Solved

Block USB Flash Drives?

Posted on 2012-04-06
9
597 Views
Last Modified: 2012-05-14
We have a smaller network of about 50 computers.

We have SBS 2011.

We also have Symantec Endpoint protection 12.1

I"m wanting to block USB flashsticks on our network.

But I want it to be allowed completely at all times for some certain users (Our department heads etc), and for other users I want it to be possible only if I enter in a password for them.

Is there a way to accomplish this?

Thanks
0
Comment
Question by:Pancake_Effect
  • 3
  • 3
  • 3
9 Comments
 
LVL 12

Expert Comment

by:FarWest
ID: 37817761
sure, there is
and it is implemented in our network,
you can configure Policies-Application and Device Control  that implemented on that group and  block all usb, and then make exceptions for other usb drivers that is in your network like printers & scanners

check this URL

http://www.symantec.com/business/support/index?page=content&id=TECH104299&locale=en_US

and if you need more help  , I can provide you with screen shots from my environment
0
 
LVL 10

Expert Comment

by:Gajendra Rathod
ID: 37818471
There is one more option

http://www.netwrix.com/usb_blocker_freeware.html

This product will allow you to control USB device on endpoint as per your requirement mention above ( per user, per computer and password basis).
0
 
LVL 4

Author Comment

by:Pancake_Effect
ID: 37824460
fryezz thanks for the link, it looks like I can simply block USB devices via group policy. That's a good start.. but sometimes users do need legit reasons for using a USB memory stick, so if that happens I'm hoping for a way that I can walk over to their office while they are on it, and I can simply type in a password and be good to go for them to have temporary access. Changing group policy settings every time to let them have access could be a pain otherwise.

Gajendra_Rathod that looks like what I want it to do exactly, but it has some pretty bad reviews saying it's buggy and is not free after 50 computers.

I'm hoping to use our resources between Group Policy and Symantec to make this work (if possible) I inherited this network here recently and it's for healthcare so it's quite important in my opinion to block USB ports...but like in most IT departments, it's always a problem of money hence why I'm hoping to utilize free solutions or what we have already(Symantec 12.1 endpoint manager or Group Policy.)
0
3 Use Cases for Connected Systems

Our Dev teams are like yours. They’re continually cranking out code for new features/bugs fixes, testing, deploying, testing some more, responding to production monitoring events and more. It’s complex. So, we thought you’d like to see what’s working for us.

 
LVL 10

Assisted Solution

by:Gajendra Rathod
Gajendra Rathod earned 500 total points
ID: 37824813
Please contact Netwrix support for quotation above product and I am sure they will reply you as it is free ware product.

Please check for below solution,

http://www.symantec.com/business/support/index?page=content&id=TECH106304





You can block USB device installation using GPO.


You can restrict or allow devices by Device IDs or Device Setup Classes
Computer Configuration
 Administrative Templates
 System
 Device Installation
 Prevent Installation of Devices that match any of these device IDs.

Computer Configuration
Administrative Templates
System
Device Installation
Prevent Installation of Devices using drivers that match
these device setup classes.
0
 
LVL 12

Expert Comment

by:FarWest
ID: 37825548
what I know that Symantec End Point client allows you to put the management password to have one time unlock (temporarily override)
but I could not verify that know,
you can give it a try on your environment and see what options are available
0
 
LVL 4

Author Comment

by:Pancake_Effect
ID: 37843313
I was able to successfully block USB via Symantec End Point, but I'm trying to figure out the one time unlock you spoke about. If I can get a one time unlock, that would work perfectly for all my dilemmas.
0
 
LVL 12

Expert Comment

by:FarWest
ID: 37843469
I think you can go on with this work arround, ( I did not try it but I hope it will work :) )

export the policy that enable the USB to a shared folder and when you go to manager office import it
after that just run update policy ( SEP Client Icon rignt click), and it well get back everything to normal

for exporting - importing ploicies check this

http://www.symantec.com/business/support/index?page=content&id=TECH95478&locale=en_US
0
 
LVL 4

Author Comment

by:Pancake_Effect
ID: 37853255
I tried Netwrix and it doesn't allow you to specify gp objects, you have to apply it to the entire domain then set up the exclusions. I really didn't like the flexibility in that.

fryezz that could work, I tried it out, but it's not really user friendly..My goal is to allow HR to do this also for users. It surprises me that windows or Symantec doesn't have a built in password system for USB devices
0
 
LVL 10

Accepted Solution

by:
Gajendra Rathod earned 500 total points
ID: 37926242
Netwrix work at OU level.

Create OU based on department.

Netwrix server can be install on any machine in domain.

I think it is good application for USB blocking
0

Featured Post

Complete VMware vSphere® ESX(i) & Hyper-V Backup

Capture your entire system, including the host, with patented disk imaging integrated with VMware VADP / Microsoft VSS and RCT. RTOs is as low as 15 seconds with Acronis Active Restore™. You can enjoy unlimited P2V/V2V migrations from any source (even from a different hypervisor)

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

How to set-up an On Demand, IPSec, Site to SIte, VPN from a Draytek Vigor Router to a Cyberoam UTM Appliance. A concise guide to the settings required on both devices
PRTG Network Monitor lets you monitor your bandwidth usage, so you know who is using up your bandwidth, and what they're using it for.
Get a first impression of how PRTG looks and learn how it works.   This video is a short introduction to PRTG, as an initial overview or as a quick start for new PRTG users.
Here's a very brief overview of the methods PRTG Network Monitor (https://www.paessler.com/prtg) offers for monitoring bandwidth, to help you decide which methods you´d like to investigate in more detail.  The methods are covered in more detail in o…

810 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question