Solved

Prevent use of USB flash drives with WIndows 7

Posted on 2012-04-12
9
683 Views
Last Modified: 2012-04-15
I have a standalone Windows 7 Professional machine and need to prevent users from copying data from it.  

It is used on a Standard user login, and I have an Administrator login for it.

How can I prevent USB flash drives from being used on the machine?

Is it possible to prevent CDs/DVDs from being burned?
0
Comment
Question by:RedLondon
  • 3
  • 2
  • 2
  • +1
9 Comments
 
LVL 16

Expert Comment

by:R. Andrew Koffron
ID: 37839847
http://support.microsoft.com/kb/555324
this might help.
be careful it's an old article.
0
 
LVL 17

Expert Comment

by:Anuroopsundd
ID: 37839854
0
 
LVL 17

Expert Comment

by:Anuroopsundd
ID: 37839861
To block your computer's ability to use USB Removable Disks follow these steps:

1.Open Registry Editor.
2.In Registry Editor, navigate to the following registry key:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\USBSTOR1.Locate the following value (DWORD):
Start and give it a value of 4. Note: As always, before making changes to your registry you should always make sure you have a valid backup. In cases where you're supposed to delete or modify keys or values from the registry it is possible to first export that key or value(s) to a .REG file before performing the changes.

1.Close Registry Editor. You do not need to reboot the computer for changes to apply


http://www.petri.co.il/disable-usb-storage-devices.htm
0
 
LVL 32

Assisted Solution

by:PowerEdgeTech
PowerEdgeTech earned 175 total points
ID: 37839889
You can block all access to removable media (CD, USB, etc.) using local policies ...

Start, type in gpedit.msc, then:
Computer Configuration (or Users Configuration), Windows Settings, Administrative Templates, System, Removable Storage Access
0
Comprehensive Backup Solutions for Microsoft

Acronis protects the complete Microsoft technology stack: Windows Server, Windows PC, laptop and Surface data; Microsoft business applications; Microsoft Hyper-V; Azure VMs; Microsoft Windows Server 2016; Microsoft Exchange 2016 and SQL Server 2016.

 
LVL 16

Expert Comment

by:R. Andrew Koffron
ID: 37839896
here's an article on how to do it in server 2008 I don't have access to a windows 7 machine right now to test if it's compatible but will try it soon.

http://mytricks.in/2012/04/how-to-disable-usb-drivecd-romfloppy-disk-use-in-an-windows-server-8-by-using-group-policy.html
0
 
LVL 28

Accepted Solution

by:
Run5k earned 225 total points
ID: 37839910
You can actually set a local group policy that will configure this a bit more gracefully than a manual registry edit:

Computer Configuration -> Administrative Templates -> System -> Removable Storage Access

You can potentially enable All Removable Storage classes: Deny all access, or if you want to retain a bit of flexibility, enable Removable Disks: Deny write access.
0
 
LVL 16

Assisted Solution

by:R. Andrew Koffron
R. Andrew Koffron earned 100 total points
ID: 37839961
just tested Run5k's and it's a much better method than the previous articles.

PowerEdgeTech's tech is the same with a minor mistake in the gp path just remove "(or Users Configuration), Windows Settings"
0
 
LVL 32

Assisted Solution

by:PowerEdgeTech
PowerEdgeTech earned 175 total points
ID: 37839999
(or Users Configuration) was there on purpose, as an optional course.  If you follow the same path under Users Configuration, you can set the policies per user rather than global per machine.  Probably not helpful on a single machine, but if implementing in a Domain environment, Users Configuration will allow you to block/allow access per user group rather than the entire machine, just in case there are individuals (like administrators) who should retain access.  But yes, I forgot to remove 'Windows Settings'.
0
 
LVL 28

Assisted Solution

by:Run5k
Run5k earned 225 total points
ID: 37840070
To expand upon PowerEdgeTech's good advice, if you want to configure local group policies that only affect non-administrators that is certainly possible, but it requires a few extra configuration steps:

How to Apply Local Group Policies to All Users Except Administrators

Explore the benefits of the Multiple Local Group Policy feature in Windows 7

http://technet.microsoft.com/en-us/library/cc766291(WS.10).aspx
0

Featured Post

Is Your Active Directory as Secure as You Think?

More than 75% of all records are compromised because of the loss or theft of a privileged credential. Experts have been exploring Active Directory infrastructure to identify key threats and establish best practices for keeping data safe. Attend this month’s webinar to learn more.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Article by: btan
The intent is not to repeat what many has know about Ransomware but more to join its dots of what is it, who are the victims, why it exists, when and how we respond on infection. Lastly, sum up in a glance to share such information with more to help…
A quick guide on how to use Group Policy to create a custom power plan and set it active on Windows 7.
This Micro Tutorial will give you a basic overview of Windows Live Photo Gallery and show you various editing filters and touches to photos you can apply. This will be demonstrated using Windows Live Photo Gallery on Windows 7 operating system.
The viewer will learn how to successfully download and install the SARDU utility on Windows 7, without downloading adware.

863 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

22 Experts available now in Live!

Get 1:1 Help Now