Back to Projects
Business Systems House 2025

Enterprise Endpoint USB Port Blocking & Whitelisting Policies

Enterprise Endpoint USB Port Blocking & Whitelisting Policies
Group Policy (GPO) USB Port Blocking Endpoint Security BitLocker To Go Active Directory

Enterprise Endpoint USB Port Blocking & Whitelisting Policies

Prevented physical USB data exfiltration and malware ingestion by enforcing strict removable media access restrictions across workstations.

Key Features & Implementation

  • Mass Storage Deny Policy: Applied domain GPOs denying read/write access to unauthorized USB mass storage device classes.
  • Hardware GUID Whitelisting: Configured hardware device ID exceptions allowing IT-approved encrypted flash drives for specific user roles.
  • Audit Incident Logging: Configured Windows Event Log forwarding to track and report unauthorized USB connection attempts.
ROOT ACCESS GRANTED