Device Control do not change registry after changes in ASR Policy in Intune/Defender

Jakub Karbowski 15 Reputation points
2024-01-19T12:29:44.3+00:00

Hola,

I have a question regarding "tattooing" records in registry by ASR Policy handling Device Control.

So the case is, in my corporate environment I configure ASR Device Control policy to block any Removable Media Storage (of course in testing environment). My concern is when I want to change this policy - of course new registry records are added, but old one are not deleted so it looks like:

  1. Block any Removable Media Storage
  2. Change ASR policy to Allow any Removable Media Storage (by change permission in Device Control bar)
  3. There are two records in endpoint devices registry Allow and Block, but of course block have higher priority - that's clear

The question is:

Why when I changed permission to Allow for the same reusable setting there is no changes in endpoint registry so all USB storage devices are blocked?

I tried also to remove blocking policy and create one with Allow permission but still - there is a existing record in registry named PolicyRules, full path: HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows Defender\Policy Manager -> PolicyRules

Deleting data related to Blocking policy solve the problem but the solution doesn't meet corporate requirements, for example blocking USB Storages for limited amount of time.

Can someone help me understand this process or describe how you handle it?

Thanks a lot...

Microsoft Intune Security
Microsoft Intune Security
Microsoft Intune: A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.Security: The precautions taken to guard against crime, attack, sabotage, espionage, or another threat.
417 questions
Microsoft Intune
Microsoft Intune
A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.
5,053 questions
{count} votes

1 answer

Sort by: Most helpful
  1. Pavel yannara Mirochnitchenko 12,576 Reputation points MVP
    2024-01-24T06:28:26.12+00:00

    This is known issue around some settings in mdm. Not all settings revert back to original. In your case, have you tried to revert the setting with Setting Catalog like this?

    User's image


Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.