Liste des domaines approuvés
Vérifié avec Microsoft 365/Office 5568.1000 — mis à jour le 4 septembre 2026
Pris en charge sur : Au minimum Windows Server 2008 R2 ou Windows 7
Chemin dans la console GPO
Configuration utilisateur\Modèles d'administration\Skype Entreprise 2016\Stratégies de fonctionnalité Microsoft Lync Description
Lorsque Lync se connecte à un domaine inconnu, il a besoin d’un accord utilisateur explicite. Une boîte de dialogue s’affiche demandant à l’utilisateur de confirmer si Lync doit continuer. Cette stratégie permet aux administrateurs de fournir des noms de domaine approuvés. Si un nom de domaine est ajouté à cette liste, Lync fera confiance à ce domaine et n’affichera pas la boîte de dialogue demandant l’autorisation. Plusieurs adresses de domaine peuvent être fournies comme valeurs séparées par des virgules. En configurant cette stratégie, Lync n’approuvera pas explicitement les domaines par défaut spécifiés ci-dessous. Il approuvera exclusivement le domaine spécifié par la stratégie. Valeurs prises en charge : \ Non configuré (par défaut)/Désactivé : par défaut, les domaines suivants seront approuvés : « lync.com, outlook.com, lync.glbdns.microsoft.com et microsoftonline.com ». Activé : liste des domaines à approuver (par exemple, « contoso.com, contoso.co.in »).
Registre
software\policies\microsoft\office\16.0\lync Générateur d'exports
BETAConfigurez l'état, la portée et les options, puis générez les sorties .reg, PowerShell, Intune et SCCM — ou ajoutez le paramètre à une collection multi-paramètres.
Ces exports écrivent le registre — ce n'est pas une GPO managée. ⓘ
Fichier .reg
Windows Registry Editor Version 5.00
; Exported from gporais.com
; Policy: Liste des domaines approuvés
; State: Enabled
; Supported on: Au minimum Windows Server 2008 R2 ou Windows 7
[HKEY_CURRENT_USER\software\policies\microsoft\office\16.0\lync]
"trustmodeldata"="" Autres formats (PowerShell, Intune, SCCM)
PowerShell
# Exported from gporais.com
# Policy: Liste des domaines approuvés
# State: Enabled
# Supported on: Au minimum Windows Server 2008 R2 ou Windows 7
# Warning: In SYSTEM context (the Intune default), HKCU targets the SYSTEM profile. Run this script using the logged-on credentials.
$path = 'HKCU:\software\policies\microsoft\office\16.0\lync'
New-Item -Path $path -Force | Out-Null
Set-ItemProperty -Path $path -Name 'trustmodeldata' -Value '' -Type String Intune XML
Aucune correspondance directe Policy CSP / OMA-URI pour cette stratégie. Utilisez l'onglet Intune Remediation, ou importez l'ADMX dans Intune. Intune Remediation
# === Detection script ===
# Exported from gporais.com
# Policy: Liste des domaines approuvés
# State: Enabled
# Supported on: Au minimum Windows Server 2008 R2 ou Windows 7
# Warning: In SYSTEM context (the Intune default), HKCU targets the SYSTEM profile. Run this script using the logged-on credentials.
