Définir les domaines autorisés pour l’authentification HTTPS dans l’installation de streaming MSIX
Vérifié avec Windows 11 25H2 — mis à jour le 30 juillet 2026
Pris en charge sur : Au moins Windows 11 version 22H2
Chemin dans la console GPO
Configuration ordinateur\Modèles d'administration\Composants Windows\Déploiement de package Appx Description
Ce paramètre de stratégie détermine si un jeton OAuth Deid doit être inclus dans les communications HTTPS vers un nom de domaine complet spécifié pour effectuer une installation de streaming MSIX. Si vous activez ce paramètre de stratégie, les communications HTTPS vers les domaines complets prédéfinis incorporent le jeton OAuth De l’utilisateur lors d’une installation MSIX de streaming. La valeur fournie est une expression régulière (script ECMA) qui sera utilisée pour établir une correspondance avec le domaine complet en majuscules de l’URL. Si vous désactivez ou ne configurez pas ce paramètre de stratégie, le jeton OAuth DeId de l’utilisateur est partagé uniquement avec les domaines configurés par défaut.
Registre
Software\Policies\Microsoft\Windows\Appx MDM / Intune (CSP)
./Device/Vendor/MSFT/Policy/Config/ApplicationManagement/ConfigureMSIXAuthenticationAuthorizedDomains Documentation Microsoft Learn Données de correspondance : Microsoft Learn (CC BY 4.0)
Générateur d'exports
BETAConfigurez l'état, la portée et les options, puis générez les sorties .reg, PowerShell, Intune et SCCM — ou ajoutez le paramètre à une collection multi-paramètres.
Ces exports écrivent le registre — ce n'est pas une GPO managée. ⓘ
Fichier .reg
Windows Registry Editor Version 5.00
; Exported from gporais.com
; Policy: Définir les domaines autorisés pour l’authentification HTTPS dans l’installation de streaming MSIX
; State: Enabled
; Supported on: Au moins Windows 11 version 22H2
[HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\Appx]
"MSIXAuthenticationAuthorizedDomains"="" Autres formats (PowerShell, Intune, SCCM)
PowerShell
# Exported from gporais.com
# Policy: Définir les domaines autorisés pour l’authentification HTTPS dans l’installation de streaming MSIX
# State: Enabled
# Supported on: Au moins Windows 11 version 22H2
$path = 'HKLM:\Software\Policies\Microsoft\Windows\Appx'
New-Item -Path $path -Force | Out-Null
Set-ItemProperty -Path $path -Name 'MSIXAuthenticationAuthorizedDomains' -Value '' -Type String Intune XML
OMA-URI: ./Device/Vendor/MSFT/Policy/Config/ApplicationManagement/ConfigureMSIXAuthenticationAuthorizedDomains
Data type: String
Value:
<enabled/>
<data id="ConfigureMSIXAuthenticationAuthorizedDomains" value=""/> Intune Remediation
# === Detection script ===
# Exported from gporais.com
# Policy: Définir les domaines autorisés pour l’authentification HTTPS dans l’installation de streaming MSIX
# State: Enabled
# Supported on: Au moins Windows 11 version 22H2
function Test-RegistryValue {
param(
[Parameter(Mandatory = $true)][string]$Path,
[Parameter(Mandatory = $true)][string]$Name,
[object]$Expected,
[ValidateSet('String', 'DWord', 'MultiString')][string]$Kind = 'String',
[switch]$Absent
)
try {
$item = Get-ItemProperty -LiteralPath $Path -Name $Name -ErrorAction Stop
} catch {
return $Absent.IsPresent
}
if ($Absent.IsPresent) { return $false }
$actual = $item.$Name
if ($Kind -eq 'DWord') { return ([int64]$actual) -eq ([int64]$Expected) }
if ($Kind -eq 'MultiString') {
