Jump to content

Custom GPO (.adm file)


Recommended Posts

Posted

I am disabling usb storage devices in my install.

I first set the registry entry to 4 via a reg file. - blocking all previously discovered devices

I then explicilty deny user rights to the usbstor.inf and usbstor.pnf. - Blocking any new devices from being discovered

Then I copy over a custom .adm that sets the registry value back to 4 everytime the machine is reset. Its the standard template for setting the usbstor to a value of 4 and everything works fine; once you go in to gpedit (uncheck "only show policy settings that can be fully managed") and enable the setting. Is there any way to enable this policy without user interaction?

[usbstor.adm]

CLASS MACHINE

CATEGORY USB STORAGE

POLICY USB STORAGE DEVICES

KEYNAME "SYSTEM\CurrentControlSet\Services\USBSTOR"

EXPLAIN This policy allows the disabling of USB storage devices

PART "Startup Type" DROPDOWNLIST REQUIRED

VALUENAME "Start"

ITEMLIST

NAME "Disabled" VALUE NUMERIC 4

END ITEMLIST

END PART

END POLICY

END CATEGORY

Thanks.


Please sign in to comment

You will be able to leave a comment after signing in



Sign In Now
  • Recently Browsing   0 members

    • No registered users viewing this page.
×
×
  • Create New...