Supprimer l’accès à l’utilisation de toutes les fonctionnalités de Windows Update
Vérifié avec Windows 11 25H2 — mis à jour le 12 juillet 2026
Pris en charge sur : Au minimum Windows XP Professionnel Service Pack 1 ou Au moins Windows 2000 Service Pack 3 à Windows 8.1 ou Windows Server 2012 R2 avec le Service Pack le plus récent. Non pris en charge sur les Windows 10 et versions ultérieures.
Chemin dans la console GPO
Configuration utilisateur\Modèles d'administration\Composants Windows\Windows Update\Gérer les mises à jour proposées de Windows Server Update Service Description
Ce paramètre permet de supprimer l’accès à Windows Update. Si vous activez ce paramètre, toutes les fonctionnalités de Windows Update seront supprimées. Cela inclut le blocage de l’accès au site Web de Windows Update (http://windowsupdate.microsoft.com) à partir du lien Windows Update du menu Démarrer, ainsi qu’à partir du menu Outils dans Internet Explorer. Le service de mise à jour automatique de Windows sera également désactivé ; vous ne recevrez pas de mises à jour critiques de Windows Update et vous ne serez pas prévenu de leur disponibilité. Ce paramètre empêche également le Gestionnaire de périphériques d’installer automatiquement les mises à jour de pilotes à partir du site Web de Windows Update. S’il est activé, vous pouvez configurer l’une des options de notification suivantes : 0 = Ne pas afficher de notifications Ce paramètre supprime tous les accès aux fonctions de Windows Update et aucune notification ne s’affiche. 1 = Afficher des notifications de redémarrage requis Ce paramètre affiche des notifications concernant des redémarrages requis afin de terminer l’installation. Sur Windows 8 et Windows RT, si cette stratégie est activée, seules les notifications associées aux redémarrages et l’impossibilité de détecter les mises à jour sont affichées. Les options de notification ne sont pas prises en charge. Les notifications seront toujours affichées sur l’écran d’ouverture de session.
Registre
Software\Microsoft\Windows\CurrentVersion\Policies\WindowsUpdate Nom de valeur : DisableWindowsUpdateAccess
Activé : DisableWindowsUpdateAccess = 1
Désactivé : DisableWindowsUpdateAccess = 0
Générateur d'exports
BETAConfigurez l'état, la portée et les options, puis générez les sorties .reg, PowerShell, Intune et SCCM — ou ajoutez le paramètre à une collection multi-paramètres.
Ces exports écrivent le registre — ce n'est pas une GPO managée. ⓘ
Fichier .reg
Windows Registry Editor Version 5.00
; Exported from gporais.com
; Policy: Supprimer l’accès à l’utilisation de toutes les fonctionnalités de Windows Update
; State: Enabled
; Supported on: Au minimum Windows XP Professionnel Service Pack 1 ou Au moins Windows 2000 Service Pack 3 à Windows 8.1 ou Windows Server 2012 R2 avec le Service Pack le plus récent. Non pris en charge sur les Windows 10 et versions ultérieures.
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\WindowsUpdate]
"DisableWindowsUpdateAccess"=dword:00000001
"DisableWindowsUpdateAccessMode"=dword:00000000 Autres formats (PowerShell, Intune, SCCM)
PowerShell
# Exported from gporais.com
# Policy: Supprimer l’accès à l’utilisation de toutes les fonctionnalités de Windows Update
# State: Enabled
# Supported on: Au minimum Windows XP Professionnel Service Pack 1 ou Au moins Windows 2000 Service Pack 3 à Windows 8.1 ou Windows Server 2012 R2 avec le Service Pack le plus récent. Non pris en charge sur les Windows 10 et versions ultérieures.
# Warning: In SYSTEM context (the Intune default), HKCU targets the SYSTEM profile. Run this script using the logged-on credentials.
