Defender for Endpoint blocking USB & Bluetooth

Heimdallr 266 Reputation points
2023-01-27T15:30:06.23+00:00

Hello,

I am trying to create scenario where I set a Hyper-v VM and a DC, to test if I can block USB & Bluetooth in a reasonable way.

I know enhanced session can pass your devices to guest machine...but I am not sure if it is a valid way to test it so I need to understand this in the first place.

Generally, what I try to achieve as my end goal is to:

  1. Create a policy that will block all USB usage, but this also raised another question - How to give USB access to certain people? for example service desk, and only to them, while block it for rest.
  2. Make sure that bluetooth will allow ONLY day to day devices like headset, mouse - No type of storage or anything that could mess with the system.

I'm pretty new to it so I've spinned a trial of Intune + Defender for endpoint, connected the VM to Intune and connected Defender with Intune. Now the settings seem to either be not working, or the Hyper-V is unable to show me real results as this is just a VM, but configuration seems to be applied properly, nothing happens though.

I've tried to start with something simple like - kill Bluetooth and USB to see if it will work at all, but nothing happened.

My setting was: Endpoint Manager>Endpoint security>Attack Surface Reduction>Removable Media

and I've blocked everthing under Connectivity and Bluetooth

Any hint how to make this work, or a working configuration? Also is that Hyper-V even able to give me results I am looking for or I need to get a physical laptop for that?

Thank you

Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,250 questions
Microsoft Intune Security
Microsoft Intune Security
Microsoft Intune: A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.Security: The precautions taken to guard against crime, attack, sabotage, espionage, or another threat.
370 questions
Microsoft Intune
Microsoft Intune
A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.
4,665 questions
0 comments No comments
{count} votes

Accepted answer
  1. Crystal-MSFT 45,656 Reputation points Microsoft Vendor
    2023-01-30T01:42:30.97+00:00

    @Heimdallr, Thanks for posting in Q&A.

    For the Hyper-v VM, based on my researching, I didn't find the bluetooth can share with the VM. For USB devices, it can only share in RDP/Enhanced session. To double confirm on this, you can contact Hyper-V support.

    https://video2.skills-academy.com/en-us/virtualization/hyper-v-on-windows/user-guide/enhanced-session-mode

    To test on the policy, I think it is better to find one physical machine. For your questions, here are my answers for your reference:

    Q1: Create a policy that will block all USB usage, but this also raised another question - How to give USB access to certain people? for example service desk, and only to them, while block it for rest.

    A1: You can try the "Excluded groups" and select the service desk grou to exclude fromt he policy.

    https://video2.skills-academy.com/en-us/mem/intune/configuration/device-profile-assign

    Q2: Make sure that bluetooth will allow ONLY day to day devices like headset, mouse - No type of storage or anything that could mess with the system.

    A2: You can check if "Bluetooth allowed services" can meet your request.

    https://video2.skills-academy.com/en-us/mem/intune/configuration/device-restrictions-windows-10#bluetooth

    Hope it can help.


    If the answer is helpful, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment".

    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.


0 additional answers

Sort by: Most helpful