Automate VM Configuration with SetupComplete.cmd

Answer Correct answer: A — Configure a SetupComplete.cmd batch file in the %windir%\setup\scripts directory to run automation scripts on newly created VMs.

Your company has an Azure Active Directory (Azure AD) tenant that is configured for hybrid coexistence with the on-premises Active Directory domain. The on-premise virtual environment consists of virtual machines (VMs) running on Windows Server 2012 R2 Hyper-V host servers. You have created some PowerShell scripts to automate the configuration of newly created VMs. You plan to create several new VMs. You need a solution that ensures the scripts are run on the new VMs. Which of the following is the best solution?

  1. Configure a SetupComplete.cmd batch file in the %windir%\setup\scripts directory. Correct Answer
  2. Configure a Group Policy Object (GPO) to run the scripts as logon scripts.
  3. Configure a Group Policy Object (GPO) to run the scripts as startup scripts.
  4. Place the scripts in a new virtual hard disk (VHD).

Community Insight

This question tests the appropriate method for running automation scripts on newly provisioned VMs, where the common trap is choosing Group Policy startup scripts, which require prior domain join and run on every boot.

When provisioning new Windows virtual machines, running automation scripts requires a mechanism that executes early in the setup process. This page establishes that using SetupComplete.cmd is the best method to ensure scripts run on newly created VMs before domain join and user logon.

Choosing C (GPO startup scripts) is incorrect because startup scripts run on every boot and require the VM to already be domain-joined, whereas newly created VMs need one-time execution before the domain join process.

Community Discussion (98 comments)

