Automated Windows maintenance, repair and update workflow for technical service and enterprise infrastructure environments.
Ernesto Nurnberg
IT Infrastructure & Technical Support Specialist
Founder of ITechBR
Windows Maintenance Automation
This project provides a real-world automation workflow for Windows maintenance and repair.
Designed to:
- Reduce manual maintenance time
- Standardize technician workflows
- Improve system reliability
- Automate Windows repair and update routines
- Generate structured logs for traceability
- Enterprise Deployment Ready: Designed to seamlessly integrate into corporate OS staging, provisioning pipelines, and reference machine engineering.
- Headless Operation Flow: Fully scriptable and policy-compliant automation that runs cleanly via administrative shells or remote deployment agents.
- Multi-Language Parsing Resiliency: Resolves OS language locale boundaries during runtime text audits, ensuring reliable diagnostic capture across localized Windows installations.
- Telemetry-Ready Records: Generates persistent, auditable execution logs optimized for compliance mapping and hardware degradation analysis.
- PowerShell
- Batch scripting
- Windows Update API
- DISM
- SFC
- CHKDSK
- Windows 10 / 11
- Temporary files cleanup
- User temp directory cleanup
- Prefetch cleanup
- Recycle bin cleanup
- Windows Update cache cleanup
- Windows catalog cache cleanup
- Structured logging with timestamps
- Automatic update search
- Automatic update download
- Automatic update installation
- EULA acceptance when required
- Restart detection after update installation
- Fully unattended execution
- Conditional DISM RestoreHealth: Runs
ScanHealthfirst; executesRestoreHealthonly when component-store corruption is repairable (exit code 10). Healthy systems skip RestoreHealth entirely. - Storage preflight: Configurable minimum free space threshold (default 10 GB,
-MinimumFreeGBparameter) before RestoreHealth. Runs lightweight cleanup and re-checks on failure. - Storage telemetry: Captures free space (GB and %) at 5 pipeline points β before Repair, after ScanHealth, before/after RestoreHealth, after StartComponentCleanup.
- RestartRequired detection: Reports when DISM servicing requires reboot (exit code 3010).
- DISM StartComponentCleanup: Post-repair component store cleanup.
- System File Checker:
sfc /scannowwith multi-language output parsing. - System volume scan:
Repair-Volumefor online volume integrity. - Error handling and execution status reporting.
- Deep CHKDSK scheduling for the next boot
- Automatic restart when required
- Post-restart CHKDSK result collection
- CHKDSK output appended to the same maintenance log
- Temporarily disables hibernation during maintenance
- Temporarily disables Fast Startup during maintenance
- Restores hibernation before finishing (or after CHKDSK post-reboot collector)
- Restores Fast Startup before finishing (or after CHKDSK post-reboot collector)
- Prevents clients from noticing slower boot behavior after service
A structured logging system is implemented across the workflow.
- Logs are stored in:
C:\Logs - Files are generated using timestamps
- Maintenance logs use the
itechbrprefix - CHKDSK results are appended after restart when available
Example:
C:\Logs
βββ itechbr-20260515_081500.log
This enables:
- Full execution traceability
- Easier troubleshooting
- Historical tracking of maintenance tasks
- Clear service reporting
The script executes a deterministic, sequential pipeline designed for unattended operations:
[Init] ββ> [Power Staging] ββ> [Inventory] ββ> [Deep Clean] ββ> [Conditional Repair] ββ> [OS Patching] ββ> [Disk Check] ββ> [Unified Reboot] ββ> [Rollback State]
- Privilege & Environment Initialization: Validates administrative privileges, generates a timestamped execution log path (C:\Logs), and provisions background logging structures.
- Power Subsystem Staging: Temporarily captures initial state and suspends Hibernation and Fast Startup (powercfg.exe) to isolate the OS from hybrid boot locks during maintenance tasks.
- System Inventory: Collects hardware, OS, software, and asset inventory for baseline documentation.
- Storage & Cache Purging: Executes automated system volume cleanup (cleanmgr.exe /sagerun) and purges temporary files, system distribution caches, and update download folders.
- Conditional Component Store Repair:
- Runs DISM
ScanHealthto evaluate component store integrity. - Executes
RestoreHealthonly when corruption is repairable (exit code 10); skips on healthy systems. - Storage preflight checks free space (configurable, default 10 GB) before RestoreHealth; runs lightweight cleanup on failure.
- Captures storage telemetry at 5 pipeline points (before/after each DISM phase).
- Runs
StartComponentCleanuppost-repair.
