Solved

Disabling USB Storage by Group Policy

Posted on 2011-03-06
5
1,753 Views
Last Modified: 2012-06-27
Points of My Scenario:
1. I am admin of a Windows Server 2003 domain
2. Workstations have Windows XP Pro, SP3
3. I have implemented a group policy to prevent the use of USB storage as per Microsoft KB555324 (http://support.microsoft.com/default.aspx?scid=kb;en-us;555324)
4. It works ONLY if the workstation has been exposed to a USB flash drive and "gpupdate /force" command is executed.
MY CHALLENGE: Although the policy works, it only works to block the same flash drive used to expose the workstation to USB storage (see point #4): other flash drives still have access.
QUESTION: What can I do to ensure the policy blocks all USB storage media?
0
Comment
Question by:waforbes100
  • 2
  • 2
5 Comments
 
LVL 25

Expert Comment

by:Dr. Klahn
ID: 35051053
A very similar question was asked here September 2008.  The responses seem to parallel what you have already done.

Server has a GPO that does what you want, although I don't know if these policies are available in XP.  Certainly disabling all removable media would do the job, but this would also disable floppy disks, ZIP drives and CD/DVDs.

An alternate possibility is a hardware approach.  Disconnect the front panel USB connector(s) from the motherboard.

0
 

Author Comment

by:waforbes100
ID: 35056456
To DrKlahn: I need to retain USB input capability (e.g. mouse, keyboard). Additionally, I have disabled all media that the policy allows, but the problem persists.
0
 
LVL 25

Assisted Solution

by:Dr. Klahn
Dr. Klahn earned 150 total points
ID: 35063503
Presumably the USB mouse and keyboard are attached through the back panel.  That is why I suggested disconnecting only the front panel USB connectors.
0
 
LVL 1

Accepted Solution

by:
dhanraj114 earned 350 total points
ID: 35066314
I have tried the given KB on my Server 2003 and Windows XP Pro network. But it sometimes blocks and sometimes releases the USBs. More blocking from GP also blocks keyboard, mouse, printer and scanner also. I was not succeeded in this. Finally i have adopted a third party software named DeviceLock, which is the perfect software for a network. It allows user based permissions, and users are fetched from Domain. It works fine with me. I suggest you for any third party software.
0
 

Author Closing Comment

by:waforbes100
ID: 35082503
My solution was to configure GPO to deny access to the USBSTOR.SYS file. In 100% of test workstations it worked!
0

Featured Post

PRTG Network Monitor: Intuitive Network Monitoring

Network Monitoring is essential to ensure that computer systems and network devices are running. Use PRTG to monitor LANs, servers, websites, applications and devices, bandwidth, virtual environments, remote systems, IoT, and many more. PRTG is easy to set up & use.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

If you are having problems installing printer drivers, or if documents repeatedly get stuck in the print queue even after re-installing the printer drivers, then follow these steps to solve the problems. Please note that the steps are shown both for…
Is your Office 365 signature not working the way you want it to? Are signature updates taking up too much of your time? Let's run through the most common problems that an IT administrator can encounter when dealing with Office 365 email signatures.
This tutorial will walk an individual through the process of configuring their Windows Server 2012 domain controller to synchronize its time with a trusted, external resource. Use Google, Bing, or other preferred search engine to locate trusted NTP …
Microsoft Active Directory, the widely used IT infrastructure, is known for its high risk of credential theft. The best way to test your Active Directory’s vulnerabilities to pass-the-ticket, pass-the-hash, privilege escalation, and malware attacks …

810 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question