Autoriser le mappage des dossiers dans Bac à sable Windows
Vérifié avec Windows 11 25H2 — mis à jour le 30 juillet 2026
Pris en charge sur : Au moins Windows 11 Professionnel, Enterprise ou Education avec Bac à sable Windows
Chemin dans la console GPO
Configuration ordinateur\Modèles d'administration\Composants Windows\Bac à sable Windows Description
Ce paramètre de stratégie active ou désactive le mappage des dossiers dans le bac à sable. Si vous activez ce paramètre de stratégie, le mappage des dossiers de l’hôte dans le bac à sable est autorisé. Si vous activez ce paramètre de stratégie et désactivez l’écriture dans les dossiers mappés, le mappage des dossiers de l’hôte dans le bac à sable sera autorisé, mais sandbox aura uniquement l’autorisation de lire les fichiers. Si vous désactivez ce paramètre de stratégie, le mappage des dossiers de l’hôte dans le bac à sable ne sera pas autorisé. Si vous ne configurez pas ce paramètre de stratégie, les dossiers mappés sont activés. Notez que l’exposition de dossiers de l’hôte dans le conteneur peut avoir des implications en matière de sécurité.
Registre
SOFTWARE\Policies\Microsoft\Windows\Sandbox Nom de valeur : AllowMappedFolders
Activé : AllowMappedFolders = 1
Désactivé : AllowMappedFolders = 0
MDM / Intune (CSP)
./Device/Vendor/MSFT/Policy/Config/WindowsSandbox/AllowMappedFolders Plusieurs correspondances CSP possibles ; la première a été retenue.
Documentation Microsoft Learn Données de correspondance : Microsoft Learn (CC BY 4.0)
Valeurs CSP
-
0- Not allowed. -
1 (Default)- Allowed.
Générateur d'exports
BETAConfigurez l'état, la portée et les options, puis générez les sorties .reg, PowerShell, Intune et SCCM — ou ajoutez le paramètre à une collection multi-paramètres.
Ces exports écrivent le registre — ce n'est pas une GPO managée. ⓘ
Fichier .reg
Windows Registry Editor Version 5.00
; Exported from gporais.com
; Policy: Autoriser le mappage des dossiers dans Bac à sable Windows
; State: Enabled
; Supported on: Au moins Windows 11 Professionnel, Enterprise ou Education avec Bac à sable Windows
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\Sandbox]
"AllowMappedFolders"=dword:00000001
"AllowWriteToMappedFolders"=dword:00000001 Autres formats (PowerShell, Intune, SCCM)
PowerShell
# Exported from gporais.com
# Policy: Autoriser le mappage des dossiers dans Bac à sable Windows
# State: Enabled
# Supported on: Au moins Windows 11 Professionnel, Enterprise ou Education avec Bac à sable Windows
$path = 'HKLM:\SOFTWARE\Policies\Microsoft\Windows\Sandbox'
New-Item -Path $path -Force | Out-Null
Set-ItemProperty -Path $path -Name 'AllowMappedFolders' -Value 1 -Type DWord
Set-ItemProperty -Path $path -Name 'AllowWriteToMappedFolders' -Value 1 -Type DWord Intune XML
OMA-URI: ./Device/Vendor/MSFT/Policy/Config/WindowsSandbox/AllowMappedFolders
Data type: String
Value:
<enabled/>
<data id="CheckBox_AllowWriteToMappedFolders" value="1"/> Intune Remediation
# === Detection script ===
# Exported from gporais.com
# Policy: Autoriser le mappage des dossiers dans Bac à sable Windows
# State: Enabled
# Supported on: Au moins Windows 11 Professionnel, Enterprise ou Education avec Bac à sable Windows
function Test-RegistryValue {
param(
[Parameter(Mandatory = $true)][string]$Path,
[Parameter(Mandatory = $true)][string]$Name,
[object]$Expected,
[ValidateSet('String', 'DWord', 'MultiString')][string]$Kind = 'String',
[switch]$Absent
)
try {
$item = Get-ItemProperty -LiteralPath $Path -Name $Name -ErrorAction Stop
} catch {
return $Absent.IsPresent
}
if ($Absent.IsPresent) { return $false }
$actual = $item.$Name
if ($Kind -eq 'DWord') { return ([int64]$actual) -eq ([int64]$Expected) }
if ($Kind -eq 'MultiString') {
$actualValues = @($actual)
$expectedValues = @($Expected)
