Utiliser un ensemble commun de paramètres Exploit Protection
Vérifié avec Windows 11 25H2 — mis à jour le 30 juillet 2026
Pris en charge sur : Windows Server 2016, Windows 10 version 1709 ou versions supérieures
Chemin dans la console GPO
Configuration ordinateur\Modèles d'administration\Composants Windows\Microsoft Defender Exploit Guard\Exploit Protection Description
Spécifiez un ensemble commun de paramètres pour le système Microsoft Defender Exploit Guard et de minimisation des applications qui peuvent être appliqués à tous les points de terminaison pour lesquels ce paramètre de stratégie de groupe est configuré. Avant d’activer ce paramètre, vous devez remplir certaines conditions préalables : - Configurez manuellement les paramètres de minimisation des applications et du système d’un appareil à l’aide de l’applet de commande PowerShell « Set-ProcessMitigation », de l’applet de commande PowerShell « ConvertTo-ProcessMitigationPolicy », ou directement dans Sécurité Windows. - Générez un fichier XML avec les paramètres de l’appareil en exécutant l’applet de commande PowerShell « Get-ProcessMitigation » ou en utilisant le bouton Exporter en bas de la zone Exploit Protection dans Sécurité Windows. - Placez le fichier XML généré dans un chemin d’accès partagé ou local. Remarque : les points de terminaison pour lesquels ce paramètre de stratégie de groupe est défini sur activé doivent pouvoir accéder au fichier XML ; dans le cas contraire, les paramètres ne seront pas appliqués. Autorisé Spécifiez l’emplacement du fichier XML dans la section Options. Vous pouvez utiliser un chemin d’accès local (ou mappé), un chemin d’accès UNC ou une URL, comme suit : - C:\MitigationSettings\Config.XML - \\Server\Share\Config.xml - https://localhost:8080/Config.xml Les paramètres du fichier XML seront appliqués au point de terminaison. Désactivé Les paramètres communs ne seront pas appliqués, et les paramètres configurés en local seront utilisés à la place. Non configuré Identique à désactivé.
Registre
Software\Policies\Microsoft\Windows Defender ExploitGuard\Exploit Protection MDM / Intune (CSP)
./Device/Vendor/MSFT/Policy/Config/ExploitGuard/ExploitProtectionSettings Documentation Microsoft Learn Données de correspondance : Microsoft Learn (CC BY 4.0)
Générateur d'exports
BETAConfigurez l'état, la portée et les options, puis générez les sorties .reg, PowerShell, Intune et SCCM — ou ajoutez le paramètre à une collection multi-paramètres.
Ces exports écrivent le registre — ce n'est pas une GPO managée. ⓘ
Fichier .reg
Windows Registry Editor Version 5.00
; Exported from gporais.com
; Policy: Utiliser un ensemble commun de paramètres Exploit Protection
; State: Enabled
; Supported on: Windows Server 2016, Windows 10 version 1709 ou versions supérieures
[HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows Defender ExploitGuard\Exploit Protection]
"ExploitProtectionSettings"="" Autres formats (PowerShell, Intune, SCCM)
PowerShell
# Exported from gporais.com
# Policy: Utiliser un ensemble commun de paramètres Exploit Protection
# State: Enabled
# Supported on: Windows Server 2016, Windows 10 version 1709 ou versions supérieures
$path = 'HKLM:\Software\Policies\Microsoft\Windows Defender ExploitGuard\Exploit Protection'
New-Item -Path $path -Force | Out-Null
Set-ItemProperty -Path $path -Name 'ExploitProtectionSettings' -Value '' -Type String Intune XML
OMA-URI: ./Device/Vendor/MSFT/Policy/Config/ExploitGuard/ExploitProtectionSettings
Data type: String
Value:
<enabled/>
<data id="ExploitProtection_Name" value=""/> Intune Remediation
# === Detection script ===
# Exported from gporais.com
# Policy: Utiliser un ensemble commun de paramètres Exploit Protection
# State: Enabled
# Supported on: Windows Server 2016, Windows 10 version 1709 ou versions supérieures
function Test-RegistryValue {
param(
[Parameter(Mandatory = $true)][string]$Path,
