How to Disable USB Ports & Block USB Mass Storage Devices

A 32 gigabyte USB flash drive sitting on top of a computer keyboard

Want to control the use of unauthorized USB devices in your network? In this guide I will show you how to disable USB ports with three different methods: Using dedicated software to block USB ports, Windows Device Manager, and Group Policies through Active Directory. 

Table of Contents

Why Disable USB Ports?

Prevent Data Theft

Your employees have intimate access to corporate data and knowledge of internal systems. Without proper access control measures stealing data is as simple as transferring it to a portable mass storage device such as a USB flash drive.

Flash drives are capable of storing greater than 1TB of data, which is more than sufficient for exfiltrating databases, spreadsheets, design files, and any other intellectual property that needs to be protected.

One use of Data Loss Prevention (DLP) software is blocking the copying of files to a USB flash drive. This prevents employees from using their privileged position to steal sensitive information such as trade secrets and personally identifiable information. 


data theft prevention - a guide to offboarding employees - CurrentWare

The employee offboarding process presents significant data security risks. Employees have intimate access to corporate data, insider knowledge of the organization’s systems, and a level of trust that can allow them to steal data undetected.

  • 70% of intellectual property theft occurs within the 90 days before an employee’s resignation announcement
  • 88% of IT workers have stated that they would take sensitive data with them if they were fired
  • 72% of CEOs admit they’ve taken valuable intellectual property (IP) from a former employer
  • 50% of respondents in a Symantec survey say they have taken information, and 40% say they will use it in their new jobs

These vulnerabilities need to be addressed as part of any insider threat management program. Click here to learn the best practices for protecting data during a termination and gain access to a downloadable IT offboarding checklist.


Protect Endpoints Against USB Malware

USB devices can unknowingly infect company computers with ransomware and other malicious software. Disabling USB ports protects endpoints against rogue USB devices by proactively preventing the transmission of malicious files.

How to Block USB Storage Devices With AccessPatrol

AccessPatrol is a granular and easy-to-use software to block USB ports. It allows you to control access to USB devices and other peripherals based on users, computers, workgroups, and domain membership. 

This level of control allows you to protect against unauthorized USB devices without blocking the legitimate use of company-controlled peripherals.

It is also a centralized USB blocker software, allowing you to control USB device permissions for thousands of users from a single console.

To block USB devices with AccessPatrol you simply need to install the CurrentWare Console on the Manager’s computer, install the CurrentWare Client on the devices you would like to control, and return to the CurrentWare console to assign device permissions based on user, endpoint, or workgroup.


CurrentWare Customer Nicholas Scheetz

“With CurrentWare, we’re certain we’re meeting today’s cybersecurity standards whilst maintaining immediate, reliant access to patient records so we can keep delivering a high-quality service to our clients”

Nicholas Scheetz
IT Service Desk Supervisor
First Choice Health

See how First Choice Health protects patient data with AccessPatrol


Devices That Can Be Controlled With AccessPatrol

In addition to preventing the use of USB devices, AccessPatrol can block or limit the use of the following devices. Endpoint device restrictions can be configured based on computer, user, or workgroup.

Device ClassDevicesAccess Permissions
Storage DevicesUSBFull / Read only / No access
DVD /CDFull / Read only / No access
FloppyFull / Read only / No access
TapeFull / Read only / No access
External Hard driveFull / Read only / No access
FirewireFull / Read only / No access
SD CardFull / Read only / No access
MM CardFull / Read only / No access
Wireless DevicesBluetoothFull / No access
InfraredFull / No access
WifiFull / No access
Communication PortsSerialFull / No access
ParallelFull / No access
Imaging DevicesScannersFull / No access
Cameras, Webcams & OthersFull / No access
OthersPrintersFull / No access
USB Ethernet AdapterFull / No access
Sound CardsFull / No access
Portable Devices (iPhones, Mobiles)Full / No access
Network ShareFull / No access

How to Prevent Specific Files From Being Transferred to External Devices

AccessPatrol allows you to prevent specific files from being transferred to external devices  based on their name or extension.  

  1. Open the CurrentWare Console
    The CurrentWare console with 50 connected clients.
  2. Select the computers or users you would like to control
  3. Under the AccessPatrol tab, select Block File Transfers
    AccessPatrol menu with Block File Transfers highlighted
  4. Under Enter File Name or Extension, type in the desired extension (CSV, BAK, CAD, etc) or file name (client-list, archive, etc) that you would like to block
    AccessPatrol's Block File Transfers window, populated with file types such as .JSON, .PSD, and .LOG
  5. Click Add
  6. Click Apply to Clients and then click OK

By default AccessPatrol’s Block File Extensions feature will not apply these restrictions to devices that have been added to the Allow List.

If you would also like to block these file transfers to authorized USB devices you simply need to click the “Apply Block File Transfers on Allowed Devices” checkbox before applying the policy to the clients.

How to Disable USB Ports For Mass Storage Devices Only

If you would like to prevent your users from using USB ports for mass storage without blocking keyboards, mice, and other desired USB devices you can do that with AccessPatrol.

