Windows 8 Sysprep - Can't skip local account creation and autologon fails, wrong admin password.

Using Windows 8 x64 Enterprise, Sysprep pauses to ask me to create a local user, which I don't want.
If I enable SkipSystemOOBE and SkipUserOOBE in OOBE under Microsoft-Windows-Shell-Setup sysprep (in oobe mode) will skip user creation and autologon works.  But it only works correctly once.  If I run sysprep again, when it tries to autologon
it will say that I have the wrong password for the local account.  After I type in the password manually it works.  If I use the same password for the local administrator account as for the autologon account, it looks to have the encrypted password
twice with an equal sign after it.
What I need to know:
How to skip local user account creation (we run on a domain but I have it connect through scripts later)
How to fix the autologon issue
Do I need the local administrator account enabled for this to work?
I have my unattend.xml file attached.
<?xml version="1.0" encoding="utf-8"?>
<unattend xmlns="urn:schemas-microsoft-com:unattend">
<settings pass="oobeSystem">
<component name="Microsoft-Windows-Shell-Setup" processorArchitecture="amd64" publicKeyToken="31bf3856ad364e35" language="neutral" versionScope="nonSxS" xmlns:wcm="http://schemas.microsoft.com/WMIConfig/2002/State" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance">
<AutoLogon>
<Password>
<Value>[removed]</Value>
<PlainText>false</PlainText>
</Password>
<Username>[removed]</Username>
<LogonCount>2</LogonCount>
<Enabled>true</Enabled>
</AutoLogon>
<FirstLogonCommands>
<SynchronousCommand wcm:action="add">
<Order>1</Order>
<CommandLine>c:\folder\abatchfile.bat</CommandLine>
<RequiresUserInput>false</RequiresUserInput>
</SynchronousCommand>
</FirstLogonCommands>
<OOBE>
<HideEULAPage>true</HideEULAPage>
<HideOEMRegistrationScreen>true</HideOEMRegistrationScreen>
<HideOnlineAccountScreens>true</HideOnlineAccountScreens>
<HideWirelessSetupInOOBE>true</HideWirelessSetupInOOBE>
<NetworkLocation>Work</NetworkLocation>
<HideLocalAccountScreen>true</HideLocalAccountScreen>
<ProtectYourPC>3</ProtectYourPC>
</OOBE>
<TimeZone>Eastern Standard Time</TimeZone>
<DisableAutoDaylightTimeSet>false</DisableAutoDaylightTimeSet>
<RegisteredOrganization>Company Name</RegisteredOrganization>
<RegisteredOwner>CompanyName</RegisteredOwner>
</component>
<component name="Microsoft-Windows-International-Core" processorArchitecture="amd64" publicKeyToken="31bf3856ad364e35" language="neutral" versionScope="nonSxS" xmlns:wcm="http://schemas.microsoft.com/WMIConfig/2002/State" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance">
<UserLocale>en-US</UserLocale>
<UILanguage>en-US</UILanguage>
<SystemLocale>en-US</SystemLocale>
<InputLocale>en-US</InputLocale>
</component>
</settings>
<settings pass="specialize">
<component name="Microsoft-Windows-Shell-Setup" processorArchitecture="amd64" publicKeyToken="31bf3856ad364e35" language="neutral" versionScope="nonSxS" xmlns:wcm="http://schemas.microsoft.com/WMIConfig/2002/State" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance">
<ComputerName>*</ComputerName>
</component>
</settings>
<cpi:offlineImage cpi:source="wim:[removed]/sources/install.wim#Windows 8 Enterprise" xmlns:cpi="urn:schemas-microsoft-com:cpi" />
</unattend>

