Détails concernant la stratégie cloud
Vérifié avec Windows 11 25H2 — mis à jour le 30 juillet 2026
Pris en charge sur : Au moins Windows 10 version 1909
Chemin dans la console GPO
Configuration ordinateur\Modèles d'administration\Composants Windows\Restrictions de client Description
Ce paramètre active et configure la fonctionnalité de restrictions de locataire basées sur les appareils pour Microsoft Azure Active Directory. Lorsque vous activez ce paramètre, les applications conformes ne pourront pas accéder aux locataires non autorisés, conformément à une stratégie définie dans votre locataire Microsoft Azure Active Directory. Remarque : La création d'une stratégie dans votre locataire d'accueil est requise et des mesures de sécurité supplémentaires pour les appareils gérés sont recommandées pour une meilleure protection. Reportez-vous aux Restrictions du locataire Microsoft Azure Active Directory pour plus de détails. https://go.microsoft.com/fwlink/?linkid=2148762 Avant d'activer la protection par pare-feu, assurez-vous qu'une stratégie Contrôle des applications pour entreprise qui balise correctement les applications a été appliquée aux appareils cibles. L’activation de la protection par pare-feu sans stratégie Contrôle des applications pour entreprise correspondante empêchera toutes les applications d’atteindre les points de terminaison Microsoft. Ce paramètre de pare-feu n'est pas pris en charge sur toutes les versions de Windows. Consultez le lien suivant pour plus d'informations. Pour plus de détails sur la configuration de WDAC avec des restrictions de locataire, consultez https://go.microsoft.com/fwlink/?linkid=2155230
Registre
SOFTWARE\Policies\Microsoft\Windows\TenantRestrictions\Payload MDM / Intune (CSP)
./Device/Vendor/MSFT/Policy/Config/TenantRestrictions/ConfigureTenantRestrictions Documentation Microsoft Learn Données de correspondance : Microsoft Learn (CC BY 4.0)
Générateur d'exports
BETAConfigurez l'état, la portée et les options, puis générez les sorties .reg, PowerShell, Intune et SCCM — ou ajoutez le paramètre à une collection multi-paramètres.
Ces exports écrivent le registre — ce n'est pas une GPO managée. ⓘ
Fichier .reg
Windows Registry Editor Version 5.00
; Exported from gporais.com
; Policy: Détails concernant la stratégie cloud
; State: Enabled
; Supported on: Au moins Windows 10 version 1909
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\TenantRestrictions\Payload]
"cloudid"=""
"tenantid"=""
"policyid"=""
"enforceFirewall"=dword:00000000
"hostnames"=hex(7):00,00
; REG_MULTI_SZ: one string per input line; edit in regedit if you need richer formatting.
"subdomainSupportedHostnames"=hex(7):00,00
; REG_MULTI_SZ: one string per input line; edit in regedit if you need richer formatting.
"ipRanges"=hex(7):00,00
; REG_MULTI_SZ: one string per input line; edit in regedit if you need richer formatting. Autres formats (PowerShell, Intune, SCCM)
PowerShell
# Exported from gporais.com
# Policy: Détails concernant la stratégie cloud
# State: Enabled
# Supported on: Au moins Windows 10 version 1909
$path = 'HKLM:\SOFTWARE\Policies\Microsoft\Windows\TenantRestrictions\Payload'
New-Item -Path $path -Force | Out-Null
Set-ItemProperty -Path $path -Name 'cloudid' -Value '' -Type String
Set-ItemProperty -Path $path -Name 'tenantid' -Value '' -Type String
Set-ItemProperty -Path $path -Name 'policyid' -Value '' -Type String
Set-ItemProperty -Path $path -Name 'enforceFirewall' -Value 0 -Type DWord
Set-ItemProperty -Path $path -Name 'hostnames' -Value @() -Type MultiString
# REG_MULTI_SZ: one string per input line; edit in regedit if you need richer formatting.
Set-ItemProperty -Path $path -Name 'subdomainSupportedHostnames' -Value @() -Type MultiString
