Re: Prevent BlueTooth USB access




"PeteL" <dontmail@xxxxxx> wrote in message
news:d3j7c4$b3c$1$8300dec7@xxxxxxxxxxxxxxxxxxx
> Is it possible to block users from connecting USB devices using GPO. I've
> created a GPO to hide drives for usb storage (DOS prompt blocked so not
> too
> worried about that aspect) but I just wondered if you can block BlueTooth
> or
> any other USB devices.
>
> TIA.
>
> Pete.
>
>

You can use this ADM template to disable USB devices, it works by disabling
the usbstor.sys driver. I'm not sure about Bluetooth though, if you know
what driver bluetooth relies on I could probably edit the adm to include
that as well.

CLASS MACHINE

CATEGORY !!category

CATEGORY !!categoryname

POLICY !!policynameusb

KEYNAME "SYSTEM\CurrentControlSet\Services\USBSTOR"

EXPLAIN !!explaintextusb

PART !!labeltextusb DROPDOWNLIST REQUIRED

VALUENAME "Start"

ITEMLIST
NAME !!Disabled VALUE NUMERIC 3 DEFAULT
NAME !!Enabled VALUE NUMERIC 4
END ITEMLIST

END PART

END POLICY

POLICY !!policynamecd

KEYNAME "SYSTEM\CurrentControlSet\Services\Cdrom"

EXPLAIN !!explaintextcd

PART !!labeltextcd DROPDOWNLIST REQUIRED

VALUENAME "Start"

ITEMLIST
NAME !!Disabled VALUE NUMERIC 1 DEFAULT
NAME !!Enabled VALUE NUMERIC 4
END ITEMLIST

END PART

END POLICY

POLICY !!policynameflpy

KEYNAME "SYSTEM\CurrentControlSet\Services\Flpydisk"

EXPLAIN !!explaintextflpy

PART !!labeltextflpy DROPDOWNLIST REQUIRED

VALUENAME "Start"

ITEMLIST
NAME !!Disabled VALUE NUMERIC 3 DEFAULT
NAME !!Enabled VALUE NUMERIC 4
END ITEMLIST

END PART

END POLICY

POLICY !!policynamels120

KEYNAME "SYSTEM\CurrentControlSet\Services\Sfloppy"

EXPLAIN !!explaintextls120

PART !!labeltextls120 DROPDOWNLIST REQUIRED

VALUENAME "Start"

ITEMLIST
NAME !!Disabled VALUE NUMERIC 3 DEFAULT
NAME !!Enabled VALUE NUMERIC 4
END ITEMLIST

END PART

END POLICY

END CATEGORY

END CATEGORY

[strings]
category="Custom Policy Settings
categoryname="Restrict Drives"
policynameusb="Disable USB"
policynamecd="Disable CD-ROM"
policynameflpy="Disable Floppy"
policynamels120="Disable High Capacity Floppy"
explaintextusb="Disables the computers USB ports by disabling the
usbstor.sys driver"
explaintextcd="Disables the computers CD-ROM Drive by disabling the
cdrom.sys driver"
explaintextflpy="Disables the computers Floppy Drive by disabling the
flpydisk.sys driver"
explaintextls120="Disables the computers High Capacity Floppy Drive by
disabling the sfloppy.sys driver"
labeltextusb="Disable USB Ports"
labeltextcd="Disable CD-ROM Drive"
labeltextflpy="Disable Floppy Drive"
labeltextls120="Disable High Capacity Floppy Drive"
Enabled="Enabled"
Disabled="Disabled"


.



Relevant Pages

  • RE: How to disable all floppy drives on the network
    ... I received a 64MB USB thumb ... > said it is the company policy that they don't allow ... > Note that disabling the floppy driver doesn't ... > sticking in ZIP drives, LS-120 drives, CD Writers, ...
    (Focus-Microsoft)
  • Global Policy to disable FDD & USB not working
    ... I have created three security group Disable_FDD (where all users floppy ... Drive is disabled), Disable_All (where USB & Floppy is disabled), ... Right clicked the Kill_floppy policy and choose "Security" ... categoryname="Restrict Drives" ...
    (microsoft.public.windows.server.active_directory)
  • RE: Restrict USB Devices.
    ... I didn't test with USB printers. ... POLICY!!policynameusb ... policynamels120="Disable High Capacity Floppy" ... explaintextcd="Disables the computers CD-ROM Drive by disabling the ...
    (microsoft.public.windows.server.active_directory)
  • Restriction of External Drives through GPO
    ... POLICY!!policynameusb ... categoryname="Restrict Drives" ... policynameusb="Disable USB" ... explaintextcd="Disables the computers CD-ROM Drive by disabling the ...
    (microsoft.public.windows.server.active_directory)
  • RE: Restrict USB Devices.
    ... But the USB port is disabled i cant have a usb printer attached, ... have something which can only disable usb thumb drives or usb storage devices ... POLICY!!policynameusb ... explaintextcd="Disables the computers CD-ROM Drive by disabling the ...
    (microsoft.public.windows.server.active_directory)