We’ve Updated Our Terms. We’ve updated our Terms Of ServicePrivacy Policy, and Data Processing Addendum, effective July 16, 2026. Please review the changes before continuing to use our services.

Data Loss Prevention

How to Block USB Drives in Group Policy

Rony Joseph
Head of Development, CurrentWare
Updated on 5 min read
Share this article

Need to block USB devices? In this article you will learn how to block USB drives with Active Directory Group Policy Objects (GPO). We will also compare using a GPO vs dedicated device control software for enforcing your removable media control policies.

Best Alternative to Group Policy for Blocking USB Devices

AccessPatrol is a device control software solution for preventing data loss to portable storage devices.

🔒 Block USB flash drives, external hard drives, and other peripheral devices
🔒 Monitor USB activities including file transfers and what devices have been used
🔒 Get DLP alerts sent to your inbox when high-risk USB activities occur

AccessPatrol’s security policies are enforced by a software agent that is installed on your employee’s computers. This keeps devices restricted and monitored even when the computers are taken off of the network.

Device Control: Group Policy vs AccessPatrol

Why Choose AccessPatrol for USB Restriction?

  1. Flexibility: Group Policy only supports domain-joined machines in a traditional Active Directory environment. AccessPatrol can integrate with your existing Active Directory OUs for ease of use while still allowing you to control non-domain machines.
  2. Ease of Use: Managing GPOs in a complex environment requires specialized skills, thorough testing, and trial & error to get right. With AccessPatrol blocking or allowing USB devices is as easy as a few clicks, saving admins valuable time in managing granular removable media device permissions in their environment.
  3. USB Activity Reports & Alerts: AccessPatrol’s reports make auditing USB activity simple and effective. Rather than combing through raw audit events data you can get automated alerts and easy-to-read reports that details File Operations to portable storage, attempts to use blocked peripheral devices, and general device usage history.
  4. Temporary Bypass: With AccessPatrol’s Access Code Generator you can provide a time-limited exemption from your USB control policies, even if the remote devices have no internet connection.
  5. Restrict File Transfers: If portable storage is a requirement in your environment, you may still want to prevent trusted devices from transferring sensitive files. With AccessPatrol’s Block File Transfers feature you can block transfers by File Name or Extension, preventing the transfer of sensitive data without limiting productivity.
  6. Seamless End-User Experience: When you update AccessPatrol’s device control policies your users will be seamlessly restricted without requiring a restart or logoff.
  7. CurrentWare Suite: AccessPatrol can be purchased as a standalone module or seamlessly integrated with the rest of the CurrentWare Suite, providing added security controls such as User Activity Monitoring and Web Filtering.

Examples of Devices That Can Be Controlled With AccessPatrol

AccessPatrol can block or limit the use of more than just USB storage devices. For full USB control, device permissions can be easily configured based on computer, user, or workgroup.

Device Class Devices Access Permissions
Storage Devices USB Full / Read only / No access
DVD /CD Full / Read only / No access
Floppy Full / Read only / No access
Tape Full / Read only / No access
External Hard drive Full / Read only / No access
Firewire Full / Read only / No access
SD Card Full / Read only / No access
MM Card Full / Read only / No access
Wireless Devices Bluetooth Full / Audio Only / No access
Infrared Full / No access
Wifi Full / No access
Communication Ports Serial Full / No access
Parallel Full / No access
Imaging Devices Scanners Full / No access
Cameras, Webcams & Others Full / No access
Others Printers Full / No access
USB Ethernet Adapter Full / No access
Sound Cards Full / No access
Portable Devices (iPhones, Mobiles) Full / No access
Network Share Full / No access

For the most up to date list of devices, see Which devices can I control with AccessPatrol?

How to Block All Removable Media Devices

AccessPatrol: How to Block USB Devices With AccessPatrol

AccessPatrol-peripheral-device-permissions-mockup-block-usb (1)

With AccessPatrol, blocking USB devices is as simple as a few clicks.

  1. Open the CurrentWare Console and select AccessPatrol
    AccessPatrol-Web-Console-copy
  2. Select the group(s) of computers or users you would like to control; AccessPatrol can control USB devices based on groups of user accounts or specific groups of computers.
  3. Under the AccessPatrol tab, select Device Permissions
    WEB_AP-Device-Permissions-Mockup-v902
  4. Under Storage Devices, you can set unique access permissions for USB, CD/DVD, Floppy, Tape, External HDD, Firewire, SD Card, and MM Cards.

