I am using wsim to edit the unattend xml file from within MDT, i have configured the answer file to disable the windows firewall for the domain profile (have tried disabling all, makes no difference.) Regardless of what i set in the xml file, when a new pc is deployed the firewall is enabled. We have not yet extended our AD schema for win7, so I dont believe that its a GPO causing my grief. Any suggestions? Also why on earth didnt MS put the actions center settings into WSIM??? How do i disable the warning notifications for backup, firewall, and defender (mcafee disables it)? I have found the HKCU keys for making the notification changes, but that seems a very messy way of doing that.