← Back to Projects
Business Systems House 2025
Enterprise Endpoint USB Port Blocking & Whitelisting Policies
Group Policy (GPO) USB Port Blocking Endpoint Security BitLocker To Go Active Directory
Enterprise Endpoint USB Port Blocking & Whitelisting Policies
Prevented physical USB data exfiltration and malware ingestion by enforcing strict removable media access restrictions across workstations.
Key Features & Implementation
- Mass Storage Deny Policy: Applied domain GPOs denying read/write access to unauthorized USB mass storage device classes.
- Hardware GUID Whitelisting: Configured hardware device ID exceptions allowing IT-approved encrypted flash drives for specific user roles.
- Audit Incident Logging: Configured Windows Event Log forwarding to track and report unauthorized USB connection attempts.