Install Antivirus before or after Sysprep & Capture?

DominicMalahov-9554 41 Reputation points
2020-08-11T14:04:24.947+00:00

Hello, I am following instructions for creating an image for win10 Pro build 1909 using windows ADK & SIM. I am at the point where I am starting to build the answer file/unattend.xml & install applications.
My question is should I install antivirus before I sysprep the machine or should I wait to install antivirus after I have the image created?
Last time I syspreped a machine with antivirus installed & captured, I deployed the image to test integrity and windows couldnt boot up, the error I received was “Windows could not finish configuring the system. To attempt to resume configuration, restart the computer”. I read one some sites to disable antivirus before sysprep. Could be from read/write protection due to the antivirus being enabled. I appreciate your help.

This is the tutorial I am following: https://www.tenforums.com/tutorials/3020-customize-windows-10-image-audit-mode-sysprep.html

Windows 10 Setup
Windows 10 Setup
Windows 10: A Microsoft operating system that runs on personal computers and tablets.Setup: The procedures involved in preparing a software program or application to operate within a computer or mobile device.
1,911 questions
0 comments No comments
{count} votes

Accepted answer
  1. Joy Qiao 4,891 Reputation points Microsoft Employee
    2020-08-12T06:07:36.95+00:00

    Hi,

    We would recommend to deploy antivirus software after sysprep completed. Because some of customers feedback antivirus software such as AVG, Bitdefender and others will have a conflict with sysprep, so they should be not added in image before deploy. However, Kaspersky Security Center 10 could be installed in image during sysprep which is recorded in a step by step manual on Kaspersky website.

    But, to avoid unnecessary troubleshooting action, we should deploy antivirus software after sysprep completed.

    As smith said, we could deploy software with SCCM, MDT. But if you are not familiar with those tools, we also could deploy with GPO.

    Here is a link for reference.

    How to deploy software packages via GPO

    Please note: Information posted in the given link is hosted by a third party. Microsoft does not guarantee the accuracy and effectiveness of information.

    Bests,

    2 people found this answer helpful.
    0 comments No comments

4 additional answers

Sort by: Most helpful
  1. Jon Alfred Smith 541 Reputation points
    2020-08-11T18:37:45.777+00:00

    Since you're asking, you must be in doubt yourself. My opinion: The days of a monolithic Ghost are gone. With MDT, or better SCCM (which I used to work with), you use a layered approach. I have usually followed Greg Shield's advices (one of the great gurus in the SCCM universe) and taken care of the OS, mostly barebones.

    With SCCM it is easy to deploy all the software when the image is booted. So is it with antivirus. So I would no install any antivirus software onto the image. The OS is protected by Windows Defender when it comes up. Then distribute your antivirus clients. These were my two cents (personally I would with Defender ...).

    1 person found this answer helpful.
    0 comments No comments

  2. Sean Liming 4,511 Reputation points
    2020-08-12T01:29:38.86+00:00

    It depends on the antivirus software. Some products are not affected by sysprep and some are. You simply have to trying them out. If you want to install them after sysprep, then you could simply create a sysprep unattended file that runs the antivirus software in pass7 sync command.

    1 person found this answer helpful.
    0 comments No comments

  3. DominicMalahov-9554 41 Reputation points
    2020-08-12T15:53:07.543+00:00

    Thank you, everyone, for your help!!!
    Currently, I only have access to use MDT & WDS.
    Agreed Best to not install it on the Image.

    I just ran into an error while using WSIM to build/generate the Catalog File.
    I believe it is due to the OSBuild of my target machine and the OSBuild of the source install.wim being different.

    I will post a new question and attach all logs & images.

    Would be best to create ISO from Windows Media Create Tool for Build 2004, fresh install on target machine & extract Build 2004 install.wim and try loading/generate the Catalog File again.

    I will update the new question link here for reference.

    Thank you Guys!!