steven_layton_sl Posted December 22, 2017 Posted December 22, 2017 Hi all I'm currently working to get the use of external USB storage devices stopped, and as its a tool I already have in place, I'm first looking at using Impero to do this. You seem to have 4 options. To control encryption you have -Allow un-encrypted devices -Allow only encrypted devices To control which devices are allowed to be used on Impero controlled PCs you have -Allow all devices -Allowed devices only Has anyone played with this? Any best practice? In terms of allowing only encrypted devices, do you have to use any specific encryption method?
minimoo Posted December 22, 2017 Posted December 22, 2017 Not an impero user here, and whilst i've not yet implemented anything - i'd been having a look at what windows does e.g. Group policy - Computer Configuration, Policies, Administrative Templates, Windows Components, BitLocker Drive Encryption, Removable Data Drives -> Deny write access to removable drives not protected by BitLocker. Sophos AV which we use also has options - but i'd probably trust Microsoft to implement the protections more reliably than sophos/impero personally.
free780 Posted December 22, 2017 Posted December 22, 2017 I tested a user GPO as you may have an AD Group as an exception. I would be tempted to run read only for a while and inform users. It depends if you want to force bitlocker to go or just ban them outright.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now