The user accounts-creation page in Windows Welcome is suppressed if a user or a group is added to a local security group. Add a user or a group to a local security group by doing one of the following:
Create a local user.
Add a domain user to a local security group with the Microsoft-Windows-Shell-Setup | UserAccounts unattended installation setting.
To suppress the user accounts-creation page in Windows Welcome, without creating a local user, use one of the following workarounds:
Workaround 1
If the computer is already joined to a domain, use the following XML example to add the Domain Users security group to the Local Users security group.
<DomainAccounts>
 <DomainAccountList wcm:action="add">
  <DomainAccount wcm:action="add">
  <Group>Users</Group>
  <Name>Domain Users</Name>
  </DomainAccount>
  <Domain>FabrikamDomain</Domain>
  </DomainAccountList>
</DomainAccounts>
Because joining a domain automatically adds the Domain Users security group to the Local Users security group, the DomainAccounts command does not affect the membership of the Local Users group. However, using this XML example to join a domain will also suppress
the user accounts-creation page in Windows Welcome.
Workaround 2
Use the Sysprep/Quit command to set the following registry value to 1:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Setup\OOBE\UnattendCreatedUser
Please remember to click “Mark as Answer” on the post that helps you, and to click “Unmark as Answer” if a marked post does not actually answer your question. This can be beneficial to other community members reading the thread. ”

Similar Messages

  • I can't open mail on Hotmail from Firefox. I can from Safari. I can open the Hotmail account page and it is complete w/ my new messages, but when I go to open them I get this messeage..."Please refresh your browser window. When you access your Windows Liv

    I can't open mail on Hotmail from Firefox. I can from Safari. I can open the Hotmail account page and it is complete w/ my new messages, but when I go to open them I get this messeage..."Please refresh your browser window. When you access your Windows Live Hotmail account from more than one computer, we ask you to sign in again to help keep your account private and secure. " when I sign in again there is no change. in English
    == URL of affected sites ==
    http://http://sn135w.snt135.mail.live.com/default.aspx?n=2087215863
    == User Agent ==
    Mozilla/5.0 (Macintosh; U; Intel Mac OS X 10_5_8; en-us) AppleWebKit/531.22.7 (KHTML, like Gecko) Version/4.0.5 Safari/531.22.7

    "Clear the Cache": Firefox > Preferences > Advanced > Network > Offline Storage (Cache): "Clear Now"
    "Remove the Cookies" from sites causing problems: Firefox > Preferences > Privacy > Cookies: "Show Cookies"
    See http://kb.mozillazine.org/Clearing_the_cache and http://kb.mozillazine.org/Cookies

  • HT201328 I have paid Bell to unlock my old iphone4 and they have said it is now unlocked. Can I skip the back up and restore process and just buy another carriers sim card from my daugther Kodoo plan, install it and active the iphone4 on itunes account in

    I have paid Bell to unlock my old iphone4 and they have said it is now unlocked. Can I skip the back up and restore process and just buy another carriers sim card from my daugther Kodoo plan, install it and active the iphone4 on itunes account in her name?
    thanks
    Dave

    The process is as follows:
    Backup the phone, Erase it, connect to iTunes for the unlock process, then your iProfile can be restored.
    You can go ahead and get the SIM, bout you have to Erase the phone and connect to iTunes before it will be unlocked.

  • Can't remember the account name and password which...

    Hi, i can't remember the account name and password which bind to my n8 mobile, therefore i can't download music any more. i tried to "forgot password", but cannot find back the account name. If I login with other account, I can't download music. what can i do? 

    Hi carolweiwei,
    Thank you for your post and welcome to the forums!
    If you cannot remember the user name and password you've used on Nokia Music, please visit this page, where you can use your mobile number to get a text message with your username and a password reset link. 
    Let us know if this helps,
    Puigchild
    If you find this post helpful, a click upon the white star at bottom would always be appreciated.
    If it also solves your problem, clicking ACCEPT AS SOLUTION below it will benefit other users!

  • I recently downloaded OS X Mavericks and i can't finish the installation as i cannot remember the admin password any ideas ?

    i recently downloaded OS X Mavericks and i can't finish the installation as i cannot remember the admin password and cant remember if i set one up or not but it doesnt give me any hints as to what it could be when it prompts me to input the password help !

    Resetting or changing an account password:
    http://support.apple.com/kb/HT1274

  • What can I do, iPad disabled/lockout and iTunes keeps asking for password, I cannot restore...iTunes grays out backup and restore but my iPad and iPod shows on Apple etc..

