Skip to content

TechDirectArchive

Hands-on IT, Cloud, Security, Veeam & DevOps

  • Home
  • About
  • Advertise With US
  • Reviews
  • Tech News
  • Contact
  • Toggle search form

Disable and Enable USB Usage for Certain Users in Windows

Posted on 26/09/202314/08/2026 Temitope Odemo By Temitope Odemo No Comments on Disable and Enable USB Usage for Certain Users in Windows
  1. Home
  2. Windows
  3. Disable and Enable USB Usage for Certain Users in Windows
Disable and Enable USB in Windows

Many organizations put security at the forefront and will never allow external devices like USB connections without going through access approval. When you connect a USB device to your computer. In this guide, I will be showing you how to Disable and Enable USB Usage for Certain Users in Windows. Please see Grant Non-Domain Admin Privileges to Manage Workstation, and how to Install Group Policy Templates for Microsoft Edge and Google Chrome browsers on Windows.

The system will detect the device and go ahead to install the required drivers and you will both be able to copy from and copy into the USB. But if there is a USB usage security policy in place then you will be prohibited from using it on the enterprise network.

It is very possible to block everyone from the use of USB on the official network but there could be times when you just need to disable certain individuals and allow access to others.

You may find the following articles useful: How to Restrict Access to USB Drives. Also, see how to link a removable media to a Deployment Share: Replicate Deployment Share to a removable device, and how to restrict access to removable Storage Drives.

Disable Usage for All and Certain Users

What is Universal Serial Bus (USB)? The name “universal serial bus” stems from its historical beginnings as a specification designed to provide a mechanism for connector standardisation – basically it was a descriptor for the specification.

You can read more articles on USB like this on How to Create a Windows 10 or 11 bootable USB with UEFI support and How to Download the files needed to create a Lenovo USB Recovery key, How to create Windows 11 Bootable USB drive with the Media Creation Tool, How to Create a Multiboot USB with Multiple OS ISOs

Disabling Removable Drives in Windows with Group Policy

1: Run gpmc.msc to Open the GPO management console.

Launch Group Policy Editor

2. On the Group Policy Management right-click your Workstation OU and Create a GPO.

Create GPO

3. Set the New GPO name to “Disable USB Access”

Create neww gpo toDisable USB Access

4. Right-click on the New GPO and select Edit.

Edit GPO to Disable-USB-Usage-for-Certain-Users-workstation-1

5. There are two configuration settings for blocking external storage devices in both the User and Computer:

Note: If you want to block USB access for all computer users, you will need to configure the settings for “Computer Configuration”. 

Disable-USB-Usage-for-Certain-Users-via User configuration

6. In the Computer Configuration section navigate here:

Computer Configuration > Policies > Administrative Templates > System > Removable Storage Access.

In the Removable Storage Access section you will see different policies allowing you to disable the use of different types of storage classes but our focus is on All Removable Storage classes: Deny all access.

Note: This policy setting takes precedence over any individual removable storage policy settings. If you enable this policy setting no access is allowed to any removable storage class.

All Removable Storage classes

7. Select Enabled and click OK.

Enabled All removable storage classes - Disable-USB-Usage-for-Certain-Users-Deny-all-Access

8. After enabling and updating the GPO by running this command gpupdate /force. Windows will detect any external device connected but you will not be able to access it, instead, you will see the below message:

How-to-Disable-USB-Usage-for-Certain-Users-Location-2

Disable USB Usage for Certain Users via GPO

There are always exceptions to some policies or rules. For example your Domain Admins will always need access to USB, so using the GPO Security Filtering will relax the policy and will not applied to these users.

1: Select your Disable USB Access policy in the Group Policy Management console and in the Security Filtering section add the Domain Admins.

How-to-Disable-USB-Usage-for-Certain-Users-Domain-Admin-2

2. Click on the Delegation tab and click the Advanced. In the security settings section select Domain Admins. Under the Permissions for Domain Admins, check Deny for Apply group policy and click OK.

This configuration will deny the application of the Disable USB Access for the Domain Admins.

Disable USB Access for the Domain Admins

Please see how to Enable or Disable SuperFetch in Windows 11, how to Check and Reset Network Data Usage in Windows 11, How to prevent installation of removable devices, and how to stop Outlook from opening links in Edge Browser

FAQs on How to Disable and Enable USB Usage for Certain Users

How to Enable USB Access for select devices using GPO?

