Liste des origines qui autorisent toutes les authentifications HTTP
Vérifié avec Microsoft Edge 152.0.4191.53 — mis à jour le 10 juillet 2026
Pris en charge sur : Microsoft Edge version 102, Windows 7 ou version ultérieure
Chemin dans la console GPO
Configuration ordinateur\Modèles d'administration\Microsoft Edge\Authentification HTTP Configuration utilisateur\Modèles d'administration\Microsoft Edge\Authentification HTTP Description
Définissez cette stratégie pour spécifier les origines qui autorisent tous les schémas Microsoft Edge d’authentification HTTP pris en charge, quelle que soit la stratégie 'AuthSchemes' (Schémas d’authentification pris en charge). Mettre en forme le modèle d’origine en fonction de ce format (https://support.google.com/chrome/a?p=url_blocklist_filter_format). Vous pouvez définir jusqu’à 1 000 exceptions dans 'AllHttpAuthSchemesAllowedForOrigins' (Liste des origines qui autorisent toutes les authentifications HTTP). Les caractères génériques sont autorisés pour le composant hôte (par exemple, « * :8000 » correspond à tous les ordinateurs hôtes sur le port 8000). Pour faire correspondre tous les schémas ou tous les ports, omettez entièrement le composant (par exemple, « example.com » correspond à n’importe quel schéma et à n’importe quel port). Un nom d’hôte (par exemple, « example.com ») correspond également à ses sous-domaines. Pour faire correspondre exactement un hôte et exclure ses sous-domaines, ajoutez-le à un point (par exemple, « .example.com »). Pour faire correspondre toutes les origines, utilisez un seul astérisque ('*'). Exemple de valeur : *.example.com
Registre
Software\Policies\Microsoft\Edge Software\Policies\Microsoft\Edge Générateur d'exports
BETAConfigurez l'état, la portée et les options, puis générez les sorties .reg, PowerShell, Intune et SCCM — ou ajoutez le paramètre à une collection multi-paramètres.
Ces exports écrivent le registre — ce n'est pas une GPO managée. ⓘ
Appliquer les deux portées crée une configuration ambiguë (la portée ordinateur prévaut sur la portée utilisateur). Ne le faites que volontairement.
Fichier .reg
Windows Registry Editor Version 5.00
; Exported from gporais.com
; Policy: Liste des origines qui autorisent toutes les authentifications HTTP
; State: Enabled
; Scope: Computer (HKLM)
; Supported on: Microsoft Edge version 102, Windows 7 ou version ultérieure
[HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Edge\AllHttpAuthSchemesAllowedForOrigins]
; List values: enter one value per line in the builder UI. Autres formats (PowerShell, Intune, SCCM)
PowerShell
# Exported from gporais.com
# Policy: Liste des origines qui autorisent toutes les authentifications HTTP
# State: Enabled
# Scope: Computer (HKLM)
# Supported on: Microsoft Edge version 102, Windows 7 ou version ultérieure
$path = 'HKLM:\Software\Policies\Microsoft\Edge\AllHttpAuthSchemesAllowedForOrigins'
New-Item -Path $path -Force | Out-Null
# List values: enter one value per line in the builder UI. Intune XML
Aucune correspondance directe Policy CSP / OMA-URI pour cette stratégie. Utilisez l'onglet Intune Remediation, ou importez l'ADMX dans Intune. Intune Remediation
# === Detection script ===
# Exported from gporais.com
# Policy: Liste des origines qui autorisent toutes les authentifications HTTP
# State: Enabled
# Scope: Computer (HKLM)
# Supported on: Microsoft Edge version 102, Windows 7 ou version ultérieure
function Test-RegistryValue {
param(
[Parameter(Mandatory = $true)][string]$Path,
[Parameter(Mandatory = $true)][string]$Name,
[object]$Expected,
[ValidateSet('String', 'DWord', 'MultiString')][string]$Kind = 'String',
[switch]$Absent
)
try {
$item = Get-ItemProperty -LiteralPath $Path -Name $Name -ErrorAction Stop
} catch {
return $Absent.IsPresent
}
if ($Absent.IsPresent) { return $false }
$actual = $item.$Name
if ($Kind -eq 'DWord') { return ([int64]$actual) -eq ([int64]$Expected) }
if ($Kind -eq 'MultiString') {
$actualValues = @($actual)
$expectedValues = @($Expected)
if ($actualValues.Count -ne $expectedValues.Count) { return $false }
for ($i = 0; $i -lt $expectedValues.Count; $i++) {
if ([string]$actualValues[$i] -ne [string]$expectedValues[$i]) { return $false }
}
return $true
}
return [string]$actual -eq [string]$Expected
}
# HKLM:\Software\Policies\Microsoft\Edge\AllHttpAuthSchemesAllowedForOrigins: List values: enter one value per line in the builder UI.