$path = 'HKCU:\Software\Microsoft\Windows\CurrentVersion\Policies\WindowsUpdate'
New-Item -Path $path -Force | Out-Null
Set-ItemProperty -Path $path -Name 'DisableWindowsUpdateAccess' -Value 1 -Type DWord
Set-ItemProperty -Path $path -Name 'DisableWindowsUpdateAccessMode' -Value 0 -Type DWord Intune XML
Aucune correspondance directe Policy CSP / OMA-URI pour cette stratégie. Utilisez l'onglet Intune Remediation, ou importez l'ADMX dans Intune. Intune Remediation
# === Detection script ===
# Exported from gporais.com
# Policy: Supprimer l’accès à l’utilisation de toutes les fonctionnalités de Windows Update
# State: Enabled
# Supported on: Au minimum Windows XP Professionnel Service Pack 1 ou Au moins Windows 2000 Service Pack 3 à Windows 8.1 ou Windows Server 2012 R2 avec le Service Pack le plus récent. Non pris en charge sur les Windows 10 et versions ultérieures.
# Warning: In SYSTEM context (the Intune default), HKCU targets the SYSTEM profile. Run this script using the logged-on credentials.
function Test-RegistryValue {
param(
[Parameter(Mandatory = $true)][string]$Path,
[Parameter(Mandatory = $true)][string]$Name,
[object]$Expected,
[ValidateSet('String', 'DWord', 'MultiString')][string]$Kind = 'String',
[switch]$Absent
)
try {
$item = Get-ItemProperty -LiteralPath $Path -Name $Name -ErrorAction Stop
} catch {
return $Absent.IsPresent
}
if ($Absent.IsPresent) { return $false }
$actual = $item.$Name
if ($Kind -eq 'DWord') { return ([int64]$actual) -eq ([int64]$Expected) }
if ($Kind -eq 'MultiString') {
$actualValues = @($actual)
$expectedValues = @($Expected)
if ($actualValues.Count -ne $expectedValues.Count) { return $false }
for ($i = 0; $i -lt $expectedValues.Count; $i++) {
if ([string]$actualValues[$i] -ne [string]$expectedValues[$i]) { return $false }
}
return $true
}
return [string]$actual -eq [string]$Expected
}
$checks = @(
(Test-RegistryValue -Path 'HKCU:\Software\Microsoft\Windows\CurrentVersion\Policies\WindowsUpdate' -Name 'DisableWindowsUpdateAccess' -Expected 1 -Kind DWord)
(Test-RegistryValue -Path 'HKCU:\Software\Microsoft\Windows\CurrentVersion\Policies\WindowsUpdate' -Name 'DisableWindowsUpdateAccessMode' -Expected 0 -Kind DWord)
)
if ($checks -notcontains $false) {
Write-Output 'Compliant'
exit 0
}
Write-Output 'Non-compliant'
exit 1
# === Remediation script ===
# Exported from gporais.com
# Policy: Supprimer l’accès à l’utilisation de toutes les fonctionnalités de Windows Update
# State: Enabled
# Supported on: Au minimum Windows XP Professionnel Service Pack 1 ou Au moins Windows 2000 Service Pack 3 à Windows 8.1 ou Windows Server 2012 R2 avec le Service Pack le plus récent. Non pris en charge sur les Windows 10 et versions ultérieures.
# Warning: In SYSTEM context (the Intune default), HKCU targets the SYSTEM profile. Run this script using the logged-on credentials.
$path = 'HKCU:\Software\Microsoft\Windows\CurrentVersion\Policies\WindowsUpdate'
New-Item -Path $path -Force | Out-Null
Set-ItemProperty -Path $path -Name 'DisableWindowsUpdateAccess' -Value 1 -Type DWord
Set-ItemProperty -Path $path -Name 'DisableWindowsUpdateAccessMode' -Value 0 -Type DWord Scripts SCCM
# Exported from gporais.com
# Policy: Supprimer l’accès à l’utilisation de toutes les fonctionnalités de Windows Update
# State: Enabled
# Supported on: Au minimum Windows XP Professionnel Service Pack 1 ou Au moins Windows 2000 Service Pack 3 à Windows 8.1 ou Windows Server 2012 R2 avec le Service Pack le plus récent. Non pris en charge sur les Windows 10 et versions ultérieures.