tryingtolearnn 👍 1 Selected: C
C would work as soon as the machine boots up
Sam2652506 👍 1 Selected: C
You need the scripts to run automatically on newly created VMs without requiring a user to log in
john0186 👍 1 Selected: C
Since the VMs are on‑premise, the right automation method is a GPO. A startup script runs as soon as the VM boots and contacts the domain controller, so it applies the initial configuration automatically. Option A only works during Sysprep imaging, which the question never mentions.
Chris_J 👍 3 Selected: C
A (SetupComplete.cmd) only runs during Windows Setup on sysprepped images. It won’t trigger automatically when you simply create new VMs from a template unless you are using full image deployment with sysprep. Most MSP VM deployments don’t use this path unless you’re doing golden images. B (Logon scripts) only run when a user logs in, not at system boot. Not ideal for initial VM configuration and fails if no one logs in. C (Startup scripts via GPO) run as the computer account during system startup, before anyone logs in. This is the correct way to ensure newly joined VMs automatically run configuration scripts as soon as they come online. D (Put scripts in a VHD) just stores them; doesn’t run them.
PParik 👍 1 Selected: C
Why Option C is Correct GPO Startup Scripts are the best solution in this hybrid AD environment because: Startup scripts run in the SYSTEM context before any user logs in, making them ideal for VM configuration tasks Since the environment uses hybrid Azure AD + on-premises AD, GPOs can be applied automatically to newly joined machines without manual intervention The scripts will run consistently and automatically every time a new VM starts and connects to the domain Startup scripts support PowerShell natively, which matches the existing automation scripts GPO scope can be controlled using Organizational Units (OUs), allowing you to target only the new VMs
c4fcfc2 👍 1 Selected: C
the requirement was: “run scripts on newly created VMs” (ongoing, scalable) And SetupComplete: only works at installation time, not after provisioning
NCIceWolf 👍 1 Selected: A
Runs once, not repeatedly It Runs before first logon Does not depend on AD, GPO processing, or user sign-in Perfect for automating baseline VM configuration
Em3rald 👍 1 Selected: A
Runs once, not repeatedly It Runs before first logon Does not depend on AD, GPO processing, or user sign-in Perfect for automating baseline VM configuration
Zdarwish 👍 1 Selected: C
Startup scripts run: • When the machine boots • Under the SYSTEM account • Before any user logs in • Every time (or once, if your script is written properly) This is exactly what you want for: • VM configuration • Server hardening • Agent installation • Registry / feature setup It also scales beautifully: any new VM in the OU gets configured automatically.
thalasi 👍 1 Selected: A
Without requiring: Domain join User logon Group Policy application Manual steps for each new VM SetupComplete.cmd runs after Sysprep completes and before the first logon
621d4ae 👍 2 Selected: C
Option Analysis A. Configure a SetupComplete.cmd batch file in %windir%\setup\scripts Runs once after Windows setup finishes. Only works for fresh installations; not flexible for multiple VMs from images. ❌ Not ideal. B. Configure a GPO to run scripts as logon scripts Logon scripts run only when a user logs in. Not suitable for system-level configuration before any user logs in. ❌ Not ideal. C. Configure a GPO to run scripts as startup scripts Startup scripts run when the computer starts, before any user logs in. Ideal for applying system-level configuration automatically to all new VMs. ✅ Best solution. D. Place the scripts in a new VHD Only stores the scripts; does not execute them automatically. ❌ Not sufficient.
621d4ae 👍 3 Selected: C
A. Configure a SetupComplete.cmd batch file in the %windir%\setup\scripts directory SetupComplete.cmd runs once at the end of Windows setup. Works only if the OS is freshly installed. ❌ Not flexible for multiple VMs created from preconfigured images. B. Configure a GPO to run the scripts as logon scripts Logon scripts run when a user logs in, not at the machine level. Scripts may not run if no user logs in, and it’s not ideal for system-level configuration. ❌ Not the best solution. C. Configure a GPO to run the scripts as startup scripts Startup scripts run when the computer starts, before any user logs in. Ideal for applying system-level configurations automatically on all new VMs. ✅ Best solution. D. Place the scripts in a new virtual hard disk (VHD) Placing scripts in a VHD only stores them, does not execute automatically. ❌ Not sufficient.
abhi_azure_devops 👍 4 Selected: A
B. GPO Logon Scripts Runs only after user login, not ideal for automation during provisioning. C. GPO Startup Scripts Requires the VM to be joined to a domain and GPOs applied — not guaranteed for newly created, unjoined VMs. D. Place scripts in VHD Just placing scripts in a VHD doesn’t guarantee execution. You still need a method to trigger them (like SetupComplete or Scheduled Task).
Sahar_A 👍 1 Selected: A
I was confused between A and C, but C will require the VM to be already joined domain! which has not happened yet for the new VM, so the Answer is A.
27c0b3a 👍 1 Selected: C
a es correcta
Zcw001 👍 2 Selected: A
