Bewerken

Delen via


Policy CSP - ADMX_RemovableStorage

Tip

This CSP contains ADMX-backed policies which require a special SyncML format to enable or disable. You must specify the data type in the SyncML as <Format>chr</Format>. For details, see Understanding ADMX-backed policies.

The payload of the SyncML must be XML-encoded; for this XML encoding, there are a variety of online encoders that you can use. To avoid encoding the payload, you can use CDATA if your MDM supports it. For more information, see CDATA Sections.

AccessRights_RebootTime_1

Scope Editions Applicable OS
❌ Device
✅ User
✅ Pro
✅ Enterprise
✅ Education
✅ Windows SE
✅ IoT Enterprise / IoT Enterprise LTSC
✅ Windows 10, version 2004 with KB5005101 [10.0.19041.1202] and later
✅ Windows 10, version 20H2 with KB5005101 [10.0.19042.1202] and later
✅ Windows 10, version 21H1 with KB5005101 [10.0.19043.1202] and later
✅ Windows 11, version 21H2 [10.0.22000] and later
./User/Vendor/MSFT/Policy/Config/ADMX_RemovableStorage/AccessRights_RebootTime_1

This policy setting configures the amount of time (in seconds) that the operating system waits to reboot in order to enforce a change in access rights to removable storage devices.

  • If you enable this policy setting, you can set the number of seconds you want the system to wait until a reboot.

  • If you disable or don't configure this setting, the operating system doesn't force a reboot.

Note

If no reboot is forced, the access right doesn't take effect until the operating system is restarted.

Description framework properties:

Property name Property value
Format chr (string)
Access Type Add, Delete, Get, Replace

Tip

This is an ADMX-backed policy and requires SyncML format for configuration. For an example of SyncML format, refer to Enabling a policy.

ADMX mapping:

Name Value
Name AccessRights_RebootTime_1
Friendly Name Set time (in seconds) to force reboot
Location User Configuration
Path System > Removable Storage Access
Registry Key Name Software\Policies\Microsoft\Windows\RemovableStorageDevices
Registry Value Name RebootTimeinSeconds_state
ADMX File Name RemovableStorage.admx

AccessRights_RebootTime_2

Scope Editions Applicable OS
✅ Device
❌ User
✅ Pro
✅ Enterprise
✅ Education
✅ Windows SE
✅ IoT Enterprise / IoT Enterprise LTSC
✅ Windows 10, version 2004 with KB5005101 [10.0.19041.1202] and later
✅ Windows 10, version 20H2 with KB5005101 [10.0.19042.1202] and later
✅ Windows 10, version 21H1 with KB5005101 [10.0.19043.1202] and later
✅ Windows 11, version 21H2 [10.0.22000] and later
./Device/Vendor/MSFT/Policy/Config/ADMX_RemovableStorage/AccessRights_RebootTime_2

This policy setting configures the amount of time (in seconds) that the operating system waits to reboot in order to enforce a change in access rights to removable storage devices.

  • If you enable this policy setting, you can set the number of seconds you want the system to wait until a reboot.

  • If you disable or don't configure this setting, the operating system doesn't force a reboot.

Note

If no reboot is forced, the access right doesn't take effect until the operating system is restarted.

Description framework properties:

Property name Property value
Format chr (string)
Access Type Add, Delete, Get, Replace

Tip

This is an ADMX-backed policy and requires SyncML format for configuration. For an example of SyncML format, refer to Enabling a policy.

ADMX mapping:

Name Value
Name AccessRights_RebootTime_2
Friendly Name Set time (in seconds) to force reboot
Location Computer Configuration
Path System > Removable Storage Access
Registry Key Name Software\Policies\Microsoft\Windows\RemovableStorageDevices
Registry Value Name RebootTimeinSeconds_state
ADMX File Name RemovableStorage.admx

CDandDVD_DenyExecute_Access_2

Scope Editions Applicable OS
✅ Device
❌ User
✅ Pro
✅ Enterprise
✅ Education
✅ Windows SE
✅ IoT Enterprise / IoT Enterprise LTSC
✅ Windows 10, version 2004 with KB5005101 [10.0.19041.1202] and later
✅ Windows 10, version 20H2 with KB5005101 [10.0.19042.1202] and later
✅ Windows 10, version 21H1 with KB5005101 [10.0.19043.1202] and later
✅ Windows 11, version 21H2 [10.0.22000] and later
./Device/Vendor/MSFT/Policy/Config/ADMX_RemovableStorage/CDandDVD_DenyExecute_Access_2

This policy setting denies execute access to the CD and DVD removable storage class.

  • If you enable this policy setting, execute access is denied to this removable storage class.

  • If you disable or don't configure this policy setting, execute access is allowed to this removable storage class.

Description framework properties:

Property name Property value
Format chr (string)
Access Type Add, Delete, Get, Replace

Tip

This is an ADMX-backed policy and requires SyncML format for configuration. For an example of SyncML format, refer to Enabling a policy.

ADMX mapping:

Name Value
Name CDandDVD_DenyExecute_Access_2
Friendly Name CD and DVD: Deny execute access
Location Computer Configuration
Path System > Removable Storage Access
Registry Key Name Software\Policies\Microsoft\Windows\RemovableStorageDevices{53f56308-b6bf-11d0-94f2-00a0c91efb8b}
Registry Value Name Deny_Execute
ADMX File Name RemovableStorage.admx

CDandDVD_DenyRead_Access_1

Scope Editions Applicable OS
❌ Device
✅ User
✅ Pro
✅ Enterprise
✅ Education
✅ Windows SE
✅ IoT Enterprise / IoT Enterprise LTSC
✅ Windows 10, version 2004 with KB5005101 [10.0.19041.1202] and later
✅ Windows 10, version 20H2 with KB5005101 [10.0.19042.1202] and later
✅ Windows 10, version 21H1 with KB5005101 [10.0.19043.1202] and later
✅ Windows 11, version 21H2 [10.0.22000] and later
./User/Vendor/MSFT/Policy/Config/ADMX_RemovableStorage/CDandDVD_DenyRead_Access_1

This policy setting denies read access to the CD and DVD removable storage class.

  • If you enable this policy setting, read access is denied to this removable storage class.

  • If you disable or don't configure this policy setting, read access is allowed to this removable storage class.

Description framework properties:

Property name Property value
Format chr (string)
Access Type Add, Delete, Get, Replace

Tip

This is an ADMX-backed policy and requires SyncML format for configuration. For an example of SyncML format, refer to Enabling a policy.

