Greetings.
I have a GPO's to control Users access to removable devices.
DC: Windows Server 2008R2.
PC: Windows 8 Professional.
So, OU "USB TEST" consist of my test user account.
I have 3 GPO, linked to this OU:
USB Deny:
User Configuration (Enabled)
Policies
Administrative Templates
System/Removable Storage Access
Policy Setting Comment
CD and DVD: Deny read access Enabled
CD and DVD: Deny write access Enabled
Floppy Drives: Deny read access Enabled
Floppy Drives: Deny write access Enabled
Removable Disks: Deny read access Enabled
Removable Disks: Deny write access Enabled
WPD Devices: Deny read access Enabled
WPD Devices: Deny write access Enabled
Apply for all Authenticated Users
USB Read
CD and DVD: Deny read access Disabled
CD and DVD: Deny write access Enabled
Floppy Drives: Deny read access Disabled
Floppy Drives: Deny write access Enabled
Removable Disks: Deny read access Disabled
Removable Disks: Deny write access Enabled
WPD Devices: Deny read access Disabled
WPD Devices: Deny write access Enabled
Apply for Global Security group "Domain\USB_Read" by Security Filtering
USB Write
CD and DVD: Deny read access Disabled
CD and DVD: Deny write access Disabled
Floppy Drives: Deny read access Disabled
Floppy Drives: Deny write access Disabled
Removable Disks: Deny read access Disabled
Removable Disks: Deny write access Disabled
WPD Devices: Deny read access Disabled
WPD Devices: Deny write access Disabled
Apply for Global Security group "Domain\USB_Write" by Security Filtering
So, I think that any users, who not in USB_Read or USB_Write groups, will not have any access to USB and other removable devices.
If User was joined to USB_Read or USB_Write group, he will have read or write access to any removable device.
And it correctly works, but with one BUG: When I plug some devices like Cellular with inside SD card, it connect and instantly disconnect. And it continues without stopping. I don't know why. If I disable policy it works correctly and connecting normal.
Maybe anybody know what is going on?
↧
After apply GPO with Removable Storage restriction policy, USB devices rapidly disconnect and reconnect
↧