Supprimer le menu Exécuter du menu Démarrer
Vérifié avec Windows 11 25H2 — mis à jour le 30 juillet 2026
Pris en charge sur : Windows Server 2012 R2, Windows 8.1, Windows RT 8.1, Windows Server 2008, Windows Server 2003, Windows 7, Windows Vista, Windows XP et Windows 2000
Chemin dans la console GPO
Configuration ordinateur\Modèles d'administration\Menu Démarrer et barre des tâches Configuration utilisateur\Modèles d'administration\Menu Démarrer et barre des tâches Description
Vous permet de supprimer la commande Exécuter des menu Démarrer, Internet Explorer et Gestionnaire des tâches. Si vous activez ce paramètre, les modifications suivantes se produisent : (1) La commande Exécuter est supprimée du menu Démarrer. (2) La commande Nouvelle tâche (Exécuter) est supprimée de Gestionnaire des tâches. (3) L’utilisateur ne pourra pas entrer les éléments suivants dans la barre d’adresses Internet Explorer : --- un chemin d’accès UNC : \\<server>\<share> ---Accessing des lecteurs locaux : par ex., C : --- l’accès aux dossiers locaux : par ex., \temp> De plus, les utilisateurs dotés de claviers étendus ne pourront plus afficher la boîte de dialogue Exécuter en appuyant sur la touche Application (la touche avec le logo Windows) + R. Si vous désactivez ou ne configurez pas ce paramètre, les utilisateurs peuvent accéder à la commande Exécuter dans le menu Démarrer et dans Gestionnaire des tâches et utiliser la barre d’adresses Internet Explorer. Remarque : ce paramètre affecte uniquement l’interface spécifiée. Cela n’empêche pas les utilisateurs d’utiliser d’autres méthodes pour exécuter des programmes. Remarque : les applications tierces disposant d’une certification Windows 2000 ou ultérieure doivent respecter ce paramètre.
Registre
Software\Microsoft\Windows\CurrentVersion\Policies\Explorer Software\Microsoft\Windows\CurrentVersion\Policies\Explorer Nom de valeur : NoRun
MDM / Intune (CSP)
./Device/Vendor/MSFT/Policy/Config/ADMX_StartMenu/NoRun ./User/Vendor/MSFT/Policy/Config/ADMX_StartMenu/NoRun Documentation Microsoft Learn Données de correspondance : Microsoft Learn (CC BY 4.0)
Générateur d'exports
BETAConfigurez l'état, la portée et les options, puis générez les sorties .reg, PowerShell, Intune et SCCM — ou ajoutez le paramètre à une collection multi-paramètres.
Ces exports écrivent le registre — ce n'est pas une GPO managée. ⓘ
Appliquer les deux portées crée une configuration ambiguë (la portée ordinateur prévaut sur la portée utilisateur). Ne le faites que volontairement.
Fichier .reg
Windows Registry Editor Version 5.00
; Exported from gporais.com
; Policy: Supprimer le menu Exécuter du menu Démarrer
; State: Enabled
; Scope: Computer (HKLM)
; Supported on: Windows Server 2012 R2, Windows 8.1, Windows RT 8.1, Windows Server 2008, Windows Server 2003, Windows 7, Windows Vista, Windows XP et Windows 2000
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer]
"NoRun"=dword:00000001 Autres formats (PowerShell, Intune, SCCM)
PowerShell
# Exported from gporais.com
# Policy: Supprimer le menu Exécuter du menu Démarrer
# State: Enabled
# Scope: Computer (HKLM)
# Supported on: Windows Server 2012 R2, Windows 8.1, Windows RT 8.1, Windows Server 2008, Windows Server 2003, Windows 7, Windows Vista, Windows XP et Windows 2000
$path = 'HKLM:\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer'
New-Item -Path $path -Force | Out-Null
Set-ItemProperty -Path $path -Name 'NoRun' -Value 1 -Type DWord Intune XML
OMA-URI: ./Device/Vendor/MSFT/Policy/Config/ADMX_StartMenu/NoRun
Data type: String
Value:
<enabled/> Intune Remediation
# === Detection script ===
# Exported from gporais.com
# Policy: Supprimer le menu Exécuter du menu Démarrer
# State: Enabled
# Scope: Computer (HKLM)
# Supported on: Windows Server 2012 R2, Windows 8.1, Windows RT 8.1, Windows Server 2008, Windows Server 2003, Windows 7, Windows Vista, Windows XP et Windows 2000
function Test-RegistryValue {
param(
[Parameter(Mandatory = $true)][string]$Path,
[Parameter(Mandatory = $true)][string]$Name,
[object]$Expected,