ADMX mapping:

Name Value
Name CDandDVD_DenyRead_Access_1
Friendly Name CD and DVD: Deny read access
Location User Configuration
Path System > Removable Storage Access
Registry Key Name Software\Policies\Microsoft\Windows\RemovableStorageDevices{53f56308-b6bf-11d0-94f2-00a0c91efb8b}
Registry Value Name Deny_Read
ADMX File Name RemovableStorage.admx

CDandDVD_DenyRead_Access_2

Scope Editions Applicable OS
✅ Device
❌ User
✅ Pro
✅ Enterprise
✅ Education
✅ Windows SE
✅ IoT Enterprise / IoT Enterprise LTSC
✅ Windows 10, version 2004 with KB5005101 [10.0.19041.1202] and later
✅ Windows 10, version 20H2 with KB5005101 [10.0.19042.1202] and later
✅ Windows 10, version 21H1 with KB5005101 [10.0.19043.1202] and later
✅ Windows 11, version 21H2 [10.0.22000] and later
./Device/Vendor/MSFT/Policy/Config/ADMX_RemovableStorage/CDandDVD_DenyRead_Access_2

This policy setting denies read access to the CD and DVD removable storage class.

  • If you enable this policy setting, read access is denied to this removable storage class.

  • If you disable or don't configure this policy setting, read access is allowed to this removable storage class.

Description framework properties:

Property name Property value
Format chr (string)
Access Type Add, Delete, Get, Replace

Tip

This is an ADMX-backed policy and requires SyncML format for configuration. For an example of SyncML format, refer to Enabling a policy.

ADMX mapping:

Name Value
Name CDandDVD_DenyRead_Access_2
Friendly Name CD and DVD: Deny read access
Location Computer Configuration
Path System > Removable Storage Access
Registry Key Name Software\Policies\Microsoft\Windows\RemovableStorageDevices{53f56308-b6bf-11d0-94f2-00a0c91efb8b}
Registry Value Name Deny_Read
ADMX File Name RemovableStorage.admx

CDandDVD_DenyWrite_Access_1

Scope Editions Applicable OS
❌ Device
✅ User
✅ Pro
✅ Enterprise
✅ Education
✅ Windows SE
✅ IoT Enterprise / IoT Enterprise LTSC
✅ Windows 10, version 2004 with KB5005101 [10.0.19041.1202] and later
✅ Windows 10, version 20H2 with KB5005101 [10.0.19042.1202] and later
✅ Windows 10, version 21H1 with KB5005101 [10.0.19043.1202] and later
✅ Windows 11, version 21H2 [10.0.22000] and later
./User/Vendor/MSFT/Policy/Config/ADMX_RemovableStorage/CDandDVD_DenyWrite_Access_1

This policy setting denies write access to the CD and DVD removable storage class.

  • If you enable this policy setting, write access is denied to this removable storage class.

  • If you disable or don't configure this policy setting, write access is allowed to this removable storage class.

Description framework properties:

Property name Property value
Format chr (string)
Access Type Add, Delete, Get, Replace

Tip

This is an ADMX-backed policy and requires SyncML format for configuration. For an example of SyncML format, refer to Enabling a policy.

ADMX mapping:

Name Value
Name CDandDVD_DenyWrite_Access_1
Friendly Name CD and DVD: Deny write access
Location User Configuration
Path System > Removable Storage Access
Registry Key Name Software\Policies\Microsoft\Windows\RemovableStorageDevices{53f56308-b6bf-11d0-94f2-00a0c91efb8b}
Registry Value Name Deny_Write
ADMX File Name RemovableStorage.admx

CDandDVD_DenyWrite_Access_2

Scope Editions Applicable OS
✅ Device
❌ User
✅ Pro
✅ Enterprise
✅ Education
✅ Windows SE
✅ IoT Enterprise / IoT Enterprise LTSC
✅ Windows 10, version 2004 with KB5005101 [10.0.19041.1202] and later
✅ Windows 10, version 20H2 with KB5005101 [10.0.19042.1202] and later
✅ Windows 10, version 21H1 with KB5005101 [10.0.19043.1202] and later
✅ Windows 11, version 21H2 [10.0.22000] and later
./Device/Vendor/MSFT/Policy/Config/ADMX_RemovableStorage/CDandDVD_DenyWrite_Access_2

This policy setting denies write access to the CD and DVD removable storage class.

  • If you enable this policy setting, write access is denied to this removable storage class.

  • If you disable or don't configure this policy setting, write access is allowed to this removable storage class.

Description framework properties:

Property name Property value
Format chr (string)
Access Type Add, Delete, Get, Replace

Tip

This is an ADMX-backed policy and requires SyncML format for configuration. For an example of SyncML format, refer to Enabling a policy.

ADMX mapping:

Name Value
Name CDandDVD_DenyWrite_Access_2
Friendly Name CD and DVD: Deny write access
Location Computer Configuration
Path System > Removable Storage Access
Registry Key Name Software\Policies\Microsoft\Windows\RemovableStorageDevices{53f56308-b6bf-11d0-94f2-00a0c91efb8b}
Registry Value Name Deny_Write
ADMX File Name RemovableStorage.admx

CustomClasses_DenyRead_Access_1

Scope Editions Applicable OS
❌ Device
✅ User
✅ Pro
✅ Enterprise
✅ Education
✅ Windows SE
✅ IoT Enterprise / IoT Enterprise LTSC
✅ Windows 10, version 2004 with KB5005101 [10.0.19041.1202] and later
✅ Windows 10, version 20H2 with KB5005101 [10.0.19042.1202] and later
✅ Windows 10, version 21H1 with KB5005101 [10.0.19043.1202] and later
✅ Windows 11, version 21H2 [10.0.22000] and later
./User/Vendor/MSFT/Policy/Config/ADMX_RemovableStorage/CustomClasses_DenyRead_Access_1

This policy setting denies read access to custom removable storage classes.

  • If you enable this policy setting, read access is denied to these removable storage classes.

  • If you disable or don't configure this policy setting, read access is allowed to these removable storage classes.

Description framework properties:

Property name Property value
Format chr (string)
Access Type Add, Delete, Get, Replace

Tip

This is an ADMX-backed policy and requires SyncML format for configuration. For an example of SyncML format, refer to Enabling a policy.

