Interdire le parcours
Vérifié avec Windows 11 25H2 — mis à jour le 10 juillet 2026
Pris en charge sur : Windows Server 2003, Windows XP et Windows 2000 uniquement
Chemin dans la console GPO
Configuration utilisateur\Modèles d'administration\Composants Windows\Planificateur de tâches Description
Limite les nouvelles planifications aux éléments figurant dans le menu Démarrer de l'utilisateur et empêche ce dernier de changer les programmes planifiés pour les tâches existantes. Ce paramètre supprime le bouton Parcourir de l'Assistant Tâche planifiée et de l'onglet Tâche de la boîte de dialogue des propriétés des tâches. Les utilisateurs ne peuvent pas modifier le contenu de la zone Exécuter ou Démarrer dans, qui détermine le programme et le chemin d'accès d'une tâche. Par conséquent, quand les utilisateurs créent une tâche, ils doivent sélectionner un programme dans une liste dans l'Assistant Tâche planifiée, qui n'affiche que la tâche qui apparaît dans le menu Démarrer et ses sous-menus. Une fois qu'une tâche est créée, les utilisateurs ne peuvent pas modifier le programme exécuté par la tâche. Important : ce paramètre n'empêche pas les utilisateurs de créer une nouvelle tâche en collant ou faisant glisser n'importe quel programme dans le dossier des tâches planifiées. Pour empêcher cette action, utilisez le paramètre Empêcher le glisser-déplacer. Remarque : ce paramètre apparaît dans les dossiers Configuration de l'ordinateur et Configuration de l'utilisateur. Si les deux paramètres sont configurés, le paramètre défini dans Configuration de l'ordinateur prévaut sur le paramètre défini dans Configuration de l'utilisateur.
Registre
Software\Policies\Microsoft\Windows\Task Scheduler5.0 Nom de valeur : Allow Browse
Générateur d'exports
BETAConfigurez l'état, la portée et les options, puis générez les sorties .reg, PowerShell, Intune et SCCM — ou ajoutez le paramètre à une collection multi-paramètres.
Ces exports écrivent le registre — ce n'est pas une GPO managée. ⓘ
Fichier .reg
Windows Registry Editor Version 5.00
; Exported from gporais.com
; Policy: Interdire le parcours
; State: Enabled
; Supported on: Windows Server 2003, Windows XP et Windows 2000 uniquement
[HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Task Scheduler5.0]
"Allow Browse"=dword:00000001 Autres formats (PowerShell, Intune, SCCM)
PowerShell
# Exported from gporais.com
# Policy: Interdire le parcours
# State: Enabled
# Supported on: Windows Server 2003, Windows XP et Windows 2000 uniquement
# Warning: In SYSTEM context (the Intune default), HKCU targets the SYSTEM profile. Run this script using the logged-on credentials.
$path = 'HKCU:\Software\Policies\Microsoft\Windows\Task Scheduler5.0'
New-Item -Path $path -Force | Out-Null
Set-ItemProperty -Path $path -Name 'Allow Browse' -Value 1 -Type DWord Intune XML
Aucune correspondance directe Policy CSP / OMA-URI pour cette stratégie. Utilisez l'onglet Intune Remediation, ou importez l'ADMX dans Intune. Intune Remediation
# === Detection script ===
# Exported from gporais.com
# Policy: Interdire le parcours
# State: Enabled
# Supported on: Windows Server 2003, Windows XP et Windows 2000 uniquement
# Warning: In SYSTEM context (the Intune default), HKCU targets the SYSTEM profile. Run this script using the logged-on credentials.
