Jump to content

Recommended Posts

Posted

Hi all,

 

So in to my new job (system admin) and getting to grips with things and one which has caught my attention is USB pens, namely that someone people have access to them and some dont.

 

Now as it was set up years ago and thus being a number of admins there is no notes on how it was carried out so i scaled through out default GPO and found it was under:

 

Computer Config> Policies> Admin Templates> Services and Drivers> USB Storage = enabled> startup type disabled

 

My question is, is this the correct way to do it?

 

As I said a number of users seems to have the access and a number dont, even me as an admin doesnt have the access and what is being used is a reg edit file to temporarily enable the usb ports and once i log off and on its disabled again.

 

I have seen some other options regarding removable media in GPO console and have a feeling it is most likely the better option but would appreciate your advice.

 

To save trouble, I wouldnt mind power still going to the USB ports (charge phones etc) and just restrict the use of using media.

Posted

Hi all dont know if anyone can answer but will post in hope lol

 

As I said I found that computers were disabled through the above setting on our default GPO, correct me if i am wrong but isnt this the registry option?

 

Now what I have thought about is how we need to temporarily enable people from time to time and it being much easier to disable it under user config in GPO so I performed the following:

User Config> Policies> Admin Templates> System> Removable Storage Access;

Removable disks: deny read and write access ENABLED

 

Now this seems to let the device be installed but not the user to access it which I dont mind as it stop confidential data from being taken off site plus any malware/virus is most likely in .exe file (not all time but it covers to an extent)

 

So my thought it now to create a folder in AD and when a user needs access to USB they simply need to be moved to that folder, maybe run a gpupdate and bobs your uncle they have temp access.

 

Would this be correct? and best way to do it?

Posted
Changing this kind of setting at the default level really isn't a good idea. Restricting drive letters, rather than restricting USB ports or power to the ports is the way to go about it. This gives you full flexibility in terms of the user using the device, rather than the device restricting all users (even yourself).
Posted

Not sure I fully understand.

 

Network Admins (myself) should only have access to USB's, and as group policy doesnt apply to use we are okay.

 

Plus group policy has been applied to the users configuration settings on our main GPO rather than computer, meaning when someone needs access on a temp basis we simply move them to a OU in AD where the defauly GPO isnt applied.

 

I would rather not restrcit drive letters as many users map drives differently here based on what they access reguarly. Would rather let power to still go to USB ports on machines as it at least lets people charge phones etc (Im being mean but not too mean lol)

Posted

It really depends on your school/company policy, but allowing end users to use USB flash should generally be allowed. Running AV software and disabling the likes of autorun/autoplay do control the spreading/distributing of viruses.

 

I still don't agree with modifying such GPO on the Default Domain Policy - it should be configured much lower down the tree as it were, as configuring at the default level will affect Admins and Servers, unless you're enabling/blocking Policy Inheritance - it's a very messy implementation that you've adopted (in my opinion).

Posted

Okay I see what you mean now, rather than disabling from deafult GPO its better to apply to OU's within the tree.

 

In your experience then is it better to disable the user settings for no read write access? Or computer settings?

 

There is only one other option within AD I can see which is:

 

Computer Config> Policies> Admin Templates> Services and Drivers> USB Storage = enabled> startup type disabled.

 

However as I said it only seemed to work for a number of computers and it does not allow power to users.

Posted

Computer settings always override user, so it would even block out Domain Admins theoretically. If this isn't a problem, then the same policy should be configured further down the tree where your computer objects are located within your structure - such as:

 

Curric OU > Workstations

 

If it's only working for certain machines, it could be Policy Inheritance is disabled, it could be a conflict of Policy or it could simply be your GPO refresh settings (default every 90 mins) are too long. In school environment, I set GPO user/computer refreshes to every 5 minutes with a randomer of 9 minutes, seeing as most ICT lessons will last anywhere from 10 mins to 1 hour, never 1 hour 30 mins (90 mins).

Posted

I would rather not apply it to work station groups in AD because when it comes to giving a user access to i would rather simply move them in to an OU where a GPO enables them, would it be correct in saying I can do the following:

 

Create a GPO called 'Disable USB' and apply to user OU's, within this GPO change the computer config settings to deny read and write to USB removable disks. OR do i change the User Config settings to deny read and write?

 

I have sat on this all day now and thik I have lost it :) so want to get it straightened out first

  • 3 weeks later...
Posted

going to have to open this again as i have ran in to an issue

 

No user now has access to read CD/DVD drive, it displays "Access Denied"

 

I have my policy which is applied to general user groups to not allow them to read/write to removable storage

 

I then have an OU which I can place user accounts in to which has another policy with the removable storage allowed but it doesnt even let users read CD/DVD's...

 

Anyone ideas to why this is or even where I can see what is preventing users from accessing their CD/DVD drives?

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...