fr-FR windows computer

Détails concernant la stratégie cloud

Vérifié avec Windows 11 25H2 — mis à jour le 30 juillet 2026

Windows 11 25H2

Pris en charge sur : Au moins Windows 10 version 1909

Chemin dans la console GPO

Configuration ordinateur\Modèles d'administration\Composants Windows\Restrictions de client

Description

Ce paramètre active et configure la fonctionnalité de restrictions de locataire basées sur les appareils pour Microsoft Azure Active Directory. Lorsque vous activez ce paramètre, les applications conformes ne pourront pas accéder aux locataires non autorisés, conformément à une stratégie définie dans votre locataire Microsoft Azure Active Directory. Remarque : La création d'une stratégie dans votre locataire d'accueil est requise et des mesures de sécurité supplémentaires pour les appareils gérés sont recommandées pour une meilleure protection. Reportez-vous aux Restrictions du locataire Microsoft Azure Active Directory pour plus de détails. https://go.microsoft.com/fwlink/?linkid=2148762 Avant d'activer la protection par pare-feu, assurez-vous qu'une stratégie Contrôle des applications pour entreprise qui balise correctement les applications a été appliquée aux appareils cibles. L’activation de la protection par pare-feu sans stratégie Contrôle des applications pour entreprise correspondante empêchera toutes les applications d’atteindre les points de terminaison Microsoft. Ce paramètre de pare-feu n'est pas pris en charge sur toutes les versions de Windows. Consultez le lien suivant pour plus d'informations. Pour plus de détails sur la configuration de WDAC avec des restrictions de locataire, consultez https://go.microsoft.com/fwlink/?linkid=2155230

Registre

HKLM SOFTWARE\Policies\Microsoft\Windows\TenantRestrictions\Payload

Plus d'options disponibles

Options

ID de cloud (facultatif) :
cloudid text
ID Azure Active Directory :
tenantid text
GUID de la stratégie :
policyid text
Activer la protection pare-feu des points de terminaison Microsoft
enforceFirewall boolean
Noms d’hôte (facultatif) :
hostnames multiText
Noms d’hôtes pris en charge par le sous-domaine (facultatif) :
subdomainSupportedHostnames multiText
Plages d’adresses IP (facultatif) :
ipRanges multiText

MDM / Intune (CSP)

./Device/Vendor/MSFT/Policy/Config/TenantRestrictions/ConfigureTenantRestrictions
Appareil Depuis [10.0.20348.320] and later | Windows 10, version 2004 with KB5006738 [10.0.19041.1320] and later | Windows 10, version 20H2 with KB5006738 [10.0.19042.1320] and later | Windows 10, version 21H1 with KB5006738 [10.0.19043.1320] and later | Windows 10, version 21H2 [10.0.19044] and later | Windows 11, version 21H2 [10.0.22000] and later Mapping officiel (Microsoft Learn)

Documentation Microsoft Learn Données de correspondance : Microsoft Learn (CC BY 4.0)

Générateur d'exports

BETA

Configurez l'état, la portée et les options, puis générez les sorties .reg, PowerShell, Intune et SCCM — ou ajoutez le paramètre à une collection multi-paramètres.

Ces exports écrivent le registre — ce n'est pas une GPO managée.

Fichier .reg

Windows Registry Editor Version 5.00

; Exported from gporais.com
; Policy: Détails concernant la stratégie cloud
; State: Enabled
; Supported on: Au moins Windows 10 version 1909

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\TenantRestrictions\Payload]
"cloudid"=""
"tenantid"=""
"policyid"=""
"enforceFirewall"=dword:00000000
"hostnames"=hex(7):00,00
; REG_MULTI_SZ: one string per input line; edit in regedit if you need richer formatting.
"subdomainSupportedHostnames"=hex(7):00,00
; REG_MULTI_SZ: one string per input line; edit in regedit if you need richer formatting.
"ipRanges"=hex(7):00,00
; REG_MULTI_SZ: one string per input line; edit in regedit if you need richer formatting.
Autres formats (PowerShell, Intune, SCCM)

PowerShell

# Exported from gporais.com
# Policy: Détails concernant la stratégie cloud
# State: Enabled
# Supported on: Au moins Windows 10 version 1909

$path = 'HKLM:\SOFTWARE\Policies\Microsoft\Windows\TenantRestrictions\Payload'
New-Item -Path $path -Force | Out-Null
Set-ItemProperty -Path $path -Name 'cloudid' -Value '' -Type String
Set-ItemProperty -Path $path -Name 'tenantid' -Value '' -Type String
Set-ItemProperty -Path $path -Name 'policyid' -Value '' -Type String
Set-ItemProperty -Path $path -Name 'enforceFirewall' -Value 0 -Type DWord
Set-ItemProperty -Path $path -Name 'hostnames' -Value @() -Type MultiString
# REG_MULTI_SZ: one string per input line; edit in regedit if you need richer formatting.
Set-ItemProperty -Path $path -Name 'subdomainSupportedHostnames' -Value @() -Type MultiString
# REG_MULTI_SZ: one string per input line; edit in regedit if you need richer formatting.
Set-ItemProperty -Path $path -Name 'ipRanges' -Value @() -Type MultiString
# REG_MULTI_SZ: one string per input line; edit in regedit if you need richer formatting.

Vous construisez une collection multi-paramètres ? Ajoutez ce paramètre et générez des exports combinés (.reg, PowerShell, GPO).

Ouvrir le Builder

Intégrer cette GPO sur votre site

Contenu à intégrer
Thème

Ajoute une ligne de script : le thème suit l’apparence de votre site et la hauteur s’ajuste au contenu. Si votre site bloque les scripts, l’intégration suit le thème du système du visiteur.

Aperçu