Désactiver le blocage des contrôles ActiveX obsolètes par Internet Explorer sur certains domaines
Vérifié avec Windows 11 25H2 — mis à jour le 30 juillet 2026
Pris en charge sur : Au moins Internet Explorer 8.0
Chemin dans la console GPO
Configuration ordinateur\Modèles d'administration\Composants Windows\Internet Explorer\Fonctionnalités de sécurité\Gestion des modules complémentaires Configuration utilisateur\Modèles d'administration\Composants Windows\Internet Explorer\Fonctionnalités de sécurité\Gestion des modules complémentaires Description
Ce paramètre de stratégie vous permet de gérer la liste des domaines sur lesquels Internet Explorer ne bloquera plus les contrôles ActiveX obsolètes. Les contrôles ActiveX absolètes ne sont jamais bloqués dans la Zone Intranet. Si vous activez ce paramètre de stratégie, vous pouvez entrer une liste personnalisée de domaines dont les contrôles ActiveX absolètes ne seront pas bloqués dans Internet Explorer. Chaque entrée de domaine doit être formatée de l'une des trois manières suivantes : 1. « domain.name.TLD ». Par exemple, si vous souhaitez inclure *.contoso.com/*, utilisez « contoso.com » 2. « hostname ». Par exemple, si vous souhaitez inclure http://exemple, utilisez « exemple » 3. « file:///path/filename.htm ». Par exemple, utilisez « file:///C:/Users/contoso/Desktop/index.htm » Si vous désactivez ou ne configurez pas ce paramètre de stratégie, la liste est supprimée et Internet Explorer continue de bloquer certains contrôles ActiveX obsolètes sur tous les domaines de la zone Internet. Pour plus d'informations, voir « Contrôles ActiveX obsolètes » dans la bibliothèque TechNet d'Internet Explorer.
Registre
Software\Microsoft\Windows\CurrentVersion\Policies\Ext Software\Microsoft\Windows\CurrentVersion\Policies\Ext Nom de valeur : ListBox_DomainAllowlist
Activé : ListBox_DomainAllowlist = 1
Désactivé : ListBox_DomainAllowlist = 0
MDM / Intune (CSP)
./Device/Vendor/MSFT/Policy/Config/InternetExplorer/DoNotBlockOutdatedActiveXControlsOnSpecificDomains ./User/Vendor/MSFT/Policy/Config/InternetExplorer/DoNotBlockOutdatedActiveXControlsOnSpecificDomains Documentation Microsoft Learn Données de correspondance : Microsoft Learn (CC BY 4.0)
Générateur d'exports
BETAConfigurez l'état, la portée et les options, puis générez les sorties .reg, PowerShell, Intune et SCCM — ou ajoutez le paramètre à une collection multi-paramètres.
Ces exports écrivent le registre — ce n'est pas une GPO managée. ⓘ
Appliquer les deux portées crée une configuration ambiguë (la portée ordinateur prévaut sur la portée utilisateur). Ne le faites que volontairement.
Fichier .reg
Windows Registry Editor Version 5.00
; Exported from gporais.com
; Policy: Désactiver le blocage des contrôles ActiveX obsolètes par Internet Explorer sur certains domaines
; State: Enabled
; Scope: Computer (HKLM)
; Supported on: Au moins Internet Explorer 8.0
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Ext]
"ListBox_DomainAllowlist"=dword:00000001
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\Domain]
; List values: enter one value per line in the builder UI. Autres formats (PowerShell, Intune, SCCM)
PowerShell
# Exported from gporais.com
# Policy: Désactiver le blocage des contrôles ActiveX obsolètes par Internet Explorer sur certains domaines
# State: Enabled
# Scope: Computer (HKLM)
# Supported on: Au moins Internet Explorer 8.0
$path = 'HKLM:\Software\Microsoft\Windows\CurrentVersion\Policies\Ext'
New-Item -Path $path -Force | Out-Null
Set-ItemProperty -Path $path -Name 'ListBox_DomainAllowlist' -Value 1 -Type DWord
$path = 'HKLM:\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\Domain'
New-Item -Path $path -Force | Out-Null
# List values: enter one value per line in the builder UI. Intune XML
OMA-URI: ./Device/Vendor/MSFT/Policy/Config/InternetExplorer/DoNotBlockOutdatedActiveXControlsOnSpecificDomains
Data type: String
Value:
<enabled/>
<!-- DomainList: enter one value per line before copying this XML payload. --> Intune Remediation
# === Detection script ===
# Exported from gporais.com
# Policy: Désactiver le blocage des contrôles ActiveX obsolètes par Internet Explorer sur certains domaines
# State: Enabled
# Scope: Computer (HKLM)
# Supported on: Au moins Internet Explorer 8.0
function Test-RegistryValue {
param(
[Parameter(Mandatory = $true)][string]$Path,
[Parameter(Mandatory = $true)][string]$Name,
[object]$Expected,
[ValidateSet('String', 'DWord', 'MultiString')][string]$Kind = 'String',
[switch]$Absent
)
try {
$item = Get-ItemProperty -LiteralPath $Path -Name $Name -ErrorAction Stop
} catch {
return $Absent.IsPresent
}
if ($Absent.IsPresent) { return $false }
$actual = $item.$Name
if ($Kind -eq 'DWord') { return ([int64]$actual) -eq ([int64]$Expected) }
if ($Kind -eq 'MultiString') {
$actualValues = @($actual)
$expectedValues = @($Expected)
if ($actualValues.Count -ne $expectedValues.Count) { return $false }
for ($i = 0; $i -lt $expectedValues.Count; $i++) {
if ([string]$actualValues[$i] -ne [string]$expectedValues[$i]) { return $false }
}
return $true
}
return [string]$actual -eq [string]$Expected
}
# HKLM:\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\Domain: List values: enter one value per line in the builder UI.
