Disable USB Ports Via Defender for Endpoint (Device Control)

Robert 21 Reputation points
2022-03-08T21:41:33.747+00:00

I am trying to disable USB ports on certain systems via USB device control. However, I can't seem to find a clear way to do this (I'm not too sure what the prerequisites are)? For example, in this article (https://thewindowsupdate.com/2021/12/16/block-usb-in-microsoft-defender-for-endpoint-and-intune/) it appears that you have to 1.) Have the Defender for Endpoint agent installed and 2.) You have to have your system managed via Intune. My question is, what if you had the Defender agent installed but you used SCCM or have co-managed systems?

Microsoft Intune Configuration
Microsoft Intune Configuration
Microsoft Intune: A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.Configuration: The process of arranging or setting up computer systems, hardware, or software.
1,921 questions
Microsoft Configuration Manager
0 comments No comments
{count} votes

2 answers

Sort by: Most helpful
  1. Simon Ren-MSFT 35,391 Reputation points Microsoft Vendor
    2022-03-09T08:37:01.303+00:00

    Hi,

    Thanks for posting in Microsoft MECM Q&A forum.

    Per my experience, we can use Group Policy or Intune to manage USB devices. For more information, please refer to below guides:
    Manage USB Devices on Windows Hosts
    MEM – All thing about USB Drive Management and Troubleshooting

    Thanks for your time. Have a nice day!

    Best regards,
    Simon


    If the response is helpful, please click "Accept Answer" and upvote it.
    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.


  2. Duncan de Waal 41 Reputation points
    2022-05-28T18:44:33.38+00:00

    I must say that the documentation on the Microsoft Learn site is not so clear, but I think this document from Peter van der Woude makes it much easier to understand: https://www.petervanderwoude.nl/post/controlling-devices-connected-to-windows-devices/
    The article assumes that you are using Microsoft Endpoint Manager but doing this via another whay like Active Directory Group Policies will be similar.


Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.