How to block the Removal Storage devices through Device control in Microsoft End Point Manager

Copper Contributor

Dear Team,

 

How to block the Removal Storage devices (USB, Pen drive, mas storage devices) through Device control in Microsoft End Point Manager. There is a option in the Device control policy "Hardware device installation by device identifiers" --->Remove matching hardware devices--->Hardware device identifiers that are blocked . This policy setting allows you to specify a list of Plug and Play hardware IDs and compatible IDs for devices that Windows is prevented from installing but we are unable to block all the removal storage device. Please share the any alternative  way to block all the USB or removal ( Mas Storage) device and how to create the exception for specific USB.

 

Thanks and Regards,

Abhishek  

 

2 Replies
The best way to block Removable Storage devices is using a GPO, it is very simple, you create the GPO, configure the settings and deploy to the machines.