Release notes
What changed in each release, and anything worth knowing before you update.
1.2.24 — 29 September 2026
Update the Forge. These changes are all on the server; boot media from 1.2.23 keeps working, though rewriting it keeps versions matched.
- Check for updates is fast and accurate. It reads the image's exact Windows build from the image itself (no mount, seconds instead of minutes), finds the newest updates for that build, and doesn't download one the image already has. Windows 11 25H2 and 26H2 are supported.
- Only updates that fit the image are offered. Updates for another Windows version or architecture, ones the image already has, and older ones a newer update replaces are listed separately and not pre-selected. An update Windows turns down no longer stops the whole run.
- Updates and app removal in one run. Choose updates and apps on either tab and run them together: one new version, one rollback point.
- Serviced images get smaller. After adding updates the Forge removes the components they replace, then compacts the image. Before, every servicing run made the image bigger. The version history shows the size before and after.
- Safer servicing. The stored image is never modified in place, so a failure or a cancel leaves it exactly as it was, and keeping the previous version for rollback no longer costs a second full copy (on a NAS, no second trip across the network).
- Better app choices. Clipchamp and other current consumer apps are pre-selected again, Windows Security and Edge can no longer be removed, and codecs and core apps are labelled so they aren't removed by accident.
- Rollback fixes. Updates undone by a rollback are offered again, and a run that changed nothing is recorded as such instead of making a new version.
1.2.23 — 29 September 2026
Update the Forge first, then rewrite your boot media. Both changes need the new boot USB: Capture Readiness lives on it, and the boot client applies the new profile setting.
- Deployment profiles can activate Windows. A new Windows activation setting chooses what each deployed PC does at first boot: leave the captured license alone (the default), use the license the manufacturer stored in that PC's own firmware, or install a product key you enter, stored encrypted like the profile's passwords. ImageForge does not supply Windows licenses; this applies one you already have. How it works.
- Capture Readiness is much easier to act on. It asks for administrator rights before it starts, shows one short list with a clear verdict, and gives a numbered to-do list. Many fixes it can now make for you after asking: remove the apps that would stop Sysprep, suspend BitLocker for one restart, scan the disk, restart Windows, run Sysprep (and explain a failure from Sysprep's own log), or restart to the boot menu so you can start from the ImageForge USB.
- A readable report. Each check saves an HTML report beside the tool, with commands you can copy, every app that would stop Sysprep, the file changes waiting for a restart, how much the image will hold and which folders take the space, and leftovers worth deleting first, such as Windows.old and the Recycle Bin.
- Fewer false alarms. Folders Windows keeps locked are no longer counted as warnings (the capture still checks them), file changes waiting for a restart are a warning rather than a stop, and a deployment image's pending Sysprep is shown as the final step.
1.2.22 — 28 September 2026
Update the Forge first, then rewrite your boot media. Most of this release runs on the boot USB.
- Deploying to a Dell (or any PC) with its storage set to RAID now boots. A deployment used to finish and then stop at "no bootable device" until the firmware was switched to AHCI. ImageForge now adds the disk-controller driver the PC is using to the deployed Windows and turns Windows' own storage drivers back on, so an image starts whichever storage mode the firmware is set to.
- Assign a deployment to a PC before anyone gets there. In Activity, choose a machine (by serial number or MAC address), the image, the profile and, optionally, its computer name. When that PC boots the ImageForge USB it offers exactly that deployment; the technician only picks and confirms the disk.
- Deploy again. After a successful deployment, the boot USB offers the same image and profile for the next machine, so a row of identical PCs no longer means browsing and choosing on every one.
- The disk picker says what each disk is. Disks are listed by model, size and connection, with the drive letters and labels on them; the ImageForge USB itself is marked and cannot be chosen, and both erase confirmations name the physical drive.
- Checks before anything is erased: an image built for a different processor (an ARM64 image on an x64 PC) is refused, a laptop on battery asks for power, and a PC started in legacy BIOS mode is warned about. The image library shows x64 or ARM64 for every image.
- A finished deployment restarts on its own after 60 seconds (press Enter to stay), or shuts down if its profile says so, so nobody has to walk back to every machine.
- Optional saved access code: a technician can save their code on their own ImageForge USB so later boots sign in automatically. Admins can turn this off in Access; codes that can read stored profile passwords are never saved.
- Capture: the source is checked before you type a name, a name is suggested, and a failed upload can be retried (or the captured image kept) instead of starting over.
- Logs in the console: a failed operation in Activity shows its error, and its logs button opens that PC's history, session and DISM logs, and boot reports. The dashboard flags PCs still booting older media.
- Importing a WIM refuses files that are not Windows images, and install.wim files holding several editions, with the command that extracts the one you want.
- Capture readiness now warns when Sysprep would fail (apps installed for one user but not provisioned for all, a previous failed Sysprep run) instead of reporting ready.
1.2.21 — 3 September 2026
Rewrite your boot media for this one.
