Block USB at User level through Group policy


hi have block usb through group policy.the real problem have here how apply @ user level. create gpo every pc in enterprise, how apply such if user object in managers ou, example, logs onto given workstation, can use usb sticks, optical drive etc, if user object in staff ou logs on same box usb storage, optical drive etc locked down, manager logs on again , it's opened again? machines in 1 ou @ moment.can busy me out please

hi

it not native feature of windows 2000 , xp.

you can have better control on if using windows vista or higher.

in windows xp , 2000 can try following options controlling @ user level.

1.create group  e.g en_usb_access

2. add users having pemissions use usb storage group.

3.set permission on hklm\system\currentcontrolset\services\usbstor using group policy, and  give allow-read permission en_usb_access group on key. remove other users/group acl

or

set permissions on following files using group policy in similar way..
%windir%\inf\usbstor.inf
%windir%\inf\usbstor.pnf
%windir%\system32\drivers\usbstor.sys

regards..



Windows Server  >  Group Policy



Comments

Popular posts from this blog

some help on Event 540

WMI Repository 4GB limit - Win 2003 Ent Question

Event ID 1302 (error 1307) DFS replication service encountered an error while writing to the debug log file