ADMX mapping:

Name Value
Name CustomClasses_DenyRead_Access_1
Friendly Name Custom Classes: Deny read access
Location User Configuration
Path System > Removable Storage Access
Registry Key Name Software\Policies\Microsoft\Windows\RemovableStorageDevices\Custom\Deny_Read
Registry Value Name Deny_Read
ADMX File Name RemovableStorage.admx

CustomClasses_DenyRead_Access_2

Scope Editions Applicable OS
✅ Device
❌ User
✅ Pro
✅ Enterprise
✅ Education
✅ Windows SE
✅ IoT Enterprise / IoT Enterprise LTSC
✅ Windows 10, version 2004 with KB5005101 [10.0.19041.1202] and later
✅ Windows 10, version 20H2 with KB5005101 [10.0.19042.1202] and later
✅ Windows 10, version 21H1 with KB5005101 [10.0.19043.1202] and later
✅ Windows 11, version 21H2 [10.0.22000] and later
./Device/Vendor/MSFT/Policy/Config/ADMX_RemovableStorage/CustomClasses_DenyRead_Access_2

This policy setting denies read access to custom removable storage classes.

  • If you enable this policy setting, read access is denied to these removable storage classes.

  • If you disable or don't configure this policy setting, read access is allowed to these removable storage classes.

Description framework properties:

Property name Property value
Format chr (string)
Access Type Add, Delete, Get, Replace

Tip

This is an ADMX-backed policy and requires SyncML format for configuration. For an example of SyncML format, refer to Enabling a policy.

ADMX mapping:

Name Value
Name CustomClasses_DenyRead_Access_2
Friendly Name Custom Classes: Deny read access
Location Computer Configuration
Path System > Removable Storage Access
Registry Key Name Software\Policies\Microsoft\Windows\RemovableStorageDevices\Custom\Deny_Read
Registry Value Name Deny_Read
ADMX File Name RemovableStorage.admx

CustomClasses_DenyWrite_Access_1

Scope Editions Applicable OS
❌ Device
✅ User
✅ Pro
✅ Enterprise
✅ Education
✅ Windows SE
✅ IoT Enterprise / IoT Enterprise LTSC
✅ Windows 10, version 2004 with KB5005101 [10.0.19041.1202] and later
✅ Windows 10, version 20H2 with KB5005101 [10.0.19042.1202] and later
✅ Windows 10, version 21H1 with KB5005101 [10.0.19043.1202] and later
✅ Windows 11, version 21H2 [10.0.22000] and later
./User/Vendor/MSFT/Policy/Config/ADMX_RemovableStorage/CustomClasses_DenyWrite_Access_1

This policy setting denies write access to custom removable storage classes.

  • If you enable this policy setting, write access is denied to these removable storage classes.

  • If you disable or don't configure this policy setting, write access is allowed to these removable storage classes.

Description framework properties:

Property name Property value
Format chr (string)
Access Type Add, Delete, Get, Replace

Tip

This is an ADMX-backed policy and requires SyncML format for configuration. For an example of SyncML format, refer to Enabling a policy.

ADMX mapping:

Name Value
Name CustomClasses_DenyWrite_Access_1
Friendly Name Custom Classes: Deny write access
Location User Configuration
Path System > Removable Storage Access
Registry Key Name Software\Policies\Microsoft\Windows\RemovableStorageDevices\Custom\Deny_Write
Registry Value Name Deny_Write
ADMX File Name RemovableStorage.admx

CustomClasses_DenyWrite_Access_2

Scope Editions Applicable OS
✅ Device
❌ User
✅ Pro
✅ Enterprise
✅ Education
✅ Windows SE
✅ IoT Enterprise / IoT Enterprise LTSC
✅ Windows 10, version 2004 with KB5005101 [10.0.19041.1202] and later
✅ Windows 10, version 20H2 with KB5005101 [10.0.19042.1202] and later
✅ Windows 10, version 21H1 with KB5005101 [10.0.19043.1202] and later
✅ Windows 11, version 21H2 [10.0.22000] and later
./Device/Vendor/MSFT/Policy/Config/ADMX_RemovableStorage/CustomClasses_DenyWrite_Access_2

This policy setting denies write access to custom removable storage classes.

  • If you enable this policy setting, write access is denied to these removable storage classes.

  • If you disable or don't configure this policy setting, write access is allowed to these removable storage classes.

Description framework properties:

Property name Property value
Format chr (string)
Access Type Add, Delete, Get, Replace

Tip

This is an ADMX-backed policy and requires SyncML format for configuration. For an example of SyncML format, refer to Enabling a policy.

ADMX mapping:

Name Value
Name CustomClasses_DenyWrite_Access_2
Friendly Name Custom Classes: Deny write access
Location Computer Configuration
Path System > Removable Storage Access
Registry Key Name Software\Policies\Microsoft\Windows\RemovableStorageDevices\Custom\Deny_Write
Registry Value Name Deny_Write
ADMX File Name RemovableStorage.admx

FloppyDrives_DenyExecute_Access_2

Scope Editions Applicable OS
✅ Device
❌ User
✅ Pro
✅ Enterprise
✅ Education
✅ Windows SE
✅ IoT Enterprise / IoT Enterprise LTSC
✅ Windows 10, version 2004 with KB5005101 [10.0.19041.1202] and later
✅ Windows 10, version 20H2 with KB5005101 [10.0.19042.1202] and later
✅ Windows 10, version 21H1 with KB5005101 [10.0.19043.1202] and later
✅ Windows 11, version 21H2 [10.0.22000] and later
./Device/Vendor/MSFT/Policy/Config/ADMX_RemovableStorage/FloppyDrives_DenyExecute_Access_2

This policy setting denies execute access to the Floppy Drives removable storage class, including USB Floppy Drives.

  • If you enable this policy setting, execute access is denied to this removable storage class.

  • If you disable or don't configure this policy setting, execute access is allowed to this removable storage class.

Description framework properties:

Property name Property value
Format chr (string)
Access Type Add, Delete, Get, Replace

Tip

This is an ADMX-backed policy and requires SyncML format for configuration. For an example of SyncML format, refer to Enabling a policy.

