how to block usb storage with intune endpoint security
Blocks USB removable storage on managed Windows devices using an Intune Endpoint security device-control profile. Covers creating the profile, scoping it to a pilot group first, and verifying the block on a test device. Use when security policy requires USB drives to be blocked on company laptops. Not for per-drive serial allowlists (that needs Defender for Endpoint device control) or for blocking USB on macOS.
TL;DR
Create an Endpoint security / Device control profile for Windows, set removable storage access to Deny, and assign it to a pilot group before the fleet. Plug a USB drive into a pilot device to confirm the block notification appears and the drive is inaccessible. Communicate the change before enforcing so users do not mistake it for broken hardware.
Steps
- Intune admin center / Endpoint security / Device control / Create profile / platform Windows 10 and later / profile type Device control. Expected: a new empty device-control profile.
- In the profile settings, set the removable storage group to deny read, write, and execute access. Expected: the profile shows Deny for the removable storage device group.
- Assign to a pilot device group first, and exclude the IT imaging group if technicians need USB for builds. Expected: assignment targets the pilot group only.
- On a pilot device, sync policy (Company Portal / Settings / Sync), plug in a USB drive, and confirm the block notification appears and the drive is inaccessible. Expected: block toast from the organization; drive letter unusable.
- Roll the assignment out to the fleet in waves and publish a short notice to users explaining why USB drives are blocked and where to request an exception. Expected: no surprise tickets about dead USB ports.
Use this when
- Security policy requires blocking USB drives on managed Windows laptops
- You are responding to a data-loss-prevention audit finding about removable media
- A pilot group needs to validate the block before fleet-wide enforcement
Not for this skill when
- You need to allowlist specific drives by serial number (use Defender for Endpoint device control instead)
- You need read-only USB access rather than a full block (configure allow-read instead of deny)
- The target devices are Macs (use the macOS device-restriction profile instead)
Compatibility
- Windows 10 and Windows 11 managed by Intune
- Intune Endpoint security device-control profiles; per-serial exceptions need Defender for Endpoint
Variants
Read-only USB for file ingest teams
Set the removable storage group to allow read and deny write. Teams can pull files off drives without copying company files onto them.
Exception process for approved encrypted drives
Keep the block fleet-wide and grant exceptions through Defender for Endpoint device-control policies keyed to the drive serial. One exception path keeps the audit clean.
Why it happens
Intune device control works at the device-class level: Windows tags USB mass-storage devices as removable storage, and the policy denies that class. It cannot distinguish one thumb drive from another, which is why per-drive exceptions live in Defender for Endpoint instead.
Edge cases
- USB keyboards, mice, and other HID devices are unaffected; only the storage class is blocked.
- Phones plugged in for charging may lose file-transfer mode; test with the phone models your users carry.
- Encrypted USB boot or recovery drives used by IT must be excluded or technicians get blocked mid-incident.
Provenance
Resolved from the public thread: https://vectle.com/posts/pst_k1wHySTlyj6Qu1aobndsnw
Maintainer review
No maintainer verification is recorded for this version.
This records the version a maintainer checked. It does not assert that the version is the latest upstream release.