SetupComplete.cmd is a special batch file that runs automatically after Windows Setup completes, but before a user logs on for the first time. This makes it ideal for automating tasks like running PowerShell scripts on newly provisioned VMs. It ensures the scripts are executed once, immediately after setup, which is typically what you want for initial configuration tasks. This method is independent of Group Policy, which may not apply immediately or reliably to new machines, especially in hybrid environments.
NicoVick 👍 2 Selected: C
C is correct
panna1 👍 1 Selected: C
GPO on startup, ensure script runs on startup.
ITCORESExam 👍 1 Selected: C
Ans: C
MdHussain 👍 1 Selected: C
Given your scenario, the best solution would be: C. Configure a Group Policy Object (GPO) to run the scripts as startup scripts. Here's why: 1.Startup scripts are executed when the machine boots up, ensuring that the configuration scripts run before any user logs in. This is particularly useful for setting up system-level configurations that need to be in place before the VM is fully operational. 2.Logon scripts (option B) run when a user logs in, which might not be ideal for initial VM setup tasks. 3.SetupComplete.cmd (option A) is typically used for tasks that need to be performed after Windows Setup completes, but it might not cover all scenarios for ongoing VM creation and configuration. 4.Placing scripts in a new VHD (option D) is not a standard method for ensuring scripts run automatically on new VMs. Configuring a GPO for startup scripts provides a reliable and centralized way to manage and automate the execution of your PowerShell scripts across multiple VMs.
AKoselnik 👍 2 Selected: A
For me the answer is A. The machine to login to the domain needs to be register in the domain that the GPO will be working. For me Put the script in the location will start them automatically. Independence on login to the domain or not.
ryof 👍 2 Selected: A
The best solution in this scenario would be A: Configure a SetupComplete.cmd batch file in the %windir%\setup\scripts directory. This method ensures that your PowerShell scripts are automatically executed after the Windows setup process is complete, making it ideal for automating the configuration of newly created VMs. The SetupComplete.cmd file runs immediately after the Windows installation is finalized and before the system restarts, allowing you to automate tasks like running your scripts without needing manual intervention. Options B and C (Group Policy Objects for logon or startup scripts) might not be ideal in this case, as they depend on user logons or startup events, which can introduce delays or inconsistencies, especially in environments where VMs are being rapidly deployed. Option D (placing scripts in a new VHD) is not specifically designed for automating VM configuration; it would involve additional steps for accessing and executing the scripts.
entidad 👍 1 Selected: C
Los startup scripts se ejecutan antes de que cualquier usuario inicie sesión, asegurando que la configuración se aplique correctamente a todas las nuevas VMs cuando se inicien. Además, este enfoque se administra centralmente desde Active Directory, lo que facilita la aplicación en múltiples máquinas.
alinuxguru70 👍 2 Selected: A
You have created some PowerShell scripts to automate the configuration of newly created VMs. You need a solution that ensures the scripts are run on the new VMs. There is nothing to imply that the script needs to be run on every startup. Therefore there is no reason to use a GPO. SetupComplete.cmd would be the appropriate answer.
Ivanvazovv 👍 1 Selected: A
Nowhere in the question is written that the new VMs will be domain joined. So GPO may not be an option at all.
Abhisk127 👍 1 Selected: C
The best solution is C. Configure a Group Policy Object (GPO) to run the scripts as startup scripts. This ensures that the PowerShell scripts are executed when the VMs start up, automating the configuration process effectively
Ponpon3185 👍 2 Selected: A
I think A because here: https://learn.microsoft.com/en-us/windows-hardware/manufacture/desktop/add-a-custom-script-to-windows-setup?view=windows-11 you could find this: "If the computer joins a domain during installation, the Group Policy that is defined in the domain is not applied to the computer until Setupcomplete.cmd is finished. This is to make sure that the Group Policy configuration activity does not interfere with the script."
gills 👍 1
That is what i am thinking. Question does not say clearly but i think the new VMs are beign created on-prem.
nnamacha 👍 2 Selected: A
Microsoft Entra ID does not support traditional Group Policy Objects (GPOs) like Active Directory Domain Services (AD DS). GPOs are a legacy feature of on-premises Active Directory environments,
victorio_27 👍 1 Selected: C
Para asegurarse de que los scripts de PowerShell se ejecuten automáticamente en las nuevas VM y configuren el sistema correctamente, la mejor opción es usar un GPO configurado para ejecutar los scripts como scripts de inicio. ✅ Opción correcta: C. Configure un objeto de política de grupo (GPO) para ejecutar los scripts como scripts de inicio.
chandiochan 👍 2 Selected: C
The SetupComplete.cmd mechanism is executed during Windows Setup after installation completes. This is useful for initial image configuration but is less flexible if you plan to use an already prepared image or if the VMs are deployed in various scenarios over time. Since your environment is domain-joined (as indicated by the hybrid coexistence with on-premises Active Directory) and you’re creating multiple new VMs, using a GPO with startup scripts is a centralized and scalable way to ensure your configuration scripts run automatically on each new VM.
