Block Bluetooth file transfer

Occasional Contributor

Can we use Defender for Endpoint to block file transfer using Bluetooth?

We use Intune\MEM.

 

Thanks.

3 Replies
Hi Sohel,

Yes, you can configure the Bluetooth allowed services setting in Device control policy which is a part of Attack Surface reduction, and specify which services you want to allow. Below provides more details.

https://docs.microsoft.com/en-us/windows/client-management/mdm/policy-csp-bluetooth#bluetooth-servic...

Thanks,
Si

@s_sim1290 

 

Hi Si,

 

I don't see hex value for "file transfer blocking" in link, any idea? 

@Sohel Hey,
to my understanding of how we block file transfer with Bluetooth is to do not allow the file transfer service in the Device Control policy that are related to allow the file transfer. So I think I would add all Bluetooth services to the "Bluetooth allowed services" list except those which would allow the file transfer.

So, do not add the following Bluetooth services to the "Bluetooth allowed services" list:

MaxMS_1-1650885336653.png

The ID´s that you should not add to your intune policy´s Bluetooth service allow list are the following:

  • 00001105-0000-1000-8000-00805F9B34FB
  • 00000008-0000-1000-8000-00805F9B34FB

If you do configure all your Bluetooth services all in one policy.

It would be appreciated if some of you pros could confirm my approach and see if I'm on the right track.

Thank you.