Jump to content

Recommended Posts

Posted

We block memory sticks at our school as a result of a couple of nasty virus outbreaks a couple of years ago. This also blocks camera's from connecting as they are recognised in most cases as external drives. Even though we use Microsoft System Centre Endpoint Protection, I am still nervous of allowing memory sticks to be used.

 

When we blocked these we put in place a few methods to assist users with transferring files to the network, such as Home Access Plus, emailing and we also assist by scanning the stick first then transferring the files to the network when they visit us.

 

It is an inconvenience but we don't have virus issues any more. Now though I need to have a rethink as more an more students are doing photography as a subject and they need to transfer files at short notice. One method is to use something like "we transfer" to get the job done. HAP doesn't seem the best approach for a few reasons though.

 

I am interested about your methods. Have you blocked memory sticks and cameras and if so, what methods have you put in place to make life easier? I would really like a drop box type solution where students can drop files somewhere and pick them up later, an FTP dumping ground if you like. I don't mind paying for the right solution as long as it isn't too pricey.

 

Many thanks

 

Ben

Posted

Mandatory profiles and very strict rules (no executables from USB, or on the home drives) mean we've kept virus free since going onto a new network setup. We've still thought about banning USB drives entirely purely because of how unreliable they are, plus with HAP and other systems in place for remote working, OneDrive etc, there seems little reason to warrant their use. On top of which, external speakers, nurses etc that all come in with USB sticks that expect to use them (especially when they're encrypted!) the inconvenience would be too high.

 

Perhaps just blocking executables?

Posted

We have blocked USBs many years ago and no viruses. We do have remote access for all, e-mail and OneDrive. We also use Surface 2s for taking photos that are then synced to OneDrive were they can be manipulated and shared.

 

Works for us

Posted

You can set a GPO to allow only known GUIDS.

You can disable the mass-storage device guid, and this should stop all memory sticks. Phones with storage, cameras with storage etc, but still allow webcams and other usb devices.

 

It's in Computer Settings -> Administrative templates -> System -> Device Installation

DevicePolicy.png

 

One of these guids will be usb mass storage, a bit of googleing should tell you which one. (I think it's the top one, but cant quite recall)

Posted
USB sticks are not blocked but there are path rules for drive letters (including CD drives D,E,F,etc). No exe files, bat files, etc.
Posted

We allow memory sticks these days.

 

If your still having a problem with viruses then your system isn't setup very securely! ;)

 

Try making the root of your shared drives read only and the virus problem will never spread anywhere.

 

That way a virus is only ever going to infect 1 PC, and that really isn't a big issue any more. We haven't had a virus "outbreak" in the 6 years since we made this simple change.

Posted

I allow the use of memory sticks across the network, regardless if you're a staff member or student. Never had the need to block it even if there are other provisions in place to allow remote access to user areas and shared drives.

 

I have software restriction policy in place that puts out a blanket ban on running .exe, .bat, .reg etc and isn't set up according like this: F:\* F:\*\* which is totally pointless.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...