lioroz 👍 1 Selected: C
The best solution in this scenario is to configure a Group Policy Object (GPO) to run the scripts as startup scripts. This ensures that the PowerShell scripts are executed when the virtual machines start up, automating the configuration process. So the correct answer is C. Configure a Group Policy Object (GPO) to run the scripts as startup scripts.
Cruzito 👍 1 Selected: C
he best solution is C. Configure a Group Policy Object (GPO) to run the scripts as startup scripts. Configuring a GPO to run the scripts as startup scripts ensures that the scripts are executed when the VMs start up, which is ideal for automating the configuration of newly created VMs. This method is reliable and integrates well with the existing Active Directory environment. Option A, configuring a SetupComplete.cmd batch file in the %windir%\setup\scripts directory, is a valid method for running scripts during the setup process of Windows. However, it is typically used for tasks that need to be executed once during the final stages of the Windows setup process, rather than for ongoing configuration tasks.
jeff1988 👍 1 Selected: C
C. Configure a Group Policy Object (GPO) to run the scripts as startup scripts. Here’s why: Startup scripts run when the computer starts, before any user logs on. This ensures that the scripts are executed as soon as the VM is powered on and before any user interaction. Logon scripts (option B) run when a user logs on, which means the scripts would only execute after a user logs in, potentially delaying the configuration. SetupComplete.cmd (option A) is used during the Windows setup process, but it is not as flexible or manageable as GPOs for ongoing VM management. Placing scripts in a new VHD (option D) is not a standard method for ensuring scripts run automatically on new VMs.
superrvirgo 👍 1
Errata, they of course might be joined to AD, hence please ignore my last sentence
zhorj1kuee 👍 3 Selected: A
Rationale: The SetupComplete.cmd file is executed immediately after the operating system setup is complete, ensuring that the scripts are run on the new virtual machines as part of their initial configuration. This solution is both direct and efficient for automating the configuration of freshly created VMs. Why not the others? B: Logon scripts via GPO: These run only when a user logs in. For automating initial configurations on new VMs, this is neither timely nor appropriate. C: Startup scripts via GPO: While they run during the computer's startup, GPOs require the machine to already be part of the Active Directory domain, which is not guaranteed for new VMs during initial setup. D: Scripts in a new VHD: While theoretically possible, this approach is cumbersome and lacks the streamlined execution of the SetupComplete.cmd method.
Bhushan90 👍 1 Selected: C
Given the options, the best solution to ensure your PowerShell scripts run on the newly created VMs is: C. Configure a Group Policy Object (GPO) to run the scripts as startup scripts. Here's why: Startup Scripts: Configuring the scripts as startup scripts ensures they run when the VM boots up, before any user logs in. This is ideal for initial configuration tasks that need to be completed before the VM is fully operational. Group Policy: Using GPOs allows you to centrally manage and enforce the execution of these scripts across all new VMs in your domain, ensuring consistency and reducing manual effort.
premanshum 👍 1 Selected: A
If any script is running in the startup, it slows down the booting time. Startup script should contain only those tems which cannot stay in static state.
SolimanAlali 👍 1 Selected: C
Configure a SetupComplete.cmd batch file in the %windir%\setup\scripts directory is another valid solution, but it is typically used for very specific scenarios during the initial setup phase of Windows deployment.
SolimanAlali 👍 1 Selected: C
This is the best approach: Start-up scripts are run when the computer starts, before any user logs on. This ensures that the scripts are run on the newly created VM as soon as it boots, making it ideal for VM configuration automation. You can configure a GPO to run these scripts on all the VMs in your environment.
58b2872 👍 1 Selected: C
The SetupComplete.cmd batch file in the %windir%\setup\scripts directory can be used only for Windows. It does not work for other operating systems like Linux.
SHAHIN_STA 👍 3 Selected: C
Correct Answer: C. Configure a Group Policy Object (GPO) to run the scripts as startup scripts. ### Why This Is Correct: - Startup scripts run before user login, making them ideal for system-level configurations. - Using a GPO ensures automatic execution across multiple VMs without manual intervention. ### Why Others Are Incorrect: - A. SetupComplete.cmd: Runs only once after Windows installation, not suitable for recurring tasks. - B. Logon Scripts: Run after user login, not suitable for system-level tasks. - D. VHD: Only stores scripts; does not automatically execute them. Conclusion: Option C ensures automatic execution on every VM startup, making it the best choice.
superrvirgo 👍 1
