Définir l’analyse de la Protection des fichiers Windows
Vérifié avec Windows 11 25H2 — mis à jour le 12 juillet 2026
Pris en charge sur : Windows Server 2003, Windows XP et Windows 2000 uniquement
Chemin dans la console GPO
Configuration ordinateur\Modèles d'administration\Système\Protection des fichiers Windows Description
Ce paramètre de stratégie permet de définir à quel moment la Protection des fichiers Windows analyse les fichiers protégés. Ce paramètre force la Protection des fichiers Windows à énumérer et à analyser tous les fichiers système afin de détecter des modifications. Si vous activez ce paramètre de stratégie, sélectionnez une fréquence dans la zone « Fréquence d’analyse ». Vous pouvez utiliser ce paramètre afin de forcer la Protection des fichiers Windows à analyser les fichiers plus fréquemment. -- « Ne pas analyser lors du démarrage », la valeur par défaut, n’analyse les fichiers qu’au moment de l’installation. -- « Analyser lors du démarrage » analyse également les fichiers à chaque démarrage de Windows XP. Ce paramètre retarde chaque démarrage. Si vous désactivez ce paramètre de stratégie ou ne le configurez pas, par défaut, les fichiers ne sont analysés qu’au moment de l’installation. Remarque : ce paramètre de stratégie n’affecte que l’analyse des fichiers. Il n’affecte pas la détection standard de modification de fichier en tâche de fond, fournie par la Protection des fichiers Windows.
Registre
Software\Policies\Microsoft\Windows NT\Windows File Protection Générateur d'exports
BETAConfigurez l'état, la portée et les options, puis générez les sorties .reg, PowerShell, Intune et SCCM — ou ajoutez le paramètre à une collection multi-paramètres.
Ces exports écrivent le registre — ce n'est pas une GPO managée. ⓘ
Fichier .reg
Windows Registry Editor Version 5.00
; Exported from gporais.com
; Policy: Définir l’analyse de la Protection des fichiers Windows
; State: Enabled
; Supported on: Windows Server 2003, Windows XP et Windows 2000 uniquement
[HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows NT\Windows File Protection]
"SfcScan"=dword:00000000 Autres formats (PowerShell, Intune, SCCM)
PowerShell
# Exported from gporais.com
# Policy: Définir l’analyse de la Protection des fichiers Windows
# State: Enabled
# Supported on: Windows Server 2003, Windows XP et Windows 2000 uniquement
$path = 'HKLM:\Software\Policies\Microsoft\Windows NT\Windows File Protection'
New-Item -Path $path -Force | Out-Null
Set-ItemProperty -Path $path -Name 'SfcScan' -Value 0 -Type DWord Intune XML
Aucune correspondance directe Policy CSP / OMA-URI pour cette stratégie. Utilisez l'onglet Intune Remediation, ou importez l'ADMX dans Intune. Intune Remediation
# === Detection script ===
# Exported from gporais.com
# Policy: Définir l’analyse de la Protection des fichiers Windows
# State: Enabled
# Supported on: Windows Server 2003, Windows XP et Windows 2000 uniquement
function Test-RegistryValue {
param(
[Parameter(Mandatory = $true)][string]$Path,
[Parameter(Mandatory = $true)][string]$Name,
[object]$Expected,
[ValidateSet('String', 'DWord', 'MultiString')][string]$Kind = 'String',
[switch]$Absent
)
try {
$item = Get-ItemProperty -LiteralPath $Path -Name $Name -ErrorAction Stop
} catch {
return $Absent.IsPresent
}
if ($Absent.IsPresent) { return $false }
$actual = $item.$Name
if ($Kind -eq 'DWord') { return ([int64]$actual) -eq ([int64]$Expected) }
if ($Kind -eq 'MultiString') {
$actualValues = @($actual)
$expectedValues = @($Expected)
if ($actualValues.Count -ne $expectedValues.Count) { return $false }
for ($i = 0; $i -lt $expectedValues.Count; $i++) {
if ([string]$actualValues[$i] -ne [string]$expectedValues[$i]) { return $false }
}
return $true
}
return [string]$actual -eq [string]$Expected
}
$checks = @(
(Test-RegistryValue -Path 'HKLM:\Software\Policies\Microsoft\Windows NT\Windows File Protection' -Name 'SfcScan' -Expected 0 -Kind DWord)
)
if ($checks -notcontains $false) {
Write-Output 'Compliant'
exit 0
}
Write-Output 'Non-compliant'
exit 1
# === Remediation script ===
# Exported from gporais.com
# Policy: Définir l’analyse de la Protection des fichiers Windows
# State: Enabled
# Supported on: Windows Server 2003, Windows XP et Windows 2000 uniquement
$path = 'HKLM:\Software\Policies\Microsoft\Windows NT\Windows File Protection'
New-Item -Path $path -Force | Out-Null
Set-ItemProperty -Path $path -Name 'SfcScan' -Value 0 -Type DWord Scripts SCCM
# Exported from gporais.com
# Policy: Définir l’analyse de la Protection des fichiers Windows
# State: Enabled
# Supported on: Windows Server 2003, Windows XP et Windows 2000 uniquement
# SCCM Configuration Item guidance:
# Create a Configuration Item of type "Setting: Script".
# Discovery script: use the Detection script below.
# Remediation script: use the Remediation script below.
# Compliance rule: the Discovery script output equals 'Compliant'.
# === Detection script ===
# Exported from gporais.com
# Policy: Définir l’analyse de la Protection des fichiers Windows
# State: Enabled
# Supported on: Windows Server 2003, Windows XP et Windows 2000 uniquement
function Test-RegistryValue {
param(
[Parameter(Mandatory = $true)][string]$Path,
[Parameter(Mandatory = $true)][string]$Name,
[object]$Expected,
[ValidateSet('String', 'DWord', 'MultiString')][string]$Kind = 'String',
[switch]$Absent
)
try {
$item = Get-ItemProperty -LiteralPath $Path -Name $Name -ErrorAction Stop
} catch {
return $Absent.IsPresent
}
if ($Absent.IsPresent) { return $false }
$actual = $item.$Name
if ($Kind -eq 'DWord') { return ([int64]$actual) -eq ([int64]$Expected) }
if ($Kind -eq 'MultiString') {
$actualValues = @($actual)
$expectedValues = @($Expected)
if ($actualValues.Count -ne $expectedValues.Count) { return $false }
for ($i = 0; $i -lt $expectedValues.Count; $i++) {
if ([string]$actualValues[$i] -ne [string]$expectedValues[$i]) { return $false }
}
return $true
}
return [string]$actual -eq [string]$Expected
}
$checks = @(
(Test-RegistryValue -Path 'HKLM:\Software\Policies\Microsoft\Windows NT\Windows File Protection' -Name 'SfcScan' -Expected 0 -Kind DWord)
)
if ($checks -notcontains $false) {
Write-Output 'Compliant'
exit 0
}
Write-Output 'Non-compliant'
exit 1
# === Remediation script ===
# Exported from gporais.com
# Policy: Définir l’analyse de la Protection des fichiers Windows
# State: Enabled
# Supported on: Windows Server 2003, Windows XP et Windows 2000 uniquement
$path = 'HKLM:\Software\Policies\Microsoft\Windows NT\Windows File Protection'
New-Item -Path $path -Force | Out-Null
Set-ItemProperty -Path $path -Name 'SfcScan' -Value 0 -Type DWord Vous construisez une collection multi-paramètres ? Ajoutez ce paramètre et générez des exports combinés (.reg, PowerShell, GPO).