Masquer les emplacements de fichier basés sur le cloud Microsoft en mode Backstage
Vérifié avec Microsoft 365/Office 5568.1000 — mis à jour le 4 septembre 2026
Pris en charge sur : Au minimum Windows Server 2008 R2 ou Windows 7
Chemin dans la console GPO
Configuration utilisateur\Modèles d'administration\Microsoft Office 2016\Divers Description
Ce paramètre de stratégie vous permet de masquer les emplacements de fichiers cloud Microsoft en mode Backstage dans Office. Cela permet d’empêcher les utilisateurs d’ouvrir, d’enregistrer ou de partager des fichiers cloud vers des emplacements tels que : OneDrive, SharePoint ou des services tiers. Ce paramètre de stratégie s’applique uniquement à Word, PowerPoint et Excel. Pour filtrer des services spécifiques, ajoutez les valeurs de tous les services à désactiver : 1 – OneDrive Personnel 4 – ThisPC 8 – SharePoint OnPrem 16 – Emplacements récents 32 – SharePoint 64 – OneDrive Entreprise 128 – Services tiers Valeurs spéciales : 0 – (par défaut) Tous les services activés. 2 – (Valeur héritée) Désactivez SharePoint et OneDrive Entreprise. 4294967295 – Tous les services facultatifs désactivés. Par exemple, OneDrive Personnel (1), ce PC (4) et les services tiers (128) peuvent tous être désactivés avec la valeur 133. Cette valeur est calculée comme suit : 1 + 4 + 128 = 133 Valeurs des paramètres communs : 1 – Désactiver OneDrive Personnel 2 – Désactiver SharePoint Online et OneDrive Entreprise 3 – Désactiver SharePoint Online, OneDrive Entreprise et OneDrive Personnel Si vous désactivez ou ne configurez pas ce paramètre de stratégie, les utilisateurs peuvent utiliser n'importe quel emplacement de fichier configuré basé sur le cloud de Microsoft pour ouvrir, enregistrer et partager des fichiers.
Registre
software\policies\microsoft\office\16.0\common\internet Générateur d'exports
BETAConfigurez l'état, la portée et les options, puis générez les sorties .reg, PowerShell, Intune et SCCM — ou ajoutez le paramètre à une collection multi-paramètres.
Ces exports écrivent le registre — ce n'est pas une GPO managée. ⓘ
Fichier .reg
Windows Registry Editor Version 5.00
; Exported from gporais.com
; Policy: Masquer les emplacements de fichier basés sur le cloud Microsoft en mode Backstage
; State: Enabled
; Supported on: Au minimum Windows Server 2008 R2 ou Windows 7
[HKEY_CURRENT_USER\software\policies\microsoft\office\16.0\common\internet]
"onlinestorage"=dword:00000000 Autres formats (PowerShell, Intune, SCCM)
PowerShell
# Exported from gporais.com
# Policy: Masquer les emplacements de fichier basés sur le cloud Microsoft en mode Backstage
# State: Enabled
# Supported on: Au minimum Windows Server 2008 R2 ou Windows 7
# Warning: In SYSTEM context (the Intune default), HKCU targets the SYSTEM profile. Run this script using the logged-on credentials.
$path = 'HKCU:\software\policies\microsoft\office\16.0\common\internet'
New-Item -Path $path -Force | Out-Null
Set-ItemProperty -Path $path -Name 'onlinestorage' -Value 0 -Type DWord Intune XML
Aucune correspondance directe Policy CSP / OMA-URI pour cette stratégie. Utilisez l'onglet Intune Remediation, ou importez l'ADMX dans Intune. Intune Remediation
# === Detection script ===
# Exported from gporais.com
# Policy: Masquer les emplacements de fichier basés sur le cloud Microsoft en mode Backstage
# State: Enabled
# Supported on: Au minimum Windows Server 2008 R2 ou Windows 7
# Warning: In SYSTEM context (the Intune default), HKCU targets the SYSTEM profile. Run this script using the logged-on credentials.