ADMX mapping:

Name Value
Name FloppyDrives_DenyExecute_Access_2
Friendly Name Floppy Drives: Deny execute access
Location Computer Configuration
Path System > Removable Storage Access
Registry Key Name Software\Policies\Microsoft\Windows\RemovableStorageDevices{53f56311-b6bf-11d0-94f2-00a0c91efb8b}
Registry Value Name Deny_Execute
ADMX File Name RemovableStorage.admx

FloppyDrives_DenyRead_Access_1

Scope Editions Applicable OS
❌ Device
✅ User
✅ Pro
✅ Enterprise
✅ Education
✅ Windows SE
✅ IoT Enterprise / IoT Enterprise LTSC
✅ Windows 10, version 2004 with KB5005101 [10.0.19041.1202] and later
✅ Windows 10, version 20H2 with KB5005101 [10.0.19042.1202] and later
✅ Windows 10, version 21H1 with KB5005101 [10.0.19043.1202] and later
✅ Windows 11, version 21H2 [10.0.22000] and later
./User/Vendor/MSFT/Policy/Config/ADMX_RemovableStorage/FloppyDrives_DenyRead_Access_1

This policy setting denies read access to the Floppy Drives removable storage class, including USB Floppy Drives.

  • If you enable this policy setting, read access is denied to this removable storage class.

  • If you disable or don't configure this policy setting, read access is allowed to this removable storage class.

Description framework properties:

Property name Property value
Format chr (string)
Access Type Add, Delete, Get, Replace

Tip

This is an ADMX-backed policy and requires SyncML format for configuration. For an example of SyncML format, refer to Enabling a policy.

ADMX mapping:

Name Value
Name FloppyDrives_DenyRead_Access_1
Friendly Name Floppy Drives: Deny read access
Location User Configuration
Path System > Removable Storage Access
Registry Key Name Software\Policies\Microsoft\Windows\RemovableStorageDevices{53f56311-b6bf-11d0-94f2-00a0c91efb8b}
Registry Value Name Deny_Read
ADMX File Name RemovableStorage.admx

FloppyDrives_DenyRead_Access_2

Scope Editions Applicable OS
✅ Device
❌ User
✅ Pro
✅ Enterprise
✅ Education
✅ Windows SE
✅ IoT Enterprise / IoT Enterprise LTSC
✅ Windows 10, version 2004 with KB5005101 [10.0.19041.1202] and later
✅ Windows 10, version 20H2 with KB5005101 [10.0.19042.1202] and later
✅ Windows 10, version 21H1 with KB5005101 [10.0.19043.1202] and later
✅ Windows 11, version 21H2 [10.0.22000] and later
./Device/Vendor/MSFT/Policy/Config/ADMX_RemovableStorage/FloppyDrives_DenyRead_Access_2

This policy setting denies read access to the Floppy Drives removable storage class, including USB Floppy Drives.

  • If you enable this policy setting, read access is denied to this removable storage class.

  • If you disable or don't configure this policy setting, read access is allowed to this removable storage class.

Description framework properties:

Property name Property value
Format chr (string)
Access Type Add, Delete, Get, Replace

Tip

This is an ADMX-backed policy and requires SyncML format for configuration. For an example of SyncML format, refer to Enabling a policy.

ADMX mapping:

Name Value
Name FloppyDrives_DenyRead_Access_2
Friendly Name Floppy Drives: Deny read access
Location Computer Configuration
Path System > Removable Storage Access
Registry Key Name Software\Policies\Microsoft\Windows\RemovableStorageDevices{53f56311-b6bf-11d0-94f2-00a0c91efb8b}
Registry Value Name Deny_Read
ADMX File Name RemovableStorage.admx

FloppyDrives_DenyWrite_Access_1

Scope Editions Applicable OS
❌ Device
✅ User
✅ Pro
✅ Enterprise
✅ Education
✅ Windows SE
✅ IoT Enterprise / IoT Enterprise LTSC
✅ Windows 10, version 2004 with KB5005101 [10.0.19041.1202] and later
✅ Windows 10, version 20H2 with KB5005101 [10.0.19042.1202] and later
✅ Windows 10, version 21H1 with KB5005101 [10.0.19043.1202] and later
✅ Windows 11, version 21H2 [10.0.22000] and later
./User/Vendor/MSFT/Policy/Config/ADMX_RemovableStorage/FloppyDrives_DenyWrite_Access_1

This policy setting denies write access to the Floppy Drives removable storage class, including USB Floppy Drives.

  • If you enable this policy setting, write access is denied to this removable storage class.

  • If you disable or don't configure this policy setting, write access is allowed to this removable storage class.

Description framework properties:

Property name Property value
Format chr (string)
Access Type Add, Delete, Get, Replace

Tip

This is an ADMX-backed policy and requires SyncML format for configuration. For an example of SyncML format, refer to Enabling a policy.

ADMX mapping:

Name Value
Name FloppyDrives_DenyWrite_Access_1
Friendly Name Floppy Drives: Deny write access
Location User Configuration
Path System > Removable Storage Access
Registry Key Name Software\Policies\Microsoft\Windows\RemovableStorageDevices{53f56311-b6bf-11d0-94f2-00a0c91efb8b}
Registry Value Name Deny_Write
ADMX File Name RemovableStorage.admx

FloppyDrives_DenyWrite_Access_2

Scope Editions Applicable OS
✅ Device
❌ User
✅ Pro
✅ Enterprise
✅ Education
✅ Windows SE
✅ IoT Enterprise / IoT Enterprise LTSC
✅ Windows 10, version 2004 with KB5005101 [10.0.19041.1202] and later
✅ Windows 10, version 20H2 with KB5005101 [10.0.19042.1202] and later
✅ Windows 10, version 21H1 with KB5005101 [10.0.19043.1202] and later
✅ Windows 11, version 21H2 [10.0.22000] and later
./Device/Vendor/MSFT/Policy/Config/ADMX_RemovableStorage/FloppyDrives_DenyWrite_Access_2

This policy setting denies write access to the Floppy Drives removable storage class, including USB Floppy Drives.

  • If you enable this policy setting, write access is denied to this removable storage class.

  • If you disable or don't configure this policy setting, write access is allowed to this removable storage class.

Description framework properties:

Property name Property value
Format chr (string)
Access Type Add, Delete, Get, Replace

Tip

This is an ADMX-backed policy and requires SyncML format for configuration. For an example of SyncML format, refer to Enabling a policy.

