Un mot de passe protège l’écran de veille
Vérifié avec Windows 11 25H2 — mis à jour le 30 juillet 2026
Pris en charge sur : Au minimum Windows 2000 Service Pack 1
Chemin dans la console GPO
Configuration utilisateur\Modèles d'administration\Panneau de configuration\Personnalisation Description
Détermine si les écrans de veille utilisés sur l’ordinateur sont protégés par un mot de passe. Si vous activez ce paramètre, tous les écrans de veille sont protégés par un mot de passe. Si vous désactivez ce paramètre, la protection par mot de passe ne peut être configurée sur aucun écran de veille. Ce paramètre désactive également la case à cocher Protégé par mot de passe dans la boîte de dialogue Écran de veille de l’application Personnalisation ou Affichage du Panneau de configuration, ce qui empêche les utilisateurs de modifier le paramètre de protection par mot de passe. Si vous ne configurez pas ce paramètre, les utilisateurs peuvent choisir s’ils souhaitent ou non activer la protection par mot de passe sur chaque écran de veille. Pour vous assurer qu’un ordinateur sera protégé par un mot de passe, activez le paramètre Activer l’écran de veille et spécifiez un délai d’attente à l’aide du paramètre Dépassement du délai d’expiration de l’écran de veille. Remarque : pour supprimer la boîte de dialogue Écran de veille, utilisez le paramètre Empêcher de modifier l’écran de veille.
Registre
Software\Policies\Microsoft\Windows\Control Panel\Desktop Nom de valeur : ScreenSaverIsSecure
Activé : ScreenSaverIsSecure = 1
Désactivé : ScreenSaverIsSecure = 0
MDM / Intune (CSP)
./User/Vendor/MSFT/Policy/Config/ADMX_ControlPanelDisplay/CPL_Personalization_ScreenSaverIsSecure Documentation Microsoft Learn Données de correspondance : Microsoft Learn (CC BY 4.0)
Générateur d'exports
BETAConfigurez l'état, la portée et les options, puis générez les sorties .reg, PowerShell, Intune et SCCM — ou ajoutez le paramètre à une collection multi-paramètres.
Ces exports écrivent le registre — ce n'est pas une GPO managée. ⓘ
Fichier .reg
Windows Registry Editor Version 5.00
; Exported from gporais.com
; Policy: Un mot de passe protège l’écran de veille
; State: Enabled
; Supported on: Au minimum Windows 2000 Service Pack 1
[HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Control Panel\Desktop]
"ScreenSaverIsSecure"="1" Autres formats (PowerShell, Intune, SCCM)
PowerShell
# Exported from gporais.com
# Policy: Un mot de passe protège l’écran de veille
# State: Enabled
# Supported on: Au minimum Windows 2000 Service Pack 1
# Warning: In SYSTEM context (the Intune default), HKCU targets the SYSTEM profile. Run this script using the logged-on credentials.
$path = 'HKCU:\Software\Policies\Microsoft\Windows\Control Panel\Desktop'
New-Item -Path $path -Force | Out-Null
Set-ItemProperty -Path $path -Name 'ScreenSaverIsSecure' -Value '1' -Type String Intune XML
OMA-URI: ./User/Vendor/MSFT/Policy/Config/ADMX_ControlPanelDisplay/CPL_Personalization_ScreenSaverIsSecure
Data type: String
Value:
<enabled/> Intune Remediation
# === Detection script ===
# Exported from gporais.com
# Policy: Un mot de passe protège l’écran de veille
# State: Enabled
# Supported on: Au minimum Windows 2000 Service Pack 1
# Warning: In SYSTEM context (the Intune default), HKCU targets the SYSTEM profile. Run this script using the logged-on credentials.
