Blocage NTLM amélioré
Vérifié avec Windows 11 25H2 — mis à jour le 15 septembre 2026 Pris en charge sur : Au moins Windows 11 version 24H2
Livrée par une mise à jour Windows : absente du paquet ADMX officiel (Administrative Templates (.admx) for Windows 11 Oct 2025 Update), présente au plus tard dans KB5124008 (build 26200.9445).
Chemin dans la console GPO
Configuration ordinateur\Modèles d'administration\Système\NTLM Registre
Software\Microsoft\Windows\CurrentVersion\Policies\System\NTLM\Parameters - Nom de valeur :
-
EnhancedNtlmBlocksREG_DWORD - Activé :
1- Désactivé :
0
Description
Ce paramètre de stratégie permet au package de sécurité NTLM de bloquer les demandes d’authentification NTLM en fonction des nouvelles stratégies de blocage améliorées au niveau de l’ordinateur. Ces stratégies de blocage améliorées vous permettent de bloquer l’authentification NTLM en fonction de nouveaux critères, tels que le type du compte, le rôle de l’appareil ou le type d’application. Si la stratégie globale est définie sur « Désactivé » ou « Non configuré », les sous-paramètres ci-dessous ne prendront pas effet. Si la stratégie globale est définie sur « Activé », les sous-stratégies ci-dessous prendront effet selon leur configuration. Sauf configuration contraire, toutes les stratégies sont définies en mode « Audit ». Les stratégies définies sur « Audit » enregistrent un avertissement concernant la demande NTLM qui peut être bloquée, mais ne la bloquent pas. Plusieurs stratégies marquées comme « Audit » peuvent être activées simultanément et seront consignées dans un journal des événements unifié. Si une stratégie est marquée comme « Activée », la demande d’authentification NTLM sera bloquée si elle correspond aux critères de cette stratégie. Si plusieurs stratégies sont marquées comme « Activées », la demande d’authentification NTLM sera bloquée si elle correspond aux critères de l’une d’elles. Un journal des événements sera généré pour la première stratégie qui bloque l’authentification NTLM. Dans les cas où coexistent des stratégies « Audit » et « Activée », la stratégie « Activée » prévaut. Toutes les stratégies de blocage améliorées décrites ici partagent la même liste verte, qui spécifie les comptes, appareils et applications autorisés à utiliser l’authentification NTLM. La liste verte peut contenir une série de noms de cibles ou de SPN pour autoriser l’authentification. Pour plus d’informations, visitez aka.ms/ntlmlogandblock.
Générateur d'exports
BETAConfigurez l'état, la portée et les options, puis générez les sorties .reg, PowerShell, Intune et SCCM — ou ajoutez le paramètre à une collection multi-paramètres.
Ces exports écrivent le registre — ce n'est pas une GPO managée. ⓘ
Fichier .reg
Windows Registry Editor Version 5.00
; Exported from gporais.com
; Policy: Blocage NTLM amélioré
; State: Enabled
; Supported on: Au moins Windows 11 version 24H2
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System\NTLM\Parameters]
"EnhancedNtlmBlocks"=dword:00000001
"BlockDomainAccountSSO"=dword:00000001
"BlockDomainControllerAuth"=dword:00000001
"EnforceMachineBinding"=dword:00000001
"BlockAll"=dword:00000001
"EnhancedMachineBlockingAllowList"=hex(7):00,00
; REG_MULTI_SZ: one string per input line; edit in regedit if you need richer formatting. Autres formats (PowerShell, Intune, SCCM)
PowerShell
# Exported from gporais.com
# Policy: Blocage NTLM amélioré
# State: Enabled
# Supported on: Au moins Windows 11 version 24H2
$path = 'HKLM:\Software\Microsoft\Windows\CurrentVersion\Policies\System\NTLM\Parameters'
New-Item -Path $path -Force | Out-Null
