Windows 10 not allowing writes to any removable media after MDM removal

Alexander Horner 21 Reputation points
2022-07-09T15:39:29.393+00:00

Hi there,

Experiencing some serious problems with my machine. I think it is to do with the fact it was connected to my organisations policies via MDM, but is not anymore. I cannot write to any external USB drives or external hard disks.

I have:

  • Reset all group policies to defaults "Not Configured"
  • Checked some suggested registry keys on my machine
  • Checked Win Defender settings for controlled folders
  • Run a Windows reinstall from an ISO generated by the Media Creation Tool whilst keeping personal files and programs
  • Run the DISM health check and restore
  • Run an SFC scan

This affects all removable devices, not just one, so it is no help trying to change Security settings or formatting drives.

219105-image.png

219106-image.png

I have been working directly with my IT admin for a while now and we're not able to get this working still.

My PC has been completely disconnected from MDM account, so no accounts show under Access work or school. However it appears this policy has not been removed. It would seem that disconnecting the MDM account has not completely cleaned up whatever was left behind.

The MDM account was connected via Azure AD/Intune, and the machine has been removed from this now.

219161-image.png

I am trying to avoid doing a complete reinstall of Windows, because reinstalling all of my applications would be a lengthy process.

Any further advice would be much appreciated,

Thanks,

Alex

(Directed to repost here from https://answers.microsoft.com/en-us/windows/forum/windows_10-hardware/windows-10-not-allowing-writes-to-any-removable/8e5b6223-a7b2-4168-b3dc-bbdaa0bf5626)

Windows
Windows
A family of Microsoft operating systems that run across personal computers, tablets, laptops, phones, internet of things devices, self-contained mixed reality headsets, large collaboration screens, and other devices.
5,778 questions
Microsoft Intune Configuration
Microsoft Intune Configuration
Microsoft Intune: A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.Configuration: The process of arranging or setting up computer systems, hardware, or software.
1,992 questions
Microsoft Intune Enrollment
Microsoft Intune Enrollment
Microsoft Intune: A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.Enrollment: The process of requesting, receiving, and installing a certificate.
1,414 questions
Microsoft Intune
Microsoft Intune
A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.
5,531 questions
0 comments No comments
{count} votes

Accepted answer
  1. Crystal-MSFT 51,726 Reputation points Microsoft Vendor
    2022-07-11T00:51:29.173+00:00

    @Alexander Horner In fact when we set policies as not configured, it means the remaining setting value will not be changed. Also some settings will still kept when the profile or policy is removed. Here is a link describes this for the reference:
    https://learn.microsoft.com/en-us/mem/intune/configuration/device-profile-troubleshoot#what-happens-when-a-profile-is-deleted-or-no-longer-applicable

    For our situation, we can check if the "Deny_Write" is in the registry key. If yes, remove it to enable Write Access to Removable Disks. here is a link with more details for the reference:
    https://www.tenforums.com/tutorials/150715-how-enable-disable-write-access-removable-disks-windows.html
    Note: Non-Microsoft link, just for the reference.

    Hope it can help.


    If the answer is helpful, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment".
    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.

    0 comments No comments

3 additional answers

Sort by: Most helpful
  1. Rahul Jindal [MVP] 10,681 Reputation points MVP
    2022-07-10T00:56:28.627+00:00

    At what stage did you unenroll the device from Intune? If it was unenrolled after the Intune policies got applied, then settings will not undo.

    Did you configure the Device control policy 'Block write access to removable storage' by any chance?

    0 comments No comments

  2. Alexander Horner 21 Reputation points
    2022-07-10T05:42:35.487+00:00

    Hi @Rahul Jindal [MVP]

    The device was indeed unenrolled after policy application, however I do believe no policies regarding removable media were in use. I can most likely obtain a list of applied policies tomorrow.

    The 'Block write access to removable storage' Group Policy is set to Not Configured on the machine. I checked this before running a group policy reset too and it was already Not Configured. Manually setting it to Disabled has had no effect even after a restart.

    No Group Policies are set to anything other than Not Configured at this time.

    Is it possible a flag to block removable media write access exists elsewhere on the machine, possibly in the registry, too?

    Many thanks,

    Alex

    0 comments No comments

  3. Alexander Horner 21 Reputation points
    2022-07-11T07:22:12.907+00:00

    Hi @Crystal-MSFT ,

    Thank you for the explanaton regarding Group Policy configurations,

    Interestingly, I had already followed the guide you had linked. For good measure however, I redownloaded and remerged the registry key they provided then restarted, and I can confirm this has now resolved the issue,

    Many thanks,

    Alex


Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.