ADMX mapping:

Name Value
Name FloppyDrives_DenyWrite_Access_2
Friendly Name Floppy Drives: Deny write access
Location Computer Configuration
Path System > Removable Storage Access
Registry Key Name Software\Policies\Microsoft\Windows\RemovableStorageDevices{53f56311-b6bf-11d0-94f2-00a0c91efb8b}
Registry Value Name Deny_Write
ADMX File Name RemovableStorage.admx

Removable_Remote_Allow_Access

Scope Editions Applicable OS
✅ Device
❌ User
✅ Pro
✅ Enterprise
✅ Education
✅ Windows SE
✅ IoT Enterprise / IoT Enterprise LTSC
✅ Windows 10, version 2004 with KB5005101 [10.0.19041.1202] and later
✅ Windows 10, version 20H2 with KB5005101 [10.0.19042.1202] and later
✅ Windows 10, version 21H1 with KB5005101 [10.0.19043.1202] and later
✅ Windows 11, version 21H2 [10.0.22000] and later
./Device/Vendor/MSFT/Policy/Config/ADMX_RemovableStorage/Removable_Remote_Allow_Access

This policy setting grants normal users direct access to removable storage devices in remote sessions.

  • If you enable this policy setting, remote users can open direct handles to removable storage devices in remote sessions.

  • If you disable or don't configure this policy setting, remote users can't open direct handles to removable storage devices in remote sessions.

Description framework properties:

Property name Property value
Format chr (string)
Access Type Add, Delete, Get, Replace

Tip

This is an ADMX-backed policy and requires SyncML format for configuration. For an example of SyncML format, refer to Enabling a policy.

ADMX mapping:

Name Value
Name Removable_Remote_Allow_Access
Friendly Name All Removable Storage: Allow direct access in remote sessions
Location Computer Configuration
Path System > Removable Storage Access
Registry Key Name Software\Policies\Microsoft\Windows\RemovableStorageDevices
Registry Value Name AllowRemoteDASD
ADMX File Name RemovableStorage.admx

RemovableDisks_DenyExecute_Access_2

Scope Editions Applicable OS
✅ Device
❌ User
✅ Pro
✅ Enterprise
✅ Education
✅ Windows SE
✅ IoT Enterprise / IoT Enterprise LTSC
✅ Windows 10, version 2004 with KB5005101 [10.0.19041.1202] and later
✅ Windows 10, version 20H2 with KB5005101 [10.0.19042.1202] and later
✅ Windows 10, version 21H1 with KB5005101 [10.0.19043.1202] and later
✅ Windows 11, version 21H2 [10.0.22000] and later
./Device/Vendor/MSFT/Policy/Config/ADMX_RemovableStorage/RemovableDisks_DenyExecute_Access_2

This policy setting denies execute access to removable disks.

  • If you enable this policy setting, execute access is denied to this removable storage class.

  • If you disable or don't configure this policy setting, execute access is allowed to this removable storage class.

Description framework properties:

Property name Property value
Format chr (string)
Access Type Add, Delete, Get, Replace

Tip

This is an ADMX-backed policy and requires SyncML format for configuration. For an example of SyncML format, refer to Enabling a policy.

ADMX mapping:

Name Value
Name RemovableDisks_DenyExecute_Access_2
Friendly Name Removable Disks: Deny execute access
Location Computer Configuration
Path System > Removable Storage Access
Registry Key Name Software\Policies\Microsoft\Windows\RemovableStorageDevices{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}
Registry Value Name Deny_Execute
ADMX File Name RemovableStorage.admx

RemovableDisks_DenyRead_Access_1

Scope Editions Applicable OS
❌ Device
✅ User
✅ Pro
✅ Enterprise
✅ Education
✅ Windows SE
✅ IoT Enterprise / IoT Enterprise LTSC
✅ Windows 10, version 2004 with KB5005101 [10.0.19041.1202] and later
✅ Windows 10, version 20H2 with KB5005101 [10.0.19042.1202] and later
✅ Windows 10, version 21H1 with KB5005101 [10.0.19043.1202] and later
✅ Windows 11, version 21H2 [10.0.22000] and later
./User/Vendor/MSFT/Policy/Config/ADMX_RemovableStorage/RemovableDisks_DenyRead_Access_1

This policy setting denies read access to removable disks.

  • If you enable this policy setting, read access is denied to this removable storage class.

  • If you disable or don't configure this policy setting, read access is allowed to this removable storage class.

Description framework properties:

Property name Property value
Format chr (string)
Access Type Add, Delete, Get, Replace

Tip

This is an ADMX-backed policy and requires SyncML format for configuration. For an example of SyncML format, refer to Enabling a policy.

ADMX mapping:

Name Value
Name RemovableDisks_DenyRead_Access_1
Friendly Name Removable Disks: Deny read access
Location User Configuration
Path System > Removable Storage Access
Registry Key Name Software\Policies\Microsoft\Windows\RemovableStorageDevices{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}
Registry Value Name Deny_Read
ADMX File Name RemovableStorage.admx

RemovableDisks_DenyRead_Access_2

Scope Editions Applicable OS
✅ Device
❌ User
✅ Pro
✅ Enterprise
✅ Education
✅ Windows SE
✅ IoT Enterprise / IoT Enterprise LTSC
✅ Windows 10, version 2004 with KB5005101 [10.0.19041.1202] and later
✅ Windows 10, version 20H2 with KB5005101 [10.0.19042.1202] and later
✅ Windows 10, version 21H1 with KB5005101 [10.0.19043.1202] and later
✅ Windows 11, version 21H2 [10.0.22000] and later
./Device/Vendor/MSFT/Policy/Config/ADMX_RemovableStorage/RemovableDisks_DenyRead_Access_2

This policy setting denies read access to removable disks.

  • If you enable this policy setting, read access is denied to this removable storage class.

  • If you disable or don't configure this policy setting, read access is allowed to this removable storage class.

Description framework properties:

Property name Property value
Format chr (string)
Access Type Add, Delete, Get, Replace

Tip

This is an ADMX-backed policy and requires SyncML format for configuration. For an example of SyncML format, refer to Enabling a policy.