[ValidateSet('String', 'DWord', 'MultiString')][string]$Kind = 'String',
[switch]$Absent
)
try {
$item = Get-ItemProperty -LiteralPath $Path -Name $Name -ErrorAction Stop
} catch {
return $Absent.IsPresent
}
if ($Absent.IsPresent) { return $false }
$actual = $item.$Name
if ($Kind -eq 'DWord') { return ([int64]$actual) -eq ([int64]$Expected) }
if ($Kind -eq 'MultiString') {
$actualValues = @($actual)
$expectedValues = @($Expected)
if ($actualValues.Count -ne $expectedValues.Count) { return $false }
for ($i = 0; $i -lt $expectedValues.Count; $i++) {
if ([string]$actualValues[$i] -ne [string]$expectedValues[$i]) { return $false }
}
return $true
}
return [string]$actual -eq [string]$Expected
}
$checks = @(
(Test-RegistryValue -Path 'HKLM:\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer' -Name 'NoRun' -Expected 1 -Kind DWord)
)
if ($checks -notcontains $false) {
Write-Output 'Compliant'
exit 0
}
Write-Output 'Non-compliant'
exit 1
# === Remediation script ===
# Exported from gporais.com
# Policy: Supprimer le menu Exécuter du menu Démarrer
# State: Enabled
# Scope: Computer (HKLM)
# Supported on: Windows Server 2012 R2, Windows 8.1, Windows RT 8.1, Windows Server 2008, Windows Server 2003, Windows 7, Windows Vista, Windows XP et Windows 2000
$path = 'HKLM:\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer'
New-Item -Path $path -Force | Out-Null
Set-ItemProperty -Path $path -Name 'NoRun' -Value 1 -Type DWord Scripts SCCM
# Exported from gporais.com
# Policy: Supprimer le menu Exécuter du menu Démarrer
# State: Enabled
# Scope: Computer (HKLM)
# Supported on: Windows Server 2012 R2, Windows 8.1, Windows RT 8.1, Windows Server 2008, Windows Server 2003, Windows 7, Windows Vista, Windows XP et Windows 2000
# SCCM Configuration Item guidance:
# Create a Configuration Item of type "Setting: Script".
# Discovery script: use the Detection script below.
# Remediation script: use the Remediation script below.
# Compliance rule: the Discovery script output equals 'Compliant'.
# === Detection script ===
# Exported from gporais.com
# Policy: Supprimer le menu Exécuter du menu Démarrer
# State: Enabled
# Scope: Computer (HKLM)
# Supported on: Windows Server 2012 R2, Windows 8.1, Windows RT 8.1, Windows Server 2008, Windows Server 2003, Windows 7, Windows Vista, Windows XP et Windows 2000
function Test-RegistryValue {
param(
[Parameter(Mandatory = $true)][string]$Path,
[Parameter(Mandatory = $true)][string]$Name,
[object]$Expected,
[ValidateSet('String', 'DWord', 'MultiString')][string]$Kind = 'String',
[switch]$Absent
)
try {
$item = Get-ItemProperty -LiteralPath $Path -Name $Name -ErrorAction Stop
} catch {
return $Absent.IsPresent
}
if ($Absent.IsPresent) { return $false }
$actual = $item.$Name
if ($Kind -eq 'DWord') { return ([int64]$actual) -eq ([int64]$Expected) }
if ($Kind -eq 'MultiString') {
$actualValues = @($actual)
$expectedValues = @($Expected)
if ($actualValues.Count -ne $expectedValues.Count) { return $false }
for ($i = 0; $i -lt $expectedValues.Count; $i++) {
if ([string]$actualValues[$i] -ne [string]$expectedValues[$i]) { return $false }
}
return $true
}
return [string]$actual -eq [string]$Expected
}
$checks = @(
(Test-RegistryValue -Path 'HKLM:\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer' -Name 'NoRun' -Expected 1 -Kind DWord)
)
if ($checks -notcontains $false) {
Write-Output 'Compliant'
exit 0
}
Write-Output 'Non-compliant'
exit 1
# === Remediation script ===
# Exported from gporais.com
# Policy: Supprimer le menu Exécuter du menu Démarrer
# State: Enabled
# Scope: Computer (HKLM)
# Supported on: Windows Server 2012 R2, Windows 8.1, Windows RT 8.1, Windows Server 2008, Windows Server 2003, Windows 7, Windows Vista, Windows XP et Windows 2000
$path = 'HKLM:\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer'
New-Item -Path $path -Force | Out-Null
Set-ItemProperty -Path $path -Name 'NoRun' -Value 1 -Type DWord Vous construisez une collection multi-paramètres ? Ajoutez ce paramètre et générez des exports combinés (.reg, PowerShell, GPO).