# SCCM Configuration Item guidance:
# Create a Configuration Item of type "Setting: Script".
# Discovery script: use the Detection script below.
# Remediation script: use the Remediation script below.
# Compliance rule: the Discovery script output equals 'Compliant'.
# === Detection script ===
# Exported from gporais.com
# Policy: Supprimer l’accès à l’utilisation de toutes les fonctionnalités de Windows Update
# State: Enabled
# Supported on: Au minimum Windows XP Professionnel Service Pack 1 ou Au moins Windows 2000 Service Pack 3 à Windows 8.1 ou Windows Server 2012 R2 avec le Service Pack le plus récent. Non pris en charge sur les Windows 10 et versions ultérieures.
# Warning: In SYSTEM context (the Intune default), HKCU targets the SYSTEM profile. Run this script using the logged-on credentials.
function Test-RegistryValue {
param(
[Parameter(Mandatory = $true)][string]$Path,
[Parameter(Mandatory = $true)][string]$Name,
[object]$Expected,
[ValidateSet('String', 'DWord', 'MultiString')][string]$Kind = 'String',
[switch]$Absent
)
try {
$item = Get-ItemProperty -LiteralPath $Path -Name $Name -ErrorAction Stop
} catch {
return $Absent.IsPresent
}
if ($Absent.IsPresent) { return $false }
$actual = $item.$Name
if ($Kind -eq 'DWord') { return ([int64]$actual) -eq ([int64]$Expected) }
if ($Kind -eq 'MultiString') {
$actualValues = @($actual)
$expectedValues = @($Expected)
if ($actualValues.Count -ne $expectedValues.Count) { return $false }
for ($i = 0; $i -lt $expectedValues.Count; $i++) {
if ([string]$actualValues[$i] -ne [string]$expectedValues[$i]) { return $false }
}
return $true
}
return [string]$actual -eq [string]$Expected
}
$checks = @(
(Test-RegistryValue -Path 'HKCU:\Software\Microsoft\Windows\CurrentVersion\Policies\WindowsUpdate' -Name 'DisableWindowsUpdateAccess' -Expected 1 -Kind DWord)
(Test-RegistryValue -Path 'HKCU:\Software\Microsoft\Windows\CurrentVersion\Policies\WindowsUpdate' -Name 'DisableWindowsUpdateAccessMode' -Expected 0 -Kind DWord)
)
if ($checks -notcontains $false) {
Write-Output 'Compliant'
exit 0
}
Write-Output 'Non-compliant'
exit 1
# === Remediation script ===
# Exported from gporais.com
# Policy: Supprimer l’accès à l’utilisation de toutes les fonctionnalités de Windows Update
# State: Enabled
# Supported on: Au minimum Windows XP Professionnel Service Pack 1 ou Au moins Windows 2000 Service Pack 3 à Windows 8.1 ou Windows Server 2012 R2 avec le Service Pack le plus récent. Non pris en charge sur les Windows 10 et versions ultérieures.
# Warning: In SYSTEM context (the Intune default), HKCU targets the SYSTEM profile. Run this script using the logged-on credentials.
$path = 'HKCU:\Software\Microsoft\Windows\CurrentVersion\Policies\WindowsUpdate'
New-Item -Path $path -Force | Out-Null
Set-ItemProperty -Path $path -Name 'DisableWindowsUpdateAccess' -Value 1 -Type DWord
Set-ItemProperty -Path $path -Name 'DisableWindowsUpdateAccessMode' -Value 0 -Type DWord Vous construisez une collection multi-paramètres ? Ajoutez ce paramètre et générez des exports combinés (.reg, PowerShell, GPO).