Restrictions Pointer et imprimer
Vérifié avec Windows 11 25H2 — mis à jour le 30 juillet 2026
Pris en charge sur : Prise en charge de Windows XP SP1 à Windows Server 2008 RTM
Chemin dans la console GPO
Configuration utilisateur\Modèles d'administration\Panneau de configuration\Imprimantes Description
Ce paramètre de stratégie contrôle le comportement Pointer et imprimer des clients, y compris les invites de sécurité pour les ordinateurs Windows Vista. Le paramètre de stratégie s’applique uniquement aux clients non administrateurs d’imprimantes et aux ordinateurs qui sont membres d’un domaine. Si vous activez ce paramètre de stratégie : - Les clients Windows XP et de versions ultérieures peuvent uniquement télécharger des composants pilotes d’impression à partir d’une liste de serveurs explicitement nommés. Si un pilote d’impression est disponible sur le client, une connexion d’imprimante est établie. Si aucun pilote d’impression n’est disponible sur le client, aucune connexion n’est établie. - Vous pouvez configurer les clients Windows Vista pour ne pas afficher les avertissements de sécurité ou les invites d’élévation lorsque les utilisateurs pointent et impriment ou lorsque les connexions d’imprimantes doivent être mises à jour. Si ce paramètre de stratégie n’est pas configuré : - Les ordinateurs client Windows Vista peuvent pointer et imprimer vers n’importe quel serveur. - Les ordinateurs Windows Vista affichent un avertissement et une invite d’élévation lorsque les utilisateurs créent une connexion d’imprimante vers n’importe quel serveur à l’aide de l’opération Pointer et imprimer. - Les ordinateurs Windows Vista affichent un avertissement et une invite d’élévation lorsque le pilote d’une connexion d’imprimante existante doit être mis à jour. - Les ordinateurs clients Windows Server 2003 et Windows XP peuvent créer une connexion d’imprimante vers n’importe quel serveur de leur forêt à l’aide de l’opération Pointer et imprimer. Si ce paramètre de stratégie est désactivé : - Les ordinateurs client Windows Vista peuvent créer une connexion d’imprimante vers n’importe quel serveur à l’aide de l’opération Pointer et imprimer. - Les ordinateurs Windows Vista n’affichent pas d’avertissement ni d’invite d’élévation lorsque les utilisateurs créent une connexion d’imprimante vers n’importe quel serveur à l’aide de l’opération Pointer et imprimer. - Les ordinateurs Windows Vista n’affichent pas d’avertissement ni d’invite d’élévation lorsque le pilote d’une connexion d’imprimante existante doit être mis à jour. - Les ordinateurs clients Windows Server 2003 et Windows XP peuvent créer une connexion d’imprimante vers n’importe quel serveur à l’aide de l’opération Pointer et imprimer. - Le paramètre Les utilisateurs peuvent pointer et imprimer vers des ordinateurs de leur forêt uniquement s’applique uniquement à Windows Server 2003 et à Windows XP SP1 (et Service Pack ultérieur).
Registre
Software\Policies\Microsoft\Windows NT\Printers\PointAndPrint Nom de valeur : Restricted
Activé : Restricted = 1
Désactivé : Restricted = 0
MDM / Intune (CSP)
./User/Vendor/MSFT/Policy/Config/Printers/PointAndPrintRestrictions_User Documentation Microsoft Learn Données de correspondance : Microsoft Learn (CC BY 4.0)
Générateur d'exports
BETAConfigurez l'état, la portée et les options, puis générez les sorties .reg, PowerShell, Intune et SCCM — ou ajoutez le paramètre à une collection multi-paramètres.
Ces exports écrivent le registre — ce n'est pas une GPO managée. ⓘ
Fichier .reg
Windows Registry Editor Version 5.00
; Exported from gporais.com
; Policy: Restrictions Pointer et imprimer
; State: Enabled
; Supported on: Prise en charge de Windows XP SP1 à Windows Server 2008 RTM
[HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows NT\Printers\PointAndPrint]
"Restricted"=dword:00000001
"TrustedServers"=dword:00000000
"ServerList"=""
"InForest"=dword:00000000
"NoWarningNoElevationOnInstall"=dword:00000000
"UpdatePromptSettings"=dword:00000000 Autres formats (PowerShell, Intune, SCCM)
PowerShell
# Exported from gporais.com
# Policy: Restrictions Pointer et imprimer
# State: Enabled
# Supported on: Prise en charge de Windows XP SP1 à Windows Server 2008 RTM
# Warning: In SYSTEM context (the Intune default), HKCU targets the SYSTEM profile. Run this script using the logged-on credentials.
