# How Win11Debloat Uses the Registry for System Changes

> Discover how Win11Debloat uses the registry for system changes by importing .reg files into system and user hives for custom configurations.

- Repository: [Jeffrey/Win11Debloat](https://github.com/Raphire/Win11Debloat)
- Tags: internals
- Published: 2026-03-10

---

**Win11Debloat applies system-wide configuration changes by importing pre-written `.reg` files stored in the `Regfiles` directory, using the `ImportRegistryFile` function to handle both system hives and individual user `NTUSER.DAT` hives depending on execution mode.**

Win11Debloat is an open-source PowerShell utility that streamlines Windows 11 customization by disabling telemetry, removing bloatware, and tweaking the user interface. Rather than embedding registry commands directly in the main script, the project maintains a clean separation between logic and configuration data. This architecture allows the tool to apply **Win11Debloat registry** modifications reliably across different deployment scenarios, including Sysprep imaging and per-user targeting.

## Registry Configuration Architecture

### Feature Metadata Mapping

The master catalog of all debloat options resides in [`Config/Features.json`](https://github.com/Raphire/Win11Debloat/blob/main/Config/Features.json). Each feature that modifies the registry includes a `RegistryKey` property that specifies the exact `.reg` filename to import, along with an `ApplyText` field containing the user-facing description shown during execution.

In [`Config/Features.json`](https://github.com/Raphire/Win11Debloat/blob/main/Config/Features.json) (lines 49-57), a typical registry-based feature is defined as:

```json
{
  "FeatureId": "DisableTelemetry",
  "Label": "telemetry, tracking & targeted ads",
  "Category": "Privacy & Suggested Content",
  "Action": "Disable",
  "RegistryKey": "Disable_Telemetry.reg",
  "ApplyText": "Disabling telemetry, diagnostic data, activity history, app‑launch tracking and targeted ads..."
}

```

When the script processes a command-line switch or GUI selection, it looks up the corresponding `FeatureId` and checks for the presence of a `RegistryKey` property to determine if a registry import is required.

## Dynamic Registry Import Logic

### The ImportRegistryFile Function

The central registry handling routine is `ImportRegistryFile`, located in `Scripts/Features/ImportRegistryFile.ps1` (lines 1-45). This function accepts two parameters: a message string for console output and the path to the `.reg` file relative to the `Regfiles` folder.

The implementation dynamically adjusts its behavior based on the execution context:

```powershell
function ImportRegistryFile {
    param ($message, $path)

    Write-Host $message

    if ($script:Params.ContainsKey("Sysprep") -or $script:Params.ContainsKey("User")) {
        $hiveDatPath = if ($script:Params.ContainsKey("Sysprep")) {
            GetUserDirectory -userName "Default" -fileName "NTUSER.DAT"
        } else {
            GetUserDirectory -userName $script:Params.Item("User") -fileName "NTUSER.DAT"
        }

        $regResult = Invoke-NonBlocking -ScriptBlock {
            param($datPath, $regFilePath)
            reg load "HKU\Default" $datPath | Out-Null
            $output = reg import $regFilePath 2>&1
            reg unload "HKU\Default" | Out-Null
            return @{ Output = $output; ExitCode = $LASTEXITCODE }
        } -ArgumentList @($hiveDatPath, "$script:RegfilesPath\Sysprep\$path")
    }
    else {
        $regResult = Invoke-NonBlocking -ScriptBlock {
            param($regFilePath)
            $output = reg import $regFilePath 2>&1
            return @{ Output = $output; ExitCode = $LASTEXITCODE }
        } -ArgumentList "$script:RegfilesPath\$path"
    }
}

```

### System-Wide Imports

In standard execution mode, the function imports `.reg` files directly against the system registry hive using the `reg import` command. The script constructs the full path by appending the provided filename to `$script:RegfilesPath`, executing the import within an `Invoke-NonBlocking` script block to capture both output and exit codes (lines 39-45).

