Forum Discussion
Block Bluetooth file transfer
Can we use Defender for Endpoint to block file transfer using Bluetooth?
We use Intune\MEM.
Thanks.
- s_sim1290Copper ContributorHi Sohel,
Yes, you can configure the Bluetooth allowed services setting in Device control policy which is a part of Attack Surface reduction, and specify which services you want to allow. Below provides more details.
https://docs.microsoft.com/en-us/windows/client-management/mdm/policy-csp-bluetooth#bluetooth-servicesallowedlist
Thanks,
Si- Sohel68Copper Contributor
- Max-MSCopper Contributor
Sohel68 Hey,
to my understanding of how we block file transfer with Bluetooth is to do not allow the file transfer service in the Device Control policy that are related to allow the file transfer. So I think I would add all Bluetooth services to the "Bluetooth allowed services" list except those which would allow the file transfer.So, do not add the following Bluetooth services to the "Bluetooth allowed services" list:
The ID´s that you should not add to your intune policy´s Bluetooth service allow list are the following:
- 00001105-0000-1000-8000-00805F9B34FB
- 00000008-0000-1000-8000-00805F9B34FB
If you do configure all your Bluetooth services all in one policy.
It would be appreciated if some of you pros could confirm my approach and see if I'm on the right track.
Thank you.
- Shubham_Taur-1Copper Contributor
Hii Sir
I would like a setting from Windows Active Directory to have block bluetooth but only connect bluetooth headphones which only transmits audio but no data or file sharing.
It is Possible or not...?
If it possible then please guide me...!