Intune USB device read only but no write policy - possible?

RDW 216 Reputation points
2020-08-07T18:37:45.51+00:00

Hi folks

Is it currently possible within Intune via a Configuration Profile to achieve the following:

  • Allow read only of USB removable disks and WPD portabledevices
  • No write capability - not even BitLocker encryption to the above devices

Not sure if this can be achieved natively with Windows 10 and Intune. If anyone can advise whether this can achieved or not, that would be great. My suspicion is that it would require a 3rd party product.

Environment:

Windows 10 Enteprise 1909 with M365 E5 license

Thanks

Rob

Microsoft Intune Configuration
Microsoft Intune Configuration
Microsoft Intune: A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.Configuration: The process of arranging or setting up computer systems, hardware, or software.
1,953 questions
0 comments No comments
{count} votes

Accepted answer
  1. Jason Sandys 31,311 Reputation points Microsoft Employee
    2020-08-07T20:27:56.25+00:00

    First, always keep in mind that Intune doesn't define or dictate what can or cannot be done in Windows. Intune (for the most part) is simply deploying a policy and it's up to Windows to implement and act upon that policy.

    For your question, the Removable Storage Access policies (available in group policy) enable you to configure this in Windows. These policies from what I can see are not available as Windows 10 CSPs at this though and thus aren't configurable directly via the Intune UI.

    You could configure these policies manually though using PowerShell and send them to your systems that way.


3 additional answers

Sort by: Most helpful
  1. Crystal-MSFT 50,676 Reputation points Microsoft Vendor
    2020-08-10T03:11:34.797+00:00

    Hi Bob,

    Research and find a setting in Administrative Template device Configuration profile named "Deny write access to removable drives not protected by BitLocker"
    may be helpful. After setting this, for removable data drives that are not BitLocker-protected, it will be mounted as read-only. If the drive is protected by BitLocker, it will be mounted with read and write access.

    16661-image.png

    Hope it can help.


  2. OO 11 Reputation points
    2022-06-27T14:12:22.91+00:00

    Thanks for including a link to the powershell scripts that appears to work.........

    0 comments No comments

  3. Joe 1 Reputation point
    2022-08-01T01:31:17.61+00:00

    Yeah, some sort of general guidance Powershell script example would really help save our already frustrating world of tech, a little bit of time.
    Thanks

    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.