Set-ItemProperty -Path $path -Name 'EnhancedNtlmBlocks' -Value 1 -Type DWord
Set-ItemProperty -Path $path -Name 'BlockDomainAccountSSO' -Value 1 -Type DWord
Set-ItemProperty -Path $path -Name 'BlockDomainControllerAuth' -Value 1 -Type DWord
Set-ItemProperty -Path $path -Name 'EnforceMachineBinding' -Value 1 -Type DWord
Set-ItemProperty -Path $path -Name 'BlockAll' -Value 1 -Type DWord
Set-ItemProperty -Path $path -Name 'EnhancedMachineBlockingAllowList' -Value @() -Type MultiString
# REG_MULTI_SZ: one string per input line; edit in regedit if you need richer formatting. Intune XML
Aucune correspondance directe Policy CSP / OMA-URI pour cette stratégie. Utilisez l'onglet Intune Remediation, ou importez l'ADMX dans Intune. Intune Remediation
# === Detection script ===
# Exported from gporais.com
# Policy: Blocage NTLM amélioré
# State: Enabled
# Supported on: Au moins Windows 11 version 24H2
function Test-RegistryValue {
param(
[Parameter(Mandatory = $true)][string]$Path,
[Parameter(Mandatory = $true)][string]$Name,
[object]$Expected,
[ValidateSet('String', 'DWord', 'MultiString')][string]$Kind = 'String',
[switch]$Absent
)
try {
$item = Get-ItemProperty -LiteralPath $Path -Name $Name -ErrorAction Stop
} catch {
return $Absent.IsPresent
}
if ($Absent.IsPresent) { return $false }
$actual = $item.$Name
if ($Kind -eq 'DWord') { return ([int64]$actual) -eq ([int64]$Expected) }
if ($Kind -eq 'MultiString') {
$actualValues = @($actual)
$expectedValues = @($Expected)
if ($actualValues.Count -ne $expectedValues.Count) { return $false }
for ($i = 0; $i -lt $expectedValues.Count; $i++) {
if ([string]$actualValues[$i] -ne [string]$expectedValues[$i]) { return $false }
}
return $true
}
return [string]$actual -eq [string]$Expected
}
$checks = @(
(Test-RegistryValue -Path 'HKLM:\Software\Microsoft\Windows\CurrentVersion\Policies\System\NTLM\Parameters' -Name 'EnhancedNtlmBlocks' -Expected 1 -Kind DWord)
(Test-RegistryValue -Path 'HKLM:\Software\Microsoft\Windows\CurrentVersion\Policies\System\NTLM\Parameters' -Name 'BlockDomainAccountSSO' -Expected 1 -Kind DWord)
(Test-RegistryValue -Path 'HKLM:\Software\Microsoft\Windows\CurrentVersion\Policies\System\NTLM\Parameters' -Name 'BlockDomainControllerAuth' -Expected 1 -Kind DWord)
(Test-RegistryValue -Path 'HKLM:\Software\Microsoft\Windows\CurrentVersion\Policies\System\NTLM\Parameters' -Name 'EnforceMachineBinding' -Expected 1 -Kind DWord)
(Test-RegistryValue -Path 'HKLM:\Software\Microsoft\Windows\CurrentVersion\Policies\System\NTLM\Parameters' -Name 'BlockAll' -Expected 1 -Kind DWord)
(Test-RegistryValue -Path 'HKLM:\Software\Microsoft\Windows\CurrentVersion\Policies\System\NTLM\Parameters' -Name 'EnhancedMachineBlockingAllowList' -Expected @() -Kind MultiString)
)
if ($checks -notcontains $false) {
Write-Output 'Compliant'
exit 0
}
Write-Output 'Non-compliant'
exit 1
# === Remediation script ===
# Exported from gporais.com
# Policy: Blocage NTLM amélioré
# State: Enabled
# Supported on: Au moins Windows 11 version 24H2
$path = 'HKLM:\Software\Microsoft\Windows\CurrentVersion\Policies\System\NTLM\Parameters'
New-Item -Path $path -Force | Out-Null
Set-ItemProperty -Path $path -Name 'EnhancedNtlmBlocks' -Value 1 -Type DWord
Set-ItemProperty -Path $path -Name 'BlockDomainAccountSSO' -Value 1 -Type DWord
Set-ItemProperty -Path $path -Name 'BlockDomainControllerAuth' -Value 1 -Type DWord
Set-ItemProperty -Path $path -Name 'EnforceMachineBinding' -Value 1 -Type DWord
Set-ItemProperty -Path $path -Name 'BlockAll' -Value 1 -Type DWord
Set-ItemProperty -Path $path -Name 'EnhancedMachineBlockingAllowList' -Value @() -Type MultiString
