Autoriser la mise en réseau dans Bac à sable Windows
Vérifié avec Windows 11 25H2 — mis à jour le 30 juillet 2026
Pris en charge sur : Au moins Windows 11 Professionnel, Enterprise ou Education avec Bac à sable Windows
Chemin dans la console GPO
Configuration ordinateur\Modèles d'administration\Composants Windows\Bac à sable Windows Description
Ce paramètre de stratégie active ou désactive la mise en réseau dans le bac à sable (sandbox). Vous pouvez désactiver l’accès réseau pour réduire la surface d’attaque exposée par le bac à sable (sandbox). Si vous activez ce paramètre de stratégie, la mise en réseau est effectuée en créant un commutateur virtuel sur l’ordinateur hôte et connecte le Bac à sable Windows à celui-ci via une carte réseau virtuelle. Si vous désactivez ce paramètre de stratégie, la mise en réseau est désactivée dans Bac à sable Windows. Si vous ne configurez pas ce paramètre de stratégie, la mise en réseau est activée. Notez que l’activation de la mise en réseau peut exposer des applications non approuvées au réseau interne.
Registre
SOFTWARE\Policies\Microsoft\Windows\Sandbox Nom de valeur : AllowNetworking
Activé : AllowNetworking = 1
Désactivé : AllowNetworking = 0
MDM / Intune (CSP)
./Device/Vendor/MSFT/Policy/Config/WindowsSandbox/AllowNetworking Documentation Microsoft Learn Données de correspondance : Microsoft Learn (CC BY 4.0)
Valeurs CSP
-
0- Not allowed. -
1 (Default)- Allowed.
Générateur d'exports
BETAConfigurez l'état, la portée et les options, puis générez les sorties .reg, PowerShell, Intune et SCCM — ou ajoutez le paramètre à une collection multi-paramètres.
Ces exports écrivent le registre — ce n'est pas une GPO managée. ⓘ
Fichier .reg
Windows Registry Editor Version 5.00
; Exported from gporais.com
; Policy: Autoriser la mise en réseau dans Bac à sable Windows
; State: Enabled
; Supported on: Au moins Windows 11 Professionnel, Enterprise ou Education avec Bac à sable Windows
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\Sandbox]
"AllowNetworking"=dword:00000001 Autres formats (PowerShell, Intune, SCCM)
PowerShell
# Exported from gporais.com
# Policy: Autoriser la mise en réseau dans Bac à sable Windows
# State: Enabled
# Supported on: Au moins Windows 11 Professionnel, Enterprise ou Education avec Bac à sable Windows
$path = 'HKLM:\SOFTWARE\Policies\Microsoft\Windows\Sandbox'
New-Item -Path $path -Force | Out-Null
Set-ItemProperty -Path $path -Name 'AllowNetworking' -Value 1 -Type DWord Intune XML
OMA-URI: ./Device/Vendor/MSFT/Policy/Config/WindowsSandbox/AllowNetworking
Data type: String
Value:
<enabled/> Intune Remediation
# === Detection script ===
# Exported from gporais.com
# Policy: Autoriser la mise en réseau dans Bac à sable Windows
# State: Enabled
# Supported on: Au moins Windows 11 Professionnel, Enterprise ou Education avec Bac à sable Windows
function Test-RegistryValue {
param(
[Parameter(Mandatory = $true)][string]$Path,
[Parameter(Mandatory = $true)][string]$Name,
[object]$Expected,
[ValidateSet('String', 'DWord', 'MultiString')][string]$Kind = 'String',
[switch]$Absent
)
try {
$item = Get-ItemProperty -LiteralPath $Path -Name $Name -ErrorAction Stop
} catch {
return $Absent.IsPresent
}
if ($Absent.IsPresent) { return $false }
$actual = $item.$Name
if ($Kind -eq 'DWord') { return ([int64]$actual) -eq ([int64]$Expected) }
