Configurer les paramètres du Presse-papiers de Microsoft Defender Application Guard
Vérifié avec Windows 11 25H2 — mis à jour le 16 juillet 2026
Pris en charge sur : Microsoft Edge sur Windows 10 Entreprise ou Windows 10 Éducation avec Microsoft Defender Application Guard en mode Entreprise
Chemin dans la console GPO
Configuration ordinateur\Modèles d'administration\Composants Windows\Microsoft Defender Application Guard Description
Ce paramètre de stratégie vous permet de déterminer comment le Presse-papiers se comporte dans Microsoft Defender Application Guard. Si vous activez ce paramètre, vous devez choisir parmi les comportements suivants : - Désactiver complètement la fonctionnalité de Presse-papiers entre l'hôte et Application Guard - Permettre au Presse-papiers de copier du contenu depuis Application Guard vers l'hôte - Permettre au Presse-Papiers de copier du contenu depuis l'hôte vers Application Guard. REMARQUE Nous vous recommandons de ne pas autoriser la copie depuis l'hôte vers Application Guard. Si vous activez cette fonctionnalité, une session potentiellement compromise d'Application Guard aura accès au Presse-papiers de le périphérique hôte et au contenu de ce dernier. Si vous choisissez d'activer la copie, vous pouvez également choisir le type de contenu qui peut être copié en utilisant les options de contenu : - 1. Autoriser la copie de texte. - 2. Autoriser la copie d'images. - 3. Autoriser la copie de texte et d'images. Si vous désactivez ce paramètre ou si vous ne le configurez pas, toutes les fonctionnalités de Presse-papiers seront désactivées dans Application Guard.
Registre
SOFTWARE\Policies\Microsoft\AppHVSI Générateur d'exports
BETAConfigurez l'état, la portée et les options, puis générez les sorties .reg, PowerShell, Intune et SCCM — ou ajoutez le paramètre à une collection multi-paramètres.
Ces exports écrivent le registre — ce n'est pas une GPO managée. ⓘ
Fichier .reg
Windows Registry Editor Version 5.00
; Exported from gporais.com
; Policy: Configurer les paramètres du Presse-papiers de Microsoft Defender Application Guard
; State: Enabled
; Supported on: Microsoft Edge sur Windows 10 Entreprise ou Windows 10 Éducation avec Microsoft Defender Application Guard en mode Entreprise
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\AppHVSI]
"AppHVSIClipboardSettings"=dword:00000000
"AppHVSIClipboardFileType"=dword:00000001 Autres formats (PowerShell, Intune, SCCM)
PowerShell
# Exported from gporais.com
# Policy: Configurer les paramètres du Presse-papiers de Microsoft Defender Application Guard
# State: Enabled
# Supported on: Microsoft Edge sur Windows 10 Entreprise ou Windows 10 Éducation avec Microsoft Defender Application Guard en mode Entreprise
$path = 'HKLM:\SOFTWARE\Policies\Microsoft\AppHVSI'
New-Item -Path $path -Force | Out-Null
Set-ItemProperty -Path $path -Name 'AppHVSIClipboardSettings' -Value 0 -Type DWord
Set-ItemProperty -Path $path -Name 'AppHVSIClipboardFileType' -Value 1 -Type DWord Intune XML
Aucune correspondance directe Policy CSP / OMA-URI pour cette stratégie. Utilisez l'onglet Intune Remediation, ou importez l'ADMX dans Intune. Intune Remediation
# === Detection script ===
# Exported from gporais.com
# Policy: Configurer les paramètres du Presse-papiers de Microsoft Defender Application Guard
# State: Enabled
# Supported on: Microsoft Edge sur Windows 10 Entreprise ou Windows 10 Éducation avec Microsoft Defender Application Guard en mode Entreprise
function Test-RegistryValue {
param(
[Parameter(Mandatory = $true)][string]$Path,
[Parameter(Mandatory = $true)][string]$Name,
[object]$Expected,
[ValidateSet('String', 'DWord', 'MultiString')][string]$Kind = 'String',
[switch]$Absent
)
try {
$item = Get-ItemProperty -LiteralPath $Path -Name $Name -ErrorAction Stop
} catch {
return $Absent.IsPresent
}
if ($Absent.IsPresent) { return $false }
$actual = $item.$Name
if ($Kind -eq 'DWord') { return ([int64]$actual) -eq ([int64]$Expected) }
if ($Kind -eq 'MultiString') {
$actualValues = @($actual)
