Updated: October 2026
A new laptop arrives, and before anyone signs in there's Solitaire, three Xbox apps and a vendor utility asking for updates. Scrubbing it by hand is fine for one machine, and a stranger's script is fine for a gaming rig. For company PCs there's a cleaner way, and this is how to debloat Windows 11 so it stays clean and keeps getting updates.
What Bloat Is on a Business PC
Bloat on a work machine comes in three piles. OEM extras, like the Dell, HP and Lenovo support and "optimizer" utilities. Consumer Store apps, like Solitaire, the Xbox apps, Clipchamp and News. And the nudges: Start menu suggestions, tips and ads in Settings.
Here's the part the YouTube thumbnails skip: removing it barely changes how fast the PC runs. When PCMag's Chris Hoffman tested four debloat tools in April 2026, a fresh Windows 11 25H2 install used 1.9 to 2.1 GB of RAM on boot. The debloated systems used between 1.8 and 2.1 GB, a saving of 100 to 200 MB at most.
So the case for debloating a business PC isn't speed. It's fewer apps to patch, fewer "what's this?" tickets, less attack surface, and a Start menu your users can find things in. That changes how you should do it.
The Microsoft-Supported Way: Remove Store Apps by Policy
Since Windows 11 25H2, Microsoft ships a policy that does the job it used to take a script for. It's called Remove Default Microsoft Store apps, published in August 2025 as KB5065996.
In Group Policy it lives at Computer Configuration > Administrative Templates > Windows Components > App Package Deployment. In Intune it's in the settings catalog, backed by the ApplicationManagement/RemoveDefaultMicrosoftStorePackages CSP. You tick the apps you don't want from a list of about two dozen, including Copilot, Clipchamp, Solitaire, the Xbox apps, News and Weather. Apps come off at the device level, and each successful removal logs Event ID 762.
Three limits matter. The policy only applies to Windows 11 Enterprise and Education, version 25H2. It's off by default. And multi-user session hosts aren't supported. If your fleet runs Pro, you're still in script territory, which is where the next section starts.
Clean the Image, Not Every Desktop
Windows tracks built-in apps in two places. Provisioned apps sit in the image and install for every new user at first sign-in. Installed apps belong to a profile that already exists. Removing one doesn't remove the other, and that's where most scripted debloats go wrong.
Remove-AppxProvisionedPackage takes an app out of the image, so new users never get it. Profiles that already have it keep it. To clear those too, pair it with Remove-AppxPackage -AllUsers for the same package.
Get the pairing wrong on a reference machine and Sysprep stops you. Microsoft documents the error as "A fatal error occurred while trying to sysprep the machine", with 0x80073cf2 in the log. The cause: an app was deprovisioned from the image but is still installed for a user. The fix is to remove it for that user as well, then run Sysprep again.
This r/sysadmin thread asks how other Windows shops debloat workstations. The top answer scripts the AppX removals, then adds that if you can't live with any bloat at all, Enterprise licensing is the cleaner route.
Why Random Debloat Scripts Are a Fleet Risk
The tools that dominate this search are community projects: Chris Titus Tech's Windows Utility, Raphire's Win11Debloat, and Tiny11 Builder for stripped-down ISOs. On a personal PC they're a reasonable weekend project. On 200 company laptops they're code from someone you've never met, running with admin rights.
PCMag's test shows what that looks like. Tiny11 Core builds a Windows image without a working Windows Update, so those machines stop getting security fixes. Win11Debloat's defaults switch off Fast Startup. Chris Titus's utility sets a batch of background services to manual start. None of those is a bug. They're the author's opinions about how Windows should behave, applied to your fleet.
Some changes don't even stick. The same test found that telemetry toggles on Home and Pro get ignored by Windows unless you run an LTSC edition. And a feature update can reinstall apps a script removed. Microsoft's own guidance on keeping removed apps from returning exists for exactly this reason.
If you do use a community script, treat it like any other change. Read it, pin the version you tested, and run it from your own repository, never piped straight from GitHub.
Britec09 tested the same promises on camera in September 2026, with frame rates and memory on one side and the things that broke on the other.
What Not to Remove
Every debloat list needs a keep list next to it. These are the ones that come back as tickets:
- Microsoft Store and App Installer. winget depends on App Installer, and plenty of line-of-business apps still update through the Store.
- Edge WebView2 Runtime. Teams, Outlook and many third-party apps render inside it.
- Windows Security. Pulling it apart leaves Defender half configured.
- Photos, Notepad, Calculator, Snipping Tool, Terminal. Users open these daily. Removing them saves nothing and costs you tickets.
- Quick Assist. Keep it if your help desk uses it for remote support.
- Xbox Identity Provider. Some sign-in flows and Game Pass for PC depend on it, so test before you pull it from a device that needs either.
The safest workflow is boring on purpose. Remove from a pilot group of ten machines, wait a week, read the tickets, then widen the ring.
In this r/sysadmin thread, one admin who had to clean Dell bloatware and extra Office language packs off 100 computers wrote their own script after finding nothing that worked. The comments are a good list of what else people strip, and what they regretted.
Run It Across the Fleet
Pick the route by edition. On Enterprise or Education 25H2, use the policy through Intune or Group Policy, and let Windows do the removal. On Pro, keep one reviewed PowerShell script in your own repository, pair the provisioned and installed removals, and log what it touched.
Then roll it out like a patch. A pilot ring first, the rest of the fleet a week later, and a re-check after every feature update, because that's when removed apps tend to reappear. For OEM junk, the cleanest fix is upstream: order devices with a clean image from the vendor, or reimage them on arrival.
Whatever runs the script needs to show you what happened on each machine. OpenFrame, Flamingo's open infrastructure layer for IT and security, runs scripts, scheduled scripts and bulk operations across devices, and nothing risky runs without a technician's approval. Our PowerShell commands guide covers the Get-AppxPackage checks worth running before and after.
Clean, Not Stripped
A debloated business PC isn't the lightest possible Windows. It's one with nothing on it that nobody asked for, and nothing missing that users need. Use the policy where your licensing allows it, clean the image rather than every desktop, and keep a keep-list.
If Copilot is on your removal list, see how to uninstall Copilot.
For the patching side of keeping a clean fleet clean, read our guide on stopping Windows Update without losing security fixes.

"Fae" Grace Meadows
Lead AI Fairy
Some things defy easy explanation: magic dust, the northern lights… and Flamingo’s AI Angels. Think Charlie’s Angels, reimagined with automation brains and serious RMM (Remote Monitoring & Management) chops. Weird? A little. Effective? Absolutely. That’s the job.
