Supprimer les liens et l’accès à Windows Update
Vérifié avec Windows 11 25H2 — mis à jour le 30 juillet 2026
Pris en charge sur : Au minimum Windows 2000 par le biais de Windows 8.1 ou Windows Server 2012 R2
Chemin dans la console GPO
Configuration utilisateur\Modèles d'administration\Menu Démarrer et barre des tâches Description
Ce paramètre de stratégie vous permet de supprimer les liens et l’accès à Windows Update. Si vous activez ce paramètre de stratégie, les utilisateurs ne peuvent pas se connecter au site Web Windows Update. Le fait d’activer ce paramètre de stratégie bloque l’accès des utilisateurs au site Web Windows Update à l’adresse http://windowsupdate.microsoft.com. Ce paramètre de stratégie supprime également le lien hypertexte Windows Update du menu Démarrer et du menu Outils dans Internet Explorer. Windows Update, l’extension en ligne de Windows, propose des mises à jour logicielles pour maintenir à jour le système d’un utilisateur. Le catalogue de produits Windows Update détermine quels sont les fichiers système, les correctifs de sécurité et les mises à jour Microsoft dont les utilisateurs ont besoin, puis il indique les versions les plus récentes qu’ils peuvent télécharger. Si vous désactivez ce paramètre de stratégie ou si vous ne le configurez pas, le lien hypertexte Windows Update est disponible dans le menu Démarrer et dans le menu Outils dans Internet Explorer. Consultez également le paramètre de stratégie « Masquer l’option Ajouter des programmes de Microsoft ».
Registre
Software\Microsoft\Windows\CurrentVersion\Policies\Explorer Nom de valeur : NoWindowsUpdate
MDM / Intune (CSP)
./User/Vendor/MSFT/Policy/Config/ADMX_StartMenu/NoWindowsUpdate Documentation Microsoft Learn Données de correspondance : Microsoft Learn (CC BY 4.0)
Générateur d'exports
BETAConfigurez l'état, la portée et les options, puis générez les sorties .reg, PowerShell, Intune et SCCM — ou ajoutez le paramètre à une collection multi-paramètres.
Ces exports écrivent le registre — ce n'est pas une GPO managée. ⓘ
Fichier .reg
Windows Registry Editor Version 5.00
; Exported from gporais.com
; Policy: Supprimer les liens et l’accès à Windows Update
; State: Enabled
; Supported on: Au minimum Windows 2000 par le biais de Windows 8.1 ou Windows Server 2012 R2
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer]
"NoWindowsUpdate"=dword:00000001 Autres formats (PowerShell, Intune, SCCM)
PowerShell
# Exported from gporais.com
# Policy: Supprimer les liens et l’accès à Windows Update
# State: Enabled
# Supported on: Au minimum Windows 2000 par le biais de Windows 8.1 ou Windows Server 2012 R2
# Warning: In SYSTEM context (the Intune default), HKCU targets the SYSTEM profile. Run this script using the logged-on credentials.
$path = 'HKCU:\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer'
New-Item -Path $path -Force | Out-Null
Set-ItemProperty -Path $path -Name 'NoWindowsUpdate' -Value 1 -Type DWord Intune XML
OMA-URI: ./User/Vendor/MSFT/Policy/Config/ADMX_StartMenu/NoWindowsUpdate
Data type: String
Value:
<enabled/> Intune Remediation
# === Detection script ===
# Exported from gporais.com
# Policy: Supprimer les liens et l’accès à Windows Update
# State: Enabled
# Supported on: Au minimum Windows 2000 par le biais de Windows 8.1 ou Windows Server 2012 R2
# Warning: In SYSTEM context (the Intune default), HKCU targets the SYSTEM profile. Run this script using the logged-on credentials.
