fr-FR laps-legacy computer

Do not allow password expiration time longer than required by policy

Vérifié avec Microsoft LAPS (legacy) 6.2 — mis à jour le 15 septembre 2026 Pris en charge sur : At least Microsoft Windows Vista or Windows Server 2003 family

Microsoft LAPS (legacy) 6.2

Obsolète : ce paramètre appartient à l’ancien Microsoft LAPS, remplacé par Windows LAPS intégré à Windows. Équivalent Windows LAPS : N’autorisez pas le délai d’expiration du mot de passe plus longtemps que ce qui est requis par la stratégie.

Chemin dans la console GPO

Configuration ordinateur\Modèles d'administration\LAPS

Registre

HKLM Software\Policies\Microsoft Services\AdmPwd
Nom de valeur :
PwdExpirationProtectionEnabled

MDM / Intune (CSP)

./Device/Vendor/MSFT/Policy/Config/ADMX_AdmPwd/POL_AdmPwd_DontAllowPwdExpirationBehindPolicy
Appareil Depuis Windows 10, version 2004 with KB5005101 [10.0.19041.1202] and later | Windows 10, version 20H2 with KB5005101 [10.0.19042.1202] and later | Windows 10, version 21H1 with KB5005101 [10.0.19043.1202] and later | Windows 11, version 21H2 [10.0.22000] and later Mapping officiel (Microsoft Learn)

Documentation Microsoft Learn Données de correspondance : Microsoft Learn (CC BY 4.0)

Description

When you enable this setting, planned password expiration longer than password age dictated by "Password Settings" policy is NOT allowed. When such expiration is detected, password is changed immediately and password expiration is set according to policy. When you disable or not configure this setting, password expiration time may be longer than required by "Password Settings" policy.

Générateur d'exports

BETA

Configurez l'état, la portée et les options, puis générez les sorties .reg, PowerShell, Intune et SCCM — ou ajoutez le paramètre à une collection multi-paramètres.

Ces exports écrivent le registre — ce n'est pas une GPO managée. ⓘ

Fichier .reg

Windows Registry Editor Version 5.00

; Exported from gporais.com
; Policy: Do not allow password expiration time longer than required by policy
; State: Enabled
; Supported on: At least Microsoft Windows Vista or Windows Server 2003 family

[HKEY_LOCAL_MACHINE\Software\Policies\Microsoft Services\AdmPwd]
"PwdExpirationProtectionEnabled"=dword:00000001
Autres formats (PowerShell, Intune, SCCM)

PowerShell

# Exported from gporais.com
# Policy: Do not allow password expiration time longer than required by policy
# State: Enabled
# Supported on: At least Microsoft Windows Vista or Windows Server 2003 family

$path = 'HKLM:\Software\Policies\Microsoft Services\AdmPwd'
New-Item -Path $path -Force | Out-Null
Set-ItemProperty -Path $path -Name 'PwdExpirationProtectionEnabled' -Value 1 -Type DWord

Vous construisez une collection multi-paramètres ? Ajoutez ce paramètre et générez des exports combinés (.reg, PowerShell, GPO).

Ouvrir le Builder

Intégrer cette GPO sur votre site

Contenu à intégrer
Thème

Ajoute une ligne de script : le thème suit l’apparence de votre site et la hauteur s’ajuste au contenu. Si votre site bloque les scripts, l’intégration suit le thème du système du visiteur.

Aperçu