Référence GPO Windows
Une référence complète des stratégies de groupe Microsoft Windows — base de données interrogeable des paramètres GPO avec chemins de registre, versions Windows supportées, étapes de configuration, implications sécurité et cas d'usage concrets. Pensée pour les administrateurs gérant Active Directory, Intune et Windows en autonome.
Qu'est-ce qu'une stratégie de groupe ?
Un objet de stratégie de groupe (GPO) est un paramètre de configuration Windows qui définit le comportement des ordinateurs et des comptes utilisateurs. Chaque stratégie correspond à une ou plusieurs valeurs de registre, s'applique à une portée précise (Ordinateur ou Utilisateur) et est livrée dans un fichier ADMX (modèle administratif). Cette référence indexe le catalogue ADMX de Microsoft avec des explications détaillées, des correspondances de registre et des conseils opérationnels qu'on ne trouve pas sur les pages officielles Microsoft Learn.
Configure offline files sync bandwidth
Sets bandwidth throttling for offline files synchronization. Empêche réseau congestion during sync operations in managed client environments.
Computer Configuration > Policies > Administrative Templates > Network > Offline Files
Supporté sur Windows 10, Windows 11, Windows Server 2016 and later
Voir la référence →Prohibit user from manually creating offline files
Empêche utilisateurs from creating offline file shortcuts manually. Applique centralized offline file management stratégies in MSP-controlled environments.
User Configuration > Policies > Administrative Templates > Network > Offline Files
Supporté sur Windows 10, Windows 11, Windows Server 2016 and later
Voir la référence →Specify script execution timeout for non-interactive logon
Sets timeout in secondes for scripts running during non-interactives système startup. Empêche runaway scripts from blocking boot.
Computer Configuration > Policies > Administrative Templates > System > Scripts
Supporté sur Windows 10, Windows 11, Windows Server 2016 and later
Voir la référence →Enable file caching for network files
Controls the size of offline files cache in kilobytes. Autorise configuration of local cache capacity for improved offline performance.
Computer Configuration > Policies > Administrative Templates > Network > Offline Files
Supporté sur Windows 10, Windows 11, Windows Server 2016 and later
Voir la référence →Prevent access to drives via My Computer
Empêche utilisateurs from accessing specified drive letters through Windows Explorer. Restreint data accès to appliquer information governance stratégies.
User Configuration > Policies > Administrative Templates > Windows Components > File Explorer
Supporté sur Windows 10, Windows 11, Windows Server 2016 and later
Voir la référence →Run shutdown scripts asynchronously
Controls parallel execution of shutdown scripts. Désactivé to ensure proper shutdown sequence for critical cleanup operations.
Computer Configuration > Policies > Administrative Templates > System > Scripts
Supporté sur Windows 10, Windows 11, Windows Server 2016 and later
Voir la référence →Remove Drive letters for removable media
Hides specified drive letters from File Explorer and My Ordinateur. Enhances security by restricting accès to removable media in MSP-managed environments.
User Configuration > Policies > Administrative Templates > Windows Components > File Explorer
Supporté sur Windows 10, Windows 11, Windows Server 2016 and later
Voir la référence →Run startup scripts asynchronously
Autorise startup scripts to run in parallel for faster boot times. Improves utilisateur experience while running multiple provisioning scripts.
Computer Configuration > Policies > Administrative Templates > System > Scripts
Supporté sur Windows 10, Windows 11, Windows Server 2016 and later
Voir la référence →Maximum wait time for logon scripts
Sets maximum time in secondes for connexion scripts to complete. Empêche excessive connexion delays in MSP-managed environments.
User Configuration > Policies > Administrative Templates > System > Scripts
Supporté sur Windows 10, Windows 11, Windows Server 2016 and later
Voir la référence →Configure network drive cache behavior
Active or désactive offline file caching système-wide. Essential for à distance worker support and business continuity in MSP-managed networks.
Computer Configuration > Policies > Administrative Templates > Network > Offline Files
Supporté sur Windows 10, Windows 11, Windows Server 2016 and later
Voir la référence →Display startup script processing messages
Shows script processing messages during startup. Set to 0 for production environments to avoid startup delays and utilisateur confusion.
