This might work. I know I've been involved in this in the past we we blocked a lot of devices but it caused issues for a specific user with a fancy dock so I had to dig around that was causing it. It was a good few years back so rusty on the specifics but it was something where we listed specific ID's to block and a quick google came up with this as closest match. Should get you started on the right trail to search up on
[SOLVED] How to disable android phone usb storage/file read+write access in windows 10?
Hello techies,
As the question suggest, I want to disable any usb storage file access, including android / iphone storage, except for charging mode.
So I went into GP editor and browse to Computer Configuration\Policies\Administrative Templates\System\Removable Storage Access and set all below to "Enable"
Removable Disks: Deny execute access
Removable Disks: Deny read access
Removable Disks: Deny write access
While this setting works great for conventional USB storage (e.g. flash drive, thumb drive etc.) but seems it does not have any impact at all if you plugged in your phone; you still able to access phone storage.
Even enabling "All Removable Storage classes: Deny all access" does nothing.
Appreciate for any suggestion. :)
3 answers
Sort by: Most helpful
-
-
Limitless Technology 39,511 Reputation points
2022-09-09T08:53:32.993+00:00 Hello there,
Go to Computer\HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\USBSTOR, and then locate the DWORD value named ''Start'' on the right-side pane. The default value data of Start is ''3''. Double-click on Start, and set its value data to ''4''.
Restart and check the machine.
By Registry Editor, you just disable the use of USB storage devices, but it won't affect the use of USB mouse, keyboard, and printer on the computer.
------------------------------------------------------------------------------------------------------------------------------
--If the reply is helpful, please Upvote and Accept it as an answer--
-
razc 21 Reputation points
2022-09-10T00:09:00.963+00:00 Hello all,
The solution is right before my eyes, how I failed to notice and try it we'll save it for another day debate :)
1) [In GPO management or gpedit.msc] Browse to Computer Configuration\Policies\Administrative Templates\System\Removable Storage Access
2) Enable the "WPD Devices: Deny read access".
Enabling it will create two key in registry which explains in detail in this site https://admx.help/?Category=Windows_10_2016&Policy=Microsoft.Policies.RemovableStorageAccess::WPDDevices_DenyRead_Access_2