Intune - Prevent unlocking of USB & External Storage

Heimdallr 266 Reputation points
2023-02-06T14:01:45.5166667+00:00

Hi,

I was thinking about something - If you use Intune to lock External Storage and USB and either completely cut off some devices, or use whitelist, that setting ventures to Registry, which means that everyone in the environment who has Administrator access like Helpdesk, can basically remove this policy locally from the machine and plug in an USB - Is there a way to prevent that other than limiting Admin rights to minimum?

I've figured out you can use MDE to run a query to see if someone plugged an USB but that can be too late

Microsoft Intune Security
Microsoft Intune Security
Microsoft Intune: A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.Security: The precautions taken to guard against crime, attack, sabotage, espionage, or another threat.
370 questions
Microsoft Intune
Microsoft Intune
A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.
4,665 questions
0 comments No comments
{count} votes

Accepted answer
  1. JatinMakhija 971 Reputation points
    2023-02-07T10:47:19.6033333+00:00

    I have not tried it but you could try to change the permissions on the usbstor registry key to read only for all users including administrators. In this way no one would be able to edit this registry key.

    If you are looking to Block USB drives using Microsoft Intune then you can follow below blog post:

    https://techpress.net/block-usb-drives-with-exceptions-using-microsoft-intune/


1 additional answer

Sort by: Most helpful
  1. Crystal-MSFT 45,656 Reputation points Microsoft Vendor
    2023-02-07T01:20:10.55+00:00

    @Heimdallr, Thanks for posting in Q&A. For Intune, it is a cloud service which can help manage device via deploying policies. For the policy it can deploy, it depends on the CSP which windows provided.

    After researching, I find the method to block USB is via administrative templates and the CSP also maps to ADMX.

    https://video2.skills-academy.com/en-us/mem/intune/configuration/administrative-templates-restrict-usb

    https://video2.skills-academy.com/en-us/windows/client-management/mdm/policy-csp-storage

    That means on windows side, the block setting is working on the registry key. In fact, Intune can only deploy policy setting to the device. If anyone has permission wants to change the registry key, it can not prevent it. But when the device sync with Intune again, the policy setting will be applied again. The result if a user can change the registry key is determined by the permission it has. Maybe you can see if there's any method from permission side to help you control the user behavior.

    Hope it can help.


    If the answer is helpful, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment".

    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.