The requirement in this exercise is to configure a newly created VMs through a PS script. This suggests that the script is to be run once. Hence, no requirement for reoccurring execution. Also, the SetupComplete.cmd is run first in order and before the scripts deployed by GPOs. And btw, what if the VMs are not to be joined to a domain? The exercise description doesn't say anything about the VMs being joined to a domain.
testumesh1980 👍 1 Selected: C
Because of coexistence with the on-premises Active Directory domain group, policies can be used
shacky100 👍 1
ans: C https://learn.microsoft.com/en-us/previous-versions/windows/it-pro/windows-server-2012-r2-and-2012/dn789196(v=ws.11)
moniker 👍 1 Selected: C
the best solution is to configure a Group Policy Object (GPO) to run the scripts as startup scripts (Option C). This ensures that the PowerShell scripts are executed when the VMs start up, which is ideal for automating the configuration of newly created VMs in a consistent manner
leonmc00 👍 1 Selected: C
As the question specifies "The on-premise virtual environment consists of virtual machines (VMs) running on Windows Server 2012 R2 Hyper-V host servers." the correct answer is C. IF the VMs were running in Azure then the answer would be A
shafiqeee 👍 1 Selected: C
should be the C
Andre369 👍 9 Selected: C
C. Configure a Group Policy Object (GPO) to run the scripts as startup scripts. By configuring a Group Policy Object (GPO) to run the scripts as startup scripts, you can automate the execution of the PowerShell scripts on the new VMs when they start up. This ensures that the scripts are executed consistently and reliably on each VM during the startup process. Option A, configuring a SetupComplete.cmd batch file in the %windir%\setup\scripts directory, is not the best solution in this scenario as it applies only to the initial installation of Windows and would not cover the configuration of newly created VMs. Option B, configuring the scripts as logon scripts through Group Policy, may not be ideal in this case as logon scripts are executed when a user logs in, whereas the requirement is to run the scripts on the VMs themselves, regardless of user logins. Option D, placing the scripts in a new virtual hard disk (VHD), would require additional configuration steps and might not be necessary or the most efficient solution for executing PowerShell scripts on the new VMs.
etrop 👍 2
Will group policy even work if the systems are not joined to the domain yet?
SivaPannier 👍 5
The custom system configuration is a one time activity for every VM. If we keep that in the startup script, the configuration will be executed every time the VM is started and it is not expected. Hence the answer should be A. Also the SetupComplete.cmd will be acting as a wrapper and it can be wired to powershell script.
asuarez 👍 1 Selected: C
The best solution to ensure that your PowerShell scripts are run on the new VMs is to configure a Group Policy Object (GPO) to run the scripts as startup scripts (Option C). This approach ensures that the scripts are executed when the VM starts up, which is ideal for initial configuration tasks.
sca88 👍 1
In this way the script will be executed on each restart of the VM... The correct answer shold be A
dirkxi 👍 1
The correct answer is C. This is not an Azure-specific question but a general Microsoft enterprise-managed question.
Pcservices 👍 1 Selected: C
Startup scripts in Group Policy apply before any user logs in, during the system boot process. This makes it a better solution for automating configurations that need to happen at the system level for every new VM. It ensures the scripts are applied when the machine starts.
Iron_Man_111 👍 6 Selected: A
Run a script after setup is complete (SetupComplete.cmd) Order of operations 1. After Windows is installed but before the logon screen appears, Windows Setup searches for the SetupComplete.cmd file in the %WINDIR%\Setup\Scripts\ directory. 2. If a SetupComplete.cmd file is found, Windows Setup runs the script. Windows Setup logs the action in the C:\Windows\Panther\UnattendGC\Setupact.log file. 3. Setup does not verify any exit codes or error levels in the script after it executes SetupComplete.cmd. 4. If the computer joins a domain during installation, the Group Policy that is defined in the domain is not applied to the computer until Setupcomplete.cmd is finished. This is to make sure that the Group Policy configuration activity does not interfere with the script.
j5y 👍 95
Ans: A After Windows is installed but before the logon screen appears, Windows Setup searches for the SetupComplete.cmd file in the %WINDIR%\Setup\Scripts\ directory
juanmacoellocloudsecarch 👍 2
In this case ... It means that you are going to deploy several VMs ... Option A is valid but... If you deploy 100VMs is not logical to go 1 by 1 creating that .bat. Option C is valir and is the best cuz with a GPO you can implement it at the same time ... SEVERAL VMs is the critical point here.
TheFivePips 👍 1 Selected: C
A could work, but has nothing to do with azure, so C is the best option
Highgate 👍 2
Neither have anything to do with Azure, but for the GPO to fire, the server would need to be joined to the domain first. While it doesn't explicitly state either way, A always fires. "After Windows is installed but before the logon screen appears, Windows Setup searches for the SetupComplete.cmd file in the %WINDIR%\Setup\Scripts\ directory. If a SetupComplete.cmd file is found, Windows Setup runs the script. This script runs with local system permissions ."