Computer Configuration > Policies > Administrative Templates > System > Scripts
Supporté sur Windows 10, Windows 11, Windows Server 2016 and later
Voir la référence →Maximum wait time for shutdown scripts
Sets maximum time in secondes to wait for shutdown scripts. Balances thorough execution with preventing indefinite shutdown delays.
Computer Configuration > Policies > Administrative Templates > System > Scripts
Supporté sur Windows 10, Windows 11, Windows Server 2016 and later
Voir la référence →Run logon scripts visible
Controls visibility of connexion script execution window. Keep hidden in production to reduce visual clutter during connexion process.
User Configuration > Policies > Administrative Templates > System > Scripts
Supporté sur Windows 10, Windows 11, Windows Server 2016 and later
Voir la référence →Set offline files synchronization warning threshold
Defines maximum age in minutes for offline files avant warning utilisateur. Ensures critical data is synchronized in timely manner.
Computer Configuration > Policies > Administrative Templates > Network > Offline Files
Supporté sur Windows 10, Windows 11, Windows Server 2016 and later
Voir la référence →Maximum wait time for startup scripts
Sets maximum time in secondes to wait for startup scripts to complete avant utilisateur connexion timeout. Critical for MSP script deployment timing.
Computer Configuration > Policies > Administrative Templates > System > Scripts
Supporté sur Windows 10, Windows 11, Windows Server 2016 and later
Voir la référence →Configure security zones for trusted sites
Adds sites to trusted security zone with relaxed restrictions. Essential for MSP support of internal LOB applications requiring specific security context.
User Configuration > Policies > Administrative Templates > Windows Components > Internet Explorer > Internet Control Panel > Security Page
Supporté sur Windows 10, Windows 11, Windows Server 2016 and later
Voir la référence →Run logoff scripts asynchronously
Active asynchronous execution of logoff scripts to speed up logout process without waiting for completion.
User Configuration > Policies > Administrative Templates > System > Scripts
Supporté sur Windows 10, Windows 11, Windows Server 2016 and later
Voir la référence →Process Group Policy asynchronously
Controls synchronous processing of Group Stratégie. Disable async to ensure stratégies apply in correct order during startup.
Computer Configuration > Policies > Administrative Templates > System > Group Policy
Supporté sur Windows 10, Windows 11, Windows Server 2016 and later
Voir la référence →Allow Windows to shutdown without logging in
Permits shutdown scripts to run without requiring utilisateur connexion. Essential for automated maintenance and patch deployment workflows.
Computer Configuration > Policies > Administrative Templates > System > Scripts
Supporté sur Windows 10, Windows 11, Windows Server 2016 and later
Voir la référence →Run startup scripts in parallel
Active parallel processing of multiple startup scripts for improved boot performance in complex provisioning scenarios.
Computer Configuration > Policies > Administrative Templates > System > Scripts
Supporté sur Windows 10, Windows 11, Windows Server 2016 and later
Voir la référence →Configure SNMP community strings
Sets SNMP community strings for authentification. MSPs should use strong, rotated community strings for security.
Computer Configuration > Policies > Administrative Templates > Network > SNMP
Supporté sur Windows 10, Windows 11, Windows Server 2016 and later
Voir la référence →Configure SmartScreen for phishing detection
Active real-time SmartScreen filter for phishing and malware detection. Critical security control for protecting client data and credentials.
User Configuration > Policies > Administrative Templates > Windows Components > Internet Explorer > Phishing Filter
Supporté sur Windows 10, Windows 11, Windows Server 2016 and later
Voir la référence →Prevent users from changing security zone settings
Locks down security zone configuration preventing utilisateur modification. Applique MSP security stratégies on client workstations.
User Configuration > Policies > Administrative Templates > Windows Components > Internet Explorer > Internet Control Panel
Supporté sur Windows 10, Windows 11, Windows Server 2016 and later
Voir la référence →Disable changing proxy settings
Empêche utilisateurs from modifying proxy configuration. Ensures consistent réseau traffic routing in MSP environments.
User Configuration > Policies > Administrative Templates > Windows Components > Internet Explorer > Internet Control Panel > Connection Page
Supporté sur Windows 10, Windows 11, Windows Server 2016 and later
Voir la référence →
