Ordre des suites de chiffrement
Vérifié avec Windows 11 25H2 — mis à jour le 30 juillet 2026
Pris en charge sur : Au moins Windows Server 2016, Windows 10
Chemin dans la console GPO
Configuration ordinateur\Modèles d'administration\Réseau\Serveur Lanman Description
Ce paramètre de stratégie détermine les suites de chiffrement utilisés par le serveur SMB. Si vous activez ce paramètre de stratégie, les suites de chiffrement sont définies dans l'ordre spécifié. Si vous activez ce paramètre de stratégie et que vous ne spécifiez pas au moins une suite de chiffrement prise en charge, ou si vous désactivez ou ne configurez pas ce paramètre de stratégie, l'ordre des suites de chiffrement par défaut sont utilisé. suites de chiffrement SMB 3.11 : AES_128_GCM AES_128_CCM AES_256_GCM AES_256_CCM suites de chiffrement SMB 3.0 et 3.02 : AES_128_CCM Comment modifier ce paramètre : Réorganiser les suites de chiffrement souhaité dans la zone d'édition, d'une suite d'un chiffrement par ligne, dans l'ordre, du plus au moins favori, à la suite de chiffrement favorite en haut. Supprimer toutes les suites de chiffrement que vous ne voulez pas utiliser. Remarque : lorsque vous configurez ce paramètre de sécurité, les modifications ne prendront effet qu'après le redémarrage de Windows.
Registre
Software\Policies\Microsoft\Windows\LanmanServer MDM / Intune (CSP)
./Device/Vendor/MSFT/Policy/Config/ADMX_LanmanServer/Pol_CipherSuiteOrder Documentation Microsoft Learn Données de correspondance : Microsoft Learn (CC BY 4.0)
Générateur d'exports
BETAConfigurez l'état, la portée et les options, puis générez les sorties .reg, PowerShell, Intune et SCCM — ou ajoutez le paramètre à une collection multi-paramètres.
Ces exports écrivent le registre — ce n'est pas une GPO managée. ⓘ
Fichier .reg
Windows Registry Editor Version 5.00
; Exported from gporais.com
; Policy: Ordre des suites de chiffrement
; State: Enabled
; Supported on: Au moins Windows Server 2016, Windows 10
[HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\LanmanServer]
"CipherSuiteOrder"=hex(7):00,00
; REG_MULTI_SZ: one string per input line; edit in regedit if you need richer formatting. Autres formats (PowerShell, Intune, SCCM)
PowerShell
# Exported from gporais.com
# Policy: Ordre des suites de chiffrement
# State: Enabled
# Supported on: Au moins Windows Server 2016, Windows 10
$path = 'HKLM:\Software\Policies\Microsoft\Windows\LanmanServer'
New-Item -Path $path -Force | Out-Null
Set-ItemProperty -Path $path -Name 'CipherSuiteOrder' -Value @() -Type MultiString
# REG_MULTI_SZ: one string per input line; edit in regedit if you need richer formatting. Intune XML
OMA-URI: ./Device/Vendor/MSFT/Policy/Config/ADMX_LanmanServer/Pol_CipherSuiteOrder
Data type: String
Value:
<enabled/>
<!-- MultiText_CipherSuiteOrder: enter one value per line before copying this XML payload. --> Intune Remediation
# === Detection script ===
# Exported from gporais.com
# Policy: Ordre des suites de chiffrement
# State: Enabled
# Supported on: Au moins Windows Server 2016, Windows 10
function Test-RegistryValue {
param(
[Parameter(Mandatory = $true)][string]$Path,
[Parameter(Mandatory = $true)][string]$Name,
[object]$Expected,
[ValidateSet('String', 'DWord', 'MultiString')][string]$Kind = 'String',
[switch]$Absent
)
try {
$item = Get-ItemProperty -LiteralPath $Path -Name $Name -ErrorAction Stop
} catch {
return $Absent.IsPresent
}
if ($Absent.IsPresent) { return $false }
