Skip to content

TechDirectArchive

Hands-on IT, Cloud, Security & DevOps Insights

  • Home
  • About
  • Advertise With US
  • Reviews
  • Contact
  • Toggle search form
Home » Windows » Restrict access to removable Storage Drives [Part 2]

Restrict access to removable Storage Drives [Part 2]

Posted on 05/11/201913/12/2024 IT Expert By IT Expert No Comments on Restrict access to removable Storage Drives [Part 2]
Retrict access to external storage

In this article, we shall discuss how to restrict access to removable Storage Drives [Part 2]. When a USB or supported port is available on the computer. Users can connect removable storage devices such as USB flash drives, external hard drives, and other types of mass storage devices) to access or export data. If you do not want users engaging and moving your data around. You might want to restrict access to these types of devices. Please see how to Disable and Enable USB Usage for Certain Users in Windows, and various Sign-in options for Windows: Ditch Password for Enhanced Security.

Some of these devices can be infected by Viruses, and malware and you do not want this in your network. Therefore, you would disable access by preventing users from connecting these devices. Please see how to disable Access to Removable Storage Devices for All Users with Windows Registry [Part 1]

Also, see how to link a removable media to a Deployment Share: Replicate Deployment share to a removable device. Here is how to Restrict IP Address Range on Windows PC, and How to prevent installation of removable devices.

Removable media

This is any type of storage device that can be removed from a device while the system is in operation (running). Here are a few examples of removable media. For security best practice, it is advisable to disable this functionality. Because it makes it easy for a user to move data from one computer to another.

Optical Discs (Blu-Ray discs, DVDS, CD-ROMs)
Memory Cards (Compact Flash card, Secure Digital card, Memory Stick)
Zip Disks/ Floppy disks
USB flash drives
External hard drives (DE, EIDE, SCSSI, and SSD)
Digital cameras
Smart phones
Other external/dockable devices which contain removable media capabilities 

I will be performing this demonstration using the Local Group Policy to prevent users from writing or reading files and folders from a removable drive. Kindly follow the steps below.

Type run in the Windows Search box as shown below
- Click on the Run App
removable storage

In the Run dialog window, type in “gpedit.msc” as shown below and
– Click on ok

security measures

This will open the group policy editor, navigate through the following paths and click on Removable Storage Access.

- Click on the User Configuration, 
- click Administrative Template to expand the menu.
- Click on System, and 
- Click on Removable Storage Access
security measures

In the Removable Storage Access list, numerous policies allow you to block the use of different types of storage classes as shown below.

- CD and DVD: Deny execute access.
- CD and DVD: Deny read access.
- CD and DVD: Deny write access.
- Custom Classes: Deny read access.
- Custom Classes: Deny write access.
- Floppy Drives: Deny execute access.
- Floppy Drives: Deny read access.
- CD and DVD: Deny execute access.
- CD and DVD: Deny read access.
- CD and DVD: Deny write access.
- Custom Classes: Deny read access.
- Custom Classes: Deny write access.
- Floppy Drives: Deny execute access.
- Floppy Drives: Deny read access.
- Floppy Drives: Deny write access.
- Removable Disks: Deny execute access.
- Removable Disks: Deny read access.
- Removable Disks: Deny write access.
- All Removable Storage classes: Deny all access.
- All Removable Storage: Allow direct access in remote sessions.
- Tape Drives: Deny execute access.
- Tape Drives: Deny read access.
- Tape Drives: Deny write access.
- Windows Portable Device – this class includes smartphones, tablets, players, etc.
- WPD Devices: Deny write access.

Here is a screenshot of the steps below, the most powerful restrict policy below highlighted “All Removable Storage Classes”: Deny All Access .

This policy allows you to deny access to all types of external storage devices. As you can see, there is currently no restriction configured.

Furthermore, To configure this, double click on All Removable Storage classes: Deny all access and enable it as shown below.

To ensure, the GPO takes effect immediately, run gpupdate /update from the command prompt or sign-out and sign-in again.

I hope you found this blog post helpful on how to restrict access to removable Storage Drives [Part 2]. If you have any questions, please let me know in the comment session.

5/5 - (1 vote)

Thank you for reading this post. Kindly share it with others.