# REG_MULTI_SZ: one string per input line; edit in regedit if you need richer formatting.
Set-ItemProperty -Path $path -Name 'ipRanges' -Value @() -Type MultiString
# REG_MULTI_SZ: one string per input line; edit in regedit if you need richer formatting. Intune XML
OMA-URI: ./Device/Vendor/MSFT/Policy/Config/TenantRestrictions/ConfigureTenantRestrictions
Data type: String
Value:
<enabled/>
<data id="PayloadCloudId" value=""/>
<data id="PayloadTenantId" value=""/>
<data id="PayloadPolicyId" value=""/>
<data id="EnforceFirewall" value="0"/>
<!-- PayloadHostnamesId: enter one value per line before copying this XML payload. -->
<!-- PayloadSubdomainSupportedHostnamesId: enter one value per line before copying this XML payload. -->
<!-- PayloadIpRangesId: enter one value per line before copying this XML payload. --> Intune Remediation
# === Detection script ===
# Exported from gporais.com
# Policy: Détails concernant la stratégie cloud
# State: Enabled
# Supported on: Au moins Windows 10 version 1909
function Test-RegistryValue {
param(
[Parameter(Mandatory = $true)][string]$Path,
[Parameter(Mandatory = $true)][string]$Name,
[object]$Expected,
[ValidateSet('String', 'DWord', 'MultiString')][string]$Kind = 'String',
[switch]$Absent
)
try {
$item = Get-ItemProperty -LiteralPath $Path -Name $Name -ErrorAction Stop
} catch {
return $Absent.IsPresent
}
if ($Absent.IsPresent) { return $false }
$actual = $item.$Name
if ($Kind -eq 'DWord') { return ([int64]$actual) -eq ([int64]$Expected) }
if ($Kind -eq 'MultiString') {
$actualValues = @($actual)
$expectedValues = @($Expected)
if ($actualValues.Count -ne $expectedValues.Count) { return $false }
for ($i = 0; $i -lt $expectedValues.Count; $i++) {
if ([string]$actualValues[$i] -ne [string]$expectedValues[$i]) { return $false }
}
return $true
}
return [string]$actual -eq [string]$Expected
}
$checks = @(
(Test-RegistryValue -Path 'HKLM:\SOFTWARE\Policies\Microsoft\Windows\TenantRestrictions\Payload' -Name 'cloudid' -Expected '' -Kind String)
(Test-RegistryValue -Path 'HKLM:\SOFTWARE\Policies\Microsoft\Windows\TenantRestrictions\Payload' -Name 'tenantid' -Expected '' -Kind String)
(Test-RegistryValue -Path 'HKLM:\SOFTWARE\Policies\Microsoft\Windows\TenantRestrictions\Payload' -Name 'policyid' -Expected '' -Kind String)
(Test-RegistryValue -Path 'HKLM:\SOFTWARE\Policies\Microsoft\Windows\TenantRestrictions\Payload' -Name 'enforceFirewall' -Expected 0 -Kind DWord)
(Test-RegistryValue -Path 'HKLM:\SOFTWARE\Policies\Microsoft\Windows\TenantRestrictions\Payload' -Name 'hostnames' -Expected @() -Kind MultiString)
(Test-RegistryValue -Path 'HKLM:\SOFTWARE\Policies\Microsoft\Windows\TenantRestrictions\Payload' -Name 'subdomainSupportedHostnames' -Expected @() -Kind MultiString)
(Test-RegistryValue -Path 'HKLM:\SOFTWARE\Policies\Microsoft\Windows\TenantRestrictions\Payload' -Name 'ipRanges' -Expected @() -Kind MultiString)
)
if ($checks -notcontains $false) {
Write-Output 'Compliant'
exit 0
}
Write-Output 'Non-compliant'
exit 1
# === Remediation script ===
# Exported from gporais.com
# Policy: Détails concernant la stratégie cloud
# State: Enabled
# Supported on: Au moins Windows 10 version 1909
$path = 'HKLM:\SOFTWARE\Policies\Microsoft\Windows\TenantRestrictions\Payload'
New-Item -Path $path -Force | Out-Null
Set-ItemProperty -Path $path -Name 'cloudid' -Value '' -Type String
Set-ItemProperty -Path $path -Name 'tenantid' -Value '' -Type String
Set-ItemProperty -Path $path -Name 'policyid' -Value '' -Type String
Set-ItemProperty -Path $path -Name 'enforceFirewall' -Value 0 -Type DWord
Set-ItemProperty -Path $path -Name 'hostnames' -Value @() -Type MultiString
# REG_MULTI_SZ: one string per input line; edit in regedit if you need richer formatting.
Set-ItemProperty -Path $path -Name 'subdomainSupportedHostnames' -Value @() -Type MultiString