    What can I do, iPad disabled/lockout and iTunes keeps asking for password, I cannot restore...iTunes grays out backup and restore but my iPad and iPod shows on Apple etc..???

    Try and force iPad into Recovery Mode:
    1. Turn off the device: Press and hold the Sleep/Wake button for a few seconds until the red slider appears, then slide the slider. Wait for the device to turn off.
    If you cannot turn off the device using the slider, press and hold the Sleep/Wake and Home buttons at the same time. When the device turns off, release the Sleep/Wake and Home buttons.
    2. Connect USB cable to computer, leave the other end alone
    3. Press and hold the Home button down and connect the docking end of cable to iPad
    4. Continue holding the Home button until you see the "Connect To iTune" screen
    5. Release the Home button
    6. Open iTune
    7. You should see "iTunes has detected an iPad in recovery mode"
    8. Use iTune to restore iPad
    Note: You need to be patient and repeat the above many times to recover your iPad

  • Macbook bound to AD won't allow network login or new local account creation

    As the title states I am having an issue related to a macbook pro that is bound to active directory. The only option we tweak when binding the macs to AD is that we opt to "create mobile account" option under directory utility.
    It also seems that while we can login through the local admin account, new local accounts cannot be created (the account creation window hangs when you create account).
    Any help would be appreciated

    Hi
    To successfully bind a mac workstation to Active Directory certain things need to be in place:
    DNS has to be fully resolving on both pointers. This is done on the PDC or whatever server is the designated DNS Server.
    Date and Time settings need to be adjusted to reflect whatever is designated as the NTP Server in the AD environment. Adjust the Date & Time Preferences Pane and find out from the Windows Network Administrator what the NTP Server IP address is.
    You must use account credentials that has authority for the AD Domain. If you're trying to use your own account it may be restricted in what it can do? A domain account has special privileges not usually accorded to ordinary user accounts.
    This assumes you're (a) not the Active Directory Network Administrator and (b) you're using the Active Directory plug-in the login options section of the Accounts Preferences Pane. It's a good idea to click the "Open Directory Utility" button when binding to Active Directory. It's also a good idea to access the Advanced Section once the Utility has opened.
    If this is failing at the bind stage then perhaps you should review the details you've been given when binding to AD? It may be worthwhile to clear the workstation from the Computer OU before you try again?
    The above is not an exhaustive list but should help?
    Tony

  • Local account credentials and licensing

    Hello, we have a Windows 2008 R2 server used for terminal services.
    The server is configured and is working fine.
    All domain users can login without issues.
    If we login with a domain administrator account, this server successfully contacts the license server and validates.
    However, we have the server locked with a local administrator account, as there is an application that runs in the background.
    Because of this, we are encountering the error: "The Remote Desktop Session Host Server Configuration tool is running with local account credentials. In Licensing Diagnosis, the Total Number of licenses Available value may be inaccurate." It gives
    the warning that we have a number of days before the remote services is disabled.
    Obviously we don't want this to happen.
    My questions is if this will actually be disabled, even though we have validated with the license server before with a domain account?
    Do we have to have server locked with a domain account to get rid of this error?
    Many Thanks,
    Ravi

    Hi Ravi,
    Thank you for your posting in Windows Server Forum.
    Yes, to get rid from this error and for better result you must always attach License server with Domain account. Means you need to join the server to a domain. Because the error which you are facing is due to “Issue with Credential” as License server
    can’t identify the local user account credentials. In your case, you need to lock server with domain account. 
    Please check below article.
    Licensing Diagnosis: Problems and Resolutions
    http://blogs.msdn.com/b/rds/archive/2008/02/01/licensing-diagnosis-problems-and-resolutions.aspx
    Hope it helps!
    Thanks.
    Dharmesh Solanki

  • Mobile Account Creation and old topic

    http://discussions.apple.com/thread.jspa?threadID=1786733&tstart=1 -- This was never successfully answered and has been archived and marked as so?
    The problem it turns out, is that Leopard doesn't seemingly like the AD user's home folder location. I've verified this still as an issue today, on 10.5.7. I tried to create a mobile account for a user on a new laptop i got -- it would prompt me for the password three times, saying it's incorrect each time before the account creation is canceled.
    If in Server 03 AD tools you first switch that user's "Home Directory" to local (or a mac server), this issue will not persist. On the AD Binding/Directory utility un-check "Require Confirmation" before creating a mobile account.
    Then you should be able to log out and login as the user (may have to first delete the user's local directory if one has been created under "Users"), so long as the Home folder is set in AD to a location that is seemingly 'agreeable' with the mac os.
    Message was edited by: Oh4Sh0

