Autoriser les mappages forts basés sur un nom pour les certificats
Vérifié avec Windows 11 25H2 — mis à jour le 23 juillet 2026
Pris en charge sur : Au minimum Windows Server 2019, Windows 10 version 2004
Chemin dans la console GPO
Configuration ordinateur\Modèles d'administration\Système\KDC Description
Ce paramètre de stratégie permet l’utilisation d’identifiants alternatifs basés sur le nom pour mapper fortement les certificats émis aux comptes d’utilisateurs Active Directory et spécifie quels certificats sont mappés à quels comptes. Sans ce paramètre activé, les certificats doivent répondre aux critères de « mappage fort » spécifiés dans aka.ms/StrongCertMapKB, qui interdisent généralement les identifiants basés sur le nom. Chaque mappage spécifié dans cette politique doit inclure un OID de politique ainsi qu'un IssuerSubject et/ou un suffixe UPN en utilisant la syntaxe spécifiée ci-dessous. Si un mappage valide pour un certificat donné est introuvable dans cette stratégie, Active Directory tentera de trouver une correspondance à l'aide des critères de mappage forts existants spécifiés dans KB5014754. Les mappages de certificats qui ne sont pas conformes aux critères de « mappage de nom fort » (cette politique) ou aux critères de « mappage fort » existants seront considérés comme invalides pour l'authentification. Le format général de la politique et quelques exemples sont répertoriés ci-dessous. Cette politique s'applique uniquement aux comptes d'utilisateurs Active Directory. Syntaxe générale ============== <thumbprint>; <list of oids>; <name-match methods> Exemples ============== IssuerThumbprint1; oid1, oid2, oid3; UpnSuffix=domain.com IssuerThumbprint2; oid1; UpnSuffix=domain.com, UpnSuffix=other.domain.com, IssuerSubject IssuerThumbprint3; oid1, oid2; IssuerSubject La stratégie doit contenir exactement une empreinte de certificat par règle, chaque règle étant représentée sous forme de tuple. Les empreintes digitales doivent être uniques et ne peuvent pas être répétées dans plusieurs règles. Les sections de chaque tuple séparées par des points-virgules doivent être dans l'ordre indiqué, tandis que les champs séparés par des virgules peuvent être dans n'importe quel ordre. Les règles elles-mêmes sont séparées par des nouvelles lignes.
Registre
Software\Microsoft\Windows\CurrentVersion\Policies\System\KDC\Parameters Nom de valeur : UseStrongNameMatches
Activé : UseStrongNameMatches = 1
Désactivé : UseStrongNameMatches = 0
Générateur d'exports
BETAConfigurez l'état, la portée et les options, puis générez les sorties .reg, PowerShell, Intune et SCCM — ou ajoutez le paramètre à une collection multi-paramètres.
Ces exports écrivent le registre — ce n'est pas une GPO managée. ⓘ
Fichier .reg
Windows Registry Editor Version 5.00
; Exported from gporais.com
; Policy: Autoriser les mappages forts basés sur un nom pour les certificats
; State: Enabled
; Supported on: Au minimum Windows Server 2019, Windows 10 version 2004
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System\KDC\Parameters]
"UseStrongNameMatches"=dword:00000001
"StrongNameMatchesList"=hex(7):00,00
; REG_MULTI_SZ: one string per input line; edit in regedit if you need richer formatting. Autres formats (PowerShell, Intune, SCCM)
PowerShell
# Exported from gporais.com
# Policy: Autoriser les mappages forts basés sur un nom pour les certificats
# State: Enabled
# Supported on: Au minimum Windows Server 2019, Windows 10 version 2004
$path = 'HKLM:\Software\Microsoft\Windows\CurrentVersion\Policies\System\KDC\Parameters'
New-Item -Path $path -Force | Out-Null
Set-ItemProperty -Path $path -Name 'UseStrongNameMatches' -Value 1 -Type DWord
Set-ItemProperty -Path $path -Name 'StrongNameMatchesList' -Value @() -Type MultiString
# REG_MULTI_SZ: one string per input line; edit in regedit if you need richer formatting. Intune XML
Aucune correspondance directe Policy CSP / OMA-URI pour cette stratégie. Utilisez l'onglet Intune Remediation, ou importez l'ADMX dans Intune. Intune Remediation
# === Detection script ===
# Exported from gporais.com
# Policy: Autoriser les mappages forts basés sur un nom pour les certificats
# State: Enabled
# Supported on: Au minimum Windows Server 2019, Windows 10 version 2004
function Test-RegistryValue {
param(
[Parameter(Mandatory = $true)][string]$Path,
[Parameter(Mandatory = $true)][string]$Name,
[object]$Expected,
[ValidateSet('String', 'DWord', 'MultiString')][string]$Kind = 'String',
