REM # Windows2019
dism.exe /online /Cleanup-Image /StartComponentCleanup
/Image:E:\

# Windows2019, Windows2022
Repair-WindowsImage -Online -RestoreHealth

# Windows2022
# For 2019 use cmdline dism.exe
##DISM 
Repair-WindowsImage -Online -StartComponentCleanup

#Unknown
Repair-WindowsImage -Online -LimitAccess -RestoreHealth -Source wim:E:\Sources\install.wim:4

Repair-WindowsImage -Online -RestoreHealth


$ImagePath = "E:\Sources\install.wim"

Get-WindowsImage -ImagePath "$ImagePath"
Get-WindowsImage -ImagePath "$ImagePath" | where ImageName -eq "Windows Server 2016 SERVERDATACENTER"

Get-WindowsImageContent -ImagePath "$ImagePath" -Index 4

#  Access is denied. (Exception from HRESULT: 0x80070005 (E_ACCESSDENIED))
# Copy locally
    Copy-Item -Path "E:\Sources\boot.wim" -Confirm -Destination "C:\Image\boot.wim" -Force
    Set-ItemProperty -Name "IsReadOnly" -Path "C:\Image\boot.wim" -Value $False
        <# Type https://docs.microsoft.com/en-us/powershell/module/microsoft.powershell.management/set-itemproperty?view=powershell-7.1
        String: Specifies a null-terminated string. Equivalent to REG_SZ.
        ExpandString: Specifies a null-terminated string that contains unexpanded references to environment variables that are expanded when the value is retrieved. Equivalent to REG_EXPAND_SZ.
        Binary: Specifies binary data in any form. Equivalent to REG_BINARY.
        DWord: Specifies a 32-bit binary number. Equivalent to REG_DWORD.
        MultiString: Specifies an array of null-terminated strings terminated by two null characters. Equivalent to REG_MULTI_SZ.
        Qword: Specifies a 64-bit binary number. Equivalent to REG_QWORD.
        Unknown: Indicates an unsupported registry data type, such as REG_RESOURCE_LIS
        #>

$ImagePath = "C:\Image\install.wim"
$MountPath = "C:\Image\wim4"
# Shows all files and packages
Get-WindowsImageContent -ImagePath "$ImagePath" -Index 4
# Mount
mkdir -Path "$MountPath"
Mount-WindowsImage -ImagePath "$ImagePath" -Index 4 -Path "$MountPath" -CheckIntegrity

#Get Features
Get-WindowsOptionalFeature -Path "$MountPath" 
Get-WindowsOptionalFeature -Path "$MountPath" | Out-GridView

Get-WindowsOptionalFeature -Path "$MountPath" -FeatureName "FaxServiceRole"
# DisabledWithPayloadRemoved
Disable-WindowsOptionalFeature -FeatureName "FaxServiceRole" -Path "$MountPath" -Remove

# Tried Enable-WindowsOptionalFeature -FeatureName "FaxServiceRole" -Path "$MountPath" -NoRestart -Source "WIM:E:\Sources\install.wim:4"

##DISM

sfc /scannow

# 2021/08/13
#2012R2
# DISM 10.0.14393.4169
dism.exe /Online /Cleanup-Image /StartComponentCleanup

dism.exe /Online /Cleanup-Image /StartComponentCleanup /ResetBase


Repair-WindowsImage -Online -CheckHealth -NoRestart -RestoreHealth -ScanHealth -ScratchDirectory D:\ -SystemDrive C:\ -WindowsDirectory C:\Windows -LogPath D:\ -LogLevel WarningsInfo -LimitAccess -Source C:\blah


defrag.exe C: -d

#WIndows 10
Dism.exe /online /Cleanup-Image /SPSuperseded

# 2012R2
Get-WindowsOptionalFeature -Online | select *, @{ N="OS Version"; E={$([environment]::OSVersion.Version).ToString()} } | ConvertTo-Csv -Delimiter `t -NoTypeInformation | clip.exe

[environment]::OSVersion.Version

Enable-WindowsOptionalFeature -Online -FeatureName "Server-Gui-Mgmt", "Server-Gui-Shell" -All
#Enable Windows Server Backup
Enable-WindowsOptionalFeature -Online -FeatureName "WindowsServerBackup" -All


BREAK

# Windows 22
Repair-WindowsImage -Online -RestoreHealth

#
Repair-WindowsImage -Online -LimitAccess -RestoreHealth -Source:wim:E:\Sources\install.wim:4 -Verbose

# Mounted
Repair-WindowsImage -Online -LimitAccess -RestoreHealth -Source:"C:\Image\wim4\Windows\WinSxS" -Verbose


$ImagePath = "E:\Sources\install.wim"

Get-WindowsImage -ImagePath "$ImagePath"
Get-WindowsImage -ImagePath "$ImagePath" | where ImageName -eq "Windows Server 2016 SERVERDATACENTER"