- Runs DISM
- System File Verification: Runs
sfc /scannowwith automated localized output parsing (supporting multi-language responses). - Automated OS Patching: Interface orchestration with the Windows Update API to search, accept EULAs, download, and install pending security updates without manual prompts.
- Post-Boot Disk Diagnostics: Schedules deep file system diagnostics (CHKDSK) for the next boot sequence and registers a transient persistence script (Scheduled Task) to aggregate post-reboot disk results into the primary session log.
- Unified Reboot Coordination: Single final restart consolidates all reboot reasons β DISM servicing, Windows Update, CHKDSK scheduled.
- Power Configuration Rollback: Restores original machine hibernation and fast-startup states (after CHKDSK collector completes) to preserve the native end-user boot experience.
This workflow is meticulously engineered for production-grade IT infrastructures:
- Zero Prompt Intervention: Completely unattended execution model, eliminating manual technician interaction and GUI blocking.
- Deterministic Behavior: Consistent execution profiles across heterogeneous hardware setups and different Windows 10/11 builds.
- Observability Framework: Built-in structured logging system that acts as a telemetry foundation for historical system tracking.
- Fail-Safe State Containment: Hardened error handling (
trapblocks) that triggers automated environmental rollbacks (restoring power and subsystem states) if execution breaks unexpectedly.
itechbr-windows-maintenance/
β
βββ README.md
βββ LICENSE
βββ .gitignore
β
βββ scripts/
β βββ ITech.bat
β βββ main.ps1 # Modular orchestrator (v2.3.1)
β βββ ITech-Maintenance.ps1 # Legacy monolithic script
β β
β βββ core/ # Infrastructure modules
β β βββ Logging.psm1
β β βββ Reporting.psm1
β β βββ Security.psm1
β β βββ NativeCommand.psm1
β β βββ PowerManagement.psm1
β β βββ TextNormalization.psm1
β β
β βββ modules/ # Functional modules
β β βββ CleanUp.psm1
β β βββ Diagnostics.psm1
β β βββ Repair.psm1
β β βββ WindowsUpdate.psm1
β β βββ Inventory.psm1
β β
β βββ tests/ # Test suites
β βββ All.Tests.ps1
β βββ Core.Tests.ps1
β βββ Logging.Tests.ps1
β βββ Security.Tests.ps1
β βββ Reporting.Tests.ps1
β βββ NativeCommand.Tests.ps1
β βββ Diagnostics.Tests.ps1
β βββ Inventory.Tests.ps1
β βββ Cleanup.Tests.ps1
β βββ chkdsk-Test.ps1
β
βββ docs/
β βββ changelog.md
β βββ how-it-works.md
β
βββ examples/
βββ sample-log.txt
To execute the modular automation framework with administrative privileges:
scripts\ITech.batOr invoke the PowerShell orchestrator directly:
.\scripts\main.ps1 # Production orchestrator (v2.3.1)# Run validation self-test suite
.\scripts\main.ps1 -SelfTest
# Block automatic reboots after patch orchestration
.\scripts\main.ps1 -NoRestart
# Bypass Windows Update pipeline
.\scripts\main.ps1 -SkipWindowsUpdate
# Skip CHKDSK scheduling
.\scripts\main.ps1 -SkipChkdsk
# Set minimum free space (GB) for DISM RestoreHealth preflight (default: 10)
.\scripts\main.ps1 -MinimumFreeGB 15.\scripts\ITech-Maintenance.ps1 -SelfTest # Legacy versions < 2.0- Golden Image Staging: Automated preparation, deep cleanup, and optimization of Windows reference machines before disk image capture (Sysprep/Clonezilla).
- Post-Deployment Validation: Unattended validation runner (
-SelfTest) to ensure core OS integrity, logging access, and subsystem functionality immediately after mass provisioning. - Enterprise Patch Management: Safe, unattended execution of critical Windows Updates across staged environments without requiring manual technician GUI interaction.
- SysAdmin Staging Routines: Automated compliance run for newly unboxed hardware units prior to enterprise enrollment.
- Preventive Maintenance Workflows: Standardized routine for client devices to maximize operating system reliability and longevity.
- Automated OS Recovery & Repair: One-click deployment script to systematically isolate and repair corrupted system files (DISM/SFC) and volume errors.
- Post-Service Optimization: Deep system cache purging and power settings restoration to deliver a clean, fast, and stable OS to the end user.
- Client Device Preparation: Turnkey delivery preparation script guaranteeing optimized state delivery before client handoff.
Detailed documentation is available in the docs directory.
- Administrator privileges
- Windows 10 or Windows 11
- Windows PowerShell 5.1 or newer
- Internet connection for Windows Update
- HTML maintenance report generation
- Remote execution support
- Configurable task profiles
MIT License