$checks = @(
(Test-RegistryValue -Path 'HKLM:\Software\Microsoft\Windows\CurrentVersion\Policies\Ext' -Name 'ListBox_DomainAllowlist' -Expected 1 -Kind DWord)
)
if ($checks -notcontains $false) {
Write-Output 'Compliant'
exit 0
}
Write-Output 'Non-compliant'
exit 1
# === Remediation script ===
# Exported from gporais.com
# Policy: Désactiver le blocage des contrôles ActiveX obsolètes par Internet Explorer sur certains domaines
# State: Enabled
# Scope: Computer (HKLM)
# Supported on: Au moins Internet Explorer 8.0
$path = 'HKLM:\Software\Microsoft\Windows\CurrentVersion\Policies\Ext'
New-Item -Path $path -Force | Out-Null
Set-ItemProperty -Path $path -Name 'ListBox_DomainAllowlist' -Value 1 -Type DWord
$path = 'HKLM:\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\Domain'
New-Item -Path $path -Force | Out-Null
# List values: enter one value per line in the builder UI. Scripts SCCM
# Exported from gporais.com
# Policy: Désactiver le blocage des contrôles ActiveX obsolètes par Internet Explorer sur certains domaines
# State: Enabled
# Scope: Computer (HKLM)
# Supported on: Au moins Internet Explorer 8.0
# SCCM Configuration Item guidance:
# Create a Configuration Item of type "Setting: Script".
# Discovery script: use the Detection script below.
# Remediation script: use the Remediation script below.
# Compliance rule: the Discovery script output equals 'Compliant'.
# === Detection script ===
# Exported from gporais.com
# Policy: Désactiver le blocage des contrôles ActiveX obsolètes par Internet Explorer sur certains domaines
# State: Enabled
# Scope: Computer (HKLM)
# Supported on: Au moins Internet Explorer 8.0
function Test-RegistryValue {
param(
[Parameter(Mandatory = $true)][string]$Path,
[Parameter(Mandatory = $true)][string]$Name,
[object]$Expected,
[ValidateSet('String', 'DWord', 'MultiString')][string]$Kind = 'String',
[switch]$Absent
)
try {
$item = Get-ItemProperty -LiteralPath $Path -Name $Name -ErrorAction Stop
} catch {
return $Absent.IsPresent
}
if ($Absent.IsPresent) { return $false }
$actual = $item.$Name
if ($Kind -eq 'DWord') { return ([int64]$actual) -eq ([int64]$Expected) }
if ($Kind -eq 'MultiString') {
$actualValues = @($actual)
$expectedValues = @($Expected)
if ($actualValues.Count -ne $expectedValues.Count) { return $false }
for ($i = 0; $i -lt $expectedValues.Count; $i++) {
if ([string]$actualValues[$i] -ne [string]$expectedValues[$i]) { return $false }
}
return $true
}
return [string]$actual -eq [string]$Expected
}
# HKLM:\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\Domain: List values: enter one value per line in the builder UI.
$checks = @(
(Test-RegistryValue -Path 'HKLM:\Software\Microsoft\Windows\CurrentVersion\Policies\Ext' -Name 'ListBox_DomainAllowlist' -Expected 1 -Kind DWord)
)
if ($checks -notcontains $false) {
Write-Output 'Compliant'
exit 0
}
Write-Output 'Non-compliant'
exit 1
# === Remediation script ===
# Exported from gporais.com
# Policy: Désactiver le blocage des contrôles ActiveX obsolètes par Internet Explorer sur certains domaines
# State: Enabled
# Scope: Computer (HKLM)
# Supported on: Au moins Internet Explorer 8.0
$path = 'HKLM:\Software\Microsoft\Windows\CurrentVersion\Policies\Ext'
New-Item -Path $path -Force | Out-Null
Set-ItemProperty -Path $path -Name 'ListBox_DomainAllowlist' -Value 1 -Type DWord
$path = 'HKLM:\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\Domain'
New-Item -Path $path -Force | Out-Null
# List values: enter one value per line in the builder UI. Vous construisez une collection multi-paramètres ? Ajoutez ce paramètre et générez des exports combinés (.reg, PowerShell, GPO).