function Test-RegistryValue {
param(
[Parameter(Mandatory = $true)][string]$Path,
[Parameter(Mandatory = $true)][string]$Name,
[object]$Expected,
[ValidateSet('String', 'DWord', 'MultiString')][string]$Kind = 'String',
[switch]$Absent
)
try {
$item = Get-ItemProperty -LiteralPath $Path -Name $Name -ErrorAction Stop
} catch {
return $Absent.IsPresent
}
if ($Absent.IsPresent) { return $false }
$actual = $item.$Name
if ($Kind -eq 'DWord') { return ([int64]$actual) -eq ([int64]$Expected) }
if ($Kind -eq 'MultiString') {
$actualValues = @($actual)
$expectedValues = @($Expected)
if ($actualValues.Count -ne $expectedValues.Count) { return $false }
for ($i = 0; $i -lt $expectedValues.Count; $i++) {
if ([string]$actualValues[$i] -ne [string]$expectedValues[$i]) { return $false }
}
return $true
}
return [string]$actual -eq [string]$Expected
}
$checks = @(
(Test-RegistryValue -Path 'HKCU:\software\policies\microsoft\office\16.0\lync' -Name 'trustmodeldata' -Expected '' -Kind String)
)
if ($checks -notcontains $false) {
Write-Output 'Compliant'
exit 0
}
Write-Output 'Non-compliant'
exit 1
# === Remediation script ===
# Exported from gporais.com
# Policy: Liste des domaines approuvés
# State: Enabled
# Supported on: Au minimum Windows Server 2008 R2 ou Windows 7
# Warning: In SYSTEM context (the Intune default), HKCU targets the SYSTEM profile. Run this script using the logged-on credentials.
$path = 'HKCU:\software\policies\microsoft\office\16.0\lync'
New-Item -Path $path -Force | Out-Null
Set-ItemProperty -Path $path -Name 'trustmodeldata' -Value '' -Type String Scripts SCCM
# Exported from gporais.com
# Policy: Liste des domaines approuvés
# State: Enabled
# Supported on: Au minimum Windows Server 2008 R2 ou Windows 7
# SCCM Configuration Item guidance:
# Create a Configuration Item of type "Setting: Script".
# Discovery script: use the Detection script below.
# Remediation script: use the Remediation script below.
# Compliance rule: the Discovery script output equals 'Compliant'.
# === Detection script ===
# Exported from gporais.com
# Policy: Liste des domaines approuvés
# State: Enabled
# Supported on: Au minimum Windows Server 2008 R2 ou Windows 7
# Warning: In SYSTEM context (the Intune default), HKCU targets the SYSTEM profile. Run this script using the logged-on credentials.
function Test-RegistryValue {
param(
[Parameter(Mandatory = $true)][string]$Path,
[Parameter(Mandatory = $true)][string]$Name,
[object]$Expected,
[ValidateSet('String', 'DWord', 'MultiString')][string]$Kind = 'String',
[switch]$Absent
)
try {
$item = Get-ItemProperty -LiteralPath $Path -Name $Name -ErrorAction Stop
} catch {
return $Absent.IsPresent
}
if ($Absent.IsPresent) { return $false }
$actual = $item.$Name
if ($Kind -eq 'DWord') { return ([int64]$actual) -eq ([int64]$Expected) }
if ($Kind -eq 'MultiString') {
$actualValues = @($actual)
$expectedValues = @($Expected)
if ($actualValues.Count -ne $expectedValues.Count) { return $false }
for ($i = 0; $i -lt $expectedValues.Count; $i++) {
if ([string]$actualValues[$i] -ne [string]$expectedValues[$i]) { return $false }
}
return $true
}
return [string]$actual -eq [string]$Expected
}
$checks = @(
(Test-RegistryValue -Path 'HKCU:\software\policies\microsoft\office\16.0\lync' -Name 'trustmodeldata' -Expected '' -Kind String)
)
if ($checks -notcontains $false) {
Write-Output 'Compliant'
exit 0
}
Write-Output 'Non-compliant'
exit 1
# === Remediation script ===
# Exported from gporais.com
# Policy: Liste des domaines approuvés
# State: Enabled
# Supported on: Au minimum Windows Server 2008 R2 ou Windows 7
# Warning: In SYSTEM context (the Intune default), HKCU targets the SYSTEM profile. Run this script using the logged-on credentials.
$path = 'HKCU:\software\policies\microsoft\office\16.0\lync'
New-Item -Path $path -Force | Out-Null
Set-ItemProperty -Path $path -Name 'trustmodeldata' -Value '' -Type String Vous construisez une collection multi-paramètres ? Ajoutez ce paramètre et générez des exports combinés (.reg, PowerShell, GPO).