how to restrict usb drives and other peripherals in windows 10, does bitlocker do, if not, do you have any solution

Software Registration 21 Reputation points
2021-05-12T17:28:34.81+00:00

I would like to manage all USB devices plugged on our computers throughout the domain. I would like to be able to block or unblock any of them, while letting other devices working in windows 10 function, example printer , mouse, keyboard. With GPO its seems to be difficult. Can Bit Locker do this? Does Windows Defender do this? And if not, what do you suggest to be able to manage this issue. Can Endpoint manage it
Thank You,
Sylvain

Azure Disk Encryption
Azure Disk Encryption
An Azure service for virtual machines (VMs) that helps address organizational security and compliance requirements by encrypting the VM boot and data disks with keys and policies that are controlled in Azure Key Vault.
174 questions
Windows Server
Windows Server
A family of Microsoft server operating systems that support enterprise-level management, data storage, applications, and communications.
13,054 questions
Windows 10 Network
Windows 10 Network
Windows 10: A Microsoft operating system that runs on personal computers and tablets.Network: A group of devices that communicate either wirelessly or via a physical connection.
2,346 questions
Microsoft Intune Configuration
Microsoft Intune Configuration
Microsoft Intune: A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.Configuration: The process of arranging or setting up computer systems, hardware, or software.
1,893 questions
{count} votes

Accepted answer
  1. Teemo Tang 11,411 Reputation points
    2021-05-13T07:22:49.347+00:00

    Hi Sylvain,

    Unfortunately, if we only focus on Windows 10 built-in features and Microsoft Windows related products, we can’t make it.
    Windows doesn’t have a function to pass/block specific USB drive but pass/block other USB drives, Microsoft’s security tools such as BitLocker, Defender, Endpoint, AppLocker neither can do it.
    From my experience, we need to use third-party security software for block policy. I ever used Symantec to pass specific USB devices and block all other USB drives, this software use hardware ID to recognize USB drive. You need to enter the hardware IDs of allowable USB devices in advance, then enable Symantec USB port protection(maybe it called this name), then other USB cannot work.

    -------------------------------------------------------------------------------------

    If the Answer is helpful, please click "Accept Answer" and upvote it.
    Please note: The mentioned product is owned and operated by a third party. Microsoft has no control regarding to the product's performance and reliability.
    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.

    0 comments No comments

0 additional answers

Sort by: Most helpful

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.