Mixxy1010 👍 4
I would vote C, assuming you are running a domain with Group policy enabled. as the question doesnt specifically state that Group policy is in use, you have to assume local scripts are run to configure the machine. hence A is the answer, even if its a really dumb way to manage your machines.
chucklu 👍 1
The second link provided in Answer does not work.
76d5e04 👍 2
Many windows server administration related questions are poping up, seems unrelevant
Didatzi 👍 4 Selected: C
Answer A is valid. Answer C is also valid, if you have the VM's joined to the AD domain. It is better to manage VM's with GPO instead of running scripts manually on each VM. Using GPO will minimize the effort and will save time. I personally prefer answer C. Here, the questions does not provide enough information to choose the correct answer between the two.
3c5adce 👍 3
Between A & C - ChatGPT4 says C. The option A, using a SetupComplete.cmd batch file, is primarily intended for tasks that need to be executed once after the operating system is installed or configured. While it can technically run scripts post-setup, it's less flexible and manageable compared to using Group Policy. Option C, configuring a Group Policy Object (GPO) to run scripts as startup scripts, provides better manageability and scalability. With GPOs, you can easily update, manage, and apply scripts across multiple VMs in the domain automatically every time the machines start up, not just after initial setup. This makes it more suitable for ongoing operations and management in a hybrid environment like yours.
MelKr 👍 2 Selected: C
Group policies can be replicated to Azure AD. The question does not state where the new VMs will be created (On Prem or in Azure). So Group Policies is the only option that works for both.
Amir1909 👍 1
A is correct
nospampls 👍 1 Selected: C
c
photon99 👍 3
This question is more oriented towards Active Directory Administartion than Azure AZ 104 at all !
Ravikrsoni 👍 4
C. Configure a Group Policy Object (GPO) to run the scripts as startup scripts. Here's why: Logon scripts: Logon scripts are executed when a user logs on. If the automation tasks should be performed in the context of a user, logon scripts might be appropriate. However, they require a user to log in, which might not be the case for certain automated tasks. Startup scripts: Startup scripts run during the system startup, before the user logs in. This makes them suitable for tasks that need to run regardless of user logins. For automated configuration tasks on VMs, especially when there might not be an interactive user session, using startup scripts through Group Policy is often the preferred method.
pal40sg 👍 3 Selected: C
In the context of Azure and hybrid environments, the best solution for ensuring that your PowerShell scripts are run on newly created VMs is option C: Configure a Group Policy Object (GPO) to run the scripts as startup scripts. Here's why: A. SetupComplete.cmd in %windir%\setup\scripts: This method is typically used for unattended installations, but it won't work for your scenario as it's mainly used during the initial setup phase of Windows.
insanetechy 👍 2
You have created some PowerShell scripts to automate the configuration of newly created VMs. You plan to create several new VMs. You need a solution that ensures the scripts are run on the new VMs. Which of the following is the best solution? option A applies scripts on the new VM's first boot whereas option C applies on new VMs every boot. here the keyword is "some PowerShell scripts" so that is more than one script and not one. So it might involve scripts to be applied on every boot. Therefore the answer is C and not A.
ntinakos 👍 5 Selected: A
A is correct
yashsj 👍 1 Selected: C
The question has setup a context stating use of hybrid use of Azure AD with OnPrem Active Directory Domain Controller. So option C seems to be correct option as it uses the information/context provided in the question. Option A might be correct option (although that can also be debated) has noting to do with Azure.
shrsrm95 👍 3 Selected: A
A seems like the correct answer, since it's a one-time configuration that needs to run after setup. The group policy options for logon and startup imply a recurrence
abinnnnnnnnnn 👍 3
Configuring a SetupComplete.cmd batch file in the %windir%\setup\scripts directory is a valid solution for running custom scripts after the Windows Setup process is complete. After Windows is installed but before the logon screen appears, Windows Setup searches for the SetupComplete.cmd file in the %windir%\setup\scripts directory. If a SetupComplete.cmd file is found, Windows Setup runs the script1. However, this solution may not be the best one for the scenario here described, as it requires the virtual machines to be offline while the Windows Setup process is running.
Jeppa 👍 1
when the user sees the desktop, so after user logon. Computer-based GPO's are triggered at computer start-up. I feel like C is correct, as it ensures the script is executed. All the other solutions do not ensure any script execution, as users might not logon at all.
VV11_SS22 👍 1
correct answer is A
dhivyamohanbabu 👍 1
A is correct
CHRIS12722222 👍 1
A
rishisoft1 👍 13