function Test-RegistryValue {
param(
[Parameter(Mandatory = $true)][string]$Path,
[Parameter(Mandatory = $true)][string]$Name,
[object]$Expected,
[ValidateSet('String', 'DWord', 'MultiString')][string]$Kind = 'String',
[switch]$Absent
)
try {
$item = Get-ItemProperty -LiteralPath $Path -Name $Name -ErrorAction Stop
} catch {
return $Absent.IsPresent
}
if ($Absent.IsPresent) { return $false }
$actual = $item.$Name
if ($Kind -eq 'DWord') { return ([int64]$actual) -eq ([int64]$Expected) }
if ($Kind -eq 'MultiString') {
$actualValues = @($actual)
$expectedValues = @($Expected)
if ($actualValues.Count -ne $expectedValues.Count) { return $false }
for ($i = 0; $i -lt $expectedValues.Count; $i++) {
if ([string]$actualValues[$i] -ne [string]$expectedValues[$i]) { return $false }
}
return $true
}
return [string]$actual -eq [string]$Expected
}
$checks = @(
(Test-RegistryValue -Path 'HKCU:\software\policies\microsoft\office\16.0\common\internet' -Name 'onlinestorage' -Expected 0 -Kind DWord)
)
if ($checks -notcontains $false) {
Write-Output 'Compliant'
exit 0
}
Write-Output 'Non-compliant'
exit 1
# === Remediation script ===
# Exported from gporais.com
# Policy: Masquer les emplacements de fichier basés sur le cloud Microsoft en mode Backstage
# State: Enabled
# Supported on: Au minimum Windows Server 2008 R2 ou Windows 7
# Warning: In SYSTEM context (the Intune default), HKCU targets the SYSTEM profile. Run this script using the logged-on credentials.
$path = 'HKCU:\software\policies\microsoft\office\16.0\common\internet'
New-Item -Path $path -Force | Out-Null
Set-ItemProperty -Path $path -Name 'onlinestorage' -Value 0 -Type DWord Scripts SCCM
# Exported from gporais.com
# Policy: Masquer les emplacements de fichier basés sur le cloud Microsoft en mode Backstage
# State: Enabled
# Supported on: Au minimum Windows Server 2008 R2 ou Windows 7
# SCCM Configuration Item guidance:
# Create a Configuration Item of type "Setting: Script".
# Discovery script: use the Detection script below.
# Remediation script: use the Remediation script below.
# Compliance rule: the Discovery script output equals 'Compliant'.
# === Detection script ===
# Exported from gporais.com
# Policy: Masquer les emplacements de fichier basés sur le cloud Microsoft en mode Backstage
# State: Enabled
# Supported on: Au minimum Windows Server 2008 R2 ou Windows 7
# Warning: In SYSTEM context (the Intune default), HKCU targets the SYSTEM profile. Run this script using the logged-on credentials.
function Test-RegistryValue {
param(
[Parameter(Mandatory = $true)][string]$Path,
[Parameter(Mandatory = $true)][string]$Name,
[object]$Expected,
[ValidateSet('String', 'DWord', 'MultiString')][string]$Kind = 'String',
[switch]$Absent
)
try {
$item = Get-ItemProperty -LiteralPath $Path -Name $Name -ErrorAction Stop
} catch {
return $Absent.IsPresent
}
if ($Absent.IsPresent) { return $false }
$actual = $item.$Name
if ($Kind -eq 'DWord') { return ([int64]$actual) -eq ([int64]$Expected) }
if ($Kind -eq 'MultiString') {
$actualValues = @($actual)
$expectedValues = @($Expected)
if ($actualValues.Count -ne $expectedValues.Count) { return $false }
for ($i = 0; $i -lt $expectedValues.Count; $i++) {
if ([string]$actualValues[$i] -ne [string]$expectedValues[$i]) { return $false }
}
return $true
}
return [string]$actual -eq [string]$Expected
}
$checks = @(
(Test-RegistryValue -Path 'HKCU:\software\policies\microsoft\office\16.0\common\internet' -Name 'onlinestorage' -Expected 0 -Kind DWord)
)
if ($checks -notcontains $false) {
Write-Output 'Compliant'
exit 0
}
Write-Output 'Non-compliant'
exit 1
# === Remediation script ===
# Exported from gporais.com
# Policy: Masquer les emplacements de fichier basés sur le cloud Microsoft en mode Backstage
# State: Enabled
# Supported on: Au minimum Windows Server 2008 R2 ou Windows 7
# Warning: In SYSTEM context (the Intune default), HKCU targets the SYSTEM profile. Run this script using the logged-on credentials.
$path = 'HKCU:\software\policies\microsoft\office\16.0\common\internet'
New-Item -Path $path -Force | Out-Null
Set-ItemProperty -Path $path -Name 'onlinestorage' -Value 0 -Type DWord Vous construisez une collection multi-paramètres ? Ajoutez ce paramètre et générez des exports combinés (.reg, PowerShell, GPO).