In this article you will learn how to improve your network security by disabling Universal Serial Bus (USB) drive usage in your Active Directory domain.
Avatar
Latest posts by Timothy Warner (see all)

Universal Serial Bus (USB) flash drives are undeniably convenient and easy to use. However, these devices pose very real security threats.

Number one, allowing your users to mount their own USB flash drives provides a vector for malicious code into your network. Number two, a malicious user can steal sensitive data by copying it to their flash drive and leaving the campus.

Here are a couple excellent articles that delve more deeply into IT security threats posed by USB devices:

You may decide to institute an IT security policy in your domain that prohibits use of personal USB devices. This is all well and good, but how many of your users will actually adhere to the policy without some kind of a control in place?

Fortunately, Windows Server 2008 R2 provides us administrators with a method for easily disabling USB drive access on Active Directory domain assets. Let’s get to work.

Defining the restriction

One important thing to keep in mind is that Microsoft made it MUCH easier to control removable drive access in Windows 7/Windows Server 2008 R2 Group Policy. If you need to restrict USB drives on earlier client operating systems (including Windows Vista), then one of the following links should prove helpful to you:

Now then: from one of your Active Directory Domain Services domain controllers or from an administrative workstation, open the Group Policy Management Console and link a new GPO to the appropriate target (domain, OU, etc.).

Within the Group Policy Editor, navigate to \Computer Configuration\Policies\Administrative Templates\System\Removable Storage Access.

NOTE: If you prefer to set these restrictions on a per-user basis instead of computer-wide, then use the Group Policy path \User Configuration\Policies\Administrative Templates\System\Removable Storage Access.

Disable USB drive - Group Policy - Removable Storage Access

Group Policy - Removable Storage Access

Note from the above screenshot that we can use Group Policy to limit access to the following device classes:

  • Optical drives (CD and DVD)
  • Floppy drives
  • Removable disks (USB devices)
  • Tape drives
  • Custom device classes

By far, the most restrictive restriction (pardon the redundancy) is the policy All Removable Storage Classes: Deny All Access. If we enable this policy, as is shown in the following screen capture, then we prevent affected users from mounting ANY class of removable media.

Disable USB drive usage - All Removable Storage classes - Deny all access

All Removable Storage classes - Deny all access

Naturally, we want to apply GPO security filtering to ensure that only our desired users and computers are affected by our new policy. From the Group Policy Management Console we can make use of the Security Filtering and/or the WMI Filtering areas to properly scope our GPO. This is depicted in the following screen image:

Disable USB drive

Disable USB drive

In order to put your new GPO into effect immediately, open an administrative command prompt and issue the following command:

gpupdate/ force

This command refreshes Group Policy throughout your Active Directory domain.

How the restriction works

Once your GPO has been ingested by your domain, a user will see the following message box whenever they attempt to mount a restricted media device:

Disabled removable drive

Disabled removable drive

It’s as simple as that!

Conclusion

In this article you learned how to leverage Windows Server 2008 Group Policy to disable USB drive us in our Active Directory domain. Have you initiated this policy in your environment? Please feel free to share your experiences and questions in the comments portion of this post.

22 Comments
  1. Avatar
    Ajeesh 12 years ago

    i just wanted to know the from where “Disable USB drive” screen will open

  2. Avatar
    Tim Warner 12 years ago

    Hi Ajeesh. The “Disable USB Drive” screenshot was taken from the Group Policy Management Console. You can open that MMC console from the Administrative Tools folder on your domain controller. Alternatively, you can click Start > Run and type gpmc.msc into the Run box. -Tim

  3. Avatar
    Fifi 11 years ago

    I failed to get the message access deny after the installation and updating the policy. I wonder where i went wrong. i created the policy in win2008 and implement the policy on Computer conf> policies> administrative templ> removable storage access > I enabled removable disks(deny read and deny write access) and enabled all removable storage classes deny all access.

    kindly assist

  4. Avatar
    Hesham Mousa 11 years ago

    this solution has a very bad effect if you want to roll back the policy as from testing such policy you cannot roll back because the policy applies on the driver NTFS permissions

  5. Avatar
    joe 11 years ago

    I want to block only pen drives And external hard drives then what about usb mouse used by clients if we did so. ??

