Today I would like to share some information with you about a special, somewhat unique edition that exists in Windows 10 and Windows 11, released by Microsoft for the Chinese government sector. What is Windows Enterprise G, also known as Windows Enterprise Government China, how does it differ from other editions, and most importantly, how (and why) you can get it.

The story begins with the confrontation between American and Chinese departments, mutual accusations of espionage, sanctions - well, just like with us. The only difference is that in our case, during the 'best years' of Russian-American relations, the most we achieved was the certification of Windows by our Big Brother. For this, they were given access to the OS source code - IT specialists in uniform had the opportunity to study the OS source code on Microsoft's premises on a PC disconnected from the internet, any networks, and removable media to prevent code leaks. The task was partially completed - the operating system (with a number of functional limitations) was certified for use in the public sector (also with a number of restrictions on its application).
However, Microsoft itself did not change the OS code for Russia - 'take it or leave it' - we were looking at the same code that was sold in stores. Then things got really messy with the code – checksums were calculated and recorded, the OS could be installed, but not updated. The initial idea was that updates would also become available after some verification, but the idea stalled. In general, since the OS was unchanged, all owners of 'certified Windows' could install updates from the Microsoft website - but deep in the paperwork from Big Brother it was stipulated that this was not allowed, which is generally logical - the 'certification' would be lost.
The Chinese went much further, which is not surprising given the scale of their public sector and the fact that 'public sector' there means almost everything - Microsoft could not afford to miss such a piece of the pie. And it has been successfully eating it for almost ten years now - although, just like with us, the 'best years' of Sino-American friendship are long gone, the Chinese public sector is successfully moving away not only from Microsoft products, but also from Intel architecture, and is generally refusing to use non-Chinese products. In some ways, this is, of course, the right thing to do. Today, however, we will talk about the work Microsoft has done to reach an agreement with the Chinese regulator to stay in the market, and we will look at the resulting product. I will tell you how you can get the necessary binaries from Microsoft's servers with your own hands and install that very Windows without telemetry, Defender, Cortana, modern apps, and all the other nonsense they force-feed us in all other editions. I will tell you how to do this for both Windows 10 and Windows 11, there are practically no differences. I'll start with a fly in the ointment. Windows Enterprise G is only available in Chinese and English. The two available interface languages are written in the ProductPolicy and are digitally signed - without changing the ProductPolicy using ProductPolicyEditor you will get a blue screen if you install a Russian language pack, and if you change it, you will only be able to work by switching the bootloader to developer mode, which does not require checking the signatures of executable code, which is unsafe. I have always used only English-language OSes myself, so this limitation did not bother me. There is no point in spitting at MS in the comments - complaining that the Russian language does not work is also pointless. C'est la vie (such is life). If you are still reading, let's start with a short description.
In general, I have already told you everything in a nutshell above. Windows Enterprise G is an edition for the Chinese government, released through the OEM channel simultaneously with all major editions of Windows 10/11, but little known to the general user. It is based on the same code as all the others – deep down it is Windows Professional, in which some components blocked in Professional are enabled by means of ProductPolicy (just like in the Enterprise or Enterprise LTSC editions, the following components disabled in Professional are enabled by policy in Enterprise G: APP-V; UE-V; Embedded functionality; ReFS support; support for 6TB vs 2TB of RAM and PersistentMemory support; use of VPN before logon; RDMA support and much more - see for yourself using ProductPolicyEditor - highly recommended for administrators to understand the differences between editions). At the same time, the Defender, so passionately disliked by many, has been almost completely removed from the OS. If you want an antivirus or a firewall, install any solution you like. Except for Microsoft Defender. It is not possible to install Defender in Enterprise G using standard means. The Microsoft Edge browser and all 'modern' UWP applications have also been removed from the OS. Although Windows 11 Enterprise G has a centered Start button, it is much more reminiscent of Windows 7 than any version of Windows 10 or even Windows 8. The changes made have a fairly significant impact on how Enterprise G works on older computers – it requires 150-300 megabytes less RAM, accesses the disk less often, and is well-behaved (no excessively frequent calls to Windows Update for Defender updates). In general, I will let you judge for yourselves whether you like it or not. I hope that after the publication of this information, builds with the Enterprise G edition will become more accessible here, and you will not have to create an image yourself following the instructions I provide below.
