Still celebrating National IT Professionals Day with 3 months of free Premium Membership. Use Code ITDAY17

x
?
Solved

block USB per user

Posted on 2016-09-26
9
Medium Priority
?
23 Views
Last Modified: 2016-11-08
hello,

we are in AD (azure) it seems that we cant setup GPO to block USB per user (only per device working).
if it not possible please recommend on any tools to execute this.

Best Regards,

Udi
0
Comment
Question by:Robert-Prodigy
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 3
  • 3
  • 2
9 Comments
 
LVL 42

Accepted Solution

by:
Adam Brown earned 1000 total points
ID: 41816315
You'll have to have a third party solution to do peripheral management on a per-user basis. I don't know of many tools that provide this, but the Sophos AV advanced license has this capability.
0
 
LVL 56

Assisted Solution

by:McKnife
McKnife earned 1000 total points
ID: 41816415
I have a way for you, but I don't know if you'd like it.
First of all, it requires a server 2012 or higher domain controller (which should be given with Azure AD, but I don't use that and am not sure what management tools it offers - is it a true GPMC that you use?)
Then, the clients need to be at least windows 8.

Does that apply to you?
0
 
LVL 42

Assisted Solution

by:Adam Brown
Adam Brown earned 1000 total points
ID: 41816510
Azure AD has very very simplistic Group Policy capabilities, so there are very few full Domain GPO features that can be utilized with an Azure AD only domain. If you have an Azure VM that is a DC, you could do a lot more, but with just Azure AD Premium, you're either going to have to add on the Enterprise Mobility Suite to do what you want or get a third party application.
0
Is Your AD Toolbox Looking More Like a Toybox?

Managing Active Directory can get complicated.  Often, the native tools for managing AD are just not up to the task.  The largest Active Directory installations in the world have relied on one tool to manage their day-to-day administration tasks: Hyena. Start your trial today.

 

Author Comment

by:Robert-Prodigy
ID: 41823479
is it possible to add GPO or to extend the option or add-on to intune AD in order to excute this? is there any other way to block USB per user?

if it possible to purchase extend GPO from Intune Microsoft I think it will be the easy way to that, but any other alternative will be good, we also thought to install hybrid internal AD only for this option but  I guess it will require to purchase server CAL

Best Regards,
0
 
LVL 56

Expert Comment

by:McKnife
ID: 41823585
If you want me to help you, please respond to both my questions, first.
0
 

Author Comment

by:Robert-Prodigy
ID: 41829374
all our clients are win 10, the AD is Intune as SAS
0
 
LVL 56

Assisted Solution

by:McKnife
McKnife earned 1000 total points
ID: 41829380
Clients on win10 - good. And with intune, can you please check if you can use these policies that my article mentions: https://www.experts-exchange.com/articles/25879/A-new-aspect-to-securing-USB-data-SID-protectors.html

That article holds the plan.
0
 

Author Comment

by:Robert-Prodigy
ID: 41829382
checking, thx
0

Featured Post

Does Powershell have you tied up in knots?

Managing Active Directory does not always have to be complicated.  If you are spending more time trying instead of doing, then it's time to look at something else. For nearly 20 years, AD admins around the world have used one tool for day-to-day AD management: Hyena. Discover why

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Here's a look at newsworthy articles and community happenings during the last month.
As managed cloud service providers, we often get asked to intervene when cloud deployments go awry. Attracted by apparent ease-of-use, flexibility and low computing costs, companies quickly adopt leading public cloud platforms such as Amazon Web Ser…
This Micro Tutorial hows how you can integrate  Mac OSX to a Windows Active Directory Domain. Apple has made it easy to allow users to bind their macs to a windows domain with relative ease. The following video show how to bind OSX Mavericks to …
This video shows how to use Hyena, from SystemTools Software, to update 100 user accounts from an external text file. View in 1080p for best video quality.

722 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question