DeviceControl Policy for USB block leads to rights / access problems when changing the user

Erik Niemann 0 Reputation points
2024-03-21T06:11:44.88+00:00

Hello together!

We distribute a device control policy via Intune that is intended to prevent access to USB flashdrives, with maintenance of an exception list for certain USB devices. The policy is rolled out to the users. This means that the policy works initially and ends up on the client via sync via the company portal.

If I then change the user on the client with admin rights (these are not part of the assignment group for the policy), I then have full access to the USB device. If I then switch back to the normal user, this user has view rights to the usb drive, but cannot read, write or execute. Normally, however, an "Access Denied" is displayed when accessing the drive. The admin account seems to change a system-wide setting here, which then enables this "view" right for all users, regardless of the USB device. Does this have anything to do with the access level (device / file system)? How can I change this so that I have full access with the admin account and none at all with the normal user? Unfortunately, I am currently lacking any approach here and I cannot find anything useful to this topic.

Many thanks in advance for your ideas.

Windows 10
Windows 10
A Microsoft operating system that runs on personal computers and tablets.
11,028 questions
Windows 11
Windows 11
A Microsoft operating system designed for productivity, creativity, and ease of use.
8,735 questions
Microsoft Intune Security
Microsoft Intune Security
Microsoft Intune: A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.Security: The precautions taken to guard against crime, attack, sabotage, espionage, or another threat.
369 questions
Microsoft Intune Configuration
Microsoft Intune Configuration
Microsoft Intune: A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.Configuration: The process of arranging or setting up computer systems, hardware, or software.
1,781 questions
Microsoft Intune
Microsoft Intune
A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.
4,640 questions
{count} votes