Many people have commented on GPO options and it's right however GPO comes in the picture when VM join the on-premise AD. But SetupComplete.cmd executes before VM join the VM. So, the order of execution is typically as follows: VM is provisioned. SetupComplete.cmd batch file runs during the first boot of the VM. VM joins the Active Directory domain. GPOs are applied to the VM. So I am thinking option 'A' is correct
BowSec 👍 2
To ensure that PowerShell scripts are run on newly created virtual machines (VMs) in a Windows Server 2012 R2 Hyper-V environment that is configured for hybrid coexistence with Azure Active Directory (Azure AD), the best solution is to configure the scripts to run as startup scripts using Group Policy. Therefore, the correct answer is C. Configure a Group Policy Object (GPO) to run the scripts as startup scripts. By configuring the PowerShell scripts as startup scripts in a Group Policy Object (GPO), the scripts will run each time a virtual machine starts up, ensuring that they are automatically configured on newly created VMs.
floradu88 👍 2
They say powershell and the cmd is batch file, so I would say b and c
margotfrpp 👍 2 Selected: C
Option A suggested configuring a SetupComplete.cmd batch file in the %windir%\setup\scripts directory on the new virtual machines. However, this does not guarantee that the PowerShell scripts will be executed on the new virtual machines. The batch file may be ignored or removed by system administrators or end-users, and this also does not guarantee that the PowerShell scripts will be executed with the appropriate permissions. On the other hand, options B and C suggest configuring Group Policy Objects (GPOs) to run the PowerShell scripts as logon or startup scripts, which ensures that the scripts will be executed with the appropriate permissions and their execution will be automatic and consistent across all new virtual machines. Therefore, options B and C are preferable to option A to ensure that the PowerShell scripts will be executed on the new virtual machines.
lokii9980 👍 1
If the scripts need to be executed after the virtual machine has finished installing and the operating system has finished setting up, then Option A - configuring a SetupComplete.cmd batch file in the %windir%\setup\scripts directory is the best solution. This method is useful if you need to configure the VM after it has been deployed and the operating system has been installed. The SetupComplete.cmd batch file is executed once the setup process is complete, before the user is logged on for the first time.
rafael0 👍 3 Selected: C
Option A may work for a single VM or a few VMs, but it is not the best solution for deploying the PowerShell scripts to multiple VMs automatically. Right?
habbey 👍 1
A is the correct answer
Krish2222 👍 2
C is also correct. Create a GPO to run the PowerShell script on startup - https://woshub.com/running-powershell-startup-scripts-using-gpo/ Deprecate the policy as needed. You will avoid adding a custom script for each of your new VMs. Handy when you are deploying 100 or more.
Krish2222 👍 2
Note: Since GPO is not automatically assigned on Azure VMs, it would be best to save the Powershell script as an ARM template and set an Azure Policy under security. The Azure policy will ensure that your template runs on startup. This is the policy that can be deprecated as needed. Apologies for the lack of clarity!
Krish2222 👍 1
If you want to run the PowerShell script at a computer startup (to disable legacy protocols: NetBIOS and LLMNR, SMBv1, configure computer security settings, etc.) or prior to the computer shutdown, you need to go to the GPO section with the computer settings: Computer Configuration -> Policies -> Windows Settings -> Scripts (Startup / Shutdown).
NaoVaz 👍 31 Selected: A
GPOs aren't a thing in Azure AD. Just putting a Script inside the VHD doesn't make it run on boot. Configuring a "SetupComplete.cmd" in the "%windir%\setup\scripts" directory is the correct approach:
BWLZ 👍 3
the newly created VMs are on-prem not on Azure AD , you are wrong , answer is C
EmnCours 👍 2 Selected: A
Correct Answer: A
nqthien041292 👍 2 Selected: A
Vote A
elishlomo 👍 3 Selected: A
A. Setupcomplete.cmd is a custom script that runs during or after the Windows Setup process. They can install apps or run other tasks using cscript/wscript scripts.
Timock 👍 13
Answer: SetupComplete.cmd After Windows is installed but before the logon screen appears, Windows Setup searches for the SetupComplete.cmd file in the %WINDIR%\Setup\Scripts\ directory. If a SetupComplete.cmd file is found, Windows Setup runs the script. Windows Setup logs the action in the C:\Windows\Panther\UnattendGC\Setupact.log file. Setup does not verify any exit codes or error levels in the script after it executes SetupComplete.cmd. If the computer joins a domain during installation, the Group Policy that is defined in the domain is not applied to the computer until Setupcomplete.cmd is finished. This is to make sure that the Group Policy configuration activity does not interfere with the script. Note: You can't reboot the system and resume running SetupComplete.cmd. You should not reboot the system by adding a command such as shutdown -r. This will put the system in a bad state. https://docs.microsoft.com/en-us/windows-hardware/manufacture/desktop/add-a-custom-script-to-windows-setup?view=windows-11
Adebowale 👍 4
Thank you for the confirmation
ppp131176 👍 4
A is correct

