Windows USB Whitelist Guide

How to Allow Only Approved USB Devices

Keep company-approved USB drives available while unknown flash drives and external storage remain blocked on Windows PCs.

  • Build a trusted list from the USB drives the organization owns
  • Assign read-only or read-write access where the work requires it
  • Export the approved list and reuse it on other Windows PCs
GiliSoft USB Lock approved USB device whitelist
GiliSoft USB Lock software box
Approved drive allowedUnknown USB storage follows the blocked policy.

What Does "Allow Only Approved USB Devices" Mean?

Short answerUnknown USB storage is restricted by default, while company-owned or specifically authorized drives are added to a trusted list. Approved drives can then receive the access level required for the job, such as read-only or read-write.

This is more precise than disabling every USB port. Keyboards, mice, printers, and other necessary peripherals can remain available while unapproved flash drives and external disks are kept out of the data-transfer path.

The identity used for approval matters. Windows can recognize hardware by device instance ID, hardware ID, compatible ID, or device setup class. A device instance ID normally identifies one installed device instance, while a broader hardware ID can match other units of the same model. Microsoft therefore recommends testing every relevant hardware instance before a policy is deployed widely.

Decide whether approval means one physical drive or an entire drive model. For sensitive workflows, approving individually inventoried company drives is usually clearer than allowing every device that reports the same model identifier.

Six Decisions Before Building a USB Allowlist

1. Which devices are genuinely required?

Inventory support, backup, print, deployment, camera, or production drives before restrictions begin. Record the owner, purpose, label, and replacement process.

2. One drive or every identical model?

Choose identifiers carefully. A rule that matches one device instance is narrower than a rule based on a shared hardware ID or setup class.

3. Read-only or read-write?

A drive used to deliver approved files may only need read access. Backup or collection work may require write access. Grant the smaller permission when possible.

4. Who owns whitelist changes?

Assign an administrator, protect settings with a password, and keep recovery information current so ordinary users cannot approve personal storage.

5. How will changes be recorded?

Use clear device labels, retain an approved-device register, and review connection events after additions, removals, or replacement drives.

6. How will the list reach other PCs?

Test the list on one Windows PC first. Export and import the approved set for repeatable local deployment, or plan centralized/custom management for a large fleet.

Ways to Allow Only Approved USB Devices on Windows

ApproachBest fitApproval methodAdministration to plan
GiliSoft USB Lock
Focused Windows tool
Offices, schools, labs, kiosks, and defined groups of Windows PCsInsert a company drive, add it to the whitelist, choose its permission, then export or import the tested listInstall on target PCs and assign the administrator password; custom development can be evaluated for large deployments
Windows Device Installation RestrictionsDomain or policy-managed PCs with administrators comfortable using device identifiersAllow named device instance IDs, hardware IDs, or classes while preventing other installationsCollect correct identifiers, understand the Plug and Play tree, and test composite devices and all hardware instances
Microsoft Defender Device ControlOrganizations already using Microsoft Defender for EndpointBuild reusable device groups and allow or deny access by device properties and policy rulesRequires eligible Microsoft security licensing, policy deployment, auditing, and ongoing rule management
Inventory and custody procedureVery small environments with only a few controlled drivesNumber company drives, assign a custodian, and physically control issuancePhysical custody alone does not stop an unknown device from working when it is connected
A tested allowlist is more than a list of brand names. Two drives with the same retail name may expose different identifiers, and a composite USB device can expose several functions. Verify the actual device behavior on the Windows versions used in the organization.

Create an Approved USB Device List with GiliSoft USB Lock

GiliSoft USB Lock is designed for the practical task of keeping known company USB storage usable while unknown drives remain restricted. Insert an approved drive, click Add, choose its permission, and give it a recognizable label. Repeat for the drives the organization actually uses, then export the completed list for another Windows PC.

GiliSoft USB Lock box

Keep approved drives available and unknown storage restricted

Create a trusted list for company flash drives, choose read-only or read-write permission, label each entry, protect administration with a password, and review access events. The same product can also restrict USB/SD storage, phones, optical media, tethering, and other transfer channels when required.

Add an approved drive to the GiliSoft USB Lock whitelist
Select the inserted drive, assign read-only or read-write permission, add a label, and save it to the approved list.
Review approved and blocked USB activity in GiliSoft USB Lock
Review connection events after testing approved and unknown devices.

Need approved-device control across many Windows PCs?

GiliSoft can evaluate custom development for large projects. Send the endpoint count, Windows versions, number of approved devices, permission rules, administrator roles, logging needs, and deployment method so the team can assess customization and licensing.

Discuss a custom approved-device deployment

How to Allow Only Approved USB Drives

  1. Inventory the company USB drives that have a legitimate job. Record the owner, purpose, label, and whether each drive needs read-only or read-write access.
  2. Install GiliSoft USB Lock on a test Windows PC, set the administrator password and recovery email, then open USB & CD Lock.
  3. Insert the first approved drive and click Add. Select the drive, choose its permission, enter a recognizable label, and save the entry.
  4. Repeat the Add process for every approved company drive. Do not approve personal devices merely because they are temporarily convenient.
  5. Export the completed whitelist. On another protected PC, import the file and reconnect each approved drive to verify access.
  6. Connect an unknown USB drive and confirm it remains restricted. Review the log and update the device register with the policy revision date.
Protect GiliSoft USB Lock whitelist administration with a password
Protect whitelist administration with a password and keep recovery information current.

For the exact Add, Export, and Import screens, follow the USB Lock whitelisting instructions. For broader endpoint policy planning, see USB device control software.

Where Approved-Only USB Access Is Useful

Support and IT maintenance drives

Allow named deployment, recovery, diagnostic, and firmware drives while personal or unregistered storage remains unavailable.

Reception, printing, and media-transfer stations

Keep one labeled business drive available for approved transfer work instead of accepting any flash drive brought to the workstation.

Labs, classrooms, and production PCs

Use read-only permission for reference material or read-write permission for controlled collection tasks, then review events when unexpected devices appear.

Departments with different permissions

Finance, HR, design, service, and operations may need different approved drives and permission levels. Maintain a documented list for each environment rather than one broad exception for the whole company.

Approved USB Device FAQ

Can GiliSoft USB Lock allow only company USB drives?

Yes. Add the company drives to the whitelist and keep unknown USB storage under the restricted policy. Give each approved entry a useful label so administrators can identify its owner or purpose.

Can approved drives have different permissions?

Yes. The Add dialog supports permission selection, including read-only and read-write access. Match the permission to the business task rather than giving every drive full write access.

Can I export the approved USB list to another PC?

Yes. Export the tested whitelist and import it on another GiliSoft USB Lock installation. Reconnect the actual drives afterward because hardware and Windows environments should still be verified.

Does USB approval encrypt the files on the drive?

No. An allowlist controls whether the Windows PC accepts the device. Choose GiliSoft USB Encryption when the drive itself needs a password-protected private area.

Will two identical USB drives be treated as the same device?

That depends on the identifier and product behavior used for matching. Test each physical unit that will be issued, label it, and keep its approval record. Do not assume identical retail models are interchangeable without verification.

Can GiliSoft support a large approved-device deployment?

Yes. GiliSoft can evaluate custom development for large Windows deployments. Provide the endpoint count, Windows versions, approved-device inventory, permission rules, administrator controls, logging requirements, and rollout method.

Research Sources

Keep company USB drives working and unknown devices out

Build and test an approved-device list with GiliSoft USB Lock, or discuss custom development for a large Windows deployment.