Solved

block USB per user

Posted on 2016-09-26
9
15 Views
Last Modified: 2016-11-08
hello,

we are in AD (azure) it seems that we cant setup GPO to block USB per user (only per device working).
if it not possible please recommend on any tools to execute this.

Best Regards,

Udi
0
Comment
Question by:Robert-Prodigy
  • 3
  • 3
  • 2
9 Comments
 
LVL 38

Accepted Solution

by:
Adam Brown earned 250 total points
ID: 41816315
You'll have to have a third party solution to do peripheral management on a per-user basis. I don't know of many tools that provide this, but the Sophos AV advanced license has this capability.
0
 
LVL 53

Assisted Solution

by:McKnife
McKnife earned 250 total points
ID: 41816415
I have a way for you, but I don't know if you'd like it.
First of all, it requires a server 2012 or higher domain controller (which should be given with Azure AD, but I don't use that and am not sure what management tools it offers - is it a true GPMC that you use?)
Then, the clients need to be at least windows 8.

Does that apply to you?
0
 
LVL 38

Assisted Solution

by:Adam Brown
Adam Brown earned 250 total points
ID: 41816510
Azure AD has very very simplistic Group Policy capabilities, so there are very few full Domain GPO features that can be utilized with an Azure AD only domain. If you have an Azure VM that is a DC, you could do a lot more, but with just Azure AD Premium, you're either going to have to add on the Enterprise Mobility Suite to do what you want or get a third party application.
0
 

Author Comment

by:Robert-Prodigy
ID: 41823479
is it possible to add GPO or to extend the option or add-on to intune AD in order to excute this? is there any other way to block USB per user?

if it possible to purchase extend GPO from Intune Microsoft I think it will be the easy way to that, but any other alternative will be good, we also thought to install hybrid internal AD only for this option but  I guess it will require to purchase server CAL

Best Regards,
0
Threat Intelligence Starter Resources

Integrating threat intelligence can be challenging, and not all companies are ready. These resources can help you build awareness and prepare for defense.

 
LVL 53

Expert Comment

by:McKnife
ID: 41823585
If you want me to help you, please respond to both my questions, first.
0
 

Author Comment

by:Robert-Prodigy
ID: 41829374
all our clients are win 10, the AD is Intune as SAS
0
 
LVL 53

Assisted Solution

by:McKnife
McKnife earned 250 total points
ID: 41829380
Clients on win10 - good. And with intune, can you please check if you can use these policies that my article mentions: https://www.experts-exchange.com/articles/25879/A-new-aspect-to-securing-USB-data-SID-protectors.html

That article holds the plan.
0
 

Author Comment

by:Robert-Prodigy
ID: 41829382
checking, thx
0

Featured Post

Why spend so long doing email signature updates?

Do you spend loads of your time carrying out email signature updates? Not very interesting are they? Don’t let signature updates get you down. Let Exclaimer Cloud - Signatures for Office 365 make managing email signatures a breeze.

Join & Write a Comment

Starting in Windows Server 2008, Microsoft introduced the Group Policy Central Store. This automatically replicating location allows IT administrators to have the latest and greatest Group Policy (GP) configuration settings available. Let’s expl…
Mapping Drives using Group policy preferences Are you still using old scripts to map your network drives if so this article will show you how to get away for old scripts and move toward Group Policy Preference for mapping them. First things f…
This tutorial will walk an individual through the process of transferring the five major, necessary Active Directory Roles, commonly referred to as the FSMO roles to another domain controller. Log onto the new domain controller with a user account t…
This tutorial will walk an individual through the process of configuring their Windows Server 2012 domain controller to synchronize its time with a trusted, external resource. Use Google, Bing, or other preferred search engine to locate trusted NTP …

758 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

21 Experts available now in Live!

Get 1:1 Help Now