WEB_AP-Device-Permissions-Mockup-v902

  1. For granular control over each device: Under Access Permissions set the desired level of restriction (Full Access, Read Only, No Access)
  2. To restrict all devices: Click “All Devices” and select the desired level of restriction.
  3. Click Apply to save your changes

Group Policy: How to Use Group Policy to Block All Removable Media Devices

Create a group policy object to store the policy you wish to impose in your domain.

disable-usb-by-group-policy

  1. Launch the Group Policy Management tool on the domain controller
  2. Right-click Group Policy Objects, click New
  3. Enter a name for the GPO and click OK
  4. Right-click the policy and click Edit.
  5. Group Policy Management Editor
  6. Navigate to Computer Configuration Policies > Administrative Templates > System > Removable Storage Access
  7. Right-click on All Removable Storage classes: Deny all access, click Edit.
  8. Click Enabled and click Apply and then OK
  9. Right-click on the OU
  10. Click Link an Existing GPO
  11. Select the GPO you created and click OK
  12. The last step is to update the group policy using the command line gpupdate /force.

Case Study: Viking Yachts Stops an Employee From Stealing Their Intellectual Property

QUOTE_VY_Stopped-Data-Theft_FB-LI-TW-2

As Viking Yachts grew, their network administrator Vincent Pecoreno was responsible for supporting over 530 users and 1500 devices across multiple geographic locations, making visibility a challenge without the right tools in place.

Once equipped with CurrentWare’s user activity monitoring and data loss prevention solutions, Viking Yachts had the insights they needed to protect their sensitive data.

Read their case study to learn more about how Vincent used CurrentWare to detect a data theft attempt from a soon-to-be-ex-employee.

How to Block Some Devices & Not Others

AccessPatrol: Block Specific Devices

With AccessPatrol, blocking specific USB devices is as simple as a few clicks.

  1. Open the CurrentWare Console and select AccessPatrol
    AccessPatrol-Web-Console-copy
  2. Select the group(s) of computers or users you would like to control
  3. Under the AccessPatrol tab, select Device Permissions
  4. Click on the exact device classes that you’d like to restrict; within each class of peripherals you can selectively disable specific device types.
    WEB_AP-Device-Permissions-Mockup-v902
  5. Under Access Permissions set the desired level of restriction (Full Access, Read Only, No Access)

WEB_AP-Device-Permissions-Mockup-v902

  • Click Apply to save your changes

  • AccessPatrol: Allow (Whitelist) Trusted Devices

    With AccessPatrol’s Allowed List you can block USB devices and other peripherals while allowing specific authorized removable media devices.

    1. Connect the desired USB device to any computer that has a CurrentWare Client installed
    2. Open the CurrentWare Console
    3. AccessPatrol-Web-Console-copy

    4. Select the folder with the computers or users you would like to control
    5. Under the AccessPatrol tab, select Allowed List
    6. availabledevicelist1

    7. Click “Add From Available Devices”
    8. Choose a device from the Vendor ID, Serial Number and/or PNP Device ID lists
    9. availabledevicelist1

    10. Click on Add to Allowed List, then click OK

    You can choose to allow devices by the following identifiers: Vendor ID, Serial number, PNP device ID.

    Device whitelisting is configured on a per-folder basis. Devices added to the allowed list for a given folder apply to any computers in that folder. AccessPatrol’s allowed list supports USBs, External Hard drives, Imaging devices, and portable devices.

    Note: Allowing a device by serial number is fully compatible with Windows 10. For Windows 7 or 8, some newer models of USB devices may not support this feature.


    Group Policy: How to Use Group Policy to Block Only Some Removable Media Devices

    Group-Policy-Block-Some-Devices-Not-Others

    1. In the Local Group Policy Editor (gpedit.msc) browse to: User Configuration > Administrative Templates > System > Removable Storage Access
    2. For each media type you’d like to control, enable Deny Read Access, Deny Write Access, or Both. With this method you can control CD/DVD, Custom Classes, Floppy Drives, Removable Disks, Tape Drives, and WPD Devices.
    3. Apply the GPO to the Users or OUs that you want to restrict

    NOTE: This feature doesn’t work in N editions of Windows 10 Pro.

    How to Allow USB Storage Devices But Restrict Specific File Transfers

    AccessPatrol: How to Prevent Specific Files From Being Transferred From USB Ports

    AccessPatrol allows you to prevent specific files from being transferred to external devices based on their filename or file extension.

    1. Open the CurrentWare Console
      AccessPatrol-Web-Console-copy
    2. Select the computers or users you would like to control
    3. Under the AccessPatrol tab, select Block File Transfers
    4. Cropped_AccessPatrol-Block-Fle-Transfers-Allowed-List

    5. Under Enter File Name or Extension, type in the desired extension (CSV, BAK, CAD, etc) or file name (client-list, archive, etc) that you would like to block
    6. Click Add, then click Close
    7. Click Apply to Clients and then click OK

    Group Policy

    This feature is not available in Group Policy

    How to Audit USB Device Usage

    AccessPatrol: How to Audit USB Device Usage

    With AccessPatrol, blocking USB devices is as simple as a few clicks.

