- #Unlocker usb mass storage device driver driver
- #Unlocker usb mass storage device driver portable
- #Unlocker usb mass storage device driver windows
To do this, you need to make changes to the registry through the GPO.
#Unlocker usb mass storage device driver driver
You can disable the USBSTOR driver from running on domain computers using Group Policy Preferences.
#Unlocker usb mass storage device driver windows
This is the only way to disable USB drives in outdated Windows XP/Windows Server 2003, since in these versions there are no separate Group Policy settings to restrict access to external USB devices. With the help of REG_DWORD parameters, I prohibited writing and running executable from USB drives. In the screenshot below, I’ve created a RemovableStorageDevices key, and a subkey named. You can manually create the specified registry keys and parameters. If the value of this parameter is equal to 1, the USB restriction is active, if 0 – there are no recstrcition on this device class. To enable one of these policies, you must create a new subkey in the specified key with the name of the device class you want to block access to (column 2) and REG_DWORD parameter with constraint type ( Deny_Read, Deny_Write or Deny_Execute). All the above policies correspond to certain registry keys in the HKLM (or HKCU) \SOFTWARE\Policies\Microsoft\Windows\RemovableStorageDevices key (by default this registry key is missing). You can more flexibly control access to external devices by configuring the registry settings that are set by the policies discussed above via the Group Policy Preferences (GPP). For this group, set permissions to read and apply the GPO, and leave only read permission for the Authenticated Users or Domain Computers group (by unchecking the Apply group policy checkbox).īlocking USB and Removable Devices via Registry and Group Policy Preferences Create a security group “Deny USB” and add this group in the security settings of the GPO. There may be another task – you need to allow the use of external USB drives for everyone except a certain group of users. In the security settings editor, specify that the Domain Admins group is not allowed to apply this GPO ( Apply group policy – Deny). Go to the Delegation tab and click the Advanced.In the Security Filtering section, add the Domain Admins group.Select your Disable USB Access policy in the Group Policy Management console.