  6. Avatar
    Rajat 10 years ago

    Hi. I used the procedure above and it was 100% successful. But i also have to find a way to enable the USB. I changed the USBSTOR value from 4 to 3, then too the usb isnt working. Can anybody please help or find a way to enable back the disabled USB? Thanks.

  7. Avatar

    Rajat, I posted an answer in the forum. I hope that helps.

  8. Avatar
    Michael 10 years ago

    i like article. Looks quite straight and forward. I haven’t tried it yet.
    But please can you help me if there’s anyway where i can monitor which users have been trying to use USB drives in the domain after i enable the policy?

  9. Avatar

    Michael, I posted your question in the forum. You can subscribe to the topic after you registered.

  10. Avatar
    Andy 10 years ago

    Does it work for server 2003 with windows 7 client ?

  11. Avatar
    ghuge 9 years ago

    Hi,
    I have enabled read write restriction for a group of users, if a user from this group is to log onto a win 8.1 system and tries accessing a usb drive it says access is denied, however if the same user logs onto a Windows server 2008 R2 system in the same domain he is allowed to access the usb drive, why may this be happening?

  12. Avatar
    Nem Muth 9 years ago

    I want to disable usb but enable CD/DVD ROM . How can I do?

  13. Avatar
    Carlitos 9 years ago

    Hi there, i really appreciate your help, that was great, but i don’t want the drive to be visible, is there any way?

  14. Avatar
    chedva 9 years ago

    i tried to do this on server 2012 (only for single user) but nothing happen and the user can use removable drives why?can anyone help me?

  15. Avatar
    John sellers 8 years ago

    I think there’s third party software that allows you to restrict/allow specific models of flash drives. This could be best for us because we have some machines that aren’t on the domain. Obviously GP wouldn’t apply to those machines but a third party solution could resolve that issue.

  16. Avatar
    Pankaj Sharma 8 years ago

    Hi Tim,

    I tried it but it did not work. Windows 2012 server. Can anyone help pleas.

  17. Avatar
    sandeep 7 years ago

    Hii

    i tried on windows server 2012r2 its working,but i logon to windows 8.1,my local disk D,E also blocked

  18. Avatar
    Subham 6 years ago

    here in this case the all clients and the domain is not able to access that but that client who connect the usb drive did he access that or not and is it possible that the domain disable the usb port using the group policy ….

  19. Avatar
    ViCiouSSoRreL 5 years ago

    I want to have the GPO denying but allow specific users access.  How can that be done?

    Currently using a computer based GPO to deny all removable media.

  20. Avatar

    I have a hardware based GPO that does not allow any removable media.

    Now I have a specific person I would like to enable.  How can that be accomplished.

    Thanks

  21. Avatar
    Saurabh 4 years ago

    Hi Team,

    We have applied Domain level USB restriction policy through GPO on our Domain controller win2k8 and after changes took place we tried connecting USB drive on several client machine (installed win 7 OS) where it is giving "Access is denied "  that means the policy is working perfectly on all client machine into the same domain. But when we have logged in to server (win 2008 & 2012 )in the same domain and connected same USB drive then it is accessible , that means the policy is not applying on servers.

    So request you please help in how to disable USB on servers also.

    Regards,

    Saurabh

  22. Avatar
    Mubashir 4 years ago

    i had used this method on my laptop which is connected with domain environment but not work.

    value changed  Computer\HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\USBSTOR\DWORD value 3

    also check gpedit.msc 

    USB not working.

Leave a reply

Please enclose code in pre tags: <pre></pre>

Your email address will not be published. Required fields are marked *

*

© 4sysops 2006 - 2023

CONTACT US

Please ask IT administration questions in the forums. Any other messages are welcome.

Sending

Log in with your credentials

or    

Forgot your details?

Create Account