if ($actualValues.Count -ne $expectedValues.Count) { return $false }
for ($i = 0; $i -lt $expectedValues.Count; $i++) {
if ([string]$actualValues[$i] -ne [string]$expectedValues[$i]) { return $false }
}
return $true
}
return [string]$actual -eq [string]$Expected
}
$checks = @(
(Test-RegistryValue -Path 'HKLM:\SOFTWARE\Policies\Microsoft\Windows\Sandbox' -Name 'AllowMappedFolders' -Expected 1 -Kind DWord)
(Test-RegistryValue -Path 'HKLM:\SOFTWARE\Policies\Microsoft\Windows\Sandbox' -Name 'AllowWriteToMappedFolders' -Expected 1 -Kind DWord)
)
if ($checks -notcontains $false) {
Write-Output 'Compliant'
exit 0
}
Write-Output 'Non-compliant'
exit 1
# === Remediation script ===
# Exported from gporais.com
# Policy: Autoriser le mappage des dossiers dans Bac à sable Windows
# State: Enabled
# Supported on: Au moins Windows 11 Professionnel, Enterprise ou Education avec Bac à sable Windows
$path = 'HKLM:\SOFTWARE\Policies\Microsoft\Windows\Sandbox'
New-Item -Path $path -Force | Out-Null
Set-ItemProperty -Path $path -Name 'AllowMappedFolders' -Value 1 -Type DWord
Set-ItemProperty -Path $path -Name 'AllowWriteToMappedFolders' -Value 1 -Type DWord Scripts SCCM
# Exported from gporais.com
# Policy: Autoriser le mappage des dossiers dans Bac à sable Windows
# State: Enabled
# Supported on: Au moins Windows 11 Professionnel, Enterprise ou Education avec Bac à sable Windows
# SCCM Configuration Item guidance:
# Create a Configuration Item of type "Setting: Script".
# Discovery script: use the Detection script below.
# Remediation script: use the Remediation script below.
# Compliance rule: the Discovery script output equals 'Compliant'.
# === Detection script ===
# Exported from gporais.com
# Policy: Autoriser le mappage des dossiers dans Bac à sable Windows
# State: Enabled
# Supported on: Au moins Windows 11 Professionnel, Enterprise ou Education avec Bac à sable Windows
function Test-RegistryValue {
param(
[Parameter(Mandatory = $true)][string]$Path,
[Parameter(Mandatory = $true)][string]$Name,
[object]$Expected,
[ValidateSet('String', 'DWord', 'MultiString')][string]$Kind = 'String',
[switch]$Absent
)
try {
$item = Get-ItemProperty -LiteralPath $Path -Name $Name -ErrorAction Stop
} catch {
return $Absent.IsPresent
}
if ($Absent.IsPresent) { return $false }
$actual = $item.$Name
if ($Kind -eq 'DWord') { return ([int64]$actual) -eq ([int64]$Expected) }
if ($Kind -eq 'MultiString') {
$actualValues = @($actual)
$expectedValues = @($Expected)
if ($actualValues.Count -ne $expectedValues.Count) { return $false }
for ($i = 0; $i -lt $expectedValues.Count; $i++) {
if ([string]$actualValues[$i] -ne [string]$expectedValues[$i]) { return $false }
}
return $true
}
return [string]$actual -eq [string]$Expected
}
$checks = @(
(Test-RegistryValue -Path 'HKLM:\SOFTWARE\Policies\Microsoft\Windows\Sandbox' -Name 'AllowMappedFolders' -Expected 1 -Kind DWord)
(Test-RegistryValue -Path 'HKLM:\SOFTWARE\Policies\Microsoft\Windows\Sandbox' -Name 'AllowWriteToMappedFolders' -Expected 1 -Kind DWord)
)
if ($checks -notcontains $false) {
Write-Output 'Compliant'
exit 0
}
Write-Output 'Non-compliant'
exit 1
# === Remediation script ===
# Exported from gporais.com
# Policy: Autoriser le mappage des dossiers dans Bac à sable Windows
# State: Enabled
# Supported on: Au moins Windows 11 Professionnel, Enterprise ou Education avec Bac à sable Windows
$path = 'HKLM:\SOFTWARE\Policies\Microsoft\Windows\Sandbox'
New-Item -Path $path -Force | Out-Null
Set-ItemProperty -Path $path -Name 'AllowMappedFolders' -Value 1 -Type DWord
Set-ItemProperty -Path $path -Name 'AllowWriteToMappedFolders' -Value 1 -Type DWord Vous construisez une collection multi-paramètres ? Ajoutez ce paramètre et générez des exports combinés (.reg, PowerShell, GPO).