$path = 'HKCU:\Software\Policies\Microsoft\Windows NT\Printers\PointAndPrint'
New-Item -Path $path -Force | Out-Null
Set-ItemProperty -Path $path -Name 'Restricted' -Value 1 -Type DWord
Set-ItemProperty -Path $path -Name 'TrustedServers' -Value 0 -Type DWord
Set-ItemProperty -Path $path -Name 'ServerList' -Value '' -Type String
Set-ItemProperty -Path $path -Name 'InForest' -Value 0 -Type DWord
Set-ItemProperty -Path $path -Name 'NoWarningNoElevationOnInstall' -Value 0 -Type DWord
Set-ItemProperty -Path $path -Name 'UpdatePromptSettings' -Value 0 -Type DWord Intune XML
OMA-URI: ./User/Vendor/MSFT/Policy/Config/Printers/PointAndPrintRestrictions_User
Data type: String
Value:
<enabled/>
<data id="PointAndPrint_TrustedServers_Chk" value="0"/>
<data id="PointAndPrint_TrustedServers_Edit" value=""/>
<data id="PointAndPrint_TrustedForest_Chk" value="0"/>
<data id="PointAndPrint_NoWarningNoElevationOnInstall_Enum" value="0"/>
<data id="PointAndPrint_NoWarningNoElevationOnUpdate_Enum" value="0"/> Intune Remediation
# === Detection script ===
# Exported from gporais.com
# Policy: Restrictions Pointer et imprimer
# State: Enabled
# Supported on: Prise en charge de Windows XP SP1 à Windows Server 2008 RTM
# Warning: In SYSTEM context (the Intune default), HKCU targets the SYSTEM profile. Run this script using the logged-on credentials.
function Test-RegistryValue {
param(
[Parameter(Mandatory = $true)][string]$Path,
[Parameter(Mandatory = $true)][string]$Name,
[object]$Expected,
[ValidateSet('String', 'DWord', 'MultiString')][string]$Kind = 'String',
[switch]$Absent
)
try {
$item = Get-ItemProperty -LiteralPath $Path -Name $Name -ErrorAction Stop
} catch {
return $Absent.IsPresent
}
if ($Absent.IsPresent) { return $false }
$actual = $item.$Name
if ($Kind -eq 'DWord') { return ([int64]$actual) -eq ([int64]$Expected) }
if ($Kind -eq 'MultiString') {
$actualValues = @($actual)
$expectedValues = @($Expected)
if ($actualValues.Count -ne $expectedValues.Count) { return $false }
for ($i = 0; $i -lt $expectedValues.Count; $i++) {
if ([string]$actualValues[$i] -ne [string]$expectedValues[$i]) { return $false }
}
return $true
}
return [string]$actual -eq [string]$Expected
}
$checks = @(
(Test-RegistryValue -Path 'HKCU:\Software\Policies\Microsoft\Windows NT\Printers\PointAndPrint' -Name 'Restricted' -Expected 1 -Kind DWord)
(Test-RegistryValue -Path 'HKCU:\Software\Policies\Microsoft\Windows NT\Printers\PointAndPrint' -Name 'TrustedServers' -Expected 0 -Kind DWord)
(Test-RegistryValue -Path 'HKCU:\Software\Policies\Microsoft\Windows NT\Printers\PointAndPrint' -Name 'ServerList' -Expected '' -Kind String)
(Test-RegistryValue -Path 'HKCU:\Software\Policies\Microsoft\Windows NT\Printers\PointAndPrint' -Name 'InForest' -Expected 0 -Kind DWord)
(Test-RegistryValue -Path 'HKCU:\Software\Policies\Microsoft\Windows NT\Printers\PointAndPrint' -Name 'NoWarningNoElevationOnInstall' -Expected 0 -Kind DWord)
(Test-RegistryValue -Path 'HKCU:\Software\Policies\Microsoft\Windows NT\Printers\PointAndPrint' -Name 'UpdatePromptSettings' -Expected 0 -Kind DWord)
)
if ($checks -notcontains $false) {
Write-Output 'Compliant'
exit 0
}
Write-Output 'Non-compliant'
exit 1
# === Remediation script ===
# Exported from gporais.com
# Policy: Restrictions Pointer et imprimer
# State: Enabled
# Supported on: Prise en charge de Windows XP SP1 à Windows Server 2008 RTM
# Warning: In SYSTEM context (the Intune default), HKCU targets the SYSTEM profile. Run this script using the logged-on credentials.
