← Back to Projects
Business Systems House 2025
Managed Device Policy & Removable Media Storage Restrictions
Active Directory Group Policy (GPO) Endpoint Security BitLocker Windows Server AD
Managed Device Policy & Removable Media Storage Restrictions
Architected and deployed centralized USB and removable storage blocking policies across corporate domain-joined workstations to prevent data leakage and malware ingestion.
Key Features & Implementation
- Granular GPO Whitelisting: Restricted mass storage access while allowing authorized, IT-approved encrypted storage drives via hardware GUID matching.
- BitLocker To Go Integration: Mandated automatic AES-256 encryption on all approved portable drives.
- Centralized Policy Auditing: Configured real-time Event Log alerts for unauthorized device insertion attempts.