I have deleted usb policy in intune but still device is getting affected? USB is still blocked. How to resolve?

Vanshika Parmar 0 Reputation points
2023-12-16T10:32:02.25+00:00

Hi, I had earlier implemented a policy to block USB using endpoint security. After that, I deleted the policy and even after syncing the USB is still blocked. Even after removing the device from Azure-AD Joined from access work or school, it is blocked.I want the policy to allow for certain devices and block for others. The policy is not working as expected. Please help me to resolve this issue.

Microsoft Security | Intune | Enrollment
Microsoft Security | Intune | Other
{count} votes

3 answers

Sort by: Most helpful
  1. Crystal-MSFT 54,206 Reputation points Microsoft External Staff
    2023-12-18T02:40:46.2066667+00:00

    @Vanshika Parmar, Thanks for posting in Q&A. From your description, I know we have removed the USB block policy. But the USB is still blocked. In General, Intune settings are based on the Windows configuration service provider (CSPs). The behavior depends on the CSP. Some CSPs remove the setting, and some CSPs keep the setting, also called tattooing. For USB the setting will be kept when we remove the profile.

    https://learn.microsoft.com/en-us/mem/intune/configuration/device-profile-troubleshoot#a-profile-is-deleted-or-no-longer-applicable

    I notice you have created the profile again with the allow setting. But it is still blocked. Please go to the following location to see if any registry key existing which can block the USB. If yes, remove them to see if the USB can be accessed.

    HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\RemovableStorageDevices

    Hope the above information can help.


    If the answer is helpful, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment".

    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.

    0 comments No comments

  2. Vanshika Parmar 0 Reputation points
    2023-12-18T05:41:02.9833333+00:00

    User's image

    In the screenshot, the deny value is set to 0 so it should be allowed but its still giving block. Giving one more screenshot for your reference:

    User's image


  3. Jatin Makhija 1,181 Reputation points
    2023-12-19T09:27:19.43+00:00

    Try using Powershell script to change registry values which unblocks USB drive. Refer to this step by step guide: https://cloudinfra.net/block-usb-drives-access-on-windows-using-intune-remediations/. Hope this will resolve your Issue.

    ---If the response is helpful, please click "Accept Answer" and upvote it.---

    0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.