1

We need to set your systems to allow administrative users to access a USB drive (if plugged into the USB port) but deny non-admin users.

I've found a plethora of online articles describing how to lock or deny users from using the USB port for drives e.g. Five ways to enable or disable USB drive access

However, I can't determine if any of these work across the board for both administrator and non administrator users

This Super User Entry implies that the setting is for non-admins, but I'm not entirely sure if I understand the response correctly. It states,

"...choose the non-administrators group"

I don't typically administer Windows, so I'm not all that familiar with how the group policy editor works with regard to settings applying to specific groups or users, etc. Same files and folder permissions. Anything beyond very basic allow/deny is beyond my core experience.

One intriguing method specifies setting file permissions on a couple of files to Deny SYSTEM and User access to the files. I'm thinking this method would be a good way to go to allow admins to have access to the files while denying non-admins; however, I'm concerned that having SYSTEM denied will throw a wrench in the works. I'd need admin/SYSTEM allowed and user/SYSTEM denied. Is that even possible?

With that said, I'd appreciate any assistance. We're using Windows Server 2008 R2 along with a bunch of Windows 8 and 10 workstations.

Preet Sangha
  • 2,747
  • 2
  • 24
  • 27
Dan7el
  • 133
  • 9

1 Answers1

0

I spoke to the person who does our system admin functions. His intention is to create a group policy that locks all users from accessing the USB ports for drives (thumb drives, etc.). Then, deny access to that group policy to the domain admins. This way, when a domain admin accesses this group policy, it won't apply to them.

We're waiting for a weekend to try this in case the work actually has some unexpected negative impacts (like locking out all USB devices as mice and keyboards) and test that it works.

I'll post back with the results when I find out.

Dan7el
  • 133
  • 9