Ne pas traiter la liste d’exécution héritée
Vérifié avec Windows 11 25H2 — mis à jour le 30 juillet 2026
Pris en charge sur : Au minimum Windows 2000
Chemin dans la console GPO
Configuration utilisateur\Modèles d'administration\Système\Ouverture de session Description
Ce paramètre de stratégie ignore la liste d’exécution héritée. Vous pouvez créer une liste personnalisée de programmes et de documents supplémentaires que le système démarre automatiquement lorsqu’il fonctionne avec Windows Vista, Windows XP Professionnel et Windows 2000 Professionnel. Ces programmes sont ajoutés à la liste d’exécution standard des programmes et des services démarrés par le système. Si vous activez ce paramètre de stratégie, le système ignore la liste d’exécution pour Windows Vista, Windows XP Professionnel et Windows 2000 Professionnel. Si vous désactivez ce paramètre de stratégie ou si vous ne le configurez pas, Windows Vista ajoute à sa liste d’exécution toutes les listes d’exécution personnalisées. Ce paramètre de stratégie apparaît dans les dossiers Configuration ordinateur et Configuration utilisateur. Si les deux paramètres de stratégie sont configurés, le paramètre de stratégie dans Configuration ordinateur prévaut sur le paramètre dans Configuration utilisateur. Remarque : pour créer une liste d’exécution personnalisée à l’aide d’un paramètre de stratégie, utilisez le paramètre de stratégie « Exécuter ces applications au démarrage ». Consultez également le paramètre de stratégie « Ne pas traiter la liste d’exécution unique ».
Registre
Software\Microsoft\Windows\CurrentVersion\Policies\Explorer Nom de valeur : DisableCurrentUserRun
MDM / Intune (CSP)
./User/Vendor/MSFT/Policy/Config/ADMX_Logon/DisableExplorerRunLegacy_1 Documentation Microsoft Learn Données de correspondance : Microsoft Learn (CC BY 4.0)
Générateur d'exports
BETAConfigurez l'état, la portée et les options, puis générez les sorties .reg, PowerShell, Intune et SCCM — ou ajoutez le paramètre à une collection multi-paramètres.
Ces exports écrivent le registre — ce n'est pas une GPO managée. ⓘ
Fichier .reg
Windows Registry Editor Version 5.00
; Exported from gporais.com
; Policy: Ne pas traiter la liste d’exécution héritée
; State: Enabled
; Supported on: Au minimum Windows 2000
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer]
"DisableCurrentUserRun"=dword:00000001 Autres formats (PowerShell, Intune, SCCM)
PowerShell
# Exported from gporais.com
# Policy: Ne pas traiter la liste d’exécution héritée
# State: Enabled
# Supported on: Au minimum Windows 2000
# Warning: In SYSTEM context (the Intune default), HKCU targets the SYSTEM profile. Run this script using the logged-on credentials.
$path = 'HKCU:\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer'
New-Item -Path $path -Force | Out-Null
Set-ItemProperty -Path $path -Name 'DisableCurrentUserRun' -Value 1 -Type DWord Intune XML
OMA-URI: ./User/Vendor/MSFT/Policy/Config/ADMX_Logon/DisableExplorerRunLegacy_1
Data type: String
Value:
<enabled/> Intune Remediation
# === Detection script ===
# Exported from gporais.com
# Policy: Ne pas traiter la liste d’exécution héritée
# State: Enabled
# Supported on: Au minimum Windows 2000
# Warning: In SYSTEM context (the Intune default), HKCU targets the SYSTEM profile. Run this script using the logged-on credentials.