I will not recommend or discourage you from using this edition, I will just express a few of my thoughts before we start working on the build.
• Whenever you start doing something with Windows builds, changing packages and editions, if possible, start with the first build in the current branch - you can deliver the updates later. That is, the build should end with .1. More details below.
• I recommend always taking the first build of the latest version for which there is an LTSC branch. For 64-bit platforms (x64 and arm64) this is now 10.0.26100.1, for the 32-bit platform Windows 11 is not released, so you should look towards Windows 10, where the first build of the latest LTSC branch is 10.0.19041.1. In my opinion, this is now the ideal for old computers that need a modern, updatable OS without unnecessary junk.
• The same updates apply to Enterprise G as to other versions of Windows, if you are comfortable, enable Windows Update or manually download MSU/CAB updates. Defender, Edge, and other junk will not come with the updates.
• Don't rush to explore the Enterprise G N edition – yes, Microsoft also builds such an edition, it has everything the same as in Enterprise G, minus the media components. But the Enterprise G N edition has never been released to the market, and updates cannot be installed on it. You can easily build version 10.0.19041.1 or 10.0.26100.1 (or any other), but it will be impossible to update Enterprise G N from Windows Update. I have actually been using Windows 11 version 10.0.25398.1 for the last year, as it is the last one officially working without processor support for the POPCNT instruction (see Microsoft added support for the POPCNT instruction to the processor requirements for Windows 11 24H2, which is not present in older CPUs / Habr (habr.com)). Microsoft officially made this build available only with Windows Server 23H2 last year, but enthusiasts, before the release of 10.0.26100.1, widely used this particular build for gaming, using UUP Dump to create client OSes, and there are many legends about it in the Steam community as the most stable version).
Before we start, here is a screenshot - I have created virtual machines for Windows 11 24H2 and Windows 10 22H2, one Professional, the second – Enterprise G, converted from the first with a script. And a fifth machine with 32-bit Windows 10 22H2 Enterprise G. The machines are configured to use dynamic memory, started with 2GB, and after 15 minutes of operation, the assigned memory value corresponds to the OS's resource needs. The numbers speak for themselves:

Well then, let's start creating our own Windows Enterprise G installation distribution.
I will describe the process step-by-step for Windows 11 build 10.0.26100.1, but for other builds (and platforms) the process is not much different, I will provide the scripts at the end of the article. I assume that you know what UUP Dump is and can download the Professional edition yourself. I recommend downloading from UUP, and not taking one downloaded from somewhere else (even from the Microsoft website) – ISO images are likely to have some updates built in, and the process of replacing the Professional edition with Enterprise G is more likely to fail. When downloading a build from Microsoft's servers using UUPDump.net, you can explicitly prohibit the integration of updates into the image. For example, from here I am downloading the 64-bit Windows 11 Professional 24H2 build 10.0.26100.1 as an example, from here the 64-bit Windows 10 Professional build 19041.1, and from here the 32-bit Windows 10 Professional build 19041.1. Next, I unpack the archive, open the ConvertConfig.ini file and specify AddUpdates=0 and SkipISO=1 in it. The first prevents the integration of updates into the created Install.wim, the second option allows you to not start the creation of an ISO image – because we want Enterprise G, why do we need an ISO with Professional? Using the links given above, click Create download package (I have a purple frame in the picture), this will create the required image with Professional.

