The latest Windows 11 26H2 image is now too large for a dual-layer DVD. I'm looking for installation media that is genuinely read-only because the computers being reinstalled may be infected, and I don't want malware modifying a writable USB drive or spreading to another system. SD-card write-protection switches don't seem fully trustworthy because they may only signal the device firmware rather than physically block writes. Is Blu-ray the only practical optical option, or is there a better way to keep Windows installation media offline and write-protected?
5 Answers
Network boot through PXE is another option if the environment supports it, but it doesn’t meet the air-gapped requirement. For an offline workflow, a verified USB installer or Blu-ray is simpler. You can also keep the ISO on a system with appropriate permissions and generate a fresh installer only when needed.
A write-protected flash device or an IODD-style device with a read-only switch can work well. Some administrators also use removable SSDs or dedicated installer drives and keep them locked away when not in use. Treat the media as disposable and recreate it from a verified image when necessary rather than relying on it indefinitely.
For truly read-only physical media, Blu-ray is basically the remaining practical optical choice. Most administrators have moved to verified ISO files and USB-based installation, though. Create the installer from a clean, trusted system, verify the image hash, and never insert that USB into a running potentially infected operating system.
For occasional installations, I’d use a USB stick made from a verified ISO, keep it disconnected except during boot, and wipe or recreate it afterward. If you need a medium that is physically immutable and must remain offline, Blu-ray or archival optical media is the straightforward answer, although the required optical drive can be harder to find than the media itself.
If the goal is rebuilding a potentially compromised machine, the usual process is to isolate it, remove or wipe the system drive, and install from freshly verified media. The existing operating system should not be running while the installer USB is being used, so it generally cannot modify the installer. Afterward, reinstall from a trusted source rather than attempting to clean the old system.

The concern is the computer being reinstalled, not the installer creation machine. I’m trying to keep the process offline and avoid giving a compromised operating system a chance to write back to the installation media.