Can I use GPO to block all USB devices except those explicitly allowed?


we're using symantec endpoint protection antivirus , considering switch system center endpoint protection.  one feature of sep need replace device control policies.

in sep, have configured block usb devices class, except explicitly allow.  we add policy's exception list hardware id of device wish allow.  when new usb device plugged in computer, if hardware id doesn't match 1 on exception list, device disabled , user sees popup informing them of this.  

this great cases when user brings in flash drive home , plugs computer.  sep disables device , prevents access drive.  some users need flash drives though, issue encrypted flash drives users.  because have set policy allow devices matching specific hardware id, when user plugs in 1 of our encrypted flash drives device installed , operates normally. 

i have been told can accomplish same thing using group policy, i'm not sure if that's correct.  as @ description of relevant policies, appears deny rule takes precedence on allow rule.  that seems prevent "block except" method use currently. 

is there way achieve our goal using group policy?

on subsequent reading, see there setting "prevent installation of devices not described other policy settings", sounds may need.  it won't let me quite granular block devices of specific class , exclude devices blocking, looks it's close can get. 


Windows Server  >  Group Policy



Comments

Popular posts from this blog

DCOM received error "2147746132" from...

ADFS 3.0 Event ID 4625 | An Error occurred During Logon | Status: 0xC000035B

DFSR RPC replication errors 5014 1726 with large files over VPN