  • Share on X (Opens in new window) X
  • Share on Reddit (Opens in new window) Reddit
  • Share on LinkedIn (Opens in new window) LinkedIn
  • Share on Facebook (Opens in new window) Facebook
  • Share on Pinterest (Opens in new window) Pinterest
  • Share on Tumblr (Opens in new window) Tumblr
  • Share on Telegram (Opens in new window) Telegram
  • Share on WhatsApp (Opens in new window) WhatsApp
  • Share on Mastodon (Opens in new window) Mastodon
  • Share on Bluesky (Opens in new window) Bluesky
  • Share on Threads (Opens in new window) Threads
  • Share on Nextdoor (Opens in new window) Nextdoor
Windows Tags:GPO, Microsoft Windows, Registry, Windows 10, Windows 11, Windows Registry

Post navigation

Previous Post: Deny Execute Access: Restrict Access to USB Drives on Windows [Part 1]
Next Post: How to create a Mapped Drive via GPO Preferences

Related Posts

  • Comprehensive Guide to Passkeys on Windows Devices
    Comprehensive Guide to Passkeys on Windows Devices Windows
  • Screenshot 2020 12 06 at 17.01.38
    Start Print Spooler Service: How to fix Print Spooler Service not running Windows
  • Change BitLocker Password in Windows
    How to Change BitLocker Password in Windows Security | Vulnerability Scans and Assessment
  • msinfo32 thumbnail
    How to use MSINFO32 to view System Information Windows
  • WCD
    Join Bulk Devices using a Provisioning Package to Azure AWS/Azure/OpenShift
  • windows 10 keyboard shortcut 1024x512 1
    How to create a Desktop shortcut in Windows Windows

More Related Articles

Comprehensive Guide to Passkeys on Windows Devices Comprehensive Guide to Passkeys on Windows Devices Windows
Screenshot 2020 12 06 at 17.01.38 Start Print Spooler Service: How to fix Print Spooler Service not running Windows
Change BitLocker Password in Windows How to Change BitLocker Password in Windows Security | Vulnerability Scans and Assessment
msinfo32 thumbnail How to use MSINFO32 to view System Information Windows
WCD Join Bulk Devices using a Provisioning Package to Azure AWS/Azure/OpenShift
windows 10 keyboard shortcut 1024x512 1 How to create a Desktop shortcut in Windows Windows

Leave a Reply Cancel reply

You must be logged in to post a comment.

Microsoft MVP

VEEAMLEGEND

vexpert-badge-stars-5

Virtual Background

GoogleNews

Categories

veeaam100

Veeam Vanguard

  • windows 1 2
    How does Dynamic Host Configuration Protocol work Windows Server
  • Startup delay mbam
    Force immediate MBAM Encryption: Why does the MBAM Agent delay most times in encrypting devices? Windows
  • fba7f screenshot 2019 04 15 at 18.33.30
    File System Overview: How to decide on the right File System to use for your USB Linux
  • Screenshot 2022 03 29 at 19.47.05
    CVE-2022-22948: Patch available to address vCenter Server information disclosure vulnerability  Security | Vulnerability Scans and Assessment
  • Downgrade
    Downgrade VMware Workstation: Fix the Processor does not support xsave on VMware Workstation Virtualization
  • HyperV
    How to install free Hyper-V Server on a VMware Workstation Virtualization
  • ACMP Defender Management
    How to Manage Microsoft Defender Antivirus with Argon ACMP Network | Monitoring
  • Norton Antivirus Free Download For Mac 1st
    How to fix repeated app-blocking connection alerts from Norton on Mac Mac

Subscribe to Blog via Email

Enter your email address to subscribe to this blog and receive notifications of new posts by email.

Join 1,803 other subscribers
  • RSS - Posts
  • RSS - Comments
  • About
  • Authors
  • Write for us
  • Advertise with us
  • General Terms and Conditions
  • Privacy policy
  • Feedly
  • Telegram
  • Youtube
  • Facebook
  • Instagram
  • LinkedIn
  • Tumblr
  • Pinterest
  • Twitter
  • mastodon

Tags

AWS Azure Bitlocker Microsoft Windows PowerShell WDS Windows 10 Windows 11 Windows Deployment Services Windows Server 2016

Copyright © 2025 TechDirectArchive

Loading Comments...

You must be logged in to post a comment.