ADMX mapping:

Name Value
Name RemovableDisks_DenyRead_Access_2
Friendly Name Removable Disks: Deny read access
Location Computer Configuration
Path System > Removable Storage Access
Registry Key Name Software\Policies\Microsoft\Windows\RemovableStorageDevices{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}
Registry Value Name Deny_Read
ADMX File Name RemovableStorage.admx

RemovableDisks_DenyWrite_Access_1

Scope Editions Applicable OS
❌ Device
✅ User
✅ Pro
✅ Enterprise
✅ Education
✅ Windows SE
✅ IoT Enterprise / IoT Enterprise LTSC
✅ Windows 10, version 2004 with KB5005101 [10.0.19041.1202] and later
✅ Windows 10, version 20H2 with KB5005101 [10.0.19042.1202] and later
✅ Windows 10, version 21H1 with KB5005101 [10.0.19043.1202] and later
✅ Windows 11, version 21H2 [10.0.22000] and later
./User/Vendor/MSFT/Policy/Config/ADMX_RemovableStorage/RemovableDisks_DenyWrite_Access_1

This policy setting denies write access to removable disks.

  • If you enable this policy setting, write access is denied to this removable storage class.

  • If you disable or don't configure this policy setting, write access is allowed to this removable storage class.

Note

To require that users write data to BitLocker-protected storage, enable the policy setting "Deny write access to drives not protected by BitLocker," which is located in "Computer Configuration\Administrative Templates\Windows Components\BitLocker Drive Encryption\Removable Data Drives".

Description framework properties:

Property name Property value
Format chr (string)
Access Type Add, Delete, Get, Replace

Tip

This is an ADMX-backed policy and requires SyncML format for configuration. For an example of SyncML format, refer to Enabling a policy.

ADMX mapping:

Name Value
Name RemovableDisks_DenyWrite_Access_1
Friendly Name Removable Disks: Deny write access
Location User Configuration
Path System > Removable Storage Access
Registry Key Name Software\Policies\Microsoft\Windows\RemovableStorageDevices{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}
Registry Value Name Deny_Write
ADMX File Name RemovableStorage.admx

RemovableStorageClasses_DenyAll_Access_1

Scope Editions Applicable OS
❌ Device
✅ User
✅ Pro
✅ Enterprise
✅ Education
✅ Windows SE
✅ IoT Enterprise / IoT Enterprise LTSC
✅ Windows 10, version 2004 with KB5005101 [10.0.19041.1202] and later
✅ Windows 10, version 20H2 with KB5005101 [10.0.19042.1202] and later
✅ Windows 10, version 21H1 with KB5005101 [10.0.19043.1202] and later
✅ Windows 11, version 21H2 [10.0.22000] and later
./User/Vendor/MSFT/Policy/Config/ADMX_RemovableStorage/RemovableStorageClasses_DenyAll_Access_1

Configure access to all removable storage classes.

This policy setting takes precedence over any individual removable storage policy settings. To manage individual classes, use the policy settings available for each class.

  • If you enable this policy setting, no access is allowed to any removable storage class.

  • If you disable or don't configure this policy setting, write and read accesses are allowed to all removable storage classes.

Description framework properties:

Property name Property value
Format chr (string)
Access Type Add, Delete, Get, Replace

Tip

This is an ADMX-backed policy and requires SyncML format for configuration. For an example of SyncML format, refer to Enabling a policy.

ADMX mapping:

Name Value
Name RemovableStorageClasses_DenyAll_Access_1
Friendly Name All Removable Storage classes: Deny all access
Location User Configuration
Path System > Removable Storage Access
Registry Key Name Software\Policies\Microsoft\Windows\RemovableStorageDevices
Registry Value Name Deny_All
ADMX File Name RemovableStorage.admx

RemovableStorageClasses_DenyAll_Access_2

Scope Editions Applicable OS
✅ Device
❌ User
✅ Pro
✅ Enterprise
✅ Education
✅ Windows SE
✅ IoT Enterprise / IoT Enterprise LTSC
✅ Windows 10, version 2004 with KB5005101 [10.0.19041.1202] and later
✅ Windows 10, version 20H2 with KB5005101 [10.0.19042.1202] and later
✅ Windows 10, version 21H1 with KB5005101 [10.0.19043.1202] and later
✅ Windows 11, version 21H2 [10.0.22000] and later
./Device/Vendor/MSFT/Policy/Config/ADMX_RemovableStorage/RemovableStorageClasses_DenyAll_Access_2

Configure access to all removable storage classes.

This policy setting takes precedence over any individual removable storage policy settings. To manage individual classes, use the policy settings available for each class.

  • If you enable this policy setting, no access is allowed to any removable storage class.

  • If you disable or don't configure this policy setting, write and read accesses are allowed to all removable storage classes.

Description framework properties:

Property name Property value
Format chr (string)
Access Type Add, Delete, Get, Replace

Tip

This is an ADMX-backed policy and requires SyncML format for configuration. For an example of SyncML format, refer to Enabling a policy.

ADMX mapping:

Name Value
Name RemovableStorageClasses_DenyAll_Access_2
Friendly Name All Removable Storage classes: Deny all access
Location Computer Configuration
Path System > Removable Storage Access
Registry Key Name Software\Policies\Microsoft\Windows\RemovableStorageDevices
Registry Value Name Deny_All
ADMX File Name RemovableStorage.admx

TapeDrives_DenyExecute_Access_2

Scope Editions Applicable OS
✅ Device
❌ User
✅ Pro
✅ Enterprise
✅ Education
✅ Windows SE
✅ IoT Enterprise / IoT Enterprise LTSC
✅ Windows 10, version 2004 with KB5005101 [10.0.19041.1202] and later
✅ Windows 10, version 20H2 with KB5005101 [10.0.19042.1202] and later
✅ Windows 10, version 21H1 with KB5005101 [10.0.19043.1202] and later
✅ Windows 11, version 21H2 [10.0.22000] and later
./Device/Vendor/MSFT/Policy/Config/ADMX_RemovableStorage/TapeDrives_DenyExecute_Access_2

This policy setting denies execute access to the Tape Drive removable storage class.

  • If you enable this policy setting, execute access is denied to this removable storage class.

  • If you disable or don't configure this policy setting, execute access is allowed to this removable storage class.

Description framework properties:

Property name Property value
Format chr (string)
Access Type Add, Delete, Get, Replace

Tip

This is an ADMX-backed policy and requires SyncML format for configuration. For an example of SyncML format, refer to Enabling a policy.