if ($Kind -eq 'MultiString') {
$actualValues = @($actual)
$expectedValues = @($Expected)
if ($actualValues.Count -ne $expectedValues.Count) { return $false }
for ($i = 0; $i -lt $expectedValues.Count; $i++) {
if ([string]$actualValues[$i] -ne [string]$expectedValues[$i]) { return $false }
}
return $true
}
return [string]$actual -eq [string]$Expected
}
$checks = @(
(Test-RegistryValue -Path 'HKLM:\SOFTWARE\Policies\Microsoft\Windows\Sandbox' -Name 'AllowNetworking' -Expected 1 -Kind DWord)
)
if ($checks -notcontains $false) {
Write-Output 'Compliant'
exit 0
}
Write-Output 'Non-compliant'
exit 1
# === Remediation script ===
# Exported from gporais.com
# Policy: Autoriser la mise en réseau dans Bac à sable Windows
# State: Enabled
# Supported on: Au moins Windows 11 Professionnel, Enterprise ou Education avec Bac à sable Windows
$path = 'HKLM:\SOFTWARE\Policies\Microsoft\Windows\Sandbox'
New-Item -Path $path -Force | Out-Null
Set-ItemProperty -Path $path -Name 'AllowNetworking' -Value 1 -Type DWord Scripts SCCM
# Exported from gporais.com
# Policy: Autoriser la mise en réseau dans Bac à sable Windows
# State: Enabled
# Supported on: Au moins Windows 11 Professionnel, Enterprise ou Education avec Bac à sable Windows
# SCCM Configuration Item guidance:
# Create a Configuration Item of type "Setting: Script".
# Discovery script: use the Detection script below.
# Remediation script: use the Remediation script below.
# Compliance rule: the Discovery script output equals 'Compliant'.
# === Detection script ===
# Exported from gporais.com
# Policy: Autoriser la mise en réseau dans Bac à sable Windows
# State: Enabled
# Supported on: Au moins Windows 11 Professionnel, Enterprise ou Education avec Bac à sable Windows
function Test-RegistryValue {
param(
[Parameter(Mandatory = $true)][string]$Path,
[Parameter(Mandatory = $true)][string]$Name,
[object]$Expected,
[ValidateSet('String', 'DWord', 'MultiString')][string]$Kind = 'String',
[switch]$Absent
)
try {
$item = Get-ItemProperty -LiteralPath $Path -Name $Name -ErrorAction Stop
} catch {
return $Absent.IsPresent
}
if ($Absent.IsPresent) { return $false }
$actual = $item.$Name
if ($Kind -eq 'DWord') { return ([int64]$actual) -eq ([int64]$Expected) }
if ($Kind -eq 'MultiString') {
$actualValues = @($actual)
$expectedValues = @($Expected)
if ($actualValues.Count -ne $expectedValues.Count) { return $false }
for ($i = 0; $i -lt $expectedValues.Count; $i++) {
if ([string]$actualValues[$i] -ne [string]$expectedValues[$i]) { return $false }
}
return $true
}
return [string]$actual -eq [string]$Expected
}
$checks = @(
(Test-RegistryValue -Path 'HKLM:\SOFTWARE\Policies\Microsoft\Windows\Sandbox' -Name 'AllowNetworking' -Expected 1 -Kind DWord)
)
if ($checks -notcontains $false) {
Write-Output 'Compliant'
exit 0
}
Write-Output 'Non-compliant'
exit 1
# === Remediation script ===
# Exported from gporais.com
# Policy: Autoriser la mise en réseau dans Bac à sable Windows
# State: Enabled
# Supported on: Au moins Windows 11 Professionnel, Enterprise ou Education avec Bac à sable Windows
$path = 'HKLM:\SOFTWARE\Policies\Microsoft\Windows\Sandbox'
New-Item -Path $path -Force | Out-Null
Set-ItemProperty -Path $path -Name 'AllowNetworking' -Value 1 -Type DWord Vous construisez une collection multi-paramètres ? Ajoutez ce paramètre et générez des exports combinés (.reg, PowerShell, GPO).