# REG_MULTI_SZ: one string per input line; edit in regedit if you need richer formatting. Scripts SCCM
# Exported from gporais.com
# Policy: Blocage NTLM amélioré
# State: Enabled
# Supported on: Au moins Windows 11 version 24H2
# SCCM Configuration Item guidance:
# Create a Configuration Item of type "Setting: Script".
# Discovery script: use the Detection script below.
# Remediation script: use the Remediation script below.
# Compliance rule: the Discovery script output equals 'Compliant'.
# === Detection script ===
# Exported from gporais.com
# Policy: Blocage NTLM amélioré
# State: Enabled
# Supported on: Au moins Windows 11 version 24H2
function Test-RegistryValue {
param(
[Parameter(Mandatory = $true)][string]$Path,
[Parameter(Mandatory = $true)][string]$Name,
[object]$Expected,
[ValidateSet('String', 'DWord', 'MultiString')][string]$Kind = 'String',
[switch]$Absent
)
try {
$item = Get-ItemProperty -LiteralPath $Path -Name $Name -ErrorAction Stop
} catch {
return $Absent.IsPresent
}
if ($Absent.IsPresent) { return $false }
$actual = $item.$Name
if ($Kind -eq 'DWord') { return ([int64]$actual) -eq ([int64]$Expected) }
if ($Kind -eq 'MultiString') {
$actualValues = @($actual)
$expectedValues = @($Expected)
if ($actualValues.Count -ne $expectedValues.Count) { return $false }
for ($i = 0; $i -lt $expectedValues.Count; $i++) {
if ([string]$actualValues[$i] -ne [string]$expectedValues[$i]) { return $false }
}
return $true
}
return [string]$actual -eq [string]$Expected
}
$checks = @(
(Test-RegistryValue -Path 'HKLM:\Software\Microsoft\Windows\CurrentVersion\Policies\System\NTLM\Parameters' -Name 'EnhancedNtlmBlocks' -Expected 1 -Kind DWord)
(Test-RegistryValue -Path 'HKLM:\Software\Microsoft\Windows\CurrentVersion\Policies\System\NTLM\Parameters' -Name 'BlockDomainAccountSSO' -Expected 1 -Kind DWord)
(Test-RegistryValue -Path 'HKLM:\Software\Microsoft\Windows\CurrentVersion\Policies\System\NTLM\Parameters' -Name 'BlockDomainControllerAuth' -Expected 1 -Kind DWord)
(Test-RegistryValue -Path 'HKLM:\Software\Microsoft\Windows\CurrentVersion\Policies\System\NTLM\Parameters' -Name 'EnforceMachineBinding' -Expected 1 -Kind DWord)
(Test-RegistryValue -Path 'HKLM:\Software\Microsoft\Windows\CurrentVersion\Policies\System\NTLM\Parameters' -Name 'BlockAll' -Expected 1 -Kind DWord)
(Test-RegistryValue -Path 'HKLM:\Software\Microsoft\Windows\CurrentVersion\Policies\System\NTLM\Parameters' -Name 'EnhancedMachineBlockingAllowList' -Expected @() -Kind MultiString)
)
if ($checks -notcontains $false) {
Write-Output 'Compliant'
exit 0
}
Write-Output 'Non-compliant'
exit 1
# === Remediation script ===
# Exported from gporais.com
# Policy: Blocage NTLM amélioré
# State: Enabled
# Supported on: Au moins Windows 11 version 24H2
$path = 'HKLM:\Software\Microsoft\Windows\CurrentVersion\Policies\System\NTLM\Parameters'
New-Item -Path $path -Force | Out-Null
Set-ItemProperty -Path $path -Name 'EnhancedNtlmBlocks' -Value 1 -Type DWord
Set-ItemProperty -Path $path -Name 'BlockDomainAccountSSO' -Value 1 -Type DWord
Set-ItemProperty -Path $path -Name 'BlockDomainControllerAuth' -Value 1 -Type DWord
Set-ItemProperty -Path $path -Name 'EnforceMachineBinding' -Value 1 -Type DWord
Set-ItemProperty -Path $path -Name 'BlockAll' -Value 1 -Type DWord
Set-ItemProperty -Path $path -Name 'EnhancedMachineBlockingAllowList' -Value @() -Type MultiString
# REG_MULTI_SZ: one string per input line; edit in regedit if you need richer formatting. Vous construisez une collection multi-paramètres ? Ajoutez ce paramètre et générez des exports combinés (.reg, PowerShell, GPO).