Still celebrating National IT Professionals Day with 3 months of free Premium Membership. Use Code ITDAY17

x
?
Solved

Server 2012 AD How to block USB drive access using GPO

Posted on 2015-02-04
4
Medium Priority
?
1,227 Views
Last Modified: 2015-02-04
We have to block access to USB drives on domain computers. We're running Windows 7 and Server 2012 AD. I've seen various articles but none seem to help with 2012. I've looked in GP but don't see \User Configuration\Policies\Administrative Templates\System\Removable Storage Access or the same one under \Computer\

I just don't see Removable Storage Access anywhere to disable and I can't find anything specific to Windows 2012 on this.
0
Comment
Question by:scubadiver_dave
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 3
4 Comments
 

Author Comment

by:scubadiver_dave
ID: 40588770
I think part of the problem is..

\Computer\Administrative Templates: Policy definitions (ADMX files) retrieved from the central store.

At some point we added some ADM templates to deal with various Office GPOs. Now we don't see the default ones like Removable Storage Access.

How can I get that back?
0
 

Author Comment

by:scubadiver_dave
ID: 40588877
I'm getting closer but can't find any current articles on who to copy ADMX files for server 2012 to the central store. All the articles are old and talk about 2008. I'm getting access denied when I try to copy the new ADMX files for Windows 8.1 and 2012 to the sysvol share.
0
 
LVL 4

Accepted Solution

by:
Praveen Kumar Bonala earned 1500 total points
ID: 40588941
Hi,
please check this link. Here you will get step by step process.

https://4sysops.com/archives/how-to-disable-usb-drive-use-in-an-active-directory-domain/
0
 

Author Comment

by:scubadiver_dave
ID: 40588953
Thanks. I've seen articles about how to do it. My problem was that the GPO wasn't there. I had to download and install newer ADMX files and was having a security issue at first because I was trying to copy the new ADMX files to a UNC path instead of just using c:\windows\sysvol.

It's all good now and I can see the GPO.
0

Featured Post

Windows Server 2016: All you need to know

Learn about Hyper-V features that increase functionality and usability of Microsoft Windows Server 2016. Also, throughout this eBook, you’ll find some basic PowerShell examples that will help you leverage the scripts in your environments!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

The recent Microsoft changes on update philosophy for Windows pre-10 and their impact on existing WSUS implementations.
By default the complete memory dump option is disabled in windows . If we want to enable the complete memory dump for a diagnostic purpose, we have a solution for it. here we are using the registry method to enable this.
This tutorial will walk an individual through the process of configuring basic necessities in order to use the 2010 version of Data Protection Manager. These include storage, agents, and protection jobs. Launch Data Protection Manager from the deskt…
The Task Scheduler is a powerful tool that is built into Windows. It allows you to schedule tasks (actions) on a recurring basis, such as hourly, daily, weekly, monthly, at log on, at startup, on idle, etc. This video Micro Tutorial is a brief intro…

688 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question