I'm trying to set up new Win8.1 systems that will have the 11.2.4 agent, but without the user login occuring to Zenworks after the Windows login. We already do this on a few hundred Win7 systems -- where bundles are assigned by system only -- but I must be overlooking something.

Here are the relevant registry settings:

[HKEY_LOCAL_MACHINE\SOFTWARE\Novell\ZCM]
"CASubject"="O=Internal Certificate Authority, OU=ZENworks, CN=AMZCM1P.corporate.<mycompany>.com"
"Version"="11.2.4.34001 Monthly Update 1"
"AgentInstallPath"="C:\\Program Files (x86)\\Novell\\ZENworks\\"
"LocalLogSeverity"=dword:00000004
"CAIsExternal"=dword:00000000
"ZENLoginUserRefreshAsync"="TRUE"
"ConsoleUsername"="<someone>"
"ConsoleSessionID"="<a number>"

[HKEY_LOCAL_MACHINE\SOFTWARE\Novell\ZCM\GroupPolicy]
"DisableExplorerRestart"="TRUE"

[HKEY_LOCAL_MACHINE\SOFTWARE\Novell\ZCM\GroupPolicy \Handler]
"deployScripts"="True"
"userFlag"="False"
"deviceFlag"="False"

[HKEY_LOCAL_MACHINE\SOFTWARE\Novell\ZCM\NAL]
"IsNalDisabled"=dword:00000000

[HKEY_LOCAL_MACHINE\SOFTWARE\Novell\ZCM\ZenLgn]
"eDirLogin"=dword:00000000
"DomainLogin"=dword:00000000
"DisableZENCredentialProvider"=dword:00000001
"DisablePassiveModeLogin"=dword:00000001
"DisablePassiveModeLoginPrompt"=dword:00000001
"EnableSeamlessLogin"=dword:00000001
"DefaultRealm"="Corporate.<mycompany>.com"

[HKEY_LOCAL_MACHINE\SOFTWARE\Novell\ZCM\ZenNotify]
"NoPreviousCompatibleRUPSecurityPolicy"=dword:0000 0001