Next, we will need the Microsoft-Windows-EditionSpecific-EnterpriseG-Package.ESD file from the same UUP – in it, Microsoft stores all (almost) the information necessary for the Enterprise G edition. We will also need the English language pack - Microsoft-Windows-Client-LanguagePack-Package_en-us~31bf3856ad364e35~amd64~en-us~.esd – if you downloaded the build via UUP Dump, this file is already available in the UUPs folder. You can download the EditionSpecific file from UUP Dump as well, for convenience, I am providing links to the file list of 64-bit builds Windows 10 10.0.1904.1, Windows 11 10.0.26100.1 and 32-bit Windows 10 10.0.19041.1.
Find the Microsoft-Windows-EditionSpecific-EnterpriseG-Package.ESD there and save it. The links to the files themselves do not last more than a day, so there is no point in writing them here. When saving the ESD file from UUPDump, be careful with the file name - the site gives it as a UID, you need to copy the name to the clipboard and specify it when saving the file.
The only thing missing on UUP for creation is the MUM/CAT pair from Microsoft-Windows-EnterpriseGEdition. However, since the digital signature of the CAT file only lists the package name Microsoft-Windows-EnterpriseGEdition, but not its version or platform, by taking the MUM/CAT files Microsoft-Windows-EnterpriseGEdition~31bf3856ad364e35~x86~~10.0.177631.mum from a leaked 32-bit Windows 10 Enterprise G image, I can simply rename them to Microsoft-Windows-EnterpriseGEdition~31bf3856ad364e35~amd64~~10.0.26100.1, edit the text MUM file and use it in the 64-bit version of Windows 11. What a fairy tale. 😊
For Windows 11 10.0.26100.1, the English language pack, unlike the packs for all previous versions of Windows 10/11, is missing the license.rtf file with the license (it is present in the Chinese language pack - if you are building the OS in Chinese, copying the license file from an external source is not required). If the license file is missing from two folders at the time of OS installation, or if its checksums do not match the desired ones for the package, you will get an OOBE (Out of box experience) error after selecting the language and country, even before specifying a username. Interestingly, in Insider Preview builds, including 10.0.26090.1, this file was present in the English language pack - and had not changed for over a year. It was logical to assume that it would also be suitable for 10.0.26100.1, which turned out to be the case. As a result, to build an image of Windows 10 Enterprise G, Windows 11 Enterprise G versions 10.0.22000.1 or 10.0.22621.1, you only need the files from UUP + the MUM/CAT pair for Microsoft-Windows-EnterpriseGEdition, while for Windows 11 10.0.26100.1 you will also need license.rtf.
Replacing the edition in any Windows image, if it is not provided for in c:\Windows\servicing\Editions\EditionMappings.xml, should be done from the first build of the current branch if you are creating an image for installation. For an already installed Windows, of course, there is no point in requiring the uninstallation of updates - if you need to replace the edition of the current OS, it is easier to perform an Upgrade than to replace packages - an Upgrade can be performed within the branch and to an older build. We are now going to talk not about upgrading the currently installed OS, but about the unattended replacement of packages in an offline WIM image, which allows you to create any edition.
What we need to create a Windows 11 Enterprise G 10.0.26100.1 image
• An install.wim image from Windows 11 Professional – English x64. We will assume that you know how to get it yourself - start with UUP Dump, select..., unpack, make sure that the ConvertConfig.ini file specifies AddUpdates=0 and SkipISO=1 (correct it if not), run uup_download_windows.cmd, agree to the warnings and wait for the UUP files to download and the distribution to be created. The desired file will be in 26100.1_amd64_en-us_professional_3d68645c_convert_virtual\26100.1.240331-1435.GE_RELEASE_CLIENTMULTI_X64FRE_EN-US\sources\install.wim (3d68645c is the identifier of my UUP package, your numbers will be different, for Windows 10 only the numbers in the build number and the name of the servicing branch will change).
• The files Microsoft-Windows-EditionSpecific-EnterpriseG-Package.ESD and Microsoft-Windows-Client-LanguagePack-Package_en-us.esd (also known as Microsoft-Windows-Client-LanguagePack-Package_en-us~31bf3856ad364e35~amd64~en-us~.esd) – are available from the same UUP Dump link. Make sure you are using the same build and platform!
