Demander des informations d’identification sur l’ordinateur client
Vérifié avec Windows 11 25H2 — mis à jour le 30 juillet 2026
Pris en charge sur : Au minimum Windows Vista avec Service Pack 1
Chemin dans la console GPO
Configuration ordinateur\Modèles d'administration\Composants Windows\Services Bureau à distance\Client Connexion Bureau à distance Description
Ce paramètre de stratégie détermine si un utilisateur est invité à fournir sur l’ordinateur client des informations d’identification pour établir une connexion à distance à un serveur Hôte de session Bureau à distance. Si vous activez ce paramètre de stratégie, un utilisateur est invité à fournir sur l’ordinateur client, plutôt que sur le serveur Hôte de session Bureau à distance, des informations d’identification pour établir une connexion à distance à un serveur Hôte de session Bureau à distance. Si les informations d’identification de l’utilisateur sont enregistrées sur l’ordinateur client, l’utilisateur n’est pas invité à les fournir de nouveau. Remarque : si vous activez ce paramètre de stratégie dans des versions de Windows Server 2008 R2 avec SP1 ou Windows Server 2008 R2 et qu’un utilisateur est invité, sur l’ordinateur client et sur le serveur Hôte de session Bureau à distance, à fournir des informations d’identification, désactivez la case à cocher Toujours demander un mot de passe dans l’onglet Paramètres d’ouverture de session de l’outil Configuration d’hôte de session Bureau à distance. Si vous désactivez ou ne configurez pas ce paramètre de stratégie, la version du système d’exploitation du serveur Hôte de session Bureau à distance détermine à quel moment un utilisateur est invité à fournir des informations d’identification pour établir une connexion à distance à un serveur Hôte de session Bureau à distance. Pour Windows Server 2003 et Windows 2000 Server, un utilisateur est invité sur le serveur Terminal Server à fournir des informations d’identification pour établir une connexion à distance. Pour Windows Server 2008 et Windows Server 2008 R2, un utilisateur est invité sur l’ordinateur client à fournir des informations d’identification pour établir une connexion à distance.
Registre
SOFTWARE\Policies\Microsoft\Windows NT\Terminal Services Nom de valeur : PromptForCredsOnClient
Activé : PromptForCredsOnClient = 1
Désactivé : PromptForCredsOnClient = 0
MDM / Intune (CSP)
./Device/Vendor/MSFT/Policy/Config/ADMX_TerminalServer/TS_PROMT_CREDS_CLIENT_COMP Documentation Microsoft Learn Données de correspondance : Microsoft Learn (CC BY 4.0)
Générateur d'exports
BETAConfigurez l'état, la portée et les options, puis générez les sorties .reg, PowerShell, Intune et SCCM — ou ajoutez le paramètre à une collection multi-paramètres.
Ces exports écrivent le registre — ce n'est pas une GPO managée. ⓘ
Fichier .reg
Windows Registry Editor Version 5.00
; Exported from gporais.com
; Policy: Demander des informations d’identification sur l’ordinateur client
; State: Enabled
; Supported on: Au minimum Windows Vista avec Service Pack 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\Terminal Services]
"PromptForCredsOnClient"=dword:00000001 Autres formats (PowerShell, Intune, SCCM)
PowerShell
# Exported from gporais.com
# Policy: Demander des informations d’identification sur l’ordinateur client
# State: Enabled
# Supported on: Au minimum Windows Vista avec Service Pack 1
$path = 'HKLM:\SOFTWARE\Policies\Microsoft\Windows NT\Terminal Services'
New-Item -Path $path -Force | Out-Null
Set-ItemProperty -Path $path -Name 'PromptForCredsOnClient' -Value 1 -Type DWord Intune XML
OMA-URI: ./Device/Vendor/MSFT/Policy/Config/ADMX_TerminalServer/TS_PROMT_CREDS_CLIENT_COMP
Data type: String
Value:
<enabled/> Intune Remediation
# === Detection script ===
# Exported from gporais.com
# Policy: Demander des informations d’identification sur l’ordinateur client
# State: Enabled
# Supported on: Au minimum Windows Vista avec Service Pack 1
function Test-RegistryValue {
