💻/🖥️ Windows 10 - Block USB Ports

TYPE AUDIENCE PRIORITY COMPLEXITY EFFORT COST UPDATED
Preparation 🏗️ ⭐⭐ ⭐⭐ 🧑 🆓 2021-06-17

Rationale

One of the most common ways in which networks and computers are compromised is through the introduction of a USB drive which has a virus on it. So if you are not dependent on using USB drives in your organisation, or you can manage to only use USD drives when you provide Administrator password, you can disable USB drive functionality for regular users for better safety.

Instructions

What you should prepare

What you should do

Take the following steps to setup a policy to prevent a user from using USB drives. Log in to the user account (i.e. not Admin account) and follow the steps:

  1. Select the Start button
  2. Search for and open "Group Policy Editor"
  3. Navigate through the tree menu to "User Configuration > Administrative Templates > System > Removable Storage Access".
    Pasted image 20210617173522.png
  4. Find and Click on "All Removable Storage Classes Deny All Access setting" from the list on the right
    Pasted image 20210617173653.png
  5. Click "Enabled" and "OK"
  6. Reboot the computer for the policy to take effect.
  7. Now if you want to connect a USB drive, you'll get the following message:
    Pasted image 20210617173824.png

If you really need to connect a USB drive, you first need to login to the Admin account where the restriction is not enforced.

Sources : Redmond