. Go to the Operating Systems/Windows 10 1903 x64 node and rename the new entries added to Windows 10 1903<Edition>x64 for ease of use.


Creating Package Folder For Future Updates

  1. Go to Deployment Workbench > Packages.
  2. Create a folder named Windows 10 1903 x64.

Now we’ll create a selection profile so that the Task Sequence only attempts to install the updates for Windows 10 1903 x64.


Creating A Selection Profile

  1. Expand the Advanced Configuration node.
  2. Right click on Selection Profiles and select New Selection Profile.
  3. Name it Windows 10 1903 x64.
  4. On the Folders page, tick the Windows 10 1903 x64 folder under Packages and complete the wizard.


Importing Applications

If you want to add some applications to be a part of your reference image, here I’ll cover how to add Microsoft Office. MDT recognises Microsoft Office and provides automated/silent install options.

  1. Go to Deployment WorkbenchDeployment Share > Applications.
  2. Right click on Applications and select New Application.
  3. In the New Application Wizard, choose Application with source files.
  4. Give the application the name: Microsoft Office.
  5. Enter the Source directory of the installation files.
  6. Enter the Destination directory: Microsoft Office.
  7. For the Command line enter anything, we’ll revisit this later.
  8. On the summary page, click Next and after the files are copied click Finish to complete the wizard.


Configuring Applications

  1. Right click on Microsoft Office, go to the Office Products Tab.
  2. Choose the desired Office Product to Install from the drop down menu.
  3. Check the desired Office language.
  4. Enter a product key, unless you will be activating Office via KMS in which case leave the Product Key option unchecked.
  5. Check the Customer name option and enter the desired information.
  6. Check the Display level option and select None in the drop down menu.
  7. Check the Accept EULA option.
  8. Check the Always suppress reboot option.
  9. Click Apply.
  10. Go to the Details tab and the Quiet install command should now read:
    setup.exe /config proplus.ww\config.xml

Microsoft Office is now set up to be installed silently by a Task Sequence. If you wish to customise the installation to a greater degree, the Office Customization Tool can be launched from the Office Products tab. This process can also be done for Microsoft Visio and Project.

To add other popular third party software, you’ll need to repeat the steps above, with the relevant Command line to quietly or silently install them.

Google Chrome – Enterprise Installer

msiexec /I googlechromestandaloneenterprise64.msi /qn

Adobe Reader – Enterprise Installer

AdobeReaderDC.exe /sAll

We now need to create a new Task Sequence to create a reference image.


Creating a Task Sequence

  1. In Deployment Workbench, go to Task Sequences.
  2. Right click and select New Task Sequence.
  3. For the ID enter: W10-1903.
  4. Name it Build Windows 10 1903.
  5. Select Standard Client Task Sequence.
  6. Select the Operating System Windows 10 1903 x64.
  7. Select Do not specify a product key at this time.
  8. Enter an Organization name.
  9. Select Do not specify an Administrator password at this time.
  10. Complete the wizard.

Now we’ll configure the Task Sequence.


Configuring the Task Sequence

  1. Right click on the Task Sequence just created and select Properties.
  2. Go to the Task Sequence tab on the Properties window of the Task Sequence.
  3. Expand the Preinstall folder, and select the Apply Patches item.
  4. Change the Selection Profile to Windows 10 1903 x64.
  5. Go to the State Restore folder and select Windows Update (Pre-Application Installation).
  6. On the right side of the Properties window, go to the Options tab.
  7. Uncheck the Disable this step tick box and do the same with Windows Update (Post-Application Installation).
  8. If you skipped the Importing Applications section, please disable the Install Applications item and go to step 16, if not please continue.
  9. Go to the Install Applications item.
  10. In the right side of the Properties box, select the Install a single application option and click the Browse… button.
  11. Select Microsoft Office and change the name Install Applications to Microsoft Office.
  12. Install other Applications, copy and paste the Install Applications item and repeat steps 13 – 15 for the applications of your choice.
  13. Click Apply and close the Task Sequence.


Blocking Internet Access to prevent Microsoft Store App Updates

To block internet access to the VM whilst the image is building, we’ll use the script from Peter Löfgren’s System Center Ramblings post.

