The following instructions assume that you are on the Section 9.0, Creating Security Policies) or that you are on the page for an existing Storage Device Control policy (see Section 13.0, Editing a Policy’s Details).
page in the Create New Storage Device Control Policy Wizard (seeThis Storage Device Control policy lets you control access to CD/DVD drives, floppy drives, and removable storage drives. For each drive, you can allow full access, allow read access only, disable all access, or default to the global Storage Device Control policy setting.
Watch a video that demonstrates how to create a Storage Device Control policy. |
The AutoPlay/AutoRun setting can only be configured on a global Storage Device Control policy. It is not available on location-based policies. This means that it is always applied regardless of the device’s location.
This setting controls the Windows AutoPlay feature. AutoPlay performs two processes. First, it launches the AutoRun process, which looks for an autorun.inf in the root directory and executes the instructions in the file. Second, it looks for specific content (music, video, and pictures) and launches the appropriate application to display or play the content. Select one of the following options:
Enable: Enables both AutoPlay and AutoRun.
Disable AutoRun: Disables the AutoRun feature so that autorun.inf instructions are not executed. AutoPlay is not disabled so music, video, and picture applications are still launched.
Disable AutoPlay/AutoRun: Disables both the AutoPlay and AutoRun features.
Inherit: Inherits this setting from other Storage Device Control policies assigned higher in the policy hierarchy. For example, if you assign this policy to a user, the setting is inherited from any Storage Device Control policies assigned to the user’s groups, folders, or zone.
You can control access to the following categories of storage devices:
CD/DVD: Controls access to any devices listed under
in Windows Device Manager.Floppy Drive: Controls access to any devices listed under
in Windows Device Manager.Removable Storage: Controls access to any devices reporting as removable storage under
in Windows Device Manager.For each storage device, select one of the following options:
Enable: Enables read and write access.
Disable: Prevents read and write access. When users attempt to access files on the device, they receive an error message from the operating system, or the application attempting to access the local storage device, that the action has failed.
Read Only: Enables read access and disable write access. When users attempt to write to the device, they receive an error message from the operating system, or the application attempting to access the local storage device, that the action has failed.
Inherit: Inherits this setting from other Storage Device Control policies assigned higher in the policy hierarchy. For example, if you assign this policy to a user, the setting is inherited from any Storage Device Control policies assigned to the user’s groups, folders, or zone.
The
access setting applies to all removable storage devices (RSDs). This includes FireWire devices, storage cards, USB devices, and any other devices reported as removable storage under in Windows Device Manager.The
list applies only to USB devices. Select this option if you want to override the access setting for specific USB devices.Each device you add to the
list must include an access assignment. The setting is used as the default access assignment for 1) any device you import that doesn’t have an assignment and 2) any device you create whose access you set to . Select from the following options:Enable: Enables read and write access.
Disable: Prevents read and write access. When users attempt to access files on the device, they receive an error message that the action has failed.
Read Only: Enables read access and disable write access. When users attempt to write to the device, they receive an error message that the action has failed.
Inherit: Inherits this setting from other Storage Device Control policies assigned higher in the policy hierarchy. For example, if you assign this policy to a user, the setting is inherited from any Storage Device Control policies assigned to the user’s groups, folders, or zone.
The following table provides instructions for managing the
list:
Task |
Steps |
Additional Details |
---|---|---|
Create a new device |
|
|
Copy an existing device from another policy |
|
All devices included in the other Storage Device Control policies are copied. If necessary, you can edit the copied devices after they are added to the list. |
Import a device from a policy export file |
|
All devices included in the export file are imported. If necessary, you can edit the imported devices after they are added to the list. For information about exporting devices, see Export a device. |
Import a device from a Device Scanner file |
|
For information about using the Device Scanner to collect data about USB devices, see |
Edit a device |
|
|
Export a device |
|
|
Delete a device |
|
|