Categories: Windows

Windows Admins Now Can Block External Devices Via Layered Group Policy

Windows Admins Now Can Block External Devices Via Layered Group Policy

Microsoft has added support for layered Group Policies, which allow IT admins to control what internal or external devices users can be installed on corporate endpoints across their organization’s network.

Devices that can be blocked or allowed to install on endpoints include printers, USB storage drives, and other USB peripherals added to a given organization’s prohibited or approved list of devices.

Benefits of controlling device installation with the help of group policies include reducing support costs and decreasing the risk of corporate data theft.

All devices come with their own set of “device identifiers” understood by the system (e.g., class, device ID, and instance ID).

Using these identifiers, an admin can create an ‘allow list’ of allowed devices that will block all other devices from being installed.

The new apply layered Group Policy feature provides more granular control over what devices are blocked from installation using a set of device identifiers such as instance IDs, hardware IDs, setup class, and removable device property.

Also Read: Don’t Be Baited! 5 Signs of Phishing in Email

Image: Microsoft

Per Microsoft, using the apply layered Group Policy with already existing device installation policies improves flexibility and intuitive usage:

  • Intuitive usage: the new policy allows you to make sure that only device classes on the prohibited list are blocked from installation
  • Flexibility: the new policy introduces hierarchical layering using the Device instance IDs > Device IDs > Device setup class > Removable devices order, which overrides conflicting prevent and allow policy settings.

If you want to apply right now in your environment, the path to the new Group Policy is Computer Configuration > Administrative Templates > System > Device Installation > Device Installation Restrictions > ‘Apply layered order of evaluation for Allow and Prevent device installation policies across all device match criteria’.

Image: Microsoft

“Applying layered Group Policy is available on all Windows 10 systems where as part of the July 2021 optional ‘C’ client release, and will be made more broadly available beginning in the August 2021 Update Tuesday release,” Microsoft said.

Also Read: 4 Reasons to Outsource Penetration Testing Services

“The Windows Server release will follow thereafter. This feature will also be supported in Windows 11.”

Additional information on the “Apply layered order of evaluation for Allow and Prevent device installation policies across all device match criteria” policy setting is available on the Microsoft 365 docs website.

Privacy Ninja

Recent Posts

Role of Enhanced Access Controls in Safeguarding Personal Data in Telecommunications

Role of Enhanced Access Controls in Safeguarding Personal Data in Telecommunications that every Organisation in…

1 week ago

Role of Effective Incident Response Procedures in Strengthening Data Security

Effective Incident Response Procedures in Strengthening Data Security that every Organisation in Singapore should know…

2 weeks ago

Strengthening Your Cyber Defenses: The Crucial Role of Regular Vulnerability Scanning

Crucial Role of Regular Vulnerability Scanning that every Organisation in Singapore should know. Strengthening Your…

2 weeks ago

Enhancing Data Security with Multi-Factor Authentication

Enhancing Data Security with Multi-Factor Authentication that every Organisation in Singapore should know. Enhancing Data…

3 weeks ago

A Strong Password Policy: Your Organization’s First Line of Defense Against Data Breaches

Strong Password Policy as a first line of defense against data breaches for Organisations in…

3 weeks ago

Enhancing Website Security: The Importance of Efficient Access Controls

Importance of Efficient Access Controls that every Organisation in Singapore should take note of. Enhancing…

4 weeks ago