param(
[Parameter(Mandatory = $true)][string]$Path,
[Parameter(Mandatory = $true)][string]$Name,
[object]$Expected,
[ValidateSet('String', 'DWord', 'MultiString')][string]$Kind = 'String',
[switch]$Absent
)
try {
$item = Get-ItemProperty -LiteralPath $Path -Name $Name -ErrorAction Stop
} catch {
return $Absent.IsPresent
}
if ($Absent.IsPresent) { return $false }
$actual = $item.$Name
if ($Kind -eq 'DWord') { return ([int64]$actual) -eq ([int64]$Expected) }
if ($Kind -eq 'MultiString') {
$actualValues = @($actual)
$expectedValues = @($Expected)
if ($actualValues.Count -ne $expectedValues.Count) { return $false }
for ($i = 0; $i -lt $expectedValues.Count; $i++) {
if ([string]$actualValues[$i] -ne [string]$expectedValues[$i]) { return $false }
}
return $true
}
return [string]$actual -eq [string]$Expected
}
$checks = @(
(Test-RegistryValue -Path 'HKLM:\SOFTWARE\Policies\Microsoft\Windows NT\Terminal Services' -Name 'PromptForCredsOnClient' -Expected 1 -Kind DWord)
)
if ($checks -notcontains $false) {
Write-Output 'Compliant'
exit 0
}
Write-Output 'Non-compliant'
exit 1
# === Remediation script ===
# Exported from gporais.com
# Policy: Demander des informations d’identification sur l’ordinateur client
# State: Enabled
# Supported on: Au minimum Windows Vista avec Service Pack 1
$path = 'HKLM:\SOFTWARE\Policies\Microsoft\Windows NT\Terminal Services'
New-Item -Path $path -Force | Out-Null
Set-ItemProperty -Path $path -Name 'PromptForCredsOnClient' -Value 1 -Type DWord Scripts SCCM
# Exported from gporais.com
# Policy: Demander des informations d’identification sur l’ordinateur client
# State: Enabled
# Supported on: Au minimum Windows Vista avec Service Pack 1
# SCCM Configuration Item guidance:
# Create a Configuration Item of type "Setting: Script".
# Discovery script: use the Detection script below.
# Remediation script: use the Remediation script below.
# Compliance rule: the Discovery script output equals 'Compliant'.
# === Detection script ===
# Exported from gporais.com
# Policy: Demander des informations d’identification sur l’ordinateur client
# State: Enabled
# Supported on: Au minimum Windows Vista avec Service Pack 1
function Test-RegistryValue {
param(
[Parameter(Mandatory = $true)][string]$Path,
[Parameter(Mandatory = $true)][string]$Name,
[object]$Expected,
[ValidateSet('String', 'DWord', 'MultiString')][string]$Kind = 'String',
[switch]$Absent
)
try {
$item = Get-ItemProperty -LiteralPath $Path -Name $Name -ErrorAction Stop
} catch {
return $Absent.IsPresent
}
if ($Absent.IsPresent) { return $false }
$actual = $item.$Name
if ($Kind -eq 'DWord') { return ([int64]$actual) -eq ([int64]$Expected) }
if ($Kind -eq 'MultiString') {
$actualValues = @($actual)
$expectedValues = @($Expected)
if ($actualValues.Count -ne $expectedValues.Count) { return $false }
for ($i = 0; $i -lt $expectedValues.Count; $i++) {
if ([string]$actualValues[$i] -ne [string]$expectedValues[$i]) { return $false }
}
return $true
}
return [string]$actual -eq [string]$Expected
}
$checks = @(
(Test-RegistryValue -Path 'HKLM:\SOFTWARE\Policies\Microsoft\Windows NT\Terminal Services' -Name 'PromptForCredsOnClient' -Expected 1 -Kind DWord)
)
if ($checks -notcontains $false) {
Write-Output 'Compliant'
exit 0
}
Write-Output 'Non-compliant'
exit 1
# === Remediation script ===
# Exported from gporais.com
# Policy: Demander des informations d’identification sur l’ordinateur client
# State: Enabled
# Supported on: Au minimum Windows Vista avec Service Pack 1
$path = 'HKLM:\SOFTWARE\Policies\Microsoft\Windows NT\Terminal Services'
New-Item -Path $path -Force | Out-Null
Set-ItemProperty -Path $path -Name 'PromptForCredsOnClient' -Value 1 -Type DWord Vous construisez une collection multi-paramètres ? Ajoutez ce paramètre et générez des exports combinés (.reg, PowerShell, GPO).