By default AccessPatrol distinguishes between USB storage devices and peripherals such as keyboards and mice. It also provides granular control over other peripheral devices such as external hard drives, SD Cards, Scanners, and Printers.

  1. Open the CurrentWare Console
  2. Select the computers or users you would like to control
  3. Under the AccessPatrol tab, select Device Blocking
    AccessPatrol menu with Device Blocking highlighted
  4. Under Storage Devices, select USB
    AccessPatrol device permissions menu with USB storage devices disabled
  5. Under Access Permissions set the desired level of restriction (Full Access, Read Only, No Access)
  6. Click Apply and then click OK

After following these steps you will be blocking USB mass storage devices while still allowing keyboards and mice to function.

How to Whitelist A Specific USB Device

Grant Ongoing Access to a Authorized USB Devices

With AccessPatrol’s Allowed List you can block all USB devices except specific company USB devices.

  1. Connect the USB device you would like to whitelist to any computer that has a CurrentWare Client installed
  2. Open the CurrentWare Console
  3. Select the folder with the computers or users you would like to control
  4. Under the AccessPatrol tab, select Allowed List
    AccessPatrol Allowed List window with Add From Available Devices highlighted
  5. Click “Add From Available Devices”
  6. Choose a device from the Vendor ID, Serial Number and/or PNP Device ID lists
    AccessPatrol Allowed List window with a list of available USB devices to allow
  7. Click on Add to Allowed List, then click OK

Administrators can use AccessPatrol’s Device Allowed List to establish a whitelist of devices that their end-users can use on company devices. 

You can choose to allow devices by the following identifiers:

  • Vendor ID
  • Serial number
  • PNP device ID

Device whitelisting is configured on a per-folder basis. Devices that are added to the allowed list will apply to any computers that are in the specified folder. AccessPatrol’s allowed list supports USBs, External Hard drives, Imaging devices, and portable devices.

Note: Allowing a device by serial number is fully compatible with Windows 10. For Windows 7 or 8, some newer models of USB devices may not support this feature. Instead of allowing by serial number, it will allow all devices from the same vendor and model.

Grant Temporary Access to USB Devices

AccessPatrol can grant temporary access to blocked devices using it’s access code generator

Administrators and authorized managers can use the generator to produce a single-use code that provides users with a set duration where the computer’s USB ports are no longer blocked by AccessPatrol. 

The access code is unique to each computer that you generate for and the computers do not need to be connected to the internet to use it. So long as the CurrentWare client is installed on the employee’s computer they can be provided with temporary access to USB devices.

  1. Generate a temporary access code
  • Open the CurrentWare Console
  • Select the computers or users you would like to provide temporary USB device access to
  • Click “Access Code Generator”
  • Choose the expiration date and duration of the access code
  • Click Generate to create a temporary access code
  1. Activate the temporary access code from the employee’s computer
  • Have the employee open the Control Panel
  • Set “View By” to large icons or small icons
  • Click “Grant access to endpoint devices”
  • Have the employee enter the temporary access code into the dialogue box, then click “Unlock”

How to Use the Device Manager to Disable USB Ports

If you would like to completely disable individual USB ports on a per-computer basis, you can do so with Windows Device Manager. 

This method is the most cumbersome to manage when an employee needs legitimate access to authorized USB devices as you will need to manually re-enable the ports from the device itself rather than using a central console.

  1. Log in to an administrator account
  2. Right-click on the Start menu
  3. Click on Device Manager
  4. Click on Universal Serial Bus controllers to view all of the USB ports
  5. Right click on the USB port that you would like to disable
  6. Select “Disable device”
  7. Restart the computer to apply the changes

To ensure that the employee does not manually re-enable the ports you will need to ensure they do not have access to an administrator account. To re-enable the ports simply perform steps 1-5 and select “Enable device”. 

How to Disable USB Ports Using Group Policy

If you would like detailed instructions on how to use a Group Policy Object to block employees from using USB devices you can visit this guide on the CurrentWare blog.

Although applying group policies is a useful way to control the usage of USB storage devices in an organization, there are disadvantages that should not go unnoticed. 

GPO vs USB Blocking Software:

  1. Applying unique USB restrictions to different departments and users with a GPO is complicated for the average user. It also requires proficiency with Active Directory to manage at-scale.
  2. Dedicated USB blocking software is easy to manage, allowing the modification of policy updates to be delegated to less technically-savvy users.
  3. Managing unique USB policies for individual users is more intuitive when using dedicated USB blocking software.

Conclusion

USB access control software is critical for protecting sensitive data against theft through unauthorized USB devices. If you would like to easily manage USB device permissions in your company you can get started with a free trial of AccessPatrol today.

Dale Strickland
Dale Strickland
Dale Strickland is a Marketing Coordinator for CurrentWare, a global provider of endpoint security and employee monitoring software. Dale’s diverse multimedia background allows him the opportunity to produce a variety of content for CurrentWare including blogs, infographics, videos, eBooks, and social media shareables.