Allowing Specific USB using Intune CSP

%3CLINGO-SUB%20id%3D%22lingo-sub-2735960%22%20slang%3D%22en-US%22%3EAllowing%20Specific%20USB%20using%20Intune%20CSP%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2735960%22%20slang%3D%22en-US%22%3E%3CP%3EDear%20All%2C%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EWe%20have%20co-managed%20environment%20and%20blocked%20all%20removable%20drives%2C%20but%20we%20have%20some%20requirement%20to%20allow%20specific%20USB.%3C%2FP%3E%3CP%3EWe%20have%20tried%20with%20following%20CSP%20url%20by%20using%20Device%20ID%20and%20device%20Class%20but%20there%20is%20no%20luck.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3ELet%20me%20know%20if%20anything%20missin%3C%2FP%3E%3CP%3EOMA-URI%3A-%20.%2FDevice%2FVendor%2FMSFT%2FPolicy%2FConfig%2FDeviceInstallation%2FAllowInstallationOfMatchingDeviceInstanceIDs%3CBR%20%2F%3EDATA%20Type%20%3A-%20String%3CBR%20%2F%3EValue%20%3A%20%3CENABLED%3E%3C%2FENABLED%3E%3CDATA%20id%3D%22%26quot%3BDeviceInstall_Instance_IDs_Allow_List%26quot%3B%22%20value%3D%22%26quot%3B1%26amp%3B%23xF000%3BUSBSTOR%5CDISK%26amp%3BVEN_SANDISK%26amp%3BPROD_CRUZER_GLIDE_3.0%26amp%3BREV_1.00%5C4C530000260327116325%26amp%3B0%26quot%3B%2F%22%3E%3C%2FDATA%3E%3C%2FP%3E%3CP%3EAllow%20USB-%20Per%20ClassID%3C%2FP%3E%3CP%3EOMA-URI%20%3A-%20.%2FDevice%2FVendor%2FMSFT%2FPolicy%2FConfig%2FDeviceInstallation%2FAllowInstallationOfMatchingDeviceSetupClasses%3CBR%20%2F%3EData%20Type%20%3A-%20String%3CBR%20%2F%3EValue%20%3A-%20%3CENABLED%3E%3C%2FENABLED%3E%3CDATA%20id%3D%22%26quot%3BDeviceInstall_Classes_Allow_List%26quot%3B%22%20value%3D%22%26quot%3B1%26amp%3B%23xF000%3B%7B4d36e967-e325-11ce-bfc1-08002be10318%7D%26quot%3B%2F%22%3E%3C%2FDATA%3E%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-2735960%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EIntune%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E
Contributor

Dear All,

 

We have co-managed environment and blocked all removable drives, but we have some requirement to allow specific USB.

We have tried with following CSP url by using Device ID and device Class but there is no luck.

 

Let me know if anything missin

OMA-URI:- ./Device/Vendor/MSFT/Policy/Config/DeviceInstallation/AllowInstallationOfMatchingDeviceInstanceIDs
DATA Type :- String
Value : <enabled/><Data id="DeviceInstall_Instance_IDs_Allow_List" value="1&#xF000;USBSTOR\DISK&VEN_SANDISK&PROD_CRUZER_GLIDE_3.0&REV_1.00\4C530000260327116325&0"/>

Allow USB- Per ClassID

OMA-URI :- ./Device/Vendor/MSFT/Policy/Config/DeviceInstallation/AllowInstallationOfMatchingDeviceSetupClasses
Data Type :- String
Value :- <enabled/><Data id="DeviceInstall_Classes_Allow_List" value="1&#xF000;{4d36e967-e325-11ce-bfc1-08002be10318}"/>

1 Reply

@Mdrafik-Shaikh 

 

If I am understanding you correctly.... you configured a block policy AND an allow policy for specific USB devices?

 

I did a blog about this sometime ago maybe it helps you somehow

 

O Removable Storage, Where Art Thou? - Intune Device Control (call4cloud.nl)