function Test-RegistryValue {
param(
[Parameter(Mandatory = $true)][string]$Path,
[Parameter(Mandatory = $true)][string]$Name,
[object]$Expected,
[ValidateSet('String', 'DWord', 'MultiString')][string]$Kind = 'String',
[switch]$Absent
)
try {
$item = Get-ItemProperty -LiteralPath $Path -Name $Name -ErrorAction Stop
} catch {
return $Absent.IsPresent
}
if ($Absent.IsPresent) { return $false }
$actual = $item.$Name
if ($Kind -eq 'DWord') { return ([int64]$actual) -eq ([int64]$Expected) }
if ($Kind -eq 'MultiString') {
$actualValues = @($actual)
$expectedValues = @($Expected)
if ($actualValues.Count -ne $expectedValues.Count) { return $false }
for ($i = 0; $i -lt $expectedValues.Count; $i++) {
if ([string]$actualValues[$i] -ne [string]$expectedValues[$i]) { return $false }
}
return $true
}
return [string]$actual -eq [string]$Expected
}
$checks = @(
(Test-RegistryValue -Path 'HKCU:\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer' -Name 'DisableCurrentUserRun' -Expected 1 -Kind DWord)
)
if ($checks -notcontains $false) {
Write-Output 'Compliant'
exit 0
}
Write-Output 'Non-compliant'
exit 1
# === Remediation script ===
# Exported from gporais.com
# Policy: Ne pas traiter la liste d’exécution héritée
# State: Enabled
# Supported on: Au minimum Windows 2000
# Warning: In SYSTEM context (the Intune default), HKCU targets the SYSTEM profile. Run this script using the logged-on credentials.
$path = 'HKCU:\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer'
New-Item -Path $path -Force | Out-Null
Set-ItemProperty -Path $path -Name 'DisableCurrentUserRun' -Value 1 -Type DWord Scripts SCCM
# Exported from gporais.com
# Policy: Ne pas traiter la liste d’exécution héritée
# State: Enabled
# Supported on: Au minimum Windows 2000
# SCCM Configuration Item guidance:
# Create a Configuration Item of type "Setting: Script".
# Discovery script: use the Detection script below.
# Remediation script: use the Remediation script below.
# Compliance rule: the Discovery script output equals 'Compliant'.
# === Detection script ===
# Exported from gporais.com
# Policy: Ne pas traiter la liste d’exécution héritée
# State: Enabled
# Supported on: Au minimum Windows 2000
# Warning: In SYSTEM context (the Intune default), HKCU targets the SYSTEM profile. Run this script using the logged-on credentials.
function Test-RegistryValue {
param(
[Parameter(Mandatory = $true)][string]$Path,
[Parameter(Mandatory = $true)][string]$Name,
[object]$Expected,
[ValidateSet('String', 'DWord', 'MultiString')][string]$Kind = 'String',
[switch]$Absent
)
try {
$item = Get-ItemProperty -LiteralPath $Path -Name $Name -ErrorAction Stop
} catch {
return $Absent.IsPresent
}
if ($Absent.IsPresent) { return $false }
$actual = $item.$Name
if ($Kind -eq 'DWord') { return ([int64]$actual) -eq ([int64]$Expected) }
if ($Kind -eq 'MultiString') {
$actualValues = @($actual)
$expectedValues = @($Expected)
if ($actualValues.Count -ne $expectedValues.Count) { return $false }
for ($i = 0; $i -lt $expectedValues.Count; $i++) {
if ([string]$actualValues[$i] -ne [string]$expectedValues[$i]) { return $false }
}
return $true
}
return [string]$actual -eq [string]$Expected
}
$checks = @(
(Test-RegistryValue -Path 'HKCU:\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer' -Name 'DisableCurrentUserRun' -Expected 1 -Kind DWord)
)
if ($checks -notcontains $false) {
Write-Output 'Compliant'
exit 0
}
Write-Output 'Non-compliant'
exit 1
# === Remediation script ===
# Exported from gporais.com
# Policy: Ne pas traiter la liste d’exécution héritée
# State: Enabled
# Supported on: Au minimum Windows 2000
# Warning: In SYSTEM context (the Intune default), HKCU targets the SYSTEM profile. Run this script using the logged-on credentials.
$path = 'HKCU:\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer'
New-Item -Path $path -Force | Out-Null
Set-ItemProperty -Path $path -Name 'DisableCurrentUserRun' -Value 1 -Type DWord Vous construisez une collection multi-paramètres ? Ajoutez ce paramètre et générez des exports combinés (.reg, PowerShell, GPO).