# REG_MULTI_SZ: one string per input line; edit in regedit if you need richer formatting.
Set-ItemProperty -Path $path -Name 'ipRanges' -Value @() -Type MultiString
# REG_MULTI_SZ: one string per input line; edit in regedit if you need richer formatting. Scripts SCCM
# Exported from gporais.com
# Policy: Détails concernant la stratégie cloud
# State: Enabled
# Supported on: Au moins Windows 10 version 1909
# SCCM Configuration Item guidance:
# Create a Configuration Item of type "Setting: Script".
# Discovery script: use the Detection script below.
# Remediation script: use the Remediation script below.
# Compliance rule: the Discovery script output equals 'Compliant'.
# === Detection script ===
# Exported from gporais.com
# Policy: Détails concernant la stratégie cloud
# State: Enabled
# Supported on: Au moins Windows 10 version 1909
function Test-RegistryValue {
param(
[Parameter(Mandatory = $true)][string]$Path,
[Parameter(Mandatory = $true)][string]$Name,
[object]$Expected,
[ValidateSet('String', 'DWord', 'MultiString')][string]$Kind = 'String',
[switch]$Absent
)
try {
$item = Get-ItemProperty -LiteralPath $Path -Name $Name -ErrorAction Stop
} catch {
return $Absent.IsPresent
}
if ($Absent.IsPresent) { return $false }
$actual = $item.$Name
if ($Kind -eq 'DWord') { return ([int64]$actual) -eq ([int64]$Expected) }
if ($Kind -eq 'MultiString') {
$actualValues = @($actual)
$expectedValues = @($Expected)
if ($actualValues.Count -ne $expectedValues.Count) { return $false }
for ($i = 0; $i -lt $expectedValues.Count; $i++) {
if ([string]$actualValues[$i] -ne [string]$expectedValues[$i]) { return $false }
}
return $true
}
return [string]$actual -eq [string]$Expected
}
$checks = @(
(Test-RegistryValue -Path 'HKLM:\SOFTWARE\Policies\Microsoft\Windows\TenantRestrictions\Payload' -Name 'cloudid' -Expected '' -Kind String)
(Test-RegistryValue -Path 'HKLM:\SOFTWARE\Policies\Microsoft\Windows\TenantRestrictions\Payload' -Name 'tenantid' -Expected '' -Kind String)
(Test-RegistryValue -Path 'HKLM:\SOFTWARE\Policies\Microsoft\Windows\TenantRestrictions\Payload' -Name 'policyid' -Expected '' -Kind String)
(Test-RegistryValue -Path 'HKLM:\SOFTWARE\Policies\Microsoft\Windows\TenantRestrictions\Payload' -Name 'enforceFirewall' -Expected 0 -Kind DWord)
(Test-RegistryValue -Path 'HKLM:\SOFTWARE\Policies\Microsoft\Windows\TenantRestrictions\Payload' -Name 'hostnames' -Expected @() -Kind MultiString)
(Test-RegistryValue -Path 'HKLM:\SOFTWARE\Policies\Microsoft\Windows\TenantRestrictions\Payload' -Name 'subdomainSupportedHostnames' -Expected @() -Kind MultiString)
(Test-RegistryValue -Path 'HKLM:\SOFTWARE\Policies\Microsoft\Windows\TenantRestrictions\Payload' -Name 'ipRanges' -Expected @() -Kind MultiString)
)
if ($checks -notcontains $false) {
Write-Output 'Compliant'
exit 0
}
Write-Output 'Non-compliant'
exit 1
# === Remediation script ===
# Exported from gporais.com
# Policy: Détails concernant la stratégie cloud
# State: Enabled
# Supported on: Au moins Windows 10 version 1909
$path = 'HKLM:\SOFTWARE\Policies\Microsoft\Windows\TenantRestrictions\Payload'
New-Item -Path $path -Force | Out-Null
Set-ItemProperty -Path $path -Name 'cloudid' -Value '' -Type String
Set-ItemProperty -Path $path -Name 'tenantid' -Value '' -Type String
Set-ItemProperty -Path $path -Name 'policyid' -Value '' -Type String
Set-ItemProperty -Path $path -Name 'enforceFirewall' -Value 0 -Type DWord
Set-ItemProperty -Path $path -Name 'hostnames' -Value @() -Type MultiString
# REG_MULTI_SZ: one string per input line; edit in regedit if you need richer formatting.
Set-ItemProperty -Path $path -Name 'subdomainSupportedHostnames' -Value @() -Type MultiString
# REG_MULTI_SZ: one string per input line; edit in regedit if you need richer formatting.
Set-ItemProperty -Path $path -Name 'ipRanges' -Value @() -Type MultiString
# REG_MULTI_SZ: one string per input line; edit in regedit if you need richer formatting. Vous construisez une collection multi-paramètres ? Ajoutez ce paramètre et générez des exports combinés (.reg, PowerShell, GPO).