Enable USB ports blocked by active directory policy

Eduar Muñoz Murcia 41 Reputation points
2022-03-09T17:31:37.93+00:00

I have a GPO in my active directory that restricts USB device connections to all client machines in the company, at this time I needed to connect a camera via USB to access the video recordings, to access the camera is necessary to move the client machine to an organizational unit that does not have the USB restriction GPO, I would like to know if there is some kind of configuration either on the client machine or in the GPO that allows me to connect only that camera via USB port. Thank you in advance for your help.

Active Directory
Active Directory
A set of directory-based technologies included in Windows Server.
5,994 questions
Windows 10 Setup
Windows 10 Setup
Windows 10: A Microsoft operating system that runs on personal computers and tablets.Setup: The procedures involved in preparing a software program or application to operate within a computer or mobile device.
1,912 questions
0 comments No comments
{count} votes

4 answers

Sort by: Most helpful
  1. Pierre Audonnet - MSFT 10,166 Reputation points Microsoft Employee
    2022-03-10T03:17:34.193+00:00

    Most of the time, what the GPO does is blocking USB Storage Device. So it should not affect other devices unless they also have a USB Storage presentation. But an export of the effective GPO will tell us (you can generate this with the command gpresult /h GPO.html).
    But maybe that's not a GPO that is blocking the ports, and you might have other products (or BIOS features) which go further than just disabling USB storage.

    1 person found this answer helpful.

  2. Limitless Technology 39,426 Reputation points
    2022-03-15T15:18:15.167+00:00

    Hi @Eduar Muñoz Murcia

    You can deny certain types of device access. For example, you can restrict USB storage devices but allow other types of USB device. This may work for you depending on the reason why you’re restricting USB?

    Open Computer Configuration => Administrative Templates => System => Removable Storage Access => in the right pane, open Removable Disks: Deny Execute Access.

    I do hope this answers your question.

    Thanks.

    --
    --If the reply is helpful, please Upvote and Accept as answer--

    0 comments No comments

  3. David Hunter 1 Reputation point
    2022-08-23T22:48:27.547+00:00

    I'm not an AD administrator, but I have a security question related to this thread: can we setup a GPO that blocks usb storage devices, but allows us to specifically allow company USB drives that we control?

    0 comments No comments

  4. Konstantinos Passadis 17,376 Reputation points MVP
    2023-04-01T10:17:17.33+00:00