### Per-User Hive Handling (Sysprep and User Modes)

When running in **Sysprep** mode, Win11Debloat targets the Default user profile to ensure changes propagate to all new user accounts created after imaging. The script loads `C:\Users\Default\NTUSER.DAT` as `HKU\Default`, imports the registry file from the `Regfiles/Sysprep/` subdirectory, then unloads the hive (lines 20-38).

For **User** mode, the process is identical but targets a specific existing user profile. The `GetUserDirectory` helper resolves the path to the specified user's `NTUSER.DAT`, allowing administrators to apply tweaks to profiles other than the currently logged-on account without logging in as that user.

## Feature Execution Flow

The orchestration of registry changes occurs in `Win11Debloat.ps1` through the `ExecuteParameter` function (lines 35-56). This entry point parses command-line arguments or GUI selections and routes registry-based features to `ImportRegistryFile`:

```powershell
function ExecuteParameter {
    param ([string]$paramKey)

    $feature = $null
    if ($script:Features.ContainsKey($paramKey)) {
        $feature = $script:Features[$paramKey]
    }

    if ($feature -and $feature.RegistryKey -and $feature.ApplyText) {
        ImportRegistryFile "> $($feature.ApplyText)" $feature.RegistryKey
        return
    }
}

```

This design allows the main script to remain agnostic of registry implementation details. When a feature requires registry modification, `ExecuteParameter` simply passes the user-friendly `ApplyText` and the `RegistryKey` filename to the import function, which handles the underlying `reg.exe` operations and hive management.

## Summary

- Win11Debloat stores all registry modifications as standalone `.reg` files in the `Regfiles/` directory, with Sysprep-specific variants located in `Regfiles/Sysprep/`.
- [`Config/Features.json`](https://github.com/Raphire/Win11Debloat/blob/main/Config/Features.json) maps command-line switches and GUI options to specific registry files via the `RegistryKey` property, enabling a data-driven approach to system customization.
- `Scripts/Features/ImportRegistryFile.ps1` contains the core logic for applying these changes, automatically detecting whether to target the system hive or load a user's `NTUSER.DAT` hive.
- **Sysprep mode** applies changes to the Default user profile, ensuring new accounts inherit the configuration.
- **User mode** allows targeting specific existing profiles by temporarily loading their registry hives during the import process.

## Frequently Asked Questions

### Where does Win11Debloat store its registry modification files?

The registry files are stored in the `Regfiles/` directory at the repository root. Files intended for Sysprep deployment (targeting the Default user profile) are located in the `Regfiles/Sysprep/` subdirectory. Each `.reg` file contains the specific key-value pairs required for a particular system tweak, such as `Disable_Telemetry.reg` or `Hide_Search_Taskbar.reg`.

### How does Win11Debloat handle registry changes for new user accounts?

When executed with the `-Sysprep` parameter, Win11Debloat loads the `NTUSER.DAT` hive from `C:\Users\Default` as `HKU\Default`, imports the relevant `.reg` files from `Regfiles/Sysprep/`, and then unloads the hive. This ensures that any new user accounts created on the system will inherit these registry settings automatically.

### Can Win11Debloat apply registry tweaks to specific existing users?

Yes. By using the `-User` parameter followed by a username, the script targets that specific user's profile directory. The `ImportRegistryFile` function locates the user's `NTUSER.DAT` file, loads it as a temporary hive, applies the registry modifications, and unloads it—all without requiring an interactive logon as that user.

### What determines whether Win11Debloat uses a registry file or another method for a feature?

The presence of the `RegistryKey` property in [`Config/Features.json`](https://github.com/Raphire/Win11Debloat/blob/main/Config/Features.json) determines the execution path. If a feature definition includes this property, `ExecuteParameter` in `Win11Debloat.ps1` routes the request to `ImportRegistryFile`. Features without a `RegistryKey` typically use alternative methods such as PowerShell cmdlets, DISM commands, or Windows API calls implemented in separate function files.