• The files Microsoft-Windows-EnterpriseGEdition~31bf3856ad364e35~amd64~~10.0.26100.1.cat, Microsoft-Windows-EnterpriseGEdition~31bf3856ad364e35~amd64~~10.0.26100.1.mum and license.rtf (included in the archive with the scripts in the next point)
• And the scripts that create the Enterprise G image from Professional. I offer a version for x64 Windows 11 24H2 10.0.26100.1, x64 Windows 10 10.0.19041.1 and x86 Windows 10 10.0.19041.1. If there is serious interest in other versions, platforms, or editions, write detailed questions in the comments or PM, and I will answer.
The downloaded script needs to be unpacked into a folder, place the install.wim from the first point and the Windows-Client-LanguagePack-Package_en-us.esd from the second into it, and unpack the Microsoft-Windows-EditionSpecific-EnterpriseG-Package.ESD into the SxS folder. The reconstructed folder contains the required MUM/CAT files for Microsoft-Windows-EnterpriseGEdition and license.rtf for build 10.0.26100.1.
Attention, the archive contains NSudo.exe – a utility that allows you to run scripts in the SYSTEM context (NT Authority\System) – using it in scripts allows you to write to the Windows image folder without changing the original owner of files and folders. This makes it more 'original', that is, the way Microsoft itself does it, but some antiviruses are triggered by it. If you don't trust my NSUDO, download it yourself from GitHub.
Now, run the command prompt in administrator mode, navigate to the folder with the unpacked script and Microsoft-Windows-EditionSpecific-EnterpriseG-Package.ESD, the Professional edition install.wim image, and the Client-LanguagePack-Package_en-us.esd language pack (the name may vary from version to version, the script will rename it anyway). The script runs the Build.cmd sub-script via NSUDO, mounts the install.wim from Professional, replaces the edition package in it with Enterprise G, performs component cleanup, unmounts the image, and makes changes to the meta tags of the install.wim image.
Using the method described here (by replacing files from EditionSpecific and the MUM/CAT pair of the Edition package), you can also easily create LTSC or Evaluation, or LTSC Evaluation editions from Professional. And also variants with Enterprise G N, LTSC Enterprise N, Enterprise Evaluation N, and LTSC Enterprise Evaluation N. It should be remembered, however, that Microsoft does not release updates for Enterprise G N and Enterprise Evaluation N (unlike Enterprise G and Enterprise Evaluation, which are easily updated) - you will not be able to install a cumulative update on Enterprise G N without first modifying update.mum. If your task is to build a home Windows computer platform with minimal hardware requirements, you can, of course, look towards 32-bit Windows 10 Enterprise G N, and update it by correcting, for example, Microsoft-Windows-EnterpriseSNEvalEdition to Microsoft-Windows-EnterpriseGNEdition in update.mum, but the gain in the case of N is not worth the trouble - 10-20 megabytes of memory, for the absence of basic codecs and the ability to update. Although, if you specifically want the system not to want updates, perhaps this is your path. I cannot, however, guarantee that the OS will not try to update itself. It won't be able to update, but it will try! 😊
I used a similar (significantly more complex, of course, but generally similar) method to create client images of Windows 11 based on build 10.0.25398.1, under which only Windows Server 23H2 (Core) was released. All the necessary EditionSpecific files are on UUP, however, the Client-LanguagePack is missing. It can be taken from slightly earlier builds - if anyone is seriously interested in this adventure, write me a PM, I will answer. It is unnecessary here. I am just studying the OS structure this way. Personally, a deep understanding of the OS structure helps me to carry out complex implementation projects, solve non-standard tasks, and, of course, I love to share my experience on those rare days when I find time to conduct training. And in short, I am always happy to help enthusiasts who are looking for their own path to knowledge. Write to me.