WAM pour l’authentification ci-dessous Windows 10 RS3 activé
Vérifié avec Microsoft Edge 152.0.4191.53 — mis à jour le 10 juillet 2026
Pris en charge sur : Microsoft Edge version 93, Windows 7 ou version ultérieure
Chemin dans la console GPO
Configuration ordinateur\Modèles d'administration\Microsoft Edge\Identité et connexion Configuration utilisateur\Modèles d'administration\Microsoft Edge\Identité et connexion Description
Configurez cette stratégie pour déterminer si WAM est utilisé pour l’authentification dans Microsoft Edge sur Windows 10 RS1 et RS2. Si vous activez ce paramètre, WAM est utilisé dans le flux d’authentification sur Windows 10 RS1 et RS2. Si vous désactivez ou ne configurez pas ce paramètre, les bibliothèques OneAuth sont utilisées à la place de WAM sur Windows 10 RS1 et RS2. Si cette stratégie est activée, les sessions de connexion précédentes (qui utilisaient OneAuth par défaut) ne peuvent pas être utilisées. Déconnectez-vous de ces profils. Cette stratégie prend effet uniquement sur Windows 10 RS1 et RS2. Sur Windows 10 RS3 et versions ultérieures, WAM est utilisé par défaut pour l’authentification dans Microsoft Edge.
Registre
Software\Policies\Microsoft\Edge Software\Policies\Microsoft\Edge Nom de valeur : WAMAuthBelowWin10RS3Enabled
Activé : WAMAuthBelowWin10RS3Enabled = 1
Désactivé : WAMAuthBelowWin10RS3Enabled = 0
Générateur d'exports
BETAConfigurez l'état, la portée et les options, puis générez les sorties .reg, PowerShell, Intune et SCCM — ou ajoutez le paramètre à une collection multi-paramètres.
Ces exports écrivent le registre — ce n'est pas une GPO managée. ⓘ
Appliquer les deux portées crée une configuration ambiguë (la portée ordinateur prévaut sur la portée utilisateur). Ne le faites que volontairement.
Fichier .reg
Windows Registry Editor Version 5.00
; Exported from gporais.com
; Policy: WAM pour l’authentification ci-dessous Windows 10 RS3 activé
; State: Enabled
; Scope: Computer (HKLM)
; Supported on: Microsoft Edge version 93, Windows 7 ou version ultérieure
[HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Edge]
"WAMAuthBelowWin10RS3Enabled"=dword:00000001 Autres formats (PowerShell, Intune, SCCM)
PowerShell
# Exported from gporais.com
# Policy: WAM pour l’authentification ci-dessous Windows 10 RS3 activé
# State: Enabled
# Scope: Computer (HKLM)
# Supported on: Microsoft Edge version 93, Windows 7 ou version ultérieure
$path = 'HKLM:\Software\Policies\Microsoft\Edge'
New-Item -Path $path -Force | Out-Null
Set-ItemProperty -Path $path -Name 'WAMAuthBelowWin10RS3Enabled' -Value 1 -Type DWord Intune XML
Aucune correspondance directe Policy CSP / OMA-URI pour cette stratégie. Utilisez l'onglet Intune Remediation, ou importez l'ADMX dans Intune. Intune Remediation
# === Detection script ===
# Exported from gporais.com
# Policy: WAM pour l’authentification ci-dessous Windows 10 RS3 activé
# State: Enabled
# Scope: Computer (HKLM)
# Supported on: Microsoft Edge version 93, Windows 7 ou version ultérieure
function Test-RegistryValue {
param(
[Parameter(Mandatory = $true)][string]$Path,
[Parameter(Mandatory = $true)][string]$Name,
[object]$Expected,
[ValidateSet('String', 'DWord', 'MultiString')][string]$Kind = 'String',
[switch]$Absent
)
try {
$item = Get-ItemProperty -LiteralPath $Path -Name $Name -ErrorAction Stop
} catch {
return $Absent.IsPresent
}
if ($Absent.IsPresent) { return $false }
$actual = $item.$Name