function Test-RegistryValue {
param(
[Parameter(Mandatory = $true)][string]$Path,
[Parameter(Mandatory = $true)][string]$Name,
[object]$Expected,
[ValidateSet('String', 'DWord', 'MultiString')][string]$Kind = 'String',
[switch]$Absent
)
try {
$item = Get-ItemProperty -LiteralPath $Path -Name $Name -ErrorAction Stop
} catch {
return $Absent.IsPresent
}
if ($Absent.IsPresent) { return $false }
$actual = $item.$Name
if ($Kind -eq 'DWord') { return ([int64]$actual) -eq ([int64]$Expected) }
if ($Kind -eq 'MultiString') {
$actualValues = @($actual)
$expectedValues = @($Expected)
if ($actualValues.Count -ne $expectedValues.Count) { return $false }
for ($i = 0; $i -lt $expectedValues.Count; $i++) {
if ([string]$actualValues[$i] -ne [string]$expectedValues[$i]) { return $false }
}
return $true
}
return [string]$actual -eq [string]$Expected
}
$checks = @(
(Test-RegistryValue -Path 'HKCU:\Software\Policies\Microsoft\Windows\Task Scheduler5.0' -Name 'Allow Browse' -Expected 1 -Kind DWord)
)
if ($checks -notcontains $false) {
Write-Output 'Compliant'
exit 0
}
Write-Output 'Non-compliant'
exit 1
# === Remediation script ===
# Exported from gporais.com
# Policy: Interdire le parcours
# State: Enabled
# Supported on: Windows Server 2003, Windows XP et Windows 2000 uniquement
# Warning: In SYSTEM context (the Intune default), HKCU targets the SYSTEM profile. Run this script using the logged-on credentials.
$path = 'HKCU:\Software\Policies\Microsoft\Windows\Task Scheduler5.0'
New-Item -Path $path -Force | Out-Null
Set-ItemProperty -Path $path -Name 'Allow Browse' -Value 1 -Type DWord Scripts SCCM
# Exported from gporais.com
# Policy: Interdire le parcours
# State: Enabled
# Supported on: Windows Server 2003, Windows XP et Windows 2000 uniquement
# SCCM Configuration Item guidance:
# Create a Configuration Item of type "Setting: Script".
# Discovery script: use the Detection script below.
# Remediation script: use the Remediation script below.
# Compliance rule: the Discovery script output equals 'Compliant'.
# === Detection script ===
# Exported from gporais.com
# Policy: Interdire le parcours
# State: Enabled
# Supported on: Windows Server 2003, Windows XP et Windows 2000 uniquement
# Warning: In SYSTEM context (the Intune default), HKCU targets the SYSTEM profile. Run this script using the logged-on credentials.
function Test-RegistryValue {
param(
[Parameter(Mandatory = $true)][string]$Path,
[Parameter(Mandatory = $true)][string]$Name,
[object]$Expected,
[ValidateSet('String', 'DWord', 'MultiString')][string]$Kind = 'String',
[switch]$Absent
)
try {
$item = Get-ItemProperty -LiteralPath $Path -Name $Name -ErrorAction Stop
} catch {
return $Absent.IsPresent
}
if ($Absent.IsPresent) { return $false }
$actual = $item.$Name
if ($Kind -eq 'DWord') { return ([int64]$actual) -eq ([int64]$Expected) }
if ($Kind -eq 'MultiString') {
$actualValues = @($actual)
$expectedValues = @($Expected)
if ($actualValues.Count -ne $expectedValues.Count) { return $false }
for ($i = 0; $i -lt $expectedValues.Count; $i++) {
if ([string]$actualValues[$i] -ne [string]$expectedValues[$i]) { return $false }
}
return $true
}
return [string]$actual -eq [string]$Expected
}
$checks = @(
(Test-RegistryValue -Path 'HKCU:\Software\Policies\Microsoft\Windows\Task Scheduler5.0' -Name 'Allow Browse' -Expected 1 -Kind DWord)
)
if ($checks -notcontains $false) {
Write-Output 'Compliant'
exit 0
}
Write-Output 'Non-compliant'
exit 1
# === Remediation script ===
# Exported from gporais.com
# Policy: Interdire le parcours
# State: Enabled
# Supported on: Windows Server 2003, Windows XP et Windows 2000 uniquement
# Warning: In SYSTEM context (the Intune default), HKCU targets the SYSTEM profile. Run this script using the logged-on credentials.
$path = 'HKCU:\Software\Policies\Microsoft\Windows\Task Scheduler5.0'
New-Item -Path $path -Force | Out-Null
Set-ItemProperty -Path $path -Name 'Allow Browse' -Value 1 -Type DWord Vous construisez une collection multi-paramètres ? Ajoutez ce paramètre et générez des exports combinés (.reg, PowerShell, GPO).