function Test-RegistryValue {
param(
[Parameter(Mandatory = $true)][string]$Path,
[Parameter(Mandatory = $true)][string]$Name,
[object]$Expected,
[ValidateSet('String', 'DWord', 'MultiString')][string]$Kind = 'String',
[switch]$Absent
)
try {
$item = Get-ItemProperty -LiteralPath $Path -Name $Name -ErrorAction Stop
} catch {
return $Absent.IsPresent
}
if ($Absent.IsPresent) { return $false }
$actual = $item.$Name
if ($Kind -eq 'DWord') { return ([int64]$actual) -eq ([int64]$Expected) }
if ($Kind -eq 'MultiString') {
$actualValues = @($actual)
$expectedValues = @($Expected)
if ($actualValues.Count -ne $expectedValues.Count) { return $false }
for ($i = 0; $i -lt $expectedValues.Count; $i++) {
if ([string]$actualValues[$i] -ne [string]$expectedValues[$i]) { return $false }
}
return $true
}
return [string]$actual -eq [string]$Expected
}
$checks = @(
(Test-RegistryValue -Path 'HKCU:\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer' -Name 'NoWindowsUpdate' -Expected 1 -Kind DWord)
)
if ($checks -notcontains $false) {
Write-Output 'Compliant'
exit 0
}
Write-Output 'Non-compliant'
exit 1
# === Remediation script ===
# Exported from gporais.com
# Policy: Supprimer les liens et l’accès à Windows Update
# State: Enabled
# Supported on: Au minimum Windows 2000 par le biais de Windows 8.1 ou Windows Server 2012 R2
# Warning: In SYSTEM context (the Intune default), HKCU targets the SYSTEM profile. Run this script using the logged-on credentials.
$path = 'HKCU:\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer'
New-Item -Path $path -Force | Out-Null
Set-ItemProperty -Path $path -Name 'NoWindowsUpdate' -Value 1 -Type DWord Scripts SCCM
# Exported from gporais.com
# Policy: Supprimer les liens et l’accès à Windows Update
# State: Enabled
# Supported on: Au minimum Windows 2000 par le biais de Windows 8.1 ou Windows Server 2012 R2
# SCCM Configuration Item guidance:
# Create a Configuration Item of type "Setting: Script".
# Discovery script: use the Detection script below.
# Remediation script: use the Remediation script below.
# Compliance rule: the Discovery script output equals 'Compliant'.
# === Detection script ===
# Exported from gporais.com
# Policy: Supprimer les liens et l’accès à Windows Update
# State: Enabled
# Supported on: Au minimum Windows 2000 par le biais de Windows 8.1 ou Windows Server 2012 R2
# Warning: In SYSTEM context (the Intune default), HKCU targets the SYSTEM profile. Run this script using the logged-on credentials.
function Test-RegistryValue {
param(
[Parameter(Mandatory = $true)][string]$Path,
[Parameter(Mandatory = $true)][string]$Name,
[object]$Expected,
[ValidateSet('String', 'DWord', 'MultiString')][string]$Kind = 'String',
[switch]$Absent
)
try {
$item = Get-ItemProperty -LiteralPath $Path -Name $Name -ErrorAction Stop
} catch {
return $Absent.IsPresent
}
if ($Absent.IsPresent) { return $false }
$actual = $item.$Name
if ($Kind -eq 'DWord') { return ([int64]$actual) -eq ([int64]$Expected) }
if ($Kind -eq 'MultiString') {
$actualValues = @($actual)
$expectedValues = @($Expected)
if ($actualValues.Count -ne $expectedValues.Count) { return $false }
for ($i = 0; $i -lt $expectedValues.Count; $i++) {
if ([string]$actualValues[$i] -ne [string]$expectedValues[$i]) { return $false }
}
return $true
}
return [string]$actual -eq [string]$Expected
}
$checks = @(
(Test-RegistryValue -Path 'HKCU:\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer' -Name 'NoWindowsUpdate' -Expected 1 -Kind DWord)
)
if ($checks -notcontains $false) {
Write-Output 'Compliant'
exit 0
}
Write-Output 'Non-compliant'
exit 1
# === Remediation script ===
# Exported from gporais.com
# Policy: Supprimer les liens et l’accès à Windows Update
# State: Enabled
# Supported on: Au minimum Windows 2000 par le biais de Windows 8.1 ou Windows Server 2012 R2
# Warning: In SYSTEM context (the Intune default), HKCU targets the SYSTEM profile. Run this script using the logged-on credentials.
$path = 'HKCU:\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer'
New-Item -Path $path -Force | Out-Null
Set-ItemProperty -Path $path -Name 'NoWindowsUpdate' -Value 1 -Type DWord Vous construisez une collection multi-paramètres ? Ajoutez ce paramètre et générez des exports combinés (.reg, PowerShell, GPO).