  1. First create a PowerShell script file called Internet-Access.ps1 with the following code:
## Creates the disable option used by the script
param (

## If the Disable command line option is not added, the script adds a Firewall Rule to block traffic on ports 80 (http) and 443 (https).
If (!$Disable)
   Write-Output "Adding internet block"
   New-NetFirewallRule -DisplayName "Block Outgoing 80, 443" -Enabled True -Direction Outbound -Profile Any -Action Block -Protocol TCP -RemotePort 80,443

## If the Disable command line option is added, the script removes the Firewall Rule created above.
If ($Disable)
   Write-Output "Removing internet block"
   Get-NetFirewallRule -DisplayName "Block Outgoing 80, 443" | Remove-NetFirewallRule
  1. Save the script in your MDT share, where the Task Sequence will be able to access it. I save my custom scripts in a folder called _scripts the Applications folder.
  2. In the Task Sequence created above, we’ll add the items required to run the PowerShell script to enable and disable the internet blocking firewall rules.
  • Go to the Task Sequence tab on the Properties window of the Task Sequence.
  • Go to State Restore and click on the Add button.
  • Go to General > Run PowerShell Script.
  • Name the new item PS Script – Disable Internet Access.
  • Enter Z:\Applications\_scripts\Internet-Access.ps1 or your own path to the PowerShell script we just created.
  • Scroll down the Task Sequence to just above the Imaging folder.
  • Once again, add a new Run PowerShell Script item.
  • Name it PS Script – Enable Internet Access.
  • Again, enter Z:\Applications\_scripts\Internet-Access.ps1 or or your own path to the PowerShell script.
  • Important: Add -Disable to the Parameters section.
  • Click Apply and OK to close the Task Sequence.

What will happen now is that after Windows boots up, a firewall rule will be added to block internet traffic on ports 80 and 443, and just before starting the SysPrep and capture process the firewall rule will be removed.

Next, we’ll create a domain user account for MDT.


Creating a service account for MDT in Active Directory

  1. Go to Active Directory Users and Computers.
  2. Create a user called mdt_admin and give it a complex password.
  3. Go to the Server or PC where the Deployment Share is hosted.
  4. Give the user mdt_admin Full Control share permissions and Full Control permissions to all the files and folders in the Deployment Share.

Next we need to configure the Bootstrap.ini and the CustomSettings.ini files to control certain aspects of the deployment environment. The settings below enable auto log in and skip the welcome screen, so these should only be used for lab or closed development environments.


Configuring Bootstrap.ini

  1. In Deployment Workbench, right click the Deployment Share and select Properties.
  2. Select the Rules tab and click the Edit Bootstrap.ini button.
  3. Add the settings below to the Bootstrap.ini.
  4. Close and Save the Bootstrap.ini



Configuring CustomSettings.ini

On the Rules tab of the Deployment Share properties window, add the settings below.



BackupFile=%TaskSequenceID%_#year(date) & "-" & month(date) & "-" & day(date) & "-" & hour(time) & "-" & minute(time)#.wim

We now need to create the boot media to boot the VM into the deployment environment.


Creating The Boot Media

  1. In Deployment Workbench, right click on the Deployment Share.
  2. Select Update Deployment Share.
  3. Select Completely regenerate the boot images.
  4. Complete the wizard. It will take some time to create the boot images.


Testing and Capturing a Reference Image

To test everything we need to copy the ISO file that we just generated. It is located in the Boot folder in the Deployment Share. Go to the Server or PC that is hosting the deployment share and navigate to the boot folder. Inside there should be a file named LiteTouchPE_x64.iso. Copy this file to a location where a Hyper-V Virtual Machine will be able to access it.

Create a new VM in Hyper-V with the following configuration:

  • 2x vCPUs
  • 4GB of RAM
  • Network Adapter with access the local network.
  • Virtual Hard Drive of at least 40GB, preferably on an SSD.
  • Boot from CD using the LiteTouchPE_x64.iso from MDT.
  • If using Hyper-V on Windows 10 1709 and above, make sure Use Automatic Checkpoints is disabled.

Start the VM and it will boot from the LiteTouchPE_x64.iso into the deployment environment. You will be presented with a screen with the name of the Task Sequence you created earlier. Select your Task Sequence and click Next and the task sequence will begin.

The Task Sequence will install Windows 10 1903, update from the WSUS server, install the optional applications if you added them, and then run Windows Update from the WSUS server again. It will then run SysPrep and the reboot back into the deployment environment and MDT will capture the image.

When this process completes the VM will be shutdown and a file named W10-1903_YEAR_MONTH_DAY_HOUR_MINUTE.wim will be in the Captures folder in the Deployment Share.


You now have a reference image for Windows 10 1903 and a Microsoft Deployment Toolkit installation, with a deployment share specifically configured for building reference images.

We’ll cover setting up a deployment share and focus on tasks to support deploying Windows to real hardware in this article.

I take great care to test my ideas and make sure my articles are accurate before posting, however mistakes do slip through sometimes. If you’d like to get in touch with me please use the comments, Twitter (you can tweet me and my DMs are open) or my contact form.

I hope this article helps you out, please consider supporting my work here. Thank you.


17 thoughts on “Building A Windows 10 1903 May 2019 Update (19H1) Reference Image with MDT

Add yours

  1. Thanks for a guide. Since in the other post you mentioned that Office 2019 is now installed differently and updated differently, I am asking, if Task Sequence described here is for Office 2016 or 2019. Basically I would like to build image with Office 2019 installed, so I need to know, how to adapt it. And what about Office updates now? If it is not handled via WSUS, how Office 2019 will update, if deployed with this image i build?