ADMX mapping:

Name Value
Name TapeDrives_DenyExecute_Access_2
Friendly Name Tape Drives: Deny execute access
Location Computer Configuration
Path System > Removable Storage Access
Registry Key Name Software\Policies\Microsoft\Windows\RemovableStorageDevices{53f5630b-b6bf-11d0-94f2-00a0c91efb8b}
Registry Value Name Deny_Execute
ADMX File Name RemovableStorage.admx

TapeDrives_DenyRead_Access_1

Scope Editions Applicable OS
❌ Device
✅ User
✅ Pro
✅ Enterprise
✅ Education
✅ Windows SE
✅ IoT Enterprise / IoT Enterprise LTSC
✅ Windows 10, version 2004 with KB5005101 [10.0.19041.1202] and later
✅ Windows 10, version 20H2 with KB5005101 [10.0.19042.1202] and later
✅ Windows 10, version 21H1 with KB5005101 [10.0.19043.1202] and later
✅ Windows 11, version 21H2 [10.0.22000] and later
./User/Vendor/MSFT/Policy/Config/ADMX_RemovableStorage/TapeDrives_DenyRead_Access_1

This policy setting denies read access to the Tape Drive removable storage class.

  • If you enable this policy setting, read access is denied to this removable storage class.

  • If you disable or don't configure this policy setting, read access is allowed to this removable storage class.

Description framework properties:

Property name Property value
Format chr (string)
Access Type Add, Delete, Get, Replace

Tip

This is an ADMX-backed policy and requires SyncML format for configuration. For an example of SyncML format, refer to Enabling a policy.

ADMX mapping:

Name Value
Name TapeDrives_DenyRead_Access_1
Friendly Name Tape Drives: Deny read access
Location User Configuration
Path System > Removable Storage Access
Registry Key Name Software\Policies\Microsoft\Windows\RemovableStorageDevices{53f5630b-b6bf-11d0-94f2-00a0c91efb8b}
Registry Value Name Deny_Read
ADMX File Name RemovableStorage.admx

TapeDrives_DenyRead_Access_2

Scope Editions Applicable OS
✅ Device
❌ User
✅ Pro
✅ Enterprise
✅ Education
✅ Windows SE
✅ IoT Enterprise / IoT Enterprise LTSC
✅ Windows 10, version 2004 with KB5005101 [10.0.19041.1202] and later
✅ Windows 10, version 20H2 with KB5005101 [10.0.19042.1202] and later
✅ Windows 10, version 21H1 with KB5005101 [10.0.19043.1202] and later
✅ Windows 11, version 21H2 [10.0.22000] and later
./Device/Vendor/MSFT/Policy/Config/ADMX_RemovableStorage/TapeDrives_DenyRead_Access_2

This policy setting denies read access to the Tape Drive removable storage class.

  • If you enable this policy setting, read access is denied to this removable storage class.

  • If you disable or don't configure this policy setting, read access is allowed to this removable storage class.

Description framework properties:

Property name Property value
Format chr (string)
Access Type Add, Delete, Get, Replace

Tip

This is an ADMX-backed policy and requires SyncML format for configuration. For an example of SyncML format, refer to Enabling a policy.

ADMX mapping:

Name Value
Name TapeDrives_DenyRead_Access_2
Friendly Name Tape Drives: Deny read access
Location Computer Configuration
Path System > Removable Storage Access
Registry Key Name Software\Policies\Microsoft\Windows\RemovableStorageDevices{53f5630b-b6bf-11d0-94f2-00a0c91efb8b}
Registry Value Name Deny_Read
ADMX File Name RemovableStorage.admx

TapeDrives_DenyWrite_Access_1

Scope Editions Applicable OS
❌ Device
✅ User
✅ Pro
✅ Enterprise
✅ Education
✅ Windows SE
✅ IoT Enterprise / IoT Enterprise LTSC
✅ Windows 10, version 2004 with KB5005101 [10.0.19041.1202] and later
✅ Windows 10, version 20H2 with KB5005101 [10.0.19042.1202] and later
✅ Windows 10, version 21H1 with KB5005101 [10.0.19043.1202] and later
✅ Windows 11, version 21H2 [10.0.22000] and later
./User/Vendor/MSFT/Policy/Config/ADMX_RemovableStorage/TapeDrives_DenyWrite_Access_1

This policy setting denies write access to the Tape Drive removable storage class.

  • If you enable this policy setting, write access is denied to this removable storage class.

  • If you disable or don't configure this policy setting, write access is allowed to this removable storage class.

Description framework properties:

Property name Property value
Format chr (string)
Access Type Add, Delete, Get, Replace

Tip

This is an ADMX-backed policy and requires SyncML format for configuration. For an example of SyncML format, refer to Enabling a policy.

ADMX mapping:

Name Value
Name TapeDrives_DenyWrite_Access_1
Friendly Name Tape Drives: Deny write access
Location User Configuration
Path System > Removable Storage Access
Registry Key Name Software\Policies\Microsoft\Windows\RemovableStorageDevices{53f5630b-b6bf-11d0-94f2-00a0c91efb8b}
Registry Value Name Deny_Write
ADMX File Name RemovableStorage.admx

TapeDrives_DenyWrite_Access_2

Scope Editions Applicable OS
✅ Device
❌ User
✅ Pro
✅ Enterprise
✅ Education
✅ Windows SE
✅ IoT Enterprise / IoT Enterprise LTSC
✅ Windows 10, version 2004 with KB5005101 [10.0.19041.1202] and later
✅ Windows 10, version 20H2 with KB5005101 [10.0.19042.1202] and later
✅ Windows 10, version 21H1 with KB5005101 [10.0.19043.1202] and later
✅ Windows 11, version 21H2 [10.0.22000] and later
./Device/Vendor/MSFT/Policy/Config/ADMX_RemovableStorage/TapeDrives_DenyWrite_Access_2

This policy setting denies write access to the Tape Drive removable storage class.

  • If you enable this policy setting, write access is denied to this removable storage class.

  • If you disable or don't configure this policy setting, write access is allowed to this removable storage class.

Description framework properties:

Property name Property value
Format chr (string)
Access Type Add, Delete, Get, Replace

Tip

This is an ADMX-backed policy and requires SyncML format for configuration. For an example of SyncML format, refer to Enabling a policy.