$expectedValues = @($Expected)
if ($actualValues.Count -ne $expectedValues.Count) { return $false }
for ($i = 0; $i -lt $expectedValues.Count; $i++) {
if ([string]$actualValues[$i] -ne [string]$expectedValues[$i]) { return $false }
}
return $true
}
return [string]$actual -eq [string]$Expected
}
$checks = @(
(Test-RegistryValue -Path 'HKLM:\SOFTWARE\Policies\Microsoft\AppHVSI' -Name 'AppHVSIClipboardSettings' -Expected 0 -Kind DWord)
(Test-RegistryValue -Path 'HKLM:\SOFTWARE\Policies\Microsoft\AppHVSI' -Name 'AppHVSIClipboardFileType' -Expected 1 -Kind DWord)
)
if ($checks -notcontains $false) {
Write-Output 'Compliant'
exit 0
}
Write-Output 'Non-compliant'
exit 1
# === Remediation script ===
# Exported from gporais.com
# Policy: Configurer les paramètres du Presse-papiers de Microsoft Defender Application Guard
# State: Enabled
# Supported on: Microsoft Edge sur Windows 10 Entreprise ou Windows 10 Éducation avec Microsoft Defender Application Guard en mode Entreprise
$path = 'HKLM:\SOFTWARE\Policies\Microsoft\AppHVSI'
New-Item -Path $path -Force | Out-Null
Set-ItemProperty -Path $path -Name 'AppHVSIClipboardSettings' -Value 0 -Type DWord
Set-ItemProperty -Path $path -Name 'AppHVSIClipboardFileType' -Value 1 -Type DWord Scripts SCCM
# Exported from gporais.com
# Policy: Configurer les paramètres du Presse-papiers de Microsoft Defender Application Guard
# State: Enabled
# Supported on: Microsoft Edge sur Windows 10 Entreprise ou Windows 10 Éducation avec Microsoft Defender Application Guard en mode Entreprise
# SCCM Configuration Item guidance:
# Create a Configuration Item of type "Setting: Script".
# Discovery script: use the Detection script below.
# Remediation script: use the Remediation script below.
# Compliance rule: the Discovery script output equals 'Compliant'.
# === Detection script ===
# Exported from gporais.com
# Policy: Configurer les paramètres du Presse-papiers de Microsoft Defender Application Guard
# State: Enabled
# Supported on: Microsoft Edge sur Windows 10 Entreprise ou Windows 10 Éducation avec Microsoft Defender Application Guard en mode Entreprise
function Test-RegistryValue {
param(
[Parameter(Mandatory = $true)][string]$Path,
[Parameter(Mandatory = $true)][string]$Name,
[object]$Expected,
[ValidateSet('String', 'DWord', 'MultiString')][string]$Kind = 'String',
[switch]$Absent
)
try {
$item = Get-ItemProperty -LiteralPath $Path -Name $Name -ErrorAction Stop
} catch {
return $Absent.IsPresent
}
if ($Absent.IsPresent) { return $false }
$actual = $item.$Name
if ($Kind -eq 'DWord') { return ([int64]$actual) -eq ([int64]$Expected) }
if ($Kind -eq 'MultiString') {
$actualValues = @($actual)
$expectedValues = @($Expected)
if ($actualValues.Count -ne $expectedValues.Count) { return $false }
for ($i = 0; $i -lt $expectedValues.Count; $i++) {
if ([string]$actualValues[$i] -ne [string]$expectedValues[$i]) { return $false }
}
return $true
}
return [string]$actual -eq [string]$Expected
}
$checks = @(
(Test-RegistryValue -Path 'HKLM:\SOFTWARE\Policies\Microsoft\AppHVSI' -Name 'AppHVSIClipboardSettings' -Expected 0 -Kind DWord)
(Test-RegistryValue -Path 'HKLM:\SOFTWARE\Policies\Microsoft\AppHVSI' -Name 'AppHVSIClipboardFileType' -Expected 1 -Kind DWord)
)
if ($checks -notcontains $false) {
Write-Output 'Compliant'
exit 0
}
Write-Output 'Non-compliant'
exit 1
# === Remediation script ===
# Exported from gporais.com
# Policy: Configurer les paramètres du Presse-papiers de Microsoft Defender Application Guard
# State: Enabled
# Supported on: Microsoft Edge sur Windows 10 Entreprise ou Windows 10 Éducation avec Microsoft Defender Application Guard en mode Entreprise
$path = 'HKLM:\SOFTWARE\Policies\Microsoft\AppHVSI'
New-Item -Path $path -Force | Out-Null
Set-ItemProperty -Path $path -Name 'AppHVSIClipboardSettings' -Value 0 -Type DWord
Set-ItemProperty -Path $path -Name 'AppHVSIClipboardFileType' -Value 1 -Type DWord Vous construisez une collection multi-paramètres ? Ajoutez ce paramètre et générez des exports combinés (.reg, PowerShell, GPO).