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

SetupComplete.cmd is specifically designed to execute scripts after Windows Setup completes but before the user logon screen appears. This makes it the ideal mechanism for one-time automation tasks during the initial provisioning of a new VM. It runs before the VM joins the domain, ensuring configuration scripts are applied reliably at creation time without relying on Active Directory connectivity.

Why the Other Options Are Wrong

Group Policy startup scripts (Option C) and logon scripts (Option B) require the VM to be domain-joined and GPOs to be applied, which cannot be guaranteed on a newly created VM during its first boot. Furthermore, startup scripts execute on every boot, not just once during initial provisioning. Placing scripts in a VHD (Option D) merely stores them on a disk and does not trigger their execution automatically.

Community Comment Notes

Commenters emphasized that "SetupComplete.cmd executes before VM join the" domain, making GPOs unreliable for initial configuration. Another user noted that keeping configuration in a startup script means "the configuration will be executed every time the VM is started", which is inefficient for one-time setup tasks. Others highlighted that just placing a script in a VHD doesn't make it run on boot.

Official Reference

Exam Strategy

For VM provisioning questions, distinguish between one-time setup tasks and persistent configuration. Remember that Group Policy requires domain join, which typically happens after the initial OS setup phase, making SetupComplete.cmd the correct choice for first-boot automation.

Related Analysis

Practice All AZ-104 Questions

Access 100 questions with complete answers and detailed explanations.

View Full AZ-104 Practice Test →

← Back to AZ-104 Study Guide