ADMX mapping:

Name Value
Name TapeDrives_DenyWrite_Access_2
Friendly Name Tape Drives: Deny write access
Location Computer Configuration
Path System > Removable Storage Access
Registry Key Name Software\Policies\Microsoft\Windows\RemovableStorageDevices{53f5630b-b6bf-11d0-94f2-00a0c91efb8b}
Registry Value Name Deny_Write
ADMX File Name RemovableStorage.admx

WPDDevices_DenyRead_Access_1

Scope Editions Applicable OS
❌ Device
✅ User
✅ Pro
✅ Enterprise
✅ Education
✅ Windows SE
✅ IoT Enterprise / IoT Enterprise LTSC
✅ Windows 10, version 2004 with KB5005101 [10.0.19041.1202] and later
✅ Windows 10, version 20H2 with KB5005101 [10.0.19042.1202] and later
✅ Windows 10, version 21H1 with KB5005101 [10.0.19043.1202] and later
✅ Windows 11, version 21H2 [10.0.22000] and later
./User/Vendor/MSFT/Policy/Config/ADMX_RemovableStorage/WPDDevices_DenyRead_Access_1

This policy setting denies read access to removable disks, which may include media players, cellular phones, auxiliary displays, and CE devices.

  • If you enable this policy setting, read access is denied to this removable storage class.

  • If you disable or don't configure this policy setting, read access is allowed to this removable storage class.

Description framework properties:

Property name Property value
Format chr (string)
Access Type Add, Delete, Get, Replace

Tip

This is an ADMX-backed policy and requires SyncML format for configuration. For an example of SyncML format, refer to Enabling a policy.

ADMX mapping:

Name Value
Name WPDDevices_DenyRead_Access_1
Friendly Name WPD Devices: Deny read access
Location User Configuration
Path System > Removable Storage Access
Registry Key Name Software\Policies\Microsoft\Windows\RemovableStorageDevices{6AC27878-A6FA-4155-BA85-F98F491D4F33}
Registry Value Name Deny_Read
ADMX File Name RemovableStorage.admx

WPDDevices_DenyRead_Access_2

Scope Editions Applicable OS
✅ Device
❌ User
✅ Pro
✅ Enterprise
✅ Education
✅ Windows SE
✅ IoT Enterprise / IoT Enterprise LTSC
✅ Windows 10, version 2004 with KB5005101 [10.0.19041.1202] and later
✅ Windows 10, version 20H2 with KB5005101 [10.0.19042.1202] and later
✅ Windows 10, version 21H1 with KB5005101 [10.0.19043.1202] and later
✅ Windows 11, version 21H2 [10.0.22000] and later
./Device/Vendor/MSFT/Policy/Config/ADMX_RemovableStorage/WPDDevices_DenyRead_Access_2

This policy setting denies read access to removable disks, which may include media players, cellular phones, auxiliary displays, and CE devices.

  • If you enable this policy setting, read access is denied to this removable storage class.

  • If you disable or don't configure this policy setting, read access is allowed to this removable storage class.

Description framework properties:

Property name Property value
Format chr (string)
Access Type Add, Delete, Get, Replace

Tip

This is an ADMX-backed policy and requires SyncML format for configuration. For an example of SyncML format, refer to Enabling a policy.

ADMX mapping:

Name Value
Name WPDDevices_DenyRead_Access_2
Friendly Name WPD Devices: Deny read access
Location Computer Configuration
Path System > Removable Storage Access
Registry Key Name Software\Policies\Microsoft\Windows\RemovableStorageDevices{6AC27878-A6FA-4155-BA85-F98F491D4F33}
Registry Value Name Deny_Read
ADMX File Name RemovableStorage.admx

WPDDevices_DenyWrite_Access_1

Scope Editions Applicable OS
❌ Device
✅ User
✅ Pro
✅ Enterprise
✅ Education
✅ Windows SE
✅ IoT Enterprise / IoT Enterprise LTSC
✅ Windows 10, version 2004 with KB5005101 [10.0.19041.1202] and later
✅ Windows 10, version 20H2 with KB5005101 [10.0.19042.1202] and later
✅ Windows 10, version 21H1 with KB5005101 [10.0.19043.1202] and later
✅ Windows 11, version 21H2 [10.0.22000] and later
./User/Vendor/MSFT/Policy/Config/ADMX_RemovableStorage/WPDDevices_DenyWrite_Access_1

This policy setting denies write access to removable disks, which may include media players, cellular phones, auxiliary displays, and CE devices.

  • If you enable this policy setting, write access is denied to this removable storage class.

  • If you disable or don't configure this policy setting, write access is allowed to this removable storage class.

Description framework properties:

Property name Property value
Format chr (string)
Access Type Add, Delete, Get, Replace

Tip

This is an ADMX-backed policy and requires SyncML format for configuration. For an example of SyncML format, refer to Enabling a policy.

ADMX mapping:

Name Value
Name WPDDevices_DenyWrite_Access_1
Friendly Name WPD Devices: Deny write access
Location User Configuration
Path System > Removable Storage Access
Registry Key Name Software\Policies\Microsoft\Windows\RemovableStorageDevices{6AC27878-A6FA-4155-BA85-F98F491D4F33}
Registry Value Name Deny_Write
ADMX File Name RemovableStorage.admx

WPDDevices_DenyWrite_Access_2

Scope Editions Applicable OS
✅ Device
❌ User
✅ Pro
✅ Enterprise
✅ Education
✅ Windows SE
✅ IoT Enterprise / IoT Enterprise LTSC
✅ Windows 10, version 2004 with KB5005101 [10.0.19041.1202] and later
✅ Windows 10, version 20H2 with KB5005101 [10.0.19042.1202] and later
✅ Windows 10, version 21H1 with KB5005101 [10.0.19043.1202] and later
✅ Windows 11, version 21H2 [10.0.22000] and later
./Device/Vendor/MSFT/Policy/Config/ADMX_RemovableStorage/WPDDevices_DenyWrite_Access_2

This policy setting denies write access to removable disks, which may include media players, cellular phones, auxiliary displays, and CE devices.

  • If you enable this policy setting, write access is denied to this removable storage class.

  • If you disable or don't configure this policy setting, write access is allowed to this removable storage class.

Description framework properties:

Property name Property value
Format chr (string)
Access Type Add, Delete, Get, Replace

Tip

This is an ADMX-backed policy and requires SyncML format for configuration. For an example of SyncML format, refer to Enabling a policy.

ADMX mapping:

Name Value
Name WPDDevices_DenyWrite_Access_2
Friendly Name WPD Devices: Deny write access
Location Computer Configuration
Path System > Removable Storage Access
Registry Key Name Software\Policies\Microsoft\Windows\RemovableStorageDevices{6AC27878-A6FA-4155-BA85-F98F491D4F33}
Registry Value Name Deny_Write
ADMX File Name RemovableStorage.admx

Policy configuration service provider