Reference Guide

Manage Policies
314
See advanced settings
Windows Device Control
This technology allows for control of all the devices on a Windows computer (disable/enable), and can
be customized by device type.
Class: Windows Portable Device (WPD) Enabled
PARENT to the next policy. Set this policy to
Enabled to use the Subclass W
indows Portable
Device (WPD): Storage policy. Setting this policy to
Disabled disables the Subclass Windows Portable
Device (WPD): Storage policy
- no matter what its
value.
Control access to all
Windows Portable Devices.
Subclass Windows Portable Device
(WPD): Storage
Full Access
CHILD of Class: Windows Portable Device (WPD) .
Class: Windows Portable Device (WPD) must be
set to Enabled to use this policy.
Full Access: Port does not have read/write data
restrictions applied.
Read Only: Allows read capabil
ity. Write data is
disabled.
Blocked: Port is blocked from read/write
capability.
Class: Human Interface Device (HID) Enabled
Control access to all Human Interface Devices
(keyboards, mice).
USB port
-level blocking and HID class-level
blocking is
only honored if we can identify the
computer chassis as a laptop/notebook form
-
factor. We rely on the computer's BIOS for the
identification of the chassis.
See advanced settings
Advanced Port Control
Policy descriptions also display in tooltips in the Management Console. In this table, master policies are
in bold font.
Policy Default Setting Description
Windows Port Control
This technology allows for control of all the physical ports on a Windows computer
(disable/enable/bypass), and can be customized by port type.
Subclass Storage: External Drive Control Full Access
CHILD of Class: Storage. Class: Storage must be set
to Enabled to use this policy.
This policy interacts with EMS Access to
unShielded Media policy. If you intend to have Full
Access to media, also set this policy to Full Access
to ensure that the media is not set to read only
and the port is not blocked.
Full Access: External Drive port does not have
read/write data restrictions appl
ied
Read Only: Allows read capability. Write data is
disabled
Blocked: Port is blocked from read/write
capability
This policy is endpoint
-based and cannot be
overridden by user policy.