# No testable registry values are available for this state.
Write-Output 'Non-compliant'
exit 1
# === Remediation script ===
# Exported from gporais.com
# Policy: Liste des origines qui autorisent toutes les authentifications HTTP
# State: Enabled
# Scope: Computer (HKLM)
# Supported on: Microsoft Edge version 102, Windows 7 ou version ultérieure
$path = 'HKLM:\Software\Policies\Microsoft\Edge\AllHttpAuthSchemesAllowedForOrigins'
New-Item -Path $path -Force | Out-Null
# List values: enter one value per line in the builder UI. Scripts SCCM
# Exported from gporais.com
# Policy: Liste des origines qui autorisent toutes les authentifications HTTP
# State: Enabled
# Scope: Computer (HKLM)
# Supported on: Microsoft Edge version 102, Windows 7 ou version ultérieure
# SCCM Configuration Item guidance:
# Create a Configuration Item of type "Setting: Script".
# Discovery script: use the Detection script below.
# Remediation script: use the Remediation script below.
# Compliance rule: the Discovery script output equals 'Compliant'.
# === Detection script ===
# Exported from gporais.com
# Policy: Liste des origines qui autorisent toutes les authentifications HTTP
# State: Enabled
# Scope: Computer (HKLM)
# Supported on: Microsoft Edge version 102, Windows 7 ou version ultérieure
function Test-RegistryValue {
param(
[Parameter(Mandatory = $true)][string]$Path,
[Parameter(Mandatory = $true)][string]$Name,
[object]$Expected,
[ValidateSet('String', 'DWord', 'MultiString')][string]$Kind = 'String',
[switch]$Absent
)
try {
$item = Get-ItemProperty -LiteralPath $Path -Name $Name -ErrorAction Stop
} catch {
return $Absent.IsPresent
}
if ($Absent.IsPresent) { return $false }
$actual = $item.$Name
if ($Kind -eq 'DWord') { return ([int64]$actual) -eq ([int64]$Expected) }
if ($Kind -eq 'MultiString') {
$actualValues = @($actual)
$expectedValues = @($Expected)
if ($actualValues.Count -ne $expectedValues.Count) { return $false }
for ($i = 0; $i -lt $expectedValues.Count; $i++) {
if ([string]$actualValues[$i] -ne [string]$expectedValues[$i]) { return $false }
}
return $true
}
return [string]$actual -eq [string]$Expected
}
# HKLM:\Software\Policies\Microsoft\Edge\AllHttpAuthSchemesAllowedForOrigins: List values: enter one value per line in the builder UI.
# No testable registry values are available for this state.
Write-Output 'Non-compliant'
exit 1
# === Remediation script ===
# Exported from gporais.com
# Policy: Liste des origines qui autorisent toutes les authentifications HTTP
# State: Enabled
# Scope: Computer (HKLM)
# Supported on: Microsoft Edge version 102, Windows 7 ou version ultérieure
$path = 'HKLM:\Software\Policies\Microsoft\Edge\AllHttpAuthSchemesAllowedForOrigins'
New-Item -Path $path -Force | Out-Null
# List values: enter one value per line in the builder UI. Vous construisez une collection multi-paramètres ? Ajoutez ce paramètre et générez des exports combinés (.reg, PowerShell, GPO).