Activer l’exécution des scripts
Vérifié avec Windows 11 25H2 — mis à jour le 30 juillet 2026
Pris en charge sur : Au moins Microsoft Windows 7 ou famille Windows Server 2008
Chemin dans la console GPO
Configuration ordinateur\Modèles d'administration\Composants Windows\Windows PowerShell Configuration utilisateur\Modèles d'administration\Composants Windows\Windows PowerShell Description
Ce paramètre de stratégie vous permet de configurer la stratégie d’exécution de scripts en déterminant quels scripts peuvent être exécutés. Si vous activez ce paramètre de stratégie, l’exécution des scripts sélectionnés dans la liste déroulante est autorisée. Le paramètre de stratégie « Autoriser uniquement les scripts signés » permet uniquement l’exécution des scripts signés par un éditeur approuvé. Le paramètre de stratégie « Autoriser les scripts locaux et les scripts signés distants » permet l’exécution de tous les scripts locaux. Les scripts provenant d’Internet doivent être signés par un éditeur approuvé. Le paramètre de stratégie « Autoriser tous les scripts » permet l’exécution de tous les scripts. Si vous désactivez ce paramètre de stratégie, aucun script ne peut être exécuté. Remarque : ce paramètre de stratégie est présent sous « Configuration ordinateur » et « Configuration utilisateur » dans l’Éditeur d’objets de stratégie de groupe. La « Configuration ordinateur » a priorité sur la « Configuration utilisateur ». Si vous désactivez ou ne configurez pas ce paramètre de stratégie, il redevient un paramètre de préférence par ordinateur. S’il n’est pas configuré, sa valeur par défaut est « Aucun script autorisé ».
Registre
Software\Policies\Microsoft\Windows\PowerShell Software\Policies\Microsoft\Windows\PowerShell Nom de valeur : EnableScripts
Activé : EnableScripts = 1
Désactivé : EnableScripts = 0
MDM / Intune (CSP)
./Device/Vendor/MSFT/Policy/Config/ADMX_PowerShellExecutionPolicy/EnableScripts ./User/Vendor/MSFT/Policy/Config/ADMX_PowerShellExecutionPolicy/EnableScripts Documentation Microsoft Learn Données de correspondance : Microsoft Learn (CC BY 4.0)
Générateur d'exports
BETAConfigurez l'état, la portée et les options, puis générez les sorties .reg, PowerShell, Intune et SCCM — ou ajoutez le paramètre à une collection multi-paramètres.
Ces exports écrivent le registre — ce n'est pas une GPO managée. ⓘ
Appliquer les deux portées crée une configuration ambiguë (la portée ordinateur prévaut sur la portée utilisateur). Ne le faites que volontairement.
Fichier .reg
Windows Registry Editor Version 5.00
; Exported from gporais.com
; Policy: Activer l’exécution des scripts
; State: Enabled
; Scope: Computer (HKLM)
; Supported on: Au moins Microsoft Windows 7 ou famille Windows Server 2008
[HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\PowerShell]
"EnableScripts"=dword:00000001
"ExecutionPolicy"="AllSigned" Autres formats (PowerShell, Intune, SCCM)
PowerShell
# Exported from gporais.com
# Policy: Activer l’exécution des scripts
# State: Enabled
# Scope: Computer (HKLM)
# Supported on: Au moins Microsoft Windows 7 ou famille Windows Server 2008
$path = 'HKLM:\Software\Policies\Microsoft\Windows\PowerShell'
New-Item -Path $path -Force | Out-Null
Set-ItemProperty -Path $path -Name 'EnableScripts' -Value 1 -Type DWord
Set-ItemProperty -Path $path -Name 'ExecutionPolicy' -Value 'AllSigned' -Type String Intune XML
OMA-URI: ./Device/Vendor/MSFT/Policy/Config/ADMX_PowerShellExecutionPolicy/EnableScripts
Data type: String
Value:
<enabled/>
<data id="ExecutionPolicy" value="AllSigned"/> Intune Remediation
# === Detection script ===
# Exported from gporais.com
# Policy: Activer l’exécution des scripts
# State: Enabled
# Scope: Computer (HKLM)
# Supported on: Au moins Microsoft Windows 7 ou famille Windows Server 2008
function Test-RegistryValue {
param(
[Parameter(Mandatory = $true)][string]$Path,
[Parameter(Mandatory = $true)][string]$Name,
[object]$Expected,
[ValidateSet('String', 'DWord', 'MultiString')][string]$Kind = 'String',
[switch]$Absent
