How to block USB Storage devices, but allow specific ones using Intune?

Brian Liu 140 Reputation points
2023-08-17T08:26:45.4833333+00:00

Hi,

I'm trying to create a configuration profile with Intune that blocks USB Storage devices, but will allow specific ones based on the Device ID number or serial number.

I've tried a number of links including the one below with no luck and the profile I create just blocks all the USB storage devices, even the one that I've specified not to block. Can anybody suggest something for me to try?

https://learn.microsoft.com/en-us/microsoft-365/security/defender-endpoint/mde-device-control-device-installation?view=o365-worldwide#deploying-and-managing-policy-via-intune

Thanks,

Windows 10
Windows 10
A Microsoft operating system that runs on personal computers and tablets.
11,774 questions
Microsoft Intune Configuration
Microsoft Intune Configuration
Microsoft Intune: A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.Configuration: The process of arranging or setting up computer systems, hardware, or software.
1,932 questions
{count} votes

Accepted answer
  1. Lu Dai-MSFT 28,421 Reputation points
    2023-08-18T01:46:21.24+00:00

    @Brian Liu Thanks for posting in our Q&A.

    For this issue, did you try to restrict USB devices and allow specific USB devices using Administrative Templates? Please refer to the following article:

    https://learn.microsoft.com/en-us/mem/intune/configuration/administrative-templates-restrict-usb


    If the answer is the right solution, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment".

    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.


1 additional answer

Sort by: Most helpful
  1. Mohamed Riswan 0 Reputation points
    2024-11-05T06:14:28.95+00:00

    So I did the below and still the USB storage device that I've allowed by Device ID is being blocked

    • Enabled "Prevent installation of devices not described by other policy settings"
    • Enabled "Allow installation of devices using drivers that match these device setup classes"
    • Enabled "Allow installation of devices that match any of these Device IDs"

    I've also tried setting up using "Attack surface reduction" option in Endpoint Security

    Register all class GUID and hardware id and compliance id still facing issue


Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.