Profile type: Select Templates > Administrative Templates.Select Devices > Configuration profiles > Create profile. Sign in to the Microsoft Intune admin center. You can use this policy as a starting point, and then add or remove settings as needed for your organization. This policy gives an example of how to block (or allow) features that affect USB devices. How to use a log file to troubleshoot devices that shouldn't be blocked.How to create an ADMX policy with USB settings in the Intune admin center.For more information on Administrative Templates, and what they are, see Use Windows 10/11 templates to configure group policy settings in Microsoft Intune. You can use Administrative Templates (ADMX) templates to configure these settings in a policy, and then deploy this policy to your Windows devices. You may also want to allow specific USB devices, such as a keyboard or mouse. Note: This method works only if the driver for USB Storage Device is already installed on your computer.Many organizations want to block specific types of USB devices, such as USB flash drives or cameras. Restart your computer for this change to Apply. On Edit DWORD pop-up, change the Value data from 3 to 4 and click OK. In the right-pane, double-click on the Start entry.Ĥ. On Registry Editor screen, navigate to HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\USBSTOR.ģ. Open Run Command > type regedit in the Run command window and click on OK.Ģ. If the USB Storage Device has already been used on your computer, you need to make changes in the registry file to prevent its use on your computer.ġ. Disable USB Storage Devices Using Registry Note: You also need to Add the System Account to Deny List, using the same steps. Click on Apply & OK to apply this change on your computer. On usbstor.PNF permissions screen, check the Deny box located next to “Full Control” entry.ĥ. On INF Properties screen, click on the Security tab > select Users entry and click on the Edit button.Ĥ. In the INF Folder, right-click on usbstor.PNF File and click on Properties.ģ. Tip: You can access this location by typing “C:\windows\INF” in the search box.Ģ. Open the File Explorer on your computer and navigate to C:\Windows\INF folder. If you are using the Home Edition of Windows 10, you can disable the use of USB Drives and on your computer by changing security settings for usbstor.PNF file.ġ. Note: It is important to apply Removable Disks: Deny Execute Access policy, if your intention is to prevent any malicious code in the USB Drive from running on your computer. If you only want to Apply the policy at User Level, navigate to User Configuration > Administrative Templates > System > Removable Storage Access. Similarly, you can disable Write Access for all Users by enabling Removable Disks: Deny Write Access Policy. This will apply the policy at Machine Level, preventing all Users on your computer from accessing files located on USB Storage Drives. On the next screen, select Disabled option > click on Apply & OK to save this setting. In the right-pane, double-click on Removable Disks: Deny Read Access entry.ĥ. Select Removable Storage Access in the left-pane. On Local Group Policy Editor screen, navigate to Computer Configuration > Administrative Templates > System > Removable Storage Access.Ĥ. On the Command screen, type gpedit.msc and click on OK.ģ. Right-click on the Start button and click on Run.Ģ. If you are using the Professional version of Windows 10, you can disable USB Drives on your computer using Group Policy Editor.ġ. Another reason for disabling USB Drives on a Windows computer is to protect data and prevent anyone making a copy of your files on the computer.
0 Comments
Leave a Reply. |
AuthorWrite something about yourself. No need to be fancy, just an overview. ArchivesCategories |