- A PC that needs a network driver from the boot media now actually gets one. When a technician PC started with no working network, ImageForge searched for a driver but could run out of time before trying a single one — and finding the drivers on the stick could itself use up the whole search. The result was "no working driver was loaded" on a machine whose correct driver was sitting on the boot media the entire time. Confirmed fixed on a Dell OptiPlex 3060, which now finds its adapter on the first attempt.
- A failing disk is reported as a failing disk. A deployment that stops because the
drive itself returned an error used to end with a raw code such as
0x8007045d. It now says the disk reported a hardware fault and what to check — its health, its cable, its port — so a dying drive is not mistaken for a problem with ImageForge. - "Still working" no longer insists that a stuck operation is normal. A step that runs far longer than expected now says so and points at the hardware, instead of reassuring a technician while a drive fails to respond.
- Boot media details (version, architecture, Secure Boot profile) are reported correctly again on the technician screen and in support logs.
1.2.20 — 2 September 2026
Rewrite your boot media for this one.
- A network adapter whose driver is already in Windows now gets used. Windows ships drivers for many adapters but lists some of them in a way that stops them loading automatically — including the adapter VMware uses by default. ImageForge now loads those itself when a PC starts with no working network, instead of reporting no driver while the right one sat unused on the boot media.
- The technician screen shows the adapter's hardware ID and what to do with it, so an unsupported network card can be identified and added without guesswork.
- The network boot page is much simpler. It now shows whether network boot is on, what it is using, and what to do next. The protocol background moved to the network boot guide.
- The 14-day trial can be started from the dashboard instead of only from the licence page.
- The disk-erase confirmation no longer cuts off its own warning. On a standard console the sentence telling you to check the disk was being truncated part-way through.
- Technician menu additions: connect to a different Forge, and reboot, without dropping to a command prompt. Image and volume pickers can now be cancelled.
- The diagnostics screen reports firmware mode, Secure Boot, boot media identity, disks as well as volumes, and where the logs are written.
1.2.19 — 1 September 2026
Rewrite your boot media for this one. This release is almost entirely about the boot media finding a network, so an old USB stick gets none of it.
- 2024-generation business laptops now get a network driver from the boot image itself. Machines built on Intel's Meteor Lake platform — current Dell Latitude and Precision, HP EliteBook G11, Lenovo ThinkPad X1 Gen 12 — had no matching wired driver inside the boot image and had to fall back to a recovery search after startup, which did not always succeed. The Intel driver in the boot image was two and a half years old; it has been replaced.
- VMware virtual machines connect reliably. The VMXNET3 adapter driver now ships inside
the boot image instead of beside it, so a VM gets its network during startup rather than
only if the post-startup recovery search happened to run. VMware, Hyper-V and VirtualBox
guests are all verified each release. Note: on VMware Workstation, set the VM's
adapter to VMXNET3 (
ethernet0.virtualDev = "vmxnet3"in the .vmx). The default E1000E adapter is not reliably driven in WinPE; see Driver packs. - Newer Realtek 5-gigabit and 10-gigabit adapters are supported (RTL8126 and RTL8127). The previous driver predated both.
- Plugged in a USB Ethernet adapter or dock after starting? The network recovery prompt has a new search for drivers again option. Previously the search ran only once at startup, so hardware attached afterwards was never picked up and the only fix was a restart.
- Every release is now checked against a published list of network adapters before it can be built. If the media cannot bring one of them online, the build fails and no media is produced. The list covers Intel, Realtek, Broadcom, Marvell/Aquantia and Qualcomm wired adapters, the USB Ethernet chipsets used by Dell, HP and Lenovo docks and by most USB-C dongles, and the four common hypervisors.
- If you hit an adapter that still is not covered, the boot client prints its hardware ID and that ID can be used to add the driver directly. See Driver packs.
1.2.18 — 18 August 2026
Rewrite your boot media for this one.
- Computer names now activate before the domain join. First boot uses Windows' supported online rename flow, then continues automatically after the required restart and joins Active Directory under the requested name.
- Deployments recover safely from a stale pending computer name left by older media instead of repeatedly rebooting while waiting for a registry-only rename to activate.
- Identity automation waits for Windows startup services, verifies the final computer name, domain membership, and secure channel, and records a clear failure if confirmation times out.
- Planned identity restarts are capped at three. ImageForge now stops safely and preserves its diagnostic log instead of allowing an unattended rename/domain-join reboot loop.
1.2.17 — 18 August 2026
Rewrite your boot media for this one.
- Domain identity changes now survive every required restart. ImageForge leaves an old domain, applies the requested computer name, and joins the destination domain as a restart-aware sequence that continues automatically under SYSTEM at startup.
- Domain problems are caught before deployment. The preflight checks domain-controller discovery, credentials, the selected OU, existing computer objects, and duplicate SPNs, with specific corrective guidance instead of discovering the problem after imaging.
