Taille maximale des recherches dans Active Directory
Vérifié avec Windows 11 25H2 — mis à jour le 30 juillet 2026
Pris en charge sur : Au minimum Windows 2000
Chemin dans la console GPO
Configuration utilisateur\Modèles d'administration\Bureau\Active Directory Description
Spécifie le nombre maximal d’objets que le système affiche en réponse à une commande d’exploration ou de recherche dans Active Directory. Ce paramètre affecte tous les affichages d’exploration associés à Active Directory, tels que ceux des composants Utilisateurs et groupes locaux et Utilisateurs et ordinateurs Active Directory, ainsi que les boîtes de dialogue utilisées pour définir les autorisations sur les objets Utilisateur ou Groupe dans Active Directory. Si vous activez ce paramètre, vous pouvez utiliser la case « Nombre d’objets renvoyés » pour limiter la réponse aux recherches dans Active Directory. Si vous désactivez ce paramètre ou ne le configurez pas, le système affiche jusqu’à 10 000 objets. Ceci consomme environ 2 Mo de mémoire ou d’espace disque. Ce paramètre est conçu pour protéger le réseau et le contrôleur de domaine des effets qu’auraient des recherches trop vastes.
Registre
Software\Policies\Microsoft\Windows\Directory UI MDM / Intune (CSP)
./User/Vendor/MSFT/Policy/Config/ADMX_Desktop/AD_QueryLimit Documentation Microsoft Learn Données de correspondance : Microsoft Learn (CC BY 4.0)
Générateur d'exports
BETAConfigurez l'état, la portée et les options, puis générez les sorties .reg, PowerShell, Intune et SCCM — ou ajoutez le paramètre à une collection multi-paramètres.
Ces exports écrivent le registre — ce n'est pas une GPO managée. ⓘ
Fichier .reg
Windows Registry Editor Version 5.00
; Exported from gporais.com
; Policy: Taille maximale des recherches dans Active Directory
; State: Enabled
; Supported on: Au minimum Windows 2000
[HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Directory UI]
"QueryLimit"=dword:00002710 Autres formats (PowerShell, Intune, SCCM)
PowerShell
# Exported from gporais.com
# Policy: Taille maximale des recherches dans Active Directory
# State: Enabled
# Supported on: Au minimum Windows 2000
# Warning: In SYSTEM context (the Intune default), HKCU targets the SYSTEM profile. Run this script using the logged-on credentials.
$path = 'HKCU:\Software\Policies\Microsoft\Windows\Directory UI'
New-Item -Path $path -Force | Out-Null
Set-ItemProperty -Path $path -Name 'QueryLimit' -Value 10000 -Type DWord Intune XML
OMA-URI: ./User/Vendor/MSFT/Policy/Config/ADMX_Desktop/AD_QueryLimit
Data type: String
Value:
<enabled/>
<data id="AD_QueryLimit_Box" value="10000"/> Intune Remediation
# === Detection script ===
# Exported from gporais.com
# Policy: Taille maximale des recherches dans Active Directory
# State: Enabled
# Supported on: Au minimum Windows 2000
# Warning: In SYSTEM context (the Intune default), HKCU targets the SYSTEM profile. Run this script using the logged-on credentials.