1. Open the Group Policy Management Console
2. Select Disable USB Access policy in the Group Policy Management console and in the Security Filtering section add the Domain Admins
3. Click on the Delegation tab and click the Advanced. In the security settings section select Domain Admins. Under the Permissions for Domain Admins, check Deny for Apply group policy and click OK.

What is USB Allowlisting?

This is just the process of allowing a list of USB’s access to the computer system of an official network.

I hope you found this blog post on how to Disable and Enable USB Usage for Certain Users in Windows interesting and helpful. In case you have any questions do not hesitate to ask in the comment section.

5/5 - (1 vote)

Thank you for reading this post. Kindly share it with others.

  • Share on X (Opens in new window) X
  • Share on Reddit (Opens in new window) Reddit
  • Share on LinkedIn (Opens in new window) LinkedIn
  • Share on Facebook (Opens in new window) Facebook
  • Share on Pinterest (Opens in new window) Pinterest
  • Share on Tumblr (Opens in new window) Tumblr
  • Share on Telegram (Opens in new window) Telegram
  • Share on WhatsApp (Opens in new window) WhatsApp
  • Share on Mastodon (Opens in new window) Mastodon
  • Share on Bluesky (Opens in new window) Bluesky
  • Share on Threads (Opens in new window) Threads
  • Share on Nextdoor (Opens in new window) Nextdoor
Windows, Windows Server Tags:GPO, GPOs, Microsoft Windows, USB, Windows 10, Windows 11, Windows Server 2016

Post navigation

Previous Post: What Is the NTUSER.DAT File in Windows?
Next Post: How to Restore Old Right-click Context Menu in Windows 11

Related Posts

  • shrink and create partition
    How to shrink and create new partition on Windows Server Windows Server
  • Computer policy could not be updated
    How to fix Computer Policy could not be updated successfully Windows
  • Featured image bootable USB
    Create a Windows 10 or 11 bootable USB with UEFI support Windows
  • 0227 15
    How to set Execution Policy via Windows PowerShell Windows Server
  • remote desktop connection 5 1280x720 1
    How to view and remove Remote Desktop connection history Windows
  • Hibernation and faststartup
    Enable or Disable hibernation: How to fix the missing fast startup option on Windows Windows

More Related Articles

shrink and create partition How to shrink and create new partition on Windows Server Windows Server
Computer policy could not be updated How to fix Computer Policy could not be updated successfully Windows
Featured image bootable USB Create a Windows 10 or 11 bootable USB with UEFI support Windows
0227 15 How to set Execution Policy via Windows PowerShell Windows Server
remote desktop connection 5 1280x720 1 How to view and remove Remote Desktop connection history Windows
Hibernation and faststartup Enable or Disable hibernation: How to fix the missing fast startup option on Windows Windows

Leave a Reply Cancel reply

You must be logged in to post a comment.

Microsoft MVP

VEEAMLEGEND

vexpert-badge-stars-5

Virtual Background

GoogleNews

Categories

veeaam100

Veeam Vanguard

  • image 8
    Enable or disable Core Isolation Memory Integrity in Windows 10 and 11 Windows
  • images copy
    How to disable automatic screen lock in Ubuntu Linux Linux
  • ansible 1
    Kinit Error: Fix Malformed representation of principal when parsing name Configuration Management Tool
  • Screenshot 2021 10 07 at 00.00.32
    How to fix this computer is a domain controller: The snap-in cannot be used on a domain controller Windows Server
  • img 1686
    The trust relationship between this workstation and the primary domain failed Windows Server
  • Snapshot VMware vSphere
    How to Create a Snapshot on vSphere Web Client Virtualization
  • vcx
    Fix Error code 0x4 Session disconnected: Your session ended because of an error, if this keeps happening, contact your system administrator Windows
  • hero activedirectory
    How to move a computer object from one container (OU) to another Windows Server

Subscribe to Blog via Email

Enter your email address to subscribe to this blog and receive notifications of new posts by email.

Join 1,768 other subscribers
  • RSS - Posts
  • RSS - Comments
  • About
  • Authors
  • Write for us
  • Advertise with us
  • General Terms and Conditions
  • Privacy policy
  • Feedly
  • Telegram
  • Youtube
  • Facebook
  • Instagram
  • LinkedIn
  • Tumblr
  • Pinterest
  • Twitter
  • mastodon

Tags

Active Directory Azure Bitlocker Microsoft Windows PowerShell WDS Windows 10 Windows 11 Windows Deployment Services Windows Server 2016

Copyright © 2026 TechDirectArchive

Loading Comments...

You must be logged in to post a comment.