Get-WindowsImageContent -ImagePath "$ImagePath" -Index 4
#  Access is denied. (Exception from HRESULT: 0x80070005 (E_ACCESSDENIED))
# Copy locally
    Copy-Item -Path "E:\Sources\boot.wim" -Confirm -Destination "C:\Image\boot.wim" -Force
    Set-ItemProperty -Name "IsReadOnly" -Path "C:\Image\boot.wim" -Value $False
        <# Type https://docs.microsoft.com/en-us/powershell/module/microsoft.powershell.management/set-itemproperty?view=powershell-7.1
        String: Specifies a null-terminated string. Equivalent to REG_SZ.
        ExpandString: Specifies a null-terminated string that contains unexpanded references to environment variables that are expanded when the value is retrieved. Equivalent to REG_EXPAND_SZ.
        Binary: Specifies binary data in any form. Equivalent to REG_BINARY.
        DWord: Specifies a 32-bit binary number. Equivalent to REG_DWORD.
        MultiString: Specifies an array of null-terminated strings terminated by two null characters. Equivalent to REG_MULTI_SZ.
        Qword: Specifies a 64-bit binary number. Equivalent to REG_QWORD.
        Unknown: Indicates an unsupported registry data type, such as REG_RESOURCE_LIS
        #>

$ImagePath = "C:\Image\install.wim"
$MountPath = "C:\Image\wim4"
# Shows all files and packages
Get-WindowsImageContent -ImagePath "$ImagePath" -Index 4
# Mount
mkdir -Path "$MountPath"
Mount-WindowsImage -ImagePath "$ImagePath" -Index 4 -Path "$MountPath" -CheckIntegrity

# Windows Features

    #Get Features
    Get-WindowsOptionalFeature -Path "$MountPath" 
    Get-WindowsOptionalFeature -Path "$MountPath" | Out-GridView

    Get-WindowsOptionalFeature -Path "$MountPath" -FeatureName "FaxServiceRole"
    # DisabledWithPayloadRemoved
    Disable-WindowsOptionalFeature -FeatureName "FaxServiceRole" -Path "$MountPath" -Remove

    # Tried Enable-WindowsOptionalFeature -FeatureName "FaxServiceRole" -Path "$MountPath" -NoRestart -Source "WIM:E:\Sources\install.wim:4"

    # Online, 2012R2
    Get-WindowsOptionalFeature -Online | Out-GridView
    Get-WindowsOptionalFeature -Online -FeatureName "FaxServiceRole"
    Get-WindowsOptionalFeature -Online | where "FeatureName" -Like "*Hyper*"
    Disable-WindowsOptionalFeature -FeatureName "FaxServiceRole" -Online -NoRestart -Remove
    
    Get-WindowsFeature | Out-GridView
    Get-WindowsFeature | where "Name" -like "*Hyper*" | select * | Out-GridView
    Uninstall-WindowsFeature -Name "NPAS" -Remove
    Uninstall-WindowsFeature -Name "FS-SMB1" -Remove

BREAK

Clear-WindowsCorruptMountPoint
$ImagePath = "C:\Image\install.wim"
$MountPath = "C:\Image\wim4"
Mount-WindowsImage -ImagePath "$ImagePath" -Index 4 -Path "$MountPath" -CheckIntegrity

Add-WindowsPackage -PackagePath "C:\Logs\windows10.0-kb5004238-x64_e3dd1cf22b1146f2469ef31f5fec0f47c8b5960b.msu" -Path "$MountPath"


BREAK
Dismount-WindowsImage -Discard -Path "$MountPath"


expand.exe $Package3 "C:\tmp\msu" -F:*

<# -------   #>

$FileName = "windows10.0-kb4584642-x64_d015746abf6392ff85470d444d8b5982c4b8a1a6.msu"
$ExtractFolder = "C:\KB"


if ((Test-Path $FileName) -eq $true) {
md "$ExtractFolder"
expand.exe "$FileName" "$ExtractFolder" -F:*

$CabFiles = Get-ChildItem -File -Filter "*.cab" -Path "$ExtractFolder"
foreach ($CabFile in $CabFiles) {
    $DestinationFolder =  "$($ExtractFolder+'\'+$CabFile.BaseName+'\')"
    md "$DestinationFolder"
    expand.exe "$($CabFile.FullName)" "$DestinationFolder" -F:*
    }


} else {Write-Host "$FileName does not exist in current directory"}

Start-Process -FilePath "$($ExtractFolder+"\Windows10.0-KB4584642-x64\amd64_microsoft-windows-e..-firsttimeinstaller_31bf3856ad364e35_10.0.17763.1549_none_a0b6a46a3905d361\MicrosoftEdgeStandaloneInstaller.exe")" -ArgumentList "/silent /installsource windowsupdate /install `"appguid={56EB18F8-B008-4CBD-B6D2-8C97FE7E9062}&needsadmin=True&usagestats=1&brand=WULS`" "


Collect 
C:\ProgramData\Microsoft\EdgeUpdate\Log\MicrosoftEdgeUpdate.log

(ConvertFrom-SddlString -Sddl "O:SYD:P(A;OICI;GA;;;SY)(A;OICI;GR;;;BA)(A;OICI;GR;;;BU)" -Type RegistryRights).DiscretionaryAcl