$actualValues = @($actual)
$expectedValues = @($Expected)
if ($actualValues.Count -ne $expectedValues.Count) { return $false }
for ($i = 0; $i -lt $expectedValues.Count; $i++) {
if ([string]$actualValues[$i] -ne [string]$expectedValues[$i]) { return $false }
}
return $true
}
return [string]$actual -eq [string]$Expected
}
$checks = @(
(Test-RegistryValue -Path 'HKLM:\Software\Policies\Microsoft\Windows\Appx' -Name 'MSIXAuthenticationAuthorizedDomains' -Expected '' -Kind String)
)
if ($checks -notcontains $false) {
Write-Output 'Compliant'
exit 0
}
Write-Output 'Non-compliant'
exit 1
# === Remediation script ===
# Exported from gporais.com
# Policy: Définir les domaines autorisés pour l’authentification HTTPS dans l’installation de streaming MSIX
# State: Enabled
# Supported on: Au moins Windows 11 version 22H2
$path = 'HKLM:\Software\Policies\Microsoft\Windows\Appx'
New-Item -Path $path -Force | Out-Null
Set-ItemProperty -Path $path -Name 'MSIXAuthenticationAuthorizedDomains' -Value '' -Type String Scripts SCCM
# Exported from gporais.com
# Policy: Définir les domaines autorisés pour l’authentification HTTPS dans l’installation de streaming MSIX
# State: Enabled
# Supported on: Au moins Windows 11 version 22H2
# SCCM Configuration Item guidance:
# Create a Configuration Item of type "Setting: Script".
# Discovery script: use the Detection script below.
# Remediation script: use the Remediation script below.
# Compliance rule: the Discovery script output equals 'Compliant'.
# === Detection script ===
# Exported from gporais.com
# Policy: Définir les domaines autorisés pour l’authentification HTTPS dans l’installation de streaming MSIX
# State: Enabled
# Supported on: Au moins Windows 11 version 22H2
function Test-RegistryValue {
param(
[Parameter(Mandatory = $true)][string]$Path,
[Parameter(Mandatory = $true)][string]$Name,
[object]$Expected,
[ValidateSet('String', 'DWord', 'MultiString')][string]$Kind = 'String',
[switch]$Absent
)
try {
$item = Get-ItemProperty -LiteralPath $Path -Name $Name -ErrorAction Stop
} catch {
return $Absent.IsPresent
}
if ($Absent.IsPresent) { return $false }
$actual = $item.$Name
if ($Kind -eq 'DWord') { return ([int64]$actual) -eq ([int64]$Expected) }
if ($Kind -eq 'MultiString') {
$actualValues = @($actual)
$expectedValues = @($Expected)
if ($actualValues.Count -ne $expectedValues.Count) { return $false }
for ($i = 0; $i -lt $expectedValues.Count; $i++) {
if ([string]$actualValues[$i] -ne [string]$expectedValues[$i]) { return $false }
}
return $true
}
return [string]$actual -eq [string]$Expected
}
$checks = @(
(Test-RegistryValue -Path 'HKLM:\Software\Policies\Microsoft\Windows\Appx' -Name 'MSIXAuthenticationAuthorizedDomains' -Expected '' -Kind String)
)
if ($checks -notcontains $false) {
Write-Output 'Compliant'
exit 0
}
Write-Output 'Non-compliant'
exit 1
# === Remediation script ===
# Exported from gporais.com
# Policy: Définir les domaines autorisés pour l’authentification HTTPS dans l’installation de streaming MSIX
# State: Enabled
# Supported on: Au moins Windows 11 version 22H2
$path = 'HKLM:\Software\Policies\Microsoft\Windows\Appx'
New-Item -Path $path -Force | Out-Null
Set-ItemProperty -Path $path -Name 'MSIXAuthenticationAuthorizedDomains' -Value '' -Type String Vous construisez une collection multi-paramètres ? Ajoutez ce paramètre et générez des exports combinés (.reg, PowerShell, GPO).