    The usual approach with Open Directory is to either use Workgroup Manager to define a managed login preference for a computer group to define that those member computers should cause the use of mobile accounts on those computers, or to do the same thing via Profile Manager.
    Note: If you are using Mavericks you must use Profile Manager as it does not support this via Workgroup Manager managed preferences.
    This will not require users to need admin authorisation.

  • Windows 8.1 "No mapping between account names and security IDs was done"

    Hi,
    A week ago, I had a problem with my laptop in which the explorer.exe was restarting itself, when I was trying to fix it, I ran the Sfc/scannow, and it turns out, there were some files broken, then, following the instructions here of how to replace the files
    manually, I get to the Command prompt, and used the command "takeown", but when continued to the "icacls" command, it shows the message:
    "No mapping between account names and security IDs was done. Successfully processed 0 files; Failed processing 1 files."
    I didn't understand what was that, and in the page didn't said anything about that message, I thought that the explorer.exe problem also corrupted this solution, in the end, turns out, it was a third party program which was incorrectly un-installed, I fixed
    and forget about the other problem, until today when I was trying to open Word, when it turns out, that Office was "installing", something that doesn't make sense as I already had it installed and worked on it in the past. But when it's close to
    the finish, it shows, Error 1920, and that I don't have the requeriment grants, later looking on the internet, there was this "solution" (since I couldn't test it, I don't know if it works) saying that I have to user the command "icacls",
    but any time that I try, it says "No mapping between accounts..." therefore, I couldn't solve it that way.
    I don't know what exactly to do, since I don't understand exactly what I broke, hope you can help me, and thanks in advance.

    Hi,
    According to your description, the current problem is your Office program.
    If I am right, there is no any other problem on your system. It narrows down to the Microsoft Office program issue.
    Please run with safe mode to troubleshoot:
    1.Click WIN+R;
    2.Type Winword.exe /safe;
    3.Press Enter.
    If the issue would be gone in safe mode, it indicates the issue is caused by add-ons, please disable the add-ons one by one to clarify which one is culprit.
    If the issue still persists, go Office forum for further help:
    http://social.technet.microsoft.com/Forums/office/en-US/home?category=officeitpro
    Meanwhile, I would like to suggest you use System Restore to roll back to a previous time when everything worked fine.
    How to  refresh, reset, or restore your PC
    http://windows.microsoft.com/en-IN/windows-8/restore-refresh-reset-pc
    If I misunderstanding, please correct me.
    Karen Hu
    TechNet Community Support

  • I updated my 2nd gen apple tv and after completing the downloading and installing the software I got an itunes picture that means i have to connect it to iTunes,, can i skip completing the downloading and instais ? because i don't have the mini usb cable

    I updated my 2nd gen apple tv and after completing the downloading and installing the software I got an itunes picture that means i have to connect it to iTunes,, can i skip this ? because i don't have the mini usb cable

    No, if you have that picture it means the update went wrong and you need to restore via iTunes.
    AC

  • Account creation and use...

    I created a skype account from Arizona, US for my mother that lives in San Diego, US... The account has been created correctly, I can login from my computer...
    But, my mother cannot login from her computer in another state...
    Should this be happeneing? or is my mom inputing the wrong name and pass?
    Thanks in advance,
    Kyle

    The problem is at your mother's end, either with your computer or how she's trying to login.   There's no restriction anywhere in the world to where you can signon to aSkype account, with the possible exception of a few countries where the government blocks Skype access.
    Are you sure that your mom has the Skype program installed on her PC, and that she's not trying to logon through the Skype website?
    Please note: I do not respond to requests for help via Private Message.

