What Does "Allow Only Approved USB Devices" Mean?
This is more precise than disabling every USB port. Keyboards, mice, printers, and other necessary peripherals can remain available while unapproved flash drives and external disks are kept out of the data-transfer path.
The identity used for approval matters. Windows can recognize hardware by device instance ID, hardware ID, compatible ID, or device setup class. A device instance ID normally identifies one installed device instance, while a broader hardware ID can match other units of the same model. Microsoft therefore recommends testing every relevant hardware instance before a policy is deployed widely.
Six Decisions Before Building a USB Allowlist
Inventory support, backup, print, deployment, camera, or production drives before restrictions begin. Record the owner, purpose, label, and replacement process.
Choose identifiers carefully. A rule that matches one device instance is narrower than a rule based on a shared hardware ID or setup class.
A drive used to deliver approved files may only need read access. Backup or collection work may require write access. Grant the smaller permission when possible.
Assign an administrator, protect settings with a password, and keep recovery information current so ordinary users cannot approve personal storage.
Use clear device labels, retain an approved-device register, and review connection events after additions, removals, or replacement drives.
Test the list on one Windows PC first. Export and import the approved set for repeatable local deployment, or plan centralized/custom management for a large fleet.
Ways to Allow Only Approved USB Devices on Windows
| Approach | Best fit | Approval method | Administration to plan |
|---|---|---|---|
| GiliSoft USB Lock Focused Windows tool | Offices, schools, labs, kiosks, and defined groups of Windows PCs | Insert a company drive, add it to the whitelist, choose its permission, then export or import the tested list | Install on target PCs and assign the administrator password; custom development can be evaluated for large deployments |
| Windows Device Installation Restrictions | Domain or policy-managed PCs with administrators comfortable using device identifiers | Allow named device instance IDs, hardware IDs, or classes while preventing other installations | Collect correct identifiers, understand the Plug and Play tree, and test composite devices and all hardware instances |
| Microsoft Defender Device Control | Organizations already using Microsoft Defender for Endpoint | Build reusable device groups and allow or deny access by device properties and policy rules | Requires eligible Microsoft security licensing, policy deployment, auditing, and ongoing rule management |
| Inventory and custody procedure | Very small environments with only a few controlled drives | Number company drives, assign a custodian, and physically control issuance | Physical custody alone does not stop an unknown device from working when it is connected |
Create an Approved USB Device List with GiliSoft USB Lock
GiliSoft USB Lock is designed for the practical task of keeping known company USB storage usable while unknown drives remain restricted. Insert an approved drive, click Add, choose its permission, and give it a recognizable label. Repeat for the drives the organization actually uses, then export the completed list for another Windows PC.
Keep approved drives available and unknown storage restricted
Create a trusted list for company flash drives, choose read-only or read-write permission, label each entry, protect administration with a password, and review access events. The same product can also restrict USB/SD storage, phones, optical media, tethering, and other transfer channels when required.


- Add individually approved company USB drives
- Assign read-only or read-write permission
- Label entries so administrators know their purpose
- Export and import a tested whitelist
- Keep unknown USB and SD storage restricted
- Protect changes and review access events
Need approved-device control across many Windows PCs?
GiliSoft can evaluate custom development for large projects. Send the endpoint count, Windows versions, number of approved devices, permission rules, administrator roles, logging needs, and deployment method so the team can assess customization and licensing.
Discuss a custom approved-device deploymentHow to Allow Only Approved USB Drives
- Inventory the company USB drives that have a legitimate job. Record the owner, purpose, label, and whether each drive needs read-only or read-write access.
- Install GiliSoft USB Lock on a test Windows PC, set the administrator password and recovery email, then open USB & CD Lock.
- Insert the first approved drive and click Add. Select the drive, choose its permission, enter a recognizable label, and save the entry.
- Repeat the Add process for every approved company drive. Do not approve personal devices merely because they are temporarily convenient.
- Export the completed whitelist. On another protected PC, import the file and reconnect each approved drive to verify access.
- Connect an unknown USB drive and confirm it remains restricted. Review the log and update the device register with the policy revision date.

For the exact Add, Export, and Import screens, follow the USB Lock whitelisting instructions. For broader endpoint policy planning, see USB device control software.
Where Approved-Only USB Access Is Useful
Support and IT maintenance drives
Allow named deployment, recovery, diagnostic, and firmware drives while personal or unregistered storage remains unavailable.
Reception, printing, and media-transfer stations
Keep one labeled business drive available for approved transfer work instead of accepting any flash drive brought to the workstation.
Labs, classrooms, and production PCs
Use read-only permission for reference material or read-write permission for controlled collection tasks, then review events when unexpected devices appear.
Departments with different permissions
Finance, HR, design, service, and operations may need different approved drives and permission levels. Maintain a documented list for each environment rather than one broad exception for the whole company.
Approved USB Device FAQ
Can GiliSoft USB Lock allow only company USB drives?
Yes. Add the company drives to the whitelist and keep unknown USB storage under the restricted policy. Give each approved entry a useful label so administrators can identify its owner or purpose.
Can approved drives have different permissions?
Yes. The Add dialog supports permission selection, including read-only and read-write access. Match the permission to the business task rather than giving every drive full write access.
Can I export the approved USB list to another PC?
Yes. Export the tested whitelist and import it on another GiliSoft USB Lock installation. Reconnect the actual drives afterward because hardware and Windows environments should still be verified.
Does USB approval encrypt the files on the drive?
No. An allowlist controls whether the Windows PC accepts the device. Choose GiliSoft USB Encryption when the drive itself needs a password-protected private area.
Will two identical USB drives be treated as the same device?
That depends on the identifier and product behavior used for matching. Test each physical unit that will be issued, label it, and keep its approval record. Do not assume identical retail models are interchangeable without verification.
Can GiliSoft support a large approved-device deployment?
Yes. GiliSoft can evaluate custom development for large Windows deployments. Provide the endpoint count, Windows versions, approved-device inventory, permission rules, administrator controls, logging requirements, and rollout method.
Research Sources
- Microsoft Learn: Manage device installation with Group Policy
- Microsoft Learn: Device Installation Policy CSP
- Microsoft Learn: Device control overview
- Microsoft Learn: Deploy and manage device control with Group Policy
- CISA: Hardware Asset Management capability description
Keep company USB drives working and unknown devices out
Build and test an approved-device list with GiliSoft USB Lock, or discuss custom development for a large Windows deployment.