function Test-RegistryValue {
param(
[Parameter(Mandatory = $true)][string]$Path,
[Parameter(Mandatory = $true)][string]$Name,
[object]$Expected,
[ValidateSet('String', 'DWord', 'MultiString')][string]$Kind = 'String',
[switch]$Absent
)
try {
$item = Get-ItemProperty -LiteralPath $Path -Name $Name -ErrorAction Stop
} catch {
return $Absent.IsPresent
}
if ($Absent.IsPresent) { return $false }
$actual = $item.$Name
if ($Kind -eq 'DWord') { return ([int64]$actual) -eq ([int64]$Expected) }
if ($Kind -eq 'MultiString') {
$actualValues = @($actual)
$expectedValues = @($Expected)
if ($actualValues.Count -ne $expectedValues.Count) { return $false }
for ($i = 0; $i -lt $expectedValues.Count; $i++) {
if ([string]$actualValues[$i] -ne [string]$expectedValues[$i]) { return $false }
}
return $true
}
return [string]$actual -eq [string]$Expected
}
$checks = @(
(Test-RegistryValue -Path 'HKCU:\Software\Policies\Microsoft\Windows\Directory UI' -Name 'QueryLimit' -Expected 10000 -Kind DWord)
)
if ($checks -notcontains $false) {
Write-Output 'Compliant'
exit 0
}
Write-Output 'Non-compliant'
exit 1
# === Remediation script ===
# Exported from gporais.com
# Policy: Taille maximale des recherches dans Active Directory
# State: Enabled
# Supported on: Au minimum Windows 2000
# Warning: In SYSTEM context (the Intune default), HKCU targets the SYSTEM profile. Run this script using the logged-on credentials.
$path = 'HKCU:\Software\Policies\Microsoft\Windows\Directory UI'
New-Item -Path $path -Force | Out-Null
Set-ItemProperty -Path $path -Name 'QueryLimit' -Value 10000 -Type DWord Scripts SCCM
# Exported from gporais.com
# Policy: Taille maximale des recherches dans Active Directory
# State: Enabled
# Supported on: Au minimum Windows 2000
# SCCM Configuration Item guidance:
# Create a Configuration Item of type "Setting: Script".
# Discovery script: use the Detection script below.
# Remediation script: use the Remediation script below.
# Compliance rule: the Discovery script output equals 'Compliant'.
# === Detection script ===
# Exported from gporais.com
# Policy: Taille maximale des recherches dans Active Directory
# State: Enabled
# Supported on: Au minimum Windows 2000
# Warning: In SYSTEM context (the Intune default), HKCU targets the SYSTEM profile. Run this script using the logged-on credentials.
function Test-RegistryValue {
param(
[Parameter(Mandatory = $true)][string]$Path,
[Parameter(Mandatory = $true)][string]$Name,
[object]$Expected,
[ValidateSet('String', 'DWord', 'MultiString')][string]$Kind = 'String',
[switch]$Absent
)
try {
$item = Get-ItemProperty -LiteralPath $Path -Name $Name -ErrorAction Stop
} catch {
return $Absent.IsPresent
}
if ($Absent.IsPresent) { return $false }
$actual = $item.$Name
if ($Kind -eq 'DWord') { return ([int64]$actual) -eq ([int64]$Expected) }
if ($Kind -eq 'MultiString') {
$actualValues = @($actual)
$expectedValues = @($Expected)
if ($actualValues.Count -ne $expectedValues.Count) { return $false }
for ($i = 0; $i -lt $expectedValues.Count; $i++) {
if ([string]$actualValues[$i] -ne [string]$expectedValues[$i]) { return $false }
}
return $true
}
return [string]$actual -eq [string]$Expected
}
$checks = @(
(Test-RegistryValue -Path 'HKCU:\Software\Policies\Microsoft\Windows\Directory UI' -Name 'QueryLimit' -Expected 10000 -Kind DWord)
)
if ($checks -notcontains $false) {
Write-Output 'Compliant'
exit 0
}
Write-Output 'Non-compliant'
exit 1
# === Remediation script ===
# Exported from gporais.com
# Policy: Taille maximale des recherches dans Active Directory
# State: Enabled
# Supported on: Au minimum Windows 2000
# Warning: In SYSTEM context (the Intune default), HKCU targets the SYSTEM profile. Run this script using the logged-on credentials.
$path = 'HKCU:\Software\Policies\Microsoft\Windows\Directory UI'
New-Item -Path $path -Force | Out-Null
Set-ItemProperty -Path $path -Name 'QueryLimit' -Value 10000 -Type DWord Vous construisez une collection multi-paramètres ? Ajoutez ce paramètre et générez des exports combinés (.reg, PowerShell, GPO).