    1. Hi there Lukas,

      In this post I only mention Office 2016. To answer your questions, I believe my post on deploying Office 2019/Office 365 covers some of them – I should probably make a post on building an image with Office 2019, but to answer your questions here:

      To build an image with Office 2019, you can download the files from the Office CDN and then add it as an Application to MDT. You’ll need to edit the customisation XML file for Office 2019 to change the install location.

      Office 2019 can update from the Office CDN on the internet or a local network location. There are scheduled tasks that run and check the configured location for updates, instead of using Windows Update.

      I hope this helps, let me know if a full post would be of interest to you.



      1. Hi, since I have never installed or deployed Office 2019, only 2016, which I included in reference image and it is working very good, I would appreciate, if I could try deploy new machines with O2019. I read your separeate O2019 post, but if it would be possible to give some instructions, how integrate this into reference image, it would be great. And mention how to make itself update. Or would you recommend to stick with O2016 for some time? I dont miss anything with O2016, so maybe it is not worth the hassle, on the other hand, I love learning new things. I know you are probably busy enough, but still would be greatly appreciated.

        Liked by 1 person

    1. That service account is also used to add the computers to Active Directory. I have mine set so that the only thing it can do is access the deployment share and add computers to AD because it’s credentials are available in plaintext on the LiteTouch image. I also only enable WDS when I am imaging for the same reason.


  2. FYI Microsoft has released a hotpatch of sorts that will allow WSIM to generate an answer file on x64 Windows installs. I put a link to their page below but I’m not sure if Akismet will block the link.

    Liked by 1 person

    1. The catch with that hotpatch is that you have to manually open Windows System Image Manager, right click underneath the Windows Image section and press “Select Windows Image…”. Then navigate to the “install.wim” file that corresponds to your Windows installer, select the version of windows to deploy, and then wait for it to build the Answer file. Once you have generated the file from there you can edit the unattend.xml file by just navigating to it from within MDT Workbench.

      Liked by 1 person

  3. Great Walk-through – Thank You!

    I am having an issue with applying updates (manually) to the image before sysprep and capture… it appears after Installing the operating system (step 54 / 59%) it gets stuck at a black screen indefinitely. I do notice the build number changes after the update… is there any way to deploy the image with windows updates already applied to the date of the capture?


    1. Hi there, yes you can add updates into the Packages folder in MDT and create a Selection Profile so the updates are only installed for the version of Windows 10 they are intended for.



  4. Sorry for my english.

    Well… importing os windows 10 is done cause mdt dont resolve install.wim in mount iso.

    Do you have resolve this error on success ?



    1. Hi there, your english is no problem. I’ve responded to your other comment here is what I said:

      You might have a Windows 10 with an install.esd instead of a .wim. You can convert it by using the command:

      dism /export-image /SourceImageFile:install.esd /SourceIndex:1 /DestinationImageFile:install.wim /Compress:max /CheckIntegrity

      Please note you should copy the Win10 files from the .iso to a directory on your hard drive before running the command above.



      1. Hello Mike,

        Very thanks for your reactive helping.

        I send more information:

        My error come on this action:

        «Adding an Operating System

        Mount the Windows 10 1903 ISO in File Explorer.
        Go to Deployment Workbench > Operating Systems.
        Right click and select New Folder.
        Enter the name Windows 10 1903 x64 and click through the wizard to create the folder.
        Right click again and select Import Operating System.
        In the wizard, select Full set of source files and then enter the root of the mounted ISO as the Source directory.»

        When i want import the files of mount ISO, i have:
        «solved error»
        «cant resolve install.wim»

        And i dont understand. I use MDT for so many version in my entreprise and its first time i have this error…
        I have test the same import whit mount windows 7 iso, windows 10 1709… its ok.

        Just windows 10 1909 is not solving.

        I go test tomorrow whit windows 10 1903. But i dont understand this error.

        If you have issu… really sorry if i am insistent.


        1. Hi, I understand. It sounds like that the Windows 10 1909 ISO file you have doesn’t contain the install.wim file in the sources directory. If you look in there, you may find an install.esd file. If you do have that file, then you can convert it with the command I posted in the previous comment.



  5. Sorry for my english.

    I cant import windows 10 1093, 1909 cause error install.wim not exist on mount iso ???

    You have the same issu?
    Do you have solved this?

    Really thx


Leave a Reply

Fill in your details below or click an icon to log in: Logo

You are commenting using your account. Log Out /  Change )

Google photo

You are commenting using your Google account. Log Out /  Change )

Twitter picture

You are commenting using your Twitter account. Log Out /  Change )

Facebook photo

You are commenting using your Facebook account. Log Out /  Change )

Connecting to %s

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Create a website or blog at

Up ↑

%d bloggers like this: