Jump to content

Recommended Posts

Posted

Hi all

 

I'm currently working to get the use of external USB storage devices stopped, and as its a tool I already have in place, I'm first looking at using Impero to do this.

 

impero_usb.PNG

 

You seem to have 4 options. To control encryption you have

 

-Allow un-encrypted devices

-Allow only encrypted devices

 

To control which devices are allowed to be used on Impero controlled PCs you have

 

-Allow all devices

-Allowed devices only

 

Has anyone played with this? Any best practice? In terms of allowing only encrypted devices, do you have to use any specific encryption method?

Posted

Not an impero user here, and whilst i've not yet implemented anything - i'd been having a look at what windows does e.g. Group policy - Computer Configuration, Policies, Administrative Templates, Windows Components, BitLocker Drive Encryption, Removable Data Drives -> Deny write access to removable drives not protected by BitLocker.

 

Sophos AV which we use also has options - but i'd probably trust Microsoft to implement the protections more reliably than sophos/impero personally.

Posted
I tested a user GPO as you may have an AD Group as an exception. I would be tempted to run read only for a while and inform users. It depends if you want to force bitlocker to go or just ban them outright.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...