Ne pas exécuter les applications Windows spécifiées
Vérifié avec Windows 11 25H2 — mis à jour le 30 juillet 2026
Pris en charge sur : Au minimum Windows 2000
Chemin dans la console GPO
Configuration utilisateur\Modèles d'administration\Système Description
Empêche Windows d’exécuter les programmes spécifiés dans ce paramètre de stratégie. Si vous activez ce paramètre de stratégie, les utilisateurs ne peuvent pas exécuter les programmes que vous ajoutez à la liste des applications non autorisées. Si vous désactivez ou ne configurez pas ce paramètre de stratégie, les utilisateurs peuvent exécuter tous les programmes. Ce paramètre de stratégie empêche uniquement les utilisateurs d’exécuter des programmes qui sont démarrés par le processus de l’Explorateur de fichiers. L’exécution de programmes lancés par le processus système ou par d’autres processus, tels que le Gestionnaire des tâches, demeure autorisée pour les utilisateurs. De plus, si les utilisateurs ont accès à l’invite de commandes (Cmd.exe), ce paramètre de stratégie ne les empêche pas de démarrer des programmes dans la fenêtre de commandes alors que cela ne serait pas possible dans l’Explorateur de fichiers. Remarque : les applications tierces disposant d’une certification Windows 2000 ou version ultérieure doivent impérativement se conformer à ce paramètre de stratégie. Remarque : pour créer une liste des applications autorisées, cliquez sur Afficher. Indiquez le nom du fichier exécutable de l’application (par exemple, Winword.exe, Poledit.exe, Powerpnt.exe) dans la colonne Valeur de la boîte de dialogue Afficher le contenu.
Registre
Software\Microsoft\Windows\CurrentVersion\Policies\Explorer Nom de valeur : DisallowRun
MDM / Intune (CSP)
./User/Vendor/MSFT/Policy/Config/ADMX_ShellCommandPromptRegEditTools/DisallowApps Documentation Microsoft Learn Données de correspondance : Microsoft Learn (CC BY 4.0)
Générateur d'exports
BETAConfigurez l'état, la portée et les options, puis générez les sorties .reg, PowerShell, Intune et SCCM — ou ajoutez le paramètre à une collection multi-paramètres.
Ces exports écrivent le registre — ce n'est pas une GPO managée. ⓘ
Fichier .reg
Windows Registry Editor Version 5.00
; Exported from gporais.com
; Policy: Ne pas exécuter les applications Windows spécifiées
; State: Enabled
; Supported on: Au minimum Windows 2000
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer]
"DisallowRun"=dword:00000001
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisallowRun]
; List values: enter one value per line in the builder UI. Autres formats (PowerShell, Intune, SCCM)
PowerShell
# Exported from gporais.com
# Policy: Ne pas exécuter les applications Windows spécifiées
# State: Enabled
# Supported on: Au minimum Windows 2000
# Warning: In SYSTEM context (the Intune default), HKCU targets the SYSTEM profile. Run this script using the logged-on credentials.
$path = 'HKCU:\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer'
New-Item -Path $path -Force | Out-Null
Set-ItemProperty -Path $path -Name 'DisallowRun' -Value 1 -Type DWord
$path = 'HKCU:\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisallowRun'
New-Item -Path $path -Force | Out-Null
# List values: enter one value per line in the builder UI. Intune XML
OMA-URI: ./User/Vendor/MSFT/Policy/Config/ADMX_ShellCommandPromptRegEditTools/DisallowApps
Data type: String
Value:
<enabled/>
<!-- DisallowAppsList: enter one value per line before copying this XML payload. --> Intune Remediation
# === Detection script ===
# Exported from gporais.com
# Policy: Ne pas exécuter les applications Windows spécifiées
# State: Enabled
# Supported on: Au minimum Windows 2000
# Warning: In SYSTEM context (the Intune default), HKCU targets the SYSTEM profile. Run this script using the logged-on credentials.
function Test-RegistryValue {
param(
[Parameter(Mandatory = $true)][string]$Path,
[Parameter(Mandatory = $true)][string]$Name,
[object]$Expected,
[ValidateSet('String', 'DWord', 'MultiString')][string]$Kind = 'String',
[switch]$Absent
)
try {
$item = Get-ItemProperty -LiteralPath $Path -Name $Name -ErrorAction Stop
} catch {
return $Absent.IsPresent
}
if ($Absent.IsPresent) { return $false }
$actual = $item.$Name
if ($Kind -eq 'DWord') { return ([int64]$actual) -eq ([int64]$Expected) }
if ($Kind -eq 'MultiString') {
$actualValues = @($actual)
$expectedValues = @($Expected)
if ($actualValues.Count -ne $expectedValues.Count) { return $false }
for ($i = 0; $i -lt $expectedValues.Count; $i++) {
if ([string]$actualValues[$i] -ne [string]$expectedValues[$i]) { return $false }
}
return $true
}
return [string]$actual -eq [string]$Expected
}
# HKCU:\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisallowRun: List values: enter one value per line in the builder UI.
