## TL;DR
Create an Endpoint security / Device control profile for Windows, set removable storage access to Deny, and assign it to a pilot group before the fleet. Plug a USB drive into a pilot device to confirm the block notification appears and the drive is inaccessible. Communicate the change before enforcing so users do not mistake it for broken hardware.

## Steps
1. Intune admin center / Endpoint security / Device control / Create profile / platform Windows 10 and later / profile type Device control. Expected: a new empty device-control profile.
2. In the profile settings, set the removable storage group to deny read, write, and execute access. Expected: the profile shows Deny for the removable storage device group.
3. Assign to a pilot device group first, and exclude the IT imaging group if technicians need USB for builds. Expected: assignment targets the pilot group only.
4. On a pilot device, sync policy (Company Portal / Settings / Sync), plug in a USB drive, and confirm the block notification appears and the drive is inaccessible. Expected: block toast from the organization; drive letter unusable.
5. Roll the assignment out to the fleet in waves and publish a short notice to users explaining why USB drives are blocked and where to request an exception. Expected: no surprise tickets about dead USB ports.

## Use this when
- Security policy requires blocking USB drives on managed Windows laptops
- You are responding to a data-loss-prevention audit finding about removable media
- A pilot group needs to validate the block before fleet-wide enforcement

## Not for this skill when
- You need to allowlist specific drives by serial number (use Defender for Endpoint device control instead)
- You need read-only USB access rather than a full block (configure allow-read instead of deny)
- The target devices are Macs (use the macOS device-restriction profile instead)

## Compatibility
- Windows 10 and Windows 11 managed by Intune
- Intune Endpoint security device-control profiles; per-serial exceptions need Defender for Endpoint

## Variants
### Read-only USB for file ingest teams
Set the removable storage group to allow read and deny write. Teams can pull files off drives without copying company files onto them.
### Exception process for approved encrypted drives
Keep the block fleet-wide and grant exceptions through Defender for Endpoint device-control policies keyed to the drive serial. One exception path keeps the audit clean.

## Why it happens
Intune device control works at the device-class level: Windows tags USB mass-storage devices as removable storage, and the policy denies that class. It cannot distinguish one thumb drive from another, which is why per-drive exceptions live in Defender for Endpoint instead.

## Edge cases
- USB keyboards, mice, and other HID devices are unaffected; only the storage class is blocked.
- Phones plugged in for charging may lose file-transfer mode; test with the phone models your users carry.
- Encrypted USB boot or recovery drives used by IT must be excluded or technicians get blocked mid-incident.

## Provenance

Resolved from the public thread: https://vectle.com/posts/pst_k1wHySTlyj6Qu1aobndsnw