$actual = $item.$Name
if ($Kind -eq 'DWord') { return ([int64]$actual) -eq ([int64]$Expected) }
if ($Kind -eq 'MultiString') {
$actualValues = @($actual)
$expectedValues = @($Expected)
if ($actualValues.Count -ne $expectedValues.Count) { return $false }
for ($i = 0; $i -lt $expectedValues.Count; $i++) {
if ([string]$actualValues[$i] -ne [string]$expectedValues[$i]) { return $false }
}
return $true
}
return [string]$actual -eq [string]$Expected
}
$checks = @(
(Test-RegistryValue -Path 'HKLM:\Software\Policies\Microsoft\Windows\LanmanServer' -Name 'CipherSuiteOrder' -Expected @() -Kind MultiString)
)
if ($checks -notcontains $false) {
Write-Output 'Compliant'
exit 0
}
Write-Output 'Non-compliant'
exit 1
# === Remediation script ===
# Exported from gporais.com
# Policy: Ordre des suites de chiffrement
# State: Enabled
# Supported on: Au moins Windows Server 2016, Windows 10
$path = 'HKLM:\Software\Policies\Microsoft\Windows\LanmanServer'
New-Item -Path $path -Force | Out-Null
Set-ItemProperty -Path $path -Name 'CipherSuiteOrder' -Value @() -Type MultiString
# REG_MULTI_SZ: one string per input line; edit in regedit if you need richer formatting. Scripts SCCM
# Exported from gporais.com
# Policy: Ordre des suites de chiffrement
# State: Enabled
# Supported on: Au moins Windows Server 2016, Windows 10
# SCCM Configuration Item guidance:
# Create a Configuration Item of type "Setting: Script".
# Discovery script: use the Detection script below.
# Remediation script: use the Remediation script below.
# Compliance rule: the Discovery script output equals 'Compliant'.
# === Detection script ===
# Exported from gporais.com
# Policy: Ordre des suites de chiffrement
# State: Enabled
# Supported on: Au moins Windows Server 2016, Windows 10
function Test-RegistryValue {
param(
[Parameter(Mandatory = $true)][string]$Path,
[Parameter(Mandatory = $true)][string]$Name,
[object]$Expected,
[ValidateSet('String', 'DWord', 'MultiString')][string]$Kind = 'String',
[switch]$Absent
)
try {
$item = Get-ItemProperty -LiteralPath $Path -Name $Name -ErrorAction Stop
} catch {
return $Absent.IsPresent
}
if ($Absent.IsPresent) { return $false }
$actual = $item.$Name
if ($Kind -eq 'DWord') { return ([int64]$actual) -eq ([int64]$Expected) }
if ($Kind -eq 'MultiString') {
$actualValues = @($actual)
$expectedValues = @($Expected)
if ($actualValues.Count -ne $expectedValues.Count) { return $false }
for ($i = 0; $i -lt $expectedValues.Count; $i++) {
if ([string]$actualValues[$i] -ne [string]$expectedValues[$i]) { return $false }
}
return $true
}
return [string]$actual -eq [string]$Expected
}
$checks = @(
(Test-RegistryValue -Path 'HKLM:\Software\Policies\Microsoft\Windows\LanmanServer' -Name 'CipherSuiteOrder' -Expected @() -Kind MultiString)
)
if ($checks -notcontains $false) {
Write-Output 'Compliant'
exit 0
}
Write-Output 'Non-compliant'
exit 1
# === Remediation script ===
# Exported from gporais.com
# Policy: Ordre des suites de chiffrement
# State: Enabled
# Supported on: Au moins Windows Server 2016, Windows 10
$path = 'HKLM:\Software\Policies\Microsoft\Windows\LanmanServer'
New-Item -Path $path -Force | Out-Null
Set-ItemProperty -Path $path -Name 'CipherSuiteOrder' -Value @() -Type MultiString
# REG_MULTI_SZ: one string per input line; edit in regedit if you need richer formatting. Vous construisez une collection multi-paramètres ? Ajoutez ce paramètre et générez des exports combinés (.reg, PowerShell, GPO).