- Replacement clones now apply the requested name across every offline Windows control set, preventing a stale control set from restoring the captured machine's identity.
- Custom first-boot commands run only after ImageForge finishes identity and domain work, with separate status and logging so a custom script cannot hide or interrupt the join.
- Website downloads, checksums, billing calls, and the admin console now use branded
image-forge.netpaths instead of exposing the service host in customer links.
1.2.16 — 17 August 2026
Rewrite your boot media for this one.
- Domain completion is resilient and diagnosable. First boot now waits for a domain
controller, retries a failed join at up to three administrator sign-ins, records details
in
C:\Windows\Setup\Scripts\ImageForge-firstboot.log, and reliably schedules the restart that completes the new computer identity. - Deployment profiles are checked before the disk is erased. Missing local/domain credentials, invalid name-template tokens, unsafe sequence widths, and a blank hostname for a domain deployment now stop while the target disk is still intact. The exact normalized Windows/AD computer name is shown in the deployment plan.
- The completion screen clearly separates a finished image apply from profile actions that still need to run in Windows, lists the expected first-boot behavior and diagnostic logs, and uploads the completed PE session log before waiting at the reboot prompt.
- ImageForge-managed local-admin and domain work runs before a profile's custom first-boot
command, so a custom
exit, failure, or restart cannot silently skip identity setup. - USB media written from the ISO now appears as IMAGEFORGE instead of the generic
USBlabel.
1.2.15 — 17 August 2026
Rewrite your boot media for this one.
- Domain joins now use the computer name selected during deployment. On a replacement clone, Active Directory could previously create or reuse the computer object under Windows' old or temporary name even though the deployed PC showed the requested name after restart. ImageForge now binds that requested name directly to the domain join, keeping Windows and AD consistent.
- This corrects new deployments. A PC already affected by the mismatch should be unjoined to a workgroup, restarted, and joined again once with its correct name.
1.2.14 — 14 August 2026
Rewrite your boot media for this one.
- Deployment images no longer stop at the Microsoft account screen. A generalized (Sysprep) image used to come up in Windows' out-of-box experience demanding a Microsoft account, with no obvious way past it. Deploying one now answers those screens automatically. Give the deployment profile a local admin account and a locale to skip setup entirely and boot straight to the sign-in screen — the deploy screen tells you if either is missing. Replacement clones are unaffected. See skipping the out-of-box experience.
- The local administrator account from a profile is now reconciled rather than re-created at first sign-in, so it no longer fails when Windows setup created it first.
1.2.13 — 14 August 2026
Rewrite your boot media for this one.
- Deployment profiles now apply to replacement clones. Domain join, the local administrator account, and custom first-boot scripts previously only ran on generalized (Sysprep) images. On a replacement clone — the default capture type — they were installed but never executed, so a profile appeared to do nothing beyond renaming the PC. They now run at the deployed PC's first sign-in. Sign in as a local administrator first: a domain join needs elevation and network access.
- Deploy now states plainly which profile settings applied immediately and which run at first sign-in, instead of reporting success for both.
- Driver packs accept vendor CAB files (such as Dell Command | Deploy) and
convert them for you. Uploads are now checked on arrival: a vendor
.exe, a wrong file, or a ZIP with no drivers in it is refused immediately with an explanation, rather than being accepted and quietly installing nothing during a deployment. The driver list shows how many drivers each pack contains. - Profile editing has a cancel button.
1.2.12 — 13 August 2026
- Webhooks work with Slack, Teams, and Discord. Chat services reject the plain
event format, so those integrations previously failed on every message. Choose a
payload format to match the receiver;
rawremains the default and is unchanged for RMM and PSA systems. - Send test event button: verify a webhook immediately instead of waiting for a real capture or deployment, and see exactly what the receiving system said.
- New webhooks and integration guide.
1.2.11 — 13 August 2026
- Deployments report their progress to the Forge. The activity view previously went quiet after the image finished downloading; it now follows the apply, driver injection, and boot-file stages on the PC being imaged.
- Console fixes: a dashboard action that did not look like a button, a misaligned status badge, and wasted space on the overview page.
1.2.10 — 13 August 2026
- Capture works again on PCs that have never used BitLocker. Those PCs were incorrectly blocked at the capture preflight. If you saw "could not read BitLocker status", this release fixes it.
1.2.9 — 13 August 2026
- Signing out of the console no longer leaves the header and its search bar usable over the locked screen.
1.2.8 — 12 August 2026
- Image categories you can create, rename, and assign, with a refreshed server console and a command search box (Ctrl K).
- Technician access codes can be issued without an expiry date.
Earlier releases
1.2.7 added the capture readiness checker and automatic Forge certificate authentication, so technicians no longer type a fingerprint by hand. 1.2.6 introduced explicit capture purposes — replacement clone or deployment image. 1.2.3 added the self-service 14-day trial. For anything older, contact contact@image-forge.net.
image-forge.net