This page lets you control which USB devices are supported. You can allow all USB devices, block all USB devices, or control access for groups or individual USB devices based on attributes such as Device Class, Manufacturer, Product, and Serial Number.
Select whether or not USB connections are supported:
Enable: Enables support for USB connections by keeping a device’s USB bus active. You can then enable or disable access for groups of USB devices or individual devices.
Disable: Disables support for USB connections by deactivating a device’s USB bus. All USB devices (keyboards, mice, storage devices, and so forth) are disabled. If you select this option, the remaining options (Default Device Access, Device Group Access Settings, and USB Device Access Settings) do not apply and are disabled.
Inherit: If the policy’s Inherit from Policy Hierarchy setting is enabled, inherits this setting from other USB Connectivity policies assigned higher in the policy hierarchy. For example, if you assign this policy to a user, the setting is inherited from any USB Connectivity policies assigned to the user’s groups, folders, or zone.
Select the default access (Enable, Disable, or Inherit) to assign to a USB device when the device:
Does not match one of the defined device groups or devices.
Matches a defined device group or device whose access is set to Default Device Access.
You can specify access settings for each of the device groups listed in the following table. Each group is defined by a specific base class code. When a device’s base class matches a group, the device receives the group’s access setting.
Device Group |
Base Class Code |
Examples |
---|---|---|
Human Interface Device (HID) |
03h |
Mice, keyboards, game controllers |
Mass Storage Class |
08h |
Flash drives, external hard drives, personal digital assistants (PDAs), mobile phones, cameras, Windows portable devices (WPDs) |
Printing Class |
07h |
Printers |
Scanning/Imaging (PTP) |
06h |
Scanners, any device that uses the Picture Transfer Protocol |
Select one of the following access settings for each group:
Disable: Disable access for all devices that are members of the device group.
If there are individual devices in the group for which you want to enable access, you can enable them in the USB Device Access Settings list. A device’s individual access setting overrides its group access setting.
For example, assume that your organization only supports SanDisk USB devices. You could disable the Mass Storage Class so that all removable storage devices are blocked and then use the USB Device Access Settings list to enable all SanDisk devices.
Enable: Enable access for all devices that are members of the device group.
If there are individual devices in the group for which you want to disable access, you can disable them in the USB Device Access Settings list. A device’s individual access setting overrides its group access setting.
Default Device Access: Give the device group the access specified by the Default Device Access setting.
Inherit: If the policy’s Inherit from Policy Hierarchy setting is enabled, inherit this setting from other USB Connectivity policies assigned higher in the policy hierarchy. For example, if you assign this policy to a user, the setting is inherited from any USB Connectivity policies assigned to the user’s groups, folders, or zone.
The device groups use one attribute (Device Class) as the match criterion. If you have devices whose access you want to control based on matching different or additional attributes, you can use the USB Device Access Settings list.
The individual device access settings override the device group access settings. For example, assume that the only mass storage device you want to allow is the Acme USB2 drive. In the Device Group Access Settings, you set Mass Storage Class to Disable. You then add the Acme USB2 to the USB Device Access Settings list and set the access to Enable. The individual setting for the Acme USB2 overrides its group setting, so the device is allowed.
Devices are evaluated against the USB Device Access Settings list from top to bottom. A device is assigned the access setting for the first device definition it matches, even if it matches another definition lower in the list. For example, assume that you want to disable all SanDisk devices except for the SanDisk Ultra. You add the SanDisk Ultra to the list and set the access to Enable. You then add a general SanDisk definition to the list and set the access to Disable. As long as the SanDisk Ultra definition is listed before the SanDisk definition in the list, the SanDisk Ultra is allowed.
The following table provides instructions for managing the USB Device Access Settings list:
Task |
Steps |
Additional Details |
---|---|---|
Create a new device definition |
|
|
Copy an existing device from another policy |
|
All devices included in the other USB Connectivity policies are copied. If necessary, you can edit the copied devices after they are added to the list. |
Import a device from a policy export file |
|
All devices included in the export file are imported. If necessary, you can edit the imported devices after they are added to the list. For information about exporting devices, see Export a device. |
Import a device from a Device Scanner file |
|
For information about using the Device Scanner to collect data about USB devices, see the ZENworks Endpoint Security Utilities Reference. |
Reorder the device list |
|
Devices are evaluated against the USB Device Access Settings list from top to bottom. A device is assigned the access setting for the first device definition it matches, even if it matches another definition lower in the list. For example, assume that you want to disable all SanDisk devices except for the SanDisk Ultra. You add the SanDisk Ultra to the list and set the access to Enable. You then add a general SanDisk definition to the list and set the access to Disable. As long as the SanDisk Ultra definition is listed before the SanDisk definition in the list, the SanDisk Ultra is allowed. |
Enable or disable a device |
|
When you add a device, it is enabled by default. You can disable a device to save it in the policy but no longer have it applied. |
Edit a device |
|
|
Rename an device |
|
|
Export a device |
|
|
Delete a device |
|
|
For trademark and copyright information, see Legal Notices.