fr-FR security-baseline computer

Enable Structured Exception Handling Overwrite Protection (SEHOP)

Vérifié avec Microsoft Security Baseline (MSS / SecGuide) 25H2 — mis à jour le 30 juillet 2026

Pris en charge sur : Au minimum Windows Vista

Chemin dans la console GPO

Configuration ordinateur\Modèles d'administration\MS Security Guide

Description

If this setting is enabled, SEHOP is enforced. For more information, see https://support.microsoft.com/en-us/help/956607/how-to-enable-structured-exception-handling-overwrite-protection-sehop-in-windows-operating-systems. If this setting is disabled or not configured, SEHOP is not enforced for 32-bit processes.

Registre

HKLM SYSTEM\CurrentControlSet\Control\Session Manager\kernel

Nom de valeur : DisableExceptionChainValidation

Activé : DisableExceptionChainValidation = 0

Désactivé : DisableExceptionChainValidation = 1

MDM / Intune (CSP)

./Device/Vendor/MSFT/Policy/Config/MSSecurityGuide/EnableStructuredExceptionHandlingOverwriteProtection
Appareil Depuis Windows 10, version 1803 [10.0.17134] and later Mapping officiel (Microsoft Learn)

Documentation Microsoft Learn Données de correspondance : Microsoft Learn (CC BY 4.0)

Générateur d'exports

BETA

Configurez l'état, la portée et les options, puis générez les sorties .reg, PowerShell, Intune et SCCM — ou ajoutez le paramètre à une collection multi-paramètres.

Ces exports écrivent le registre — ce n'est pas une GPO managée.

Fichier .reg

Windows Registry Editor Version 5.00

; Exported from gporais.com
; Policy: Enable Structured Exception Handling Overwrite Protection (SEHOP)
; State: Enabled
; Supported on: Au minimum Windows Vista

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\kernel]
"DisableExceptionChainValidation"=dword:00000000
Autres formats (PowerShell, Intune, SCCM)

PowerShell

# Exported from gporais.com
# Policy: Enable Structured Exception Handling Overwrite Protection (SEHOP)
# State: Enabled
# Supported on: Au minimum Windows Vista

$path = 'HKLM:\SYSTEM\CurrentControlSet\Control\Session Manager\kernel'
New-Item -Path $path -Force | Out-Null
Set-ItemProperty -Path $path -Name 'DisableExceptionChainValidation' -Value 0 -Type DWord

Vous construisez une collection multi-paramètres ? Ajoutez ce paramètre et générez des exports combinés (.reg, PowerShell, GPO).

Ouvrir le Builder

Intégrer cette GPO sur votre site

Contenu à intégrer
Thème

Ajoute une ligne de script : le thème suit l’apparence de votre site et la hauteur s’ajuste au contenu. Si votre site bloque les scripts, l’intégration suit le thème du système du visiteur.

Aperçu