$path = 'HKCU:\Software\Policies\Microsoft\Windows NT\Printers\PointAndPrint'
New-Item -Path $path -Force | Out-Null
Set-ItemProperty -Path $path -Name 'Restricted' -Value 1 -Type DWord
Set-ItemProperty -Path $path -Name 'TrustedServers' -Value 0 -Type DWord
Set-ItemProperty -Path $path -Name 'ServerList' -Value '' -Type String
Set-ItemProperty -Path $path -Name 'InForest' -Value 0 -Type DWord
Set-ItemProperty -Path $path -Name 'NoWarningNoElevationOnInstall' -Value 0 -Type DWord
Set-ItemProperty -Path $path -Name 'UpdatePromptSettings' -Value 0 -Type DWord Scripts SCCM
# Exported from gporais.com
# Policy: Restrictions Pointer et imprimer
# State: Enabled
# Supported on: Prise en charge de Windows XP SP1 à Windows Server 2008 RTM
# SCCM Configuration Item guidance:
# Create a Configuration Item of type "Setting: Script".
# Discovery script: use the Detection script below.
# Remediation script: use the Remediation script below.
# Compliance rule: the Discovery script output equals 'Compliant'.
# === Detection script ===
# Exported from gporais.com
# Policy: Restrictions Pointer et imprimer
# State: Enabled
# Supported on: Prise en charge de Windows XP SP1 à Windows Server 2008 RTM
# Warning: In SYSTEM context (the Intune default), HKCU targets the SYSTEM profile. Run this script using the logged-on credentials.
function Test-RegistryValue {
param(
[Parameter(Mandatory = $true)][string]$Path,
[Parameter(Mandatory = $true)][string]$Name,
[object]$Expected,
[ValidateSet('String', 'DWord', 'MultiString')][string]$Kind = 'String',
[switch]$Absent
)
try {
$item = Get-ItemProperty -LiteralPath $Path -Name $Name -ErrorAction Stop
} catch {
return $Absent.IsPresent
}
if ($Absent.IsPresent) { return $false }
$actual = $item.$Name
if ($Kind -eq 'DWord') { return ([int64]$actual) -eq ([int64]$Expected) }
if ($Kind -eq 'MultiString') {
$actualValues = @($actual)
$expectedValues = @($Expected)
if ($actualValues.Count -ne $expectedValues.Count) { return $false }
for ($i = 0; $i -lt $expectedValues.Count; $i++) {
if ([string]$actualValues[$i] -ne [string]$expectedValues[$i]) { return $false }
}
return $true
}
return [string]$actual -eq [string]$Expected
}
$checks = @(
(Test-RegistryValue -Path 'HKCU:\Software\Policies\Microsoft\Windows NT\Printers\PointAndPrint' -Name 'Restricted' -Expected 1 -Kind DWord)
(Test-RegistryValue -Path 'HKCU:\Software\Policies\Microsoft\Windows NT\Printers\PointAndPrint' -Name 'TrustedServers' -Expected 0 -Kind DWord)
(Test-RegistryValue -Path 'HKCU:\Software\Policies\Microsoft\Windows NT\Printers\PointAndPrint' -Name 'ServerList' -Expected '' -Kind String)
(Test-RegistryValue -Path 'HKCU:\Software\Policies\Microsoft\Windows NT\Printers\PointAndPrint' -Name 'InForest' -Expected 0 -Kind DWord)
(Test-RegistryValue -Path 'HKCU:\Software\Policies\Microsoft\Windows NT\Printers\PointAndPrint' -Name 'NoWarningNoElevationOnInstall' -Expected 0 -Kind DWord)
(Test-RegistryValue -Path 'HKCU:\Software\Policies\Microsoft\Windows NT\Printers\PointAndPrint' -Name 'UpdatePromptSettings' -Expected 0 -Kind DWord)
)
if ($checks -notcontains $false) {
Write-Output 'Compliant'
exit 0
}
Write-Output 'Non-compliant'
exit 1
# === Remediation script ===
# Exported from gporais.com
# Policy: Restrictions Pointer et imprimer
# State: Enabled
# Supported on: Prise en charge de Windows XP SP1 à Windows Server 2008 RTM
# Warning: In SYSTEM context (the Intune default), HKCU targets the SYSTEM profile. Run this script using the logged-on credentials.
$path = 'HKCU:\Software\Policies\Microsoft\Windows NT\Printers\PointAndPrint'
New-Item -Path $path -Force | Out-Null
Set-ItemProperty -Path $path -Name 'Restricted' -Value 1 -Type DWord
Set-ItemProperty -Path $path -Name 'TrustedServers' -Value 0 -Type DWord
Set-ItemProperty -Path $path -Name 'ServerList' -Value '' -Type String
Set-ItemProperty -Path $path -Name 'InForest' -Value 0 -Type DWord
Set-ItemProperty -Path $path -Name 'NoWarningNoElevationOnInstall' -Value 0 -Type DWord
Set-ItemProperty -Path $path -Name 'UpdatePromptSettings' -Value 0 -Type DWord Vous construisez une collection multi-paramètres ? Ajoutez ce paramètre et générez des exports combinés (.reg, PowerShell, GPO).