Jump to content

Device control USB data storage block


Recommended Posts

Hi,

i am currently trying to setup device control that blocks all USB's except ones that we whitelist according to their serialnumber and vendor ID.

Now i have created 2 policies and have tried playing with the policy hierarchy.

 

This is the all USB block policy:

image.thumb.png.77beb4d7455f014da3e87d71e4b1247c.png

This is the settings i have set.

image.png.ae65c66e289e2e58f16a9e6e74a2f096.png

 

The following is a test i ran to see if the exception i create will go through the block policy.

image.thumb.png.1e9675ddcd4c4712db07170fdcf67fa4.png

I have first made sure the block works, i also have an report what PC's has tried using an USB but has been blocked. according to that report i have taken the vendor, model and serial. The reasoning to instead choosing "allow" i have chosen "warn" is to make sure our users are consciously clicking on allow.

image.png.fa4b4b184ce780a154063cc811f44d61.png

 

When i apply the second exception policy, for some reason it gets confused and starts letting through all USB's and ignores both policies.

Am i doing something wrong? i have also tried combining both in 1 policy. but it will just block everything.

Link to comment
Share on other sites

Guest
This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
×
×
  • Create New...