A humanoid robot points to a computer screen showing Windows setup options as a person watches.
A hands-on test from XDA-Developers' Joe Rice-Jones gave Claude Code administrator rights on a clean Windows 11 virtual machine. The agent finished the setup in 11 minutes. It also left behind a few mistakes and a short list of tasks Windows reserves for the person at the keyboard.

This is one test on one VM, so treat it as a case study, not a verdict on AI setup tools. The result is useful anyway. It shows what an auditable, script-driven agent workflow looks like on Windows, and where that workflow still needs a human to check the work.

The test setup​

The machine was a Hyper-V VM with 4 virtual CPUs and 8 GB of RAM. It ran Windows 11 Pro 26H2, build 26300.9457, and the author took a checkpoint first so everything could be rolled back. Microsoft's release-health page lists 26H2 as a General Availability Channel release with an availability date of 2026-09-29, so this was a shipping build and not an Insider preview.

Claude Code ran under a separate local admin account called "agent". It was installed with its native PowerShell installer. The author deliberately left out Git for Windows and WSL, so the agent started from what Microsoft ships.

The prompt was fixed. It asked the agent to:

  • fully update the PC, drivers included
  • remove preinstalled junk and ads
  • install a sensible common software set
  • fix the defaults most people change
  • make the PC backed up and secure
  • save any PowerShell longer than a few lines as a script under C:\Users\agent\_scripts\ and run it with -File
  • ask before anything irreversible
  • finish with a summary of what changed and how to undo it

The author scored the result against a 10-item rubric the agent never saw. Each item was worth 0 to 2 points, and updates and security counted double. The item-by-item scoring isn't published, so the total can't be recalculated independently.

What the agent did​

The run started at 9:48 PM and ended at 9:59 PM, after 43 tool calls. It used six numbered scripts, from 01-safety-net.ps1 to 06-backup.ps1. Each script opened with a header explaining what it did and how to undo it.

  • Questions asked. About two minutes in, it asked which accounts should get the new settings, how aggressive the debloat should be, and which software set to install. It recommended an option for each, and the author took all three. At the end it asked about Memory Integrity and warned that the reboot would end its own session. The author declined.
  • Updates. It skipped the Settings app and drove the Windows Update API from PowerShell. It opted in to updates for other Microsoft products and searched for software and driver updates. It installed a Defender platform update (KB5007651) and the Malicious Software Removal Tool (KB890830) in about 76 seconds, with no reboot.
  • Debloat. It removed 21 packages for every account, including Clipchamp, Solitaire, personal Teams, the new Outlook, the Xbox apps and Widgets. The Store, Calculator and Photos stayed.
  • Apps. It installed 12 apps through winget so they stay updatable: Firefox, 7-Zip, VLC, SumatraPDF, Bitwarden, Notepad++, VS Code, PowerToys, Everything, ShareX, PowerShell 7 and Git.
  • Settings. It applied Explorer, search and ad settings to three registry hives: its own account, the author's signed-out account (loaded offline after confirming nobody was signed in), and the Default profile for future accounts. It also restored the classic right-click menu.

The restore-point detail​

The agent enabled System Restore, made a restore point before touching anything, and scheduled a daily restore-point task. The author notes that Windows normally skips a new restore point if one was made in the last 24 hours. The agent removed that limit first, then tested the task and got a second restore point four minutes after the first.

Microsoft's documentation backs up the mechanism. A DWORD value called SystemRestorePointCreationFrequency under HKLM\Software\Microsoft\Windows NT\CurrentVersion\SystemRestore can change how often restore points are created, and by default the key doesn't exist. If the value is 0, System Restore does not skip creating the new restore point. That fits what the author describes. Microsoft doesn't say which value the agent actually set.

This is legacy System Restore, not the newer point-in-time restore feature. Microsoft describes that newer feature as capturing full system state, including local files, with a frequency and retention that admins can configure. Don't assume the agent's restore points protect your documents. They don't, and the agent said so in its backup script.

Where the agent stopped​

Two points were lost to Windows protections the agent chose not to fight.

  • Default browser. Firefox was installed but Edge stayed the default. The agent listed this, plus activating Windows, under "Things only you can do". Microsoft's developer documentation explains why. Windows does not allow programmatic changes to default apps without user interaction in the system UI, and registry-based changes are not supported for apps. The practical fix is to set the default yourself in Settings.
  • Widgets policy. A policy write was blocked even with admin rights, and the agent did not try to get around it. The Widgets app was already removed, so nothing was lost.

File backup was also left to the user. It needs the user's own account or NAS credentials, so the agent asked about a network share and the author declined for the test.

BitLocker was already on. Windows had encrypted the drive and uploaded the recovery key to the author's Microsoft account during setup. The agent noticed this, didn't claim credit, and told the author to confirm the key was there, which it was. Microsoft's guidance says storing the recovery password in a Microsoft account is the default recommended method for devices not joined to Entra ID or Active Directory.

What went wrong​

The author describes none of these as machine-breaking, but they are the reason to review an agent's work.

The undo lists were wiped. The debloat and install scripts each saved a CSV of what they had changed. The agent then tidied both files with one in-place pipeline: Import-Csv $c | ForEach { ... } | Export-Csv $c. The author says both files ended up at zero bytes, because the pipeline streams and Export-Csv opens and truncates the file before Import-Csv has finished reading. Wrapping the read in parentheses so it completes first avoids this. Microsoft's cmdlet documentation only shows importing and exporting as separate steps, so that streaming explanation is the author's, not Microsoft's.

The final summary still said each step had been checked. The author didn't dock points for reversibility, because the app lists remain in the scripts and summary, the registry backups for all three profiles are intact, and the restore point covers the rest. Undoing the changes is possible, just less convenient than promised.

Startup apps slipped in. Everything and ShareX added themselves to startup during install, and Task Manager rates ShareX as high impact. Firefox later started at sign-in too, after being opened once and the PC restarted. The agent didn't create these entries, but it didn't flag or remove them either.

Limits of the result​

Claude Code, using Opus 5.5, scored 22 out of 24, with two interventions that were both questions the agent chose to ask. The author concedes a Hyper-V VM is the easy version of this test, with no OEM drivers, no manufacturer bloat and no firmware updates. A real-hardware follow-up is planned.

Logging also had gaps. The author relied on built-in Windows logging, but two Windows Update installs never showed up in that timeline. They are known only because the agent kept its own log. So independent verification worked only partly.

Practical takeaways​

If you try something similar, use a checkpoint or a disposable VM first and keep the prompt fixed. The prompt's requirements to save scripts to disk and write undo instructions are what made this run auditable. After the run, check these yourself:

  1. Open the undo and log files and confirm they aren't empty.
  2. Review Task Manager's Startup apps list for new entries.
  3. Set your default browser and other defaults in Settings.
  4. Set up a real file backup, because restore points aren't one.
  5. Confirm your BitLocker recovery key is saved where you expect.

The standout behavior in this test was restraint. The agent asked before the big choices, stopped at protections Windows enforces on purpose, and reported what only the user could do. The weak spot was self-verification, so don't take "each step was checked" on faith.

 

References

  1. An AI agent took over my blank Windows machine and finished in minutes what would take me hours XDA 2026-10-06T10:00:16+00:00
  2. Import-CSV: How to Read a CSV File in PowerShell? - SharePoint Diary sharepointdiary.com