      1. Open the CurrentWare Console and select AccessPatrol

    AccessPatrol-Web-Console-copy

      1. Select Device Reports, then select the Report Type, Computers/Users, Reporting Period, and other options for your USB activity report.

    AccessPatrol-Run-Report-Window-1080×608

    1. Click Run Report to generate a report that is populated with data that meets the parameters you set.

    Group Policy: How to Monitor the Use of Removable Storage Devices

    Microsoft has released instructions on monitoring the use of removable storage devices with group policy.

    If you configure this policy setting, an audit event is generated each time a user attempts to copy, move, or save a resource to a removable storage device.

    Auditing USB device usage in this way involves manually combing through event logs in search of specific event IDs, such as event 4663, which logs successful attempts to write to or read from a removable storage device.

    How to Allow Temporary Access to USB Devices

    AccessPatrol: How to Temporarily Allow Blocked USB Devices

    AccessPatrol can grant temporary access to blocked devices using it’s access code generator.

    Administrators and authorized managers can use the generator to produce a single-use code that provides users with a set duration where the computer’s USB ports are no longer disabled by AccessPatrol.

    The access code is unique to each computer that you generate for and the computers do not need to be connected to the internet to use it.

    1. Generate a temporary access code
      accesscodegen
    • Open the CurrentWare Console
    • Select the computers or users you would like to provide temporary USB device access to
    • Click “Access Code Generator”
    • Choose the expiration date and duration of the access code
    • Click Generate to create a temporary access code
    1. Activate the temporary access code from the employee’s computer

    grant-access-to-endpoint-devices

    • Have the employee open the Control Panel
    • Set “View By” to large icons or small icons
    • Click “Grant access to endpoint devices”
    • Have the employee enter the temporary access code into the dialogue box, then click “Unlock”

    Group Policy: How to Bypass GPO USB Blocking

    Group Policy does not support temporarily bypassing GPOs for a set period of time.

    To temporarily allow access to USB devices you will need to manually disable the GPO and manually re-enable it when the end-user no longer requires access to USB devices.

    To do this, open the Group Policy Management Console (GPMC), right click the USB blocking GPO under the OU and uncheck the option “Link Enabled”.

    To reenable the GPO, simply repeat the process and recheck “Link Enabled”

    Removable Media Policy Template
    Free Download

    Removable Media Policy Template

    • Set data security standards for portable storage
    • Define the acceptable use of removable media
    • Inform your users about their security responsibilities

    Get started today—Download the FREE template and customize it to fit the needs of your organization.

    Get the FREE Template

    Disadvantages of Using Group Policy to Block USBs

    Although applying group policies is a viable way to control the use of USB storage devices in an organization, there are disadvantages that should not go unnoticed. Here are some of the pitfalls to using GPOs you want to consider before depending on it for data security in your organization.

    Limited Granularity

    Group Policy might not offer the level of control needed for complex environments. For example, you might want to block storage devices except for those on an allow list. While some filtering by device ID is possible, it may not be as precise as needed.

    Complex to Setup & Maintain

    Using the Group Policy Object Editor to manage USB security policies can be overwhelming for those without a background in Active Directory and Group Policy management. From an organizational standpoint, the time and expertise needed to administer and modify USB restriction policies in this way might not be readily available. The complexity of GPOs is further compounded when it comes to applying unique USB restrictions to different departments, computers, and users in your organization.

    With AccessPatrol blocking USB devices is as easy as a few clicks. The time savings from not having to manually create and manage GPOs allows IT pros to focus their time on higher value tasks. Should USB restriction policies need an update the task can be readily delegated to someone with access to an authorized (and uniquely restricted) Operator account.

    Misconfiguration Will Affect Performance

    Group Policy Objects have mandatory updates that regularly occur at a set interval or when a PC is rebooted. You can modify the length of time between updates, however misconfigurations will bog down your network with an abundance of traffic.

    With CurrentWare’s lightweight server and client your AccessPatrol USB security policies will seamlessly update without hogging bandwidth and system resources.

    Limited to Domain-Joined Machines

    Group Policy only supports domain-joined machines in a traditional Active Directory environment. In mixed environments where IT pros need to manage both domain-joined and non-domain-joined machines, having AccessPatrol as a dedicated USB control software provides critical security controls for all of their managed devices.

    AccessPatrol-peripheral-device-permissions-mockup-block-usb

    Ready to take back control over USB device usage in your organization? Get started today with a FREE trial of AccessPatrol, CurrentWare’s device control software.

    Keep reading

    More articles
    By clicking “Accept All Cookies”, you agree to the storing of cookies on your device to enhance site navigation, analyze site usage, and assist in our marketing efforts. Privacy Policy