function Test-RegistryValue {
param(
[Parameter(Mandatory = $true)][string]$Path,
[Parameter(Mandatory = $true)][string]$Name,
[object]$Expected,
[ValidateSet('String', 'DWord', 'MultiString')][string]$Kind = 'String',
[switch]$Absent
)
try {
$item = Get-ItemProperty -LiteralPath $Path -Name $Name -ErrorAction Stop
} catch {
return $Absent.IsPresent
}
if ($Absent.IsPresent) { return $false }
$actual = $item.$Name
if ($Kind -eq 'DWord') { return ([int64]$actual) -eq ([int64]$Expected) }
if ($Kind -eq 'MultiString') {
$actualValues = @($actual)
$expectedValues = @($Expected)
if ($actualValues.Count -ne $expectedValues.Count) { return $false }
for ($i = 0; $i -lt $expectedValues.Count; $i++) {
if ([string]$actualValues[$i] -ne [string]$expectedValues[$i]) { return $false }
}
return $true
}
return [string]$actual -eq [string]$Expected
}
$checks = @(
(Test-RegistryValue -Path 'HKCU:\Software\Policies\Microsoft\Windows\Control Panel\Desktop' -Name 'ScreenSaverIsSecure' -Expected '1' -Kind String)
)
if ($checks -notcontains $false) {
Write-Output 'Compliant'
exit 0
}
Write-Output 'Non-compliant'
exit 1
# === Remediation script ===
# Exported from gporais.com
# Policy: Un mot de passe protège l’écran de veille
# State: Enabled
# Supported on: Au minimum Windows 2000 Service Pack 1
# Warning: In SYSTEM context (the Intune default), HKCU targets the SYSTEM profile. Run this script using the logged-on credentials.
$path = 'HKCU:\Software\Policies\Microsoft\Windows\Control Panel\Desktop'
New-Item -Path $path -Force | Out-Null
Set-ItemProperty -Path $path -Name 'ScreenSaverIsSecure' -Value '1' -Type String Scripts SCCM
# Exported from gporais.com
# Policy: Un mot de passe protège l’écran de veille
# State: Enabled
# Supported on: Au minimum Windows 2000 Service Pack 1
# SCCM Configuration Item guidance:
# Create a Configuration Item of type "Setting: Script".
# Discovery script: use the Detection script below.
# Remediation script: use the Remediation script below.
# Compliance rule: the Discovery script output equals 'Compliant'.
# === Detection script ===
# Exported from gporais.com
# Policy: Un mot de passe protège l’écran de veille
# State: Enabled
# Supported on: Au minimum Windows 2000 Service Pack 1
# Warning: In SYSTEM context (the Intune default), HKCU targets the SYSTEM profile. Run this script using the logged-on credentials.
function Test-RegistryValue {
param(
[Parameter(Mandatory = $true)][string]$Path,
[Parameter(Mandatory = $true)][string]$Name,
[object]$Expected,
[ValidateSet('String', 'DWord', 'MultiString')][string]$Kind = 'String',
[switch]$Absent
)
try {
$item = Get-ItemProperty -LiteralPath $Path -Name $Name -ErrorAction Stop
} catch {
return $Absent.IsPresent
}
if ($Absent.IsPresent) { return $false }
$actual = $item.$Name
if ($Kind -eq 'DWord') { return ([int64]$actual) -eq ([int64]$Expected) }
if ($Kind -eq 'MultiString') {
$actualValues = @($actual)
$expectedValues = @($Expected)
if ($actualValues.Count -ne $expectedValues.Count) { return $false }
for ($i = 0; $i -lt $expectedValues.Count; $i++) {
if ([string]$actualValues[$i] -ne [string]$expectedValues[$i]) { return $false }
}
return $true
}
return [string]$actual -eq [string]$Expected
}
$checks = @(
(Test-RegistryValue -Path 'HKCU:\Software\Policies\Microsoft\Windows\Control Panel\Desktop' -Name 'ScreenSaverIsSecure' -Expected '1' -Kind String)
)
if ($checks -notcontains $false) {
Write-Output 'Compliant'
exit 0
}
Write-Output 'Non-compliant'
exit 1
# === Remediation script ===
# Exported from gporais.com
# Policy: Un mot de passe protège l’écran de veille
# State: Enabled
# Supported on: Au minimum Windows 2000 Service Pack 1
# Warning: In SYSTEM context (the Intune default), HKCU targets the SYSTEM profile. Run this script using the logged-on credentials.
$path = 'HKCU:\Software\Policies\Microsoft\Windows\Control Panel\Desktop'
New-Item -Path $path -Force | Out-Null
Set-ItemProperty -Path $path -Name 'ScreenSaverIsSecure' -Value '1' -Type String Vous construisez une collection multi-paramètres ? Ajoutez ce paramètre et générez des exports combinés (.reg, PowerShell, GPO).