$checks = @(
(Test-RegistryValue -Path 'HKCU:\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer' -Name 'DisallowRun' -Expected 1 -Kind DWord)
)
if ($checks -notcontains $false) {
Write-Output 'Compliant'
exit 0
}
Write-Output 'Non-compliant'
exit 1
# === Remediation script ===
# Exported from gporais.com
# Policy: Ne pas exécuter les applications Windows spécifiées
# State: Enabled
# Supported on: Au minimum Windows 2000
# Warning: In SYSTEM context (the Intune default), HKCU targets the SYSTEM profile. Run this script using the logged-on credentials.
$path = 'HKCU:\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer'
New-Item -Path $path -Force | Out-Null
Set-ItemProperty -Path $path -Name 'DisallowRun' -Value 1 -Type DWord
$path = 'HKCU:\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisallowRun'
New-Item -Path $path -Force | Out-Null
# List values: enter one value per line in the builder UI. Scripts SCCM
# Exported from gporais.com
# Policy: Ne pas exécuter les applications Windows spécifiées
# State: Enabled
# Supported on: Au minimum Windows 2000
# SCCM Configuration Item guidance:
# Create a Configuration Item of type "Setting: Script".
# Discovery script: use the Detection script below.
# Remediation script: use the Remediation script below.
# Compliance rule: the Discovery script output equals 'Compliant'.
# === Detection script ===
# Exported from gporais.com
# Policy: Ne pas exécuter les applications Windows spécifiées
# State: Enabled
# Supported on: Au minimum Windows 2000
# Warning: In SYSTEM context (the Intune default), HKCU targets the SYSTEM profile. Run this script using the logged-on credentials.
function Test-RegistryValue {
param(
[Parameter(Mandatory = $true)][string]$Path,
[Parameter(Mandatory = $true)][string]$Name,
[object]$Expected,
[ValidateSet('String', 'DWord', 'MultiString')][string]$Kind = 'String',
[switch]$Absent
)
try {
$item = Get-ItemProperty -LiteralPath $Path -Name $Name -ErrorAction Stop
} catch {
return $Absent.IsPresent
}
if ($Absent.IsPresent) { return $false }
$actual = $item.$Name
if ($Kind -eq 'DWord') { return ([int64]$actual) -eq ([int64]$Expected) }
if ($Kind -eq 'MultiString') {
$actualValues = @($actual)
$expectedValues = @($Expected)
if ($actualValues.Count -ne $expectedValues.Count) { return $false }
for ($i = 0; $i -lt $expectedValues.Count; $i++) {
if ([string]$actualValues[$i] -ne [string]$expectedValues[$i]) { return $false }
}
return $true
}
return [string]$actual -eq [string]$Expected
}
# HKCU:\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisallowRun: List values: enter one value per line in the builder UI.
$checks = @(
(Test-RegistryValue -Path 'HKCU:\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer' -Name 'DisallowRun' -Expected 1 -Kind DWord)
)
if ($checks -notcontains $false) {
Write-Output 'Compliant'
exit 0
}
Write-Output 'Non-compliant'
exit 1
# === Remediation script ===
# Exported from gporais.com
# Policy: Ne pas exécuter les applications Windows spécifiées
# State: Enabled
# Supported on: Au minimum Windows 2000
# Warning: In SYSTEM context (the Intune default), HKCU targets the SYSTEM profile. Run this script using the logged-on credentials.
$path = 'HKCU:\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer'
New-Item -Path $path -Force | Out-Null
Set-ItemProperty -Path $path -Name 'DisallowRun' -Value 1 -Type DWord
$path = 'HKCU:\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisallowRun'
New-Item -Path $path -Force | Out-Null
# List values: enter one value per line in the builder UI. Vous construisez une collection multi-paramètres ? Ajoutez ce paramètre et générez des exports combinés (.reg, PowerShell, GPO).