Intune - USB blocking for mobile phone

Mo Alom 1 Reputation point
2021-02-15T13:01:15.97+00:00

Hi All,

We are planning to deploy Microsoft Defender as our endpoint security solution and use Intune to apply device control.

We intend to block access to all mobile phones connected via USB on our W10 workstations. Trying to find a solution on how best to apply this configuration and if its even possible.

We are using the Microsoft Defender for Endpoint baselines to block write access to any USB devices that are not encrypted. However, this does not prevent the phones connecting to the W10 workstation via USB and apply as a storage device.

Tried to use device config profiles policy to add allowed device class IDs for all plug and play USBs. That too don't work and blocks all USBs devices.

Used the identifiers based on the article below
https://learn.microsoft.com/en-us/windows-hardware/drivers/install/system-defined-device-setup-classes-available-to-vendors

Would appreciate any suggestions.

Thanks,
Mo

Windows 10 Security
Windows 10 Security
Windows 10: A Microsoft operating system that runs on personal computers and tablets.Security: The precautions taken to guard against crime, attack, sabotage, espionage, or another threat.
2,916 questions
Microsoft Intune Configuration
Microsoft Intune Configuration
Microsoft Intune: A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.Configuration: The process of arranging or setting up computer systems, hardware, or software.
1,904 questions
Microsoft Intune
Microsoft Intune
A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.
5,108 questions
{count} votes

3 answers

Sort by: Most helpful
  1. Lu Dai-MSFT 28,406 Reputation points
    2021-02-16T03:20:36.467+00:00

    @Mo Alom Thanks for posting in our Q&A. From your description, I know that we need to block all USB connection from mobile devices to win10 devices. If there is anything misunderstanding, feel free to let us know.

    For this issue, we suggest to try to create a profile to block Removable storage and USB connection in device configuration profile > Device Restriction > General. We can read the following article as a reference.
    https://learn.microsoft.com/en-us/windows/security/threat-protection/device-control/control-usb-devices-using-intune#block-installation-and-usage-of-removable-storage

    Hope it will help.


    If the response is helpful, please click "Accept Answer" and upvote it.
    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.


  2. Mo Alom 1 Reputation point
    2021-02-16T23:36:33.99+00:00

    This is what I have attempted to do so far but I get access denied to all removal drives

    Microsoft Defender for Endpoint baseline - Settings
    BitLocker removable drive policy – Configured
    - Configure encryption method for removable data-drives - AES 256bit XTS
    - Block write access to removable data-drives not protected by BitLocker – Yes

    Device Configuration – Device Restriction Profile - Settings
    Removable storage - Block
    USB connection - Block

    Device Configuration – Administrative template Profile - Settings
    Allow installation of devices that match any of these device IDs – Enabled

        Added device class ID:  
        Disk Drives  
        Class = DiskDrive  
        ClassGuid = {4d36e967-e325-11ce-bfc1-08002be10318}  
        This class includes hard disk drives. See also the HDC and SCSIAdapter classes.  
    
        Used the identifier based on the article below  
        https://learn.microsoft.com/en-us/windows-hardware/drivers/install/system-defined-device-setup-classes-available-to-vendors
    

  3. Bagitman 581 Reputation points
    2021-02-17T11:09:11.313+00:00

    There are policies for Phones (WPD devices):
    WPD Devices: Deny read access
    WPD Devices: Deny write access
    (see https://admx.help/?Category=Windows_10_2016&Policy=Microsoft.Policies.RemovableStorageAccess::WPDDevices_DenyRead_Access_1)
    This will not only block phones, but also include media players, auxiliary displays, and CE devices (according to MS documentation).
    This will NOT deny access to other USB devices as mouse, keyboard, USB sticks or removable hard drives.

    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.