Avatar of Abraham Deutsch
Abraham Deutsch

asked on 

Restrict specific user from using removable drivers

I am looking to restrict a user from using removable drivers on their laptops, this can be accomplished with a local GP, but wondering if there is a way to apply the policy or do it in a different way so I can apply it only to standard users [or specific user] not to admin users.

Also, would I like to lock if possible to boot from USB so they cannot remove or change their password

Windows 10 not joined domain
Windows 10Windows OSOS SecuritySecurityLaptops Notebooks

Avatar of undefined
Last Comment
Abraham Deutsch
Avatar of yo_bee
yo_bee
Flag of United States of America image

This can be done via the GPMC on your domain the same way you do it via GPEDIT.MSC.  The only difference is that you will need to use one of the filtering methods (Security Filtering, WMI, OU, Delegation)

User Configuration | Administrative Templates | System | Removable Storage Access | <select your setting>

Apply the proper Security filtering and link it to the proper OU and you should be set.
 
My policy applies to Computers, but the same principal applies for the User Configuration settings. Deny-Access-to-Removable-Storage.htm

User generated image
User generated image
Avatar of arnold
arnold
Flag of United States of America image

On a laptop, the GPO would need to be local or otherwise it will not apply if the logon occurs while the user is away from the LAn.


If there is an enterprise clas anti-virus, mcaffee, Symantec, etc. it might be possible to restrict using a policy of the anti-virus.

The only way to prevent boot from USB is by locking the access to the bios while making sure it does not provide an option to boot of USB. Or ....
Avatar of Abraham Deutsch
Abraham Deutsch

ASKER

I am not sure where I find the option of filtering when I open Edit Group policy I get this window, and do not see the option of filtering
please help
User generated image
Avatar of yo_bee
yo_bee
Flag of United States of America image

Looks like you are using GPEDIT.msc not GPMC. GPEDIT is local only and  would not have the security filtering. You need to us GPMC which can be accessed via a domain controller or a computer with RSAT installed.
Avatar of Abraham Deutsch

ASKER

I tried to install RSAT but since this laptops are not joined to a domain, it does not seem to work.
User generated image
Avatar of arnold
arnold
Flag of United States of America image

on the laptop you would need to use regedit and effectively block USB to be functional only as a mouse, keyboard and likely webcam, not storage.

These are the limits.
Avatar of Abraham Deutsch

ASKER

Since I am not sure how to do it please provide more details which registry key to edit and how to it in a way it should apply to all user, highly appreciated
Avatar of arnold
arnold
Flag of United States of America image

Con a laptop that is not joined to a domain, the change is applicable to all.

https://www.raymond.cc/blog/how-to-disable-removable-storage-devices-such-as-usb-drives/

Look at the manual entry, disable the loading/starting if the usbstor driver while retaining the other functionalities.

This does not prevent the user from booting the system using a USB bootable/cd/DVD bootable to offload data if they are so intent on.
Avatar of Abraham Deutsch

ASKER

Just tested it I changed the value to 4 but USB it still accessible on the laptop

 is there any difference if it's done by local gp or by regedit? Also is there a difference if the policy is applied at the user configuration or at the computer configuration?
Avatar of yo_bee
yo_bee
Flag of United States of America image

Sorry I assumed that this was a domain computer based on the details I the question.
Avatar of arnold
arnold
Flag of United States of America image

The registry change requires a reboot as the driver loads on boot up.
ASKER CERTIFIED SOLUTION
Avatar of Abraham Deutsch
Abraham Deutsch

Blurred text
THIS SOLUTION IS ONLY AVAILABLE TO MEMBERS.
View this solution by signing up for a free trial.
Members can start a 7-Day free trial and enjoy unlimited access to the platform.
See Pricing Options
Start Free Trial
Windows OS
Windows OS

This topic area includes legacy versions of Windows prior to Windows 2000: Windows 3/3.1, Windows 95 and Windows 98, plus any other Windows-related versions including Windows Mobile.

129K
Questions
--
Followers
--
Top Experts
Get a personalized solution from industry experts
Ask the experts
Read over 600 more reviews

TRUSTED BY

IBM logoIntel logoMicrosoft logoUbisoft logoSAP logo
Qualcomm logoCitrix Systems logoWorkday logoErnst & Young logo
High performer badgeUsers love us badge
LinkedIn logoFacebook logoX logoInstagram logoTikTok logoYouTube logo