)
try {
$item = Get-ItemProperty -LiteralPath $Path -Name $Name -ErrorAction Stop
} catch {
return $Absent.IsPresent
}
if ($Absent.IsPresent) { return $false }
$actual = $item.$Name
if ($Kind -eq 'DWord') { return ([int64]$actual) -eq ([int64]$Expected) }
if ($Kind -eq 'MultiString') {
$actualValues = @($actual)
$expectedValues = @($Expected)
if ($actualValues.Count -ne $expectedValues.Count) { return $false }
for ($i = 0; $i -lt $expectedValues.Count; $i++) {
if ([string]$actualValues[$i] -ne [string]$expectedValues[$i]) { return $false }
}
return $true
}
return [string]$actual -eq [string]$Expected
}
$checks = @(
(Test-RegistryValue -Path 'HKLM:\Software\Policies\Microsoft\Windows\PowerShell' -Name 'EnableScripts' -Expected 1 -Kind DWord)
(Test-RegistryValue -Path 'HKLM:\Software\Policies\Microsoft\Windows\PowerShell' -Name 'ExecutionPolicy' -Expected 'AllSigned' -Kind String)
)
if ($checks -notcontains $false) {
Write-Output 'Compliant'
exit 0
}
Write-Output 'Non-compliant'
exit 1
# === Remediation script ===
# Exported from gporais.com
# Policy: Activer l’exécution des scripts
# State: Enabled
# Scope: Computer (HKLM)
# Supported on: Au moins Microsoft Windows 7 ou famille Windows Server 2008
$path = 'HKLM:\Software\Policies\Microsoft\Windows\PowerShell'
New-Item -Path $path -Force | Out-Null
Set-ItemProperty -Path $path -Name 'EnableScripts' -Value 1 -Type DWord
Set-ItemProperty -Path $path -Name 'ExecutionPolicy' -Value 'AllSigned' -Type String Scripts SCCM
# Exported from gporais.com
# Policy: Activer l’exécution des scripts
# State: Enabled
# Scope: Computer (HKLM)
# Supported on: Au moins Microsoft Windows 7 ou famille Windows Server 2008
# SCCM Configuration Item guidance:
# Create a Configuration Item of type "Setting: Script".
# Discovery script: use the Detection script below.
# Remediation script: use the Remediation script below.
# Compliance rule: the Discovery script output equals 'Compliant'.
# === Detection script ===
# Exported from gporais.com
# Policy: Activer l’exécution des scripts
# State: Enabled
# Scope: Computer (HKLM)
# Supported on: Au moins Microsoft Windows 7 ou famille Windows Server 2008
function Test-RegistryValue {
param(
[Parameter(Mandatory = $true)][string]$Path,
[Parameter(Mandatory = $true)][string]$Name,
[object]$Expected,
[ValidateSet('String', 'DWord', 'MultiString')][string]$Kind = 'String',
[switch]$Absent
)
try {
$item = Get-ItemProperty -LiteralPath $Path -Name $Name -ErrorAction Stop
} catch {
return $Absent.IsPresent
}
if ($Absent.IsPresent) { return $false }
$actual = $item.$Name
if ($Kind -eq 'DWord') { return ([int64]$actual) -eq ([int64]$Expected) }
if ($Kind -eq 'MultiString') {
$actualValues = @($actual)
$expectedValues = @($Expected)
if ($actualValues.Count -ne $expectedValues.Count) { return $false }
for ($i = 0; $i -lt $expectedValues.Count; $i++) {
if ([string]$actualValues[$i] -ne [string]$expectedValues[$i]) { return $false }
}
return $true
}
return [string]$actual -eq [string]$Expected
}
$checks = @(
(Test-RegistryValue -Path 'HKLM:\Software\Policies\Microsoft\Windows\PowerShell' -Name 'EnableScripts' -Expected 1 -Kind DWord)
(Test-RegistryValue -Path 'HKLM:\Software\Policies\Microsoft\Windows\PowerShell' -Name 'ExecutionPolicy' -Expected 'AllSigned' -Kind String)
)
if ($checks -notcontains $false) {
Write-Output 'Compliant'
exit 0
}
Write-Output 'Non-compliant'
exit 1
# === Remediation script ===
# Exported from gporais.com
# Policy: Activer l’exécution des scripts
# State: Enabled
# Scope: Computer (HKLM)
# Supported on: Au moins Microsoft Windows 7 ou famille Windows Server 2008
$path = 'HKLM:\Software\Policies\Microsoft\Windows\PowerShell'
New-Item -Path $path -Force | Out-Null
Set-ItemProperty -Path $path -Name 'EnableScripts' -Value 1 -Type DWord
Set-ItemProperty -Path $path -Name 'ExecutionPolicy' -Value 'AllSigned' -Type String Vous construisez une collection multi-paramètres ? Ajoutez ce paramètre et générez des exports combinés (.reg, PowerShell, GPO).