if ($Kind -eq 'DWord') { return ([int64]$actual) -eq ([int64]$Expected) }
if ($Kind -eq 'MultiString') {
$actualValues = @($actual)
$expectedValues = @($Expected)
if ($actualValues.Count -ne $expectedValues.Count) { return $false }
for ($i = 0; $i -lt $expectedValues.Count; $i++) {
if ([string]$actualValues[$i] -ne [string]$expectedValues[$i]) { return $false }
}
return $true
}
return [string]$actual -eq [string]$Expected
}
$checks = @(
(Test-RegistryValue -Path 'HKLM:\Software\Policies\Microsoft\Edge' -Name 'WAMAuthBelowWin10RS3Enabled' -Expected 1 -Kind DWord)
)
if ($checks -notcontains $false) {
Write-Output 'Compliant'
exit 0
}
Write-Output 'Non-compliant'
exit 1
# === Remediation script ===
# Exported from gporais.com
# Policy: WAM pour l’authentification ci-dessous Windows 10 RS3 activé
# State: Enabled
# Scope: Computer (HKLM)
# Supported on: Microsoft Edge version 93, Windows 7 ou version ultérieure
$path = 'HKLM:\Software\Policies\Microsoft\Edge'
New-Item -Path $path -Force | Out-Null
Set-ItemProperty -Path $path -Name 'WAMAuthBelowWin10RS3Enabled' -Value 1 -Type DWord Scripts SCCM
# Exported from gporais.com
# Policy: WAM pour l’authentification ci-dessous Windows 10 RS3 activé
# State: Enabled
# Scope: Computer (HKLM)
# Supported on: Microsoft Edge version 93, Windows 7 ou version ultérieure
# SCCM Configuration Item guidance:
# Create a Configuration Item of type "Setting: Script".
# Discovery script: use the Detection script below.
# Remediation script: use the Remediation script below.
# Compliance rule: the Discovery script output equals 'Compliant'.
# === Detection script ===
# Exported from gporais.com
# Policy: WAM pour l’authentification ci-dessous Windows 10 RS3 activé
# State: Enabled
# Scope: Computer (HKLM)
# Supported on: Microsoft Edge version 93, Windows 7 ou version ultérieure
function Test-RegistryValue {
param(
[Parameter(Mandatory = $true)][string]$Path,
[Parameter(Mandatory = $true)][string]$Name,
[object]$Expected,
[ValidateSet('String', 'DWord', 'MultiString')][string]$Kind = 'String',
[switch]$Absent
)
try {
$item = Get-ItemProperty -LiteralPath $Path -Name $Name -ErrorAction Stop
} catch {
return $Absent.IsPresent
}
if ($Absent.IsPresent) { return $false }
$actual = $item.$Name
if ($Kind -eq 'DWord') { return ([int64]$actual) -eq ([int64]$Expected) }
if ($Kind -eq 'MultiString') {
$actualValues = @($actual)
$expectedValues = @($Expected)
if ($actualValues.Count -ne $expectedValues.Count) { return $false }
for ($i = 0; $i -lt $expectedValues.Count; $i++) {
if ([string]$actualValues[$i] -ne [string]$expectedValues[$i]) { return $false }
}
return $true
}
return [string]$actual -eq [string]$Expected
}
$checks = @(
(Test-RegistryValue -Path 'HKLM:\Software\Policies\Microsoft\Edge' -Name 'WAMAuthBelowWin10RS3Enabled' -Expected 1 -Kind DWord)
)
if ($checks -notcontains $false) {
Write-Output 'Compliant'
exit 0
}
Write-Output 'Non-compliant'
exit 1
# === Remediation script ===
# Exported from gporais.com
# Policy: WAM pour l’authentification ci-dessous Windows 10 RS3 activé
# State: Enabled
# Scope: Computer (HKLM)
# Supported on: Microsoft Edge version 93, Windows 7 ou version ultérieure
$path = 'HKLM:\Software\Policies\Microsoft\Edge'
New-Item -Path $path -Force | Out-Null
Set-ItemProperty -Path $path -Name 'WAMAuthBelowWin10RS3Enabled' -Value 1 -Type DWord Vous construisez une collection multi-paramètres ? Ajoutez ce paramètre et générez des exports combinés (.reg, PowerShell, GPO).