[Parameter(Mandatory = $true)][string]$Name,
[object]$Expected,
[ValidateSet('String', 'DWord', 'MultiString')][string]$Kind = 'String',
[switch]$Absent
)
try {
$item = Get-ItemProperty -LiteralPath $Path -Name $Name -ErrorAction Stop
} catch {
return $Absent.IsPresent
}
if ($Absent.IsPresent) { return $false }
$actual = $item.$Name
if ($Kind -eq 'DWord') { return ([int64]$actual) -eq ([int64]$Expected) }
if ($Kind -eq 'MultiString') {
$actualValues = @($actual)
$expectedValues = @($Expected)
if ($actualValues.Count -ne $expectedValues.Count) { return $false }
for ($i = 0; $i -lt $expectedValues.Count; $i++) {
if ([string]$actualValues[$i] -ne [string]$expectedValues[$i]) { return $false }
}
return $true
}
return [string]$actual -eq [string]$Expected
}
$checks = @(
(Test-RegistryValue -Path 'HKLM:\Software\Policies\Microsoft\Windows Defender ExploitGuard\Exploit Protection' -Name 'ExploitProtectionSettings' -Expected '' -Kind String)
)
if ($checks -notcontains $false) {
Write-Output 'Compliant'
exit 0
}
Write-Output 'Non-compliant'
exit 1
# === Remediation script ===
# Exported from gporais.com
# Policy: Utiliser un ensemble commun de paramètres Exploit Protection
# State: Enabled
# Supported on: Windows Server 2016, Windows 10 version 1709 ou versions supérieures
$path = 'HKLM:\Software\Policies\Microsoft\Windows Defender ExploitGuard\Exploit Protection'
New-Item -Path $path -Force | Out-Null
Set-ItemProperty -Path $path -Name 'ExploitProtectionSettings' -Value '' -Type String Scripts SCCM
# Exported from gporais.com
# Policy: Utiliser un ensemble commun de paramètres Exploit Protection
# State: Enabled
# Supported on: Windows Server 2016, Windows 10 version 1709 ou versions supérieures
# SCCM Configuration Item guidance:
# Create a Configuration Item of type "Setting: Script".
# Discovery script: use the Detection script below.
# Remediation script: use the Remediation script below.
# Compliance rule: the Discovery script output equals 'Compliant'.
# === Detection script ===
# Exported from gporais.com
# Policy: Utiliser un ensemble commun de paramètres Exploit Protection
# State: Enabled
# Supported on: Windows Server 2016, Windows 10 version 1709 ou versions supérieures
function Test-RegistryValue {
param(
[Parameter(Mandatory = $true)][string]$Path,
[Parameter(Mandatory = $true)][string]$Name,
[object]$Expected,
[ValidateSet('String', 'DWord', 'MultiString')][string]$Kind = 'String',
[switch]$Absent
)
try {
$item = Get-ItemProperty -LiteralPath $Path -Name $Name -ErrorAction Stop
} catch {
return $Absent.IsPresent
}
if ($Absent.IsPresent) { return $false }
$actual = $item.$Name
if ($Kind -eq 'DWord') { return ([int64]$actual) -eq ([int64]$Expected) }
if ($Kind -eq 'MultiString') {
$actualValues = @($actual)
$expectedValues = @($Expected)
if ($actualValues.Count -ne $expectedValues.Count) { return $false }
for ($i = 0; $i -lt $expectedValues.Count; $i++) {
if ([string]$actualValues[$i] -ne [string]$expectedValues[$i]) { return $false }
}
return $true
}
return [string]$actual -eq [string]$Expected
}
$checks = @(
(Test-RegistryValue -Path 'HKLM:\Software\Policies\Microsoft\Windows Defender ExploitGuard\Exploit Protection' -Name 'ExploitProtectionSettings' -Expected '' -Kind String)
)
if ($checks -notcontains $false) {
Write-Output 'Compliant'
exit 0
}
Write-Output 'Non-compliant'
exit 1
# === Remediation script ===
# Exported from gporais.com
# Policy: Utiliser un ensemble commun de paramètres Exploit Protection
# State: Enabled
# Supported on: Windows Server 2016, Windows 10 version 1709 ou versions supérieures
$path = 'HKLM:\Software\Policies\Microsoft\Windows Defender ExploitGuard\Exploit Protection'
New-Item -Path $path -Force | Out-Null
Set-ItemProperty -Path $path -Name 'ExploitProtectionSettings' -Value '' -Type String Vous construisez une collection multi-paramètres ? Ajoutez ce paramètre et générez des exports combinés (.reg, PowerShell, GPO).