[switch]$Absent
)
try {
$item = Get-ItemProperty -LiteralPath $Path -Name $Name -ErrorAction Stop
} catch {
return $Absent.IsPresent
}
if ($Absent.IsPresent) { return $false }
$actual = $item.$Name
if ($Kind -eq 'DWord') { return ([int64]$actual) -eq ([int64]$Expected) }
if ($Kind -eq 'MultiString') {
$actualValues = @($actual)
$expectedValues = @($Expected)
if ($actualValues.Count -ne $expectedValues.Count) { return $false }
for ($i = 0; $i -lt $expectedValues.Count; $i++) {
if ([string]$actualValues[$i] -ne [string]$expectedValues[$i]) { return $false }
}
return $true
}
return [string]$actual -eq [string]$Expected
}
$checks = @(
(Test-RegistryValue -Path 'HKLM:\Software\Microsoft\Windows\CurrentVersion\Policies\System\KDC\Parameters' -Name 'UseStrongNameMatches' -Expected 1 -Kind DWord)
(Test-RegistryValue -Path 'HKLM:\Software\Microsoft\Windows\CurrentVersion\Policies\System\KDC\Parameters' -Name 'StrongNameMatchesList' -Expected @() -Kind MultiString)
)
if ($checks -notcontains $false) {
Write-Output 'Compliant'
exit 0
}
Write-Output 'Non-compliant'
exit 1
# === Remediation script ===
# Exported from gporais.com
# Policy: Autoriser les mappages forts basés sur un nom pour les certificats
# State: Enabled
# Supported on: Au minimum Windows Server 2019, Windows 10 version 2004
$path = 'HKLM:\Software\Microsoft\Windows\CurrentVersion\Policies\System\KDC\Parameters'
New-Item -Path $path -Force | Out-Null
Set-ItemProperty -Path $path -Name 'UseStrongNameMatches' -Value 1 -Type DWord
Set-ItemProperty -Path $path -Name 'StrongNameMatchesList' -Value @() -Type MultiString
# REG_MULTI_SZ: one string per input line; edit in regedit if you need richer formatting. Scripts SCCM
# Exported from gporais.com
# Policy: Autoriser les mappages forts basés sur un nom pour les certificats
# State: Enabled
# Supported on: Au minimum Windows Server 2019, Windows 10 version 2004
# SCCM Configuration Item guidance:
# Create a Configuration Item of type "Setting: Script".
# Discovery script: use the Detection script below.
# Remediation script: use the Remediation script below.
# Compliance rule: the Discovery script output equals 'Compliant'.
# === Detection script ===
# Exported from gporais.com
# Policy: Autoriser les mappages forts basés sur un nom pour les certificats
# State: Enabled
# Supported on: Au minimum Windows Server 2019, Windows 10 version 2004
function Test-RegistryValue {
param(
[Parameter(Mandatory = $true)][string]$Path,
[Parameter(Mandatory = $true)][string]$Name,
[object]$Expected,
[ValidateSet('String', 'DWord', 'MultiString')][string]$Kind = 'String',
[switch]$Absent
)
try {
$item = Get-ItemProperty -LiteralPath $Path -Name $Name -ErrorAction Stop
} catch {
return $Absent.IsPresent
}
if ($Absent.IsPresent) { return $false }
$actual = $item.$Name
if ($Kind -eq 'DWord') { return ([int64]$actual) -eq ([int64]$Expected) }
if ($Kind -eq 'MultiString') {
$actualValues = @($actual)
$expectedValues = @($Expected)
if ($actualValues.Count -ne $expectedValues.Count) { return $false }
for ($i = 0; $i -lt $expectedValues.Count; $i++) {
if ([string]$actualValues[$i] -ne [string]$expectedValues[$i]) { return $false }
}
return $true
}
return [string]$actual -eq [string]$Expected
}
$checks = @(
(Test-RegistryValue -Path 'HKLM:\Software\Microsoft\Windows\CurrentVersion\Policies\System\KDC\Parameters' -Name 'UseStrongNameMatches' -Expected 1 -Kind DWord)
(Test-RegistryValue -Path 'HKLM:\Software\Microsoft\Windows\CurrentVersion\Policies\System\KDC\Parameters' -Name 'StrongNameMatchesList' -Expected @() -Kind MultiString)
)
if ($checks -notcontains $false) {
Write-Output 'Compliant'
exit 0
}
Write-Output 'Non-compliant'
exit 1
# === Remediation script ===
# Exported from gporais.com
# Policy: Autoriser les mappages forts basés sur un nom pour les certificats
# State: Enabled
# Supported on: Au minimum Windows Server 2019, Windows 10 version 2004
$path = 'HKLM:\Software\Microsoft\Windows\CurrentVersion\Policies\System\KDC\Parameters'
New-Item -Path $path -Force | Out-Null
Set-ItemProperty -Path $path -Name 'UseStrongNameMatches' -Value 1 -Type DWord
Set-ItemProperty -Path $path -Name 'StrongNameMatchesList' -Value @() -Type MultiString
# REG_MULTI_SZ: one string per input line; edit in regedit if you need richer formatting. Vous construisez une collection multi-paramètres ? Ajoutez ce paramètre et générez des exports combinés (.reg, PowerShell, GPO).