Forum Discussion

Anonymous's avatar
Anonymous
Mar 10, 2023
Solved

Monitoring copied files on External drive - USB

Hello Guys,   i struggle to find a way in Defender for EPP or other solutions to monitor when a user copied files on an external peripheral such as hard drive and USB.   Some one have the procedu...
  • Anonymous's avatar
    Anonymous
    Mar 15, 2023
    Thanks for that ! For the ultimate goals of this, here's what I found: The goal of monitoring this kind of activity obviously relates to a DLP strategy. So in our case, we are managing devices in Intune and have Defender E3/E5 licenses. So, for other people who have the same type of IT setting, you can use Microsoft Purview->Insider Risk management to be more efficient in this type of use case. But, for a temporary solution you can use the Advanced hunting section to investigation with the query above and in the TimeLine for Plug and play device/USB/External/thunderbolt log event type.

Resources