This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

How to Add USB Device Exemption for New USB Devices

I have for the last several months had my Device Policy set to "Detect but do not block".

I have finally unchecked this option to start effectively blocking access to removable storage devices.

So here is my question.  Now that the Device Policy is set to block, if I have an employee who brings a personal USB device from home and I choose to allow them to use it on a limited basis of some sort, how do I go about adding the device to the exemption list?

From what I am experiencing, with the Device Policy now set to "blocking", when a user adds a USB thumb drive to their PC, it does not allow the device to install and therefore does not appear to get reported to the Enterprise Console at all.

I wasn't sure how that process worked and if what I am experiencing is normal or abnormal.  I would have thought it would allow the device to be installed, detect it, get its device ID, report it to EC and apply the policy to either block, allow, read-only, etc.and if reported and needed you could easily exempt the device.

But from what I am currently experiencing, in order to exempt the newly introduced device, I will have to change the Device Policy to "Detect but do not block" long enough for the device to be detected, add the exemption and then change the Device Policy back to "blocking" mode.

I do have a support ticket on another issue regarding USB devices and will address it with them when I have contact with them again.

In the meantime while I am waiting, I was curious if anyone else had any knowledge on this process and how it worked.

Thanks!

:33895


This thread was automatically locked due to age.
Parents
  • Wow - that was interesting.  It took FOREVER before Enterprise Console logged the blocked device event.  I am not sure the time span but I just now checked and the blocked event is just now appearing.

    So now I will try to exempt the device and see if it works correctly.

    Sorry for the confusion.  Just not patient enough I don't guess.

    Again - thanks Christian for your post.  I'll post back in a bit to let you know if it works or not.

    Thanks much!

    :33903
Reply
  • Wow - that was interesting.  It took FOREVER before Enterprise Console logged the blocked device event.  I am not sure the time span but I just now checked and the blocked event is just now appearing.

    So now I will try to exempt the device and see if it works correctly.

    Sorry for the confusion.  Just not patient enough I don't guess.

    Again - thanks Christian for your post.  I'll post back in a bit to let you know if it works or not.

    Thanks much!

    :33903
Children
No Data