Video Screencast Help
Search Video Help Close Back
to help
Not able to make it to Vision this year? Get a sampling in the Best of Vision on Demand group.

SEP USB Blocking

Created: 27 Jul 2010 | 7 comments
bmano's picture
0 0 Votes
Login to vote

Hello all,

We are looking at blocking all USB mass storage devices on your domain. However, from time to time some users still require USB access. If it is blocked for all users/machines, can it somehow be unblocked for some users? Can they be prompted for a password or something?

Thank you.

Discussion Filed Under:

Comments

kavin's picture
27
Jul
2010
0 Votes 0
Login to vote

You will have to use the SEP client in Usermode Please check this link

http://service1.symantec.com/SUPPORT/ent-security....

Mohammad Altaf Khan's picture
27
Jul
2010
0 Votes 0
Login to vote

HI

Create New sub Group
uncheck the inheritance.
goto policy TAB->click TASK on application and device control policy -> withdraw policy.

then move those client to that group.  

or
Create New group
allow USB or assgin default Device and appliaction control policy on that group
and move those cleint to that group.

pete_4u2002's picture
27
Jul
2010
0 Votes 0
Login to vote

add specific USB which needs to be accessed under whitelist, when needs to be accessed used the white listed USB only.

AravindKM's picture
27
Jul
2010
0 Votes 0
Login to vote

In SEPM you can assign policy in group level only.You cannot assign a policy to a particular client.So create another group ,remove inheritance and keep the policy as not blocking USB.When a client is required for USB access,move that client to this group and restart smc service/give update policy in the client..(This is for getting the policy effective immediately otherwise it will receive this policy in it's next heart beat only..)

Please don't forget to mark your thread solved with whatever answer helped you : ) Thanks & Regards Aravind

Shadi.A's picture
27
Jul
2010
0 Votes 0
Login to vote

Exclude from Blocking a specific USB Storage in your network

If you have a specific USB Storage in your network, (for example in the IT department)
and you want it to be usable even on the computers that are in the Blocked USB Group:

You can get the "device id" of your USB Flash from device manger or device ID Viewer , ...
and add it in hardware diveces in policy components,
then in the application and device control policy that you have blocked USB Storages,
Click the ADD button under Excluded from Blocking and select the specific USB Storage that you have created.

bmano's picture
27
Jul
2010
0 Votes 0
Login to vote

Thank you for all your responses. What I really wanted was when a USB is detected, SEP prompts you for a password to allow the device.

AravindKM's picture
27
Jul
2010
0 Votes 0
Login to vote

Currently such an option is not present in SEP.You may add this as an idea in the idea section of this form..

Please don't forget to mark your thread solved with whatever answer helped you : ) Thanks & Regards Aravind