  • Can anyone help.  For security reasons I reset my admin password on my Macbook Pro a few days ago and didn't write it down.  Now I've forgotten it.  I didnt receive an installation disc when I purchased my Macbook Pro online - it didn't come with one-help

    Please see question above, but also note, I have the Applecare Protection Plan but am unable to get through to anyone on a weekend and I desperately need to use my laptop this weekend.  I can't log in at all now as I've forgotten my admin password.  A few weeks ago I also changed the password on my husband's new MacBook Pro and again forgot the password.  I spoke to someone at Apple and they helped me to reset it within minutes, by restarting the computer holding Command+something else (I can't remember what it was). A black screen with writing came up and I had to type in something like "password" (not sure exactly).  Anyway, this was a very quick and efficient process but I didn't write it down unfortunately.  Does anyone out there know what to do?  Thanks in anticipation

    Forgot Your Account Password
    For Lion/Mountain Lion
        Boot to the Recovery HD:
    Restart the computer and after the chime press and hold down the COMMAND and R keys until the menu screen appears. Alternatively, restart the computer and after the chime press and hold down the OPTION key until the boot manager screen appears. Select the Recovery HD and click on the downward pointing arrow button.
         When the menubar appears select Terminal from the Utilities menu.
         Enter resetpassword at the prompt and press RETURN. Follow
         instructions in the dialog window that will appear.
         Or see Reset a Mac OS X 10.7 Lion Password and
         OS X Lion- Apple ID can be used to reset your user account password.

  • Can't get past login screen and accidentally added a Firmware password?

    Hi, please can you help me.
    Up until about a week ago my Mac Mini Server (running snow leopard server) was working fine, but when I re-started my user name and password stopped working (the panel shakes).
    I booted the computer from the Install DVD and changed the password. When I restarted this still didn't work. I booted again from the DVD and changed the password again, it came up with a warning about the password also needed to be changed elsewhere.
    I had a look round the utilities on the DVD and saw the Change Firmware Password (I know now this was a massive mistake!), so I changed that and clicked add!
    Now I cant boot from the DVD as all the Keyboard start-up commands don't work.
    I have tried starting up, holding down Command-Option-O-F. This didn't work.
    Checked to make sure the Keyboard is working.
    I also tried removing all RAM and holding down Command-Option-P-R and waited for this to chime 3 times.
    I cant find any thing else to try on the internet.
    I think to solve my initial problem, I need to Boot from the DVD and change the ROOT password, somehow login as the ROOT account then change the passwords. Is this right?
    Any help would be greatly appreciated,
    Thanks,
    Regards Andy

    If you can remember the firmware password you set:
    Boot the computer with the install DVD in the drive (I'm assuming you have the external optical drive, based on your previous post) and hold down the OPTION key. You will see a screen with an input field. Enter your firmware password here, then press enter. The boot manager will load, showing you the internal HD as well as the DVD. Boot from the DVD, and go back into the firmware password utility. Enter the password in the old password field, and leave the new password fields blank. This will remove the firmware password.
    If you *can not* remember the firmware password you set:
    Open up the computer and remove only 1 of the 2 installed RAM sticks. Boot the computer holding COMMAND + OPTION + P +R and wait for 3 startup chimes. This will remove the firmware password.
    Once you have removed the password and are booted to the DVD:
    See this article: http://support.apple.com/kb/ht1274
    You want the section labeled "Resetting the original administrator account password."
    Message was edited by: John.Kitzmiller to fix spelling mistakes.

  • Is there a way to keep selected apps that you have on your admin account inaccessible and unseen from another admin account on the same Mac?

    My sister and I share computers, but it's really her Mac because she got it for her birthday.  I'm using it because there is no other place to hold my iTunes library, documents, photos, etc.
    She complains that I make the computer too slow after I downloaded/installed too many apps from the Mac App Store using my admin account and my iTunes account.   However, they show up on her account as well, and she doesn't want to see them or have her computer slow down, so she deletes them.  Is there a way to make certain apps unseen and inaccessible from other admin users on the same machine?

    Only by storing them on an encrypted disk image. Anyone who has an administrator password to a Mac can use it to access all unencrypted data on the system.
    (59941)

Maybe you are looking for