Approved USB Network Device Policy

Allow Only Approved USB Network Adapters on Windows

Keep registered company USB Wi-Fi and Ethernet adapters available while personal, unlisted, and newly introduced network devices remain blocked.

  • Approve required hardware before blocking
  • Restrict every unlisted USB network adapter
  • Test exceptions before wider deployment
Select an approved USB network adapter for the USB Ethernet whitelist

Register required devices first, then apply the restriction to everything not on the approved list.

Approve Required Devices Before Blocking Unknown Adapters

The safest deployment order is simple: inventory required USB network hardware, register the approved physical devices, activate the USB Ethernet restriction, and then verify both allowed and blocked results.

Quick answerIn GiliSoft USB Lock, connect every approved USB Wi-Fi or Ethernet adapter and add it to the USB Ethernet Whitelist. Enable Disable USB Ethernet only after the list is complete. A listed device should work; an unknown adapter should remain unavailable.
Approve firstIdentify company adapters and register each physical device before activating the block.
Block the restKeep personal, unknown, and newly introduced USB network adapters unavailable.
Review changesAdd replacements deliberately and remove exceptions that no longer have a business owner.

Define the Approved-Only Rule

Your goalRecommended controlWhat remains available
Approved company adapterAdd the physical device to the USB Ethernet whitelistIt remains usable after the restriction is active.
Replacement of an approved adapterRegister the new physical device and remove the retired entryApproval does not transfer automatically by model name.
Temporary support adapterAdd it for a documented period and remove it afterwardThe exception ends with the support task.
Personal or unknown adapterLeave it unlistedThe USB Ethernet restriction blocks the device.
Step 1: approve required hardware
1

Build the Initial Approved-Adapter List

Start with devices required for normal work, support, travel, docks, and recovery.

  1. List every USB Wi-Fi, Ethernet adapter, and dock network interface required for approved work.
  2. Install and open GiliSoft USB Lock, then select USB Ethernet Lock.
  3. Connect one approved adapter at a time so its displayed name can be matched to the physical device.
  4. Confirm each entry has an owner and purpose. Do not enable Disable USB Ethernet until the required list is complete.
The policy screen keeps the default restriction and approved-adapter list together. Click to enlarge.
Do not whitelist by name alone. Similar adapters can share a model description. Confirm that the selected entry appears for the physical device currently connected and retain its USB Ethernet ID for support records.

Register Each Approved Physical Adapter

Approval belongs to the selected physical device, not to every adapter with a similar product name. Connect and add devices one at a time.

  1. Connect the approved USB Wi-Fi or USB Ethernet adapter.
  2. Click Add under USB Ethernet Whitelist.
  3. Select the connected adapter and click OK.
  4. Confirm its name and USB Ethernet ID appear in the table, then label the physical adapter for the assigned user or PC.
The selection dialog lists currently detected USB network hardware. Add only the device being reviewed.
Step 2: block everything unlisted
2

Enable USB Ethernet Blocking

Activate the restriction after approved hardware has been registered and reviewed.

  1. Review every row in the USB Ethernet whitelist and remove entries that were added only for testing.
  2. Select Disable USB Ethernet and save the policy.
  3. Reconnect a whitelisted adapter and confirm the expected network connection works.
  4. Connect a separate unlisted adapter and confirm it cannot provide another network connection.
Inventory approved hardware > Add each adapter > Enable USB Ethernet blocking > Test approved and unknown devices
Test locally first. Do not enable a new adapter restriction through the same USB network connection used to manage a remote PC.
Step 3: control exceptions
3

Handle Temporary and Replacement Adapters

New hardware remains blocked until an administrator reviews and adds that physical device.

Do not open the complete adapter category when one employee needs temporary hardware. Add that specific adapter, record its expiry or return date, then remove the entry when the task ends.

Temporary exception

Record who approved the device, why it is needed, and when its access should end.

Replacement hardware

Register the new device separately and remove the lost, failed, or retired adapter entry.

A stale whitelist weakens the policy. Remove retired and missing devices promptly instead of leaving unused exceptions available.
Step 4: deploy the verified rule
4

Roll Out the Approved-Only Policy

Test one representative PC before applying the same rule to additional Windows endpoints.

Pilot PC

Test approved adapters, an unknown adapter, built-in networking, docks, and unrelated USB peripherals.

Additional PCs

Confirm the required devices and support owner for each workstation before enforcing the restriction.

Do not treat the whitelist as network authorization. It controls whether the USB adapter is allowed on the PC. Firewall, Wi-Fi credentials, VPN, and network access policy still require their own controls.

Compare Ways to Allow Only Approved Adapters

MethodDefault blockApproved-device exceptionsAdministration
GiliSoft USB LockYes, for USB network adaptersDedicated USB Ethernet whitelistVisible policy and device list
Disable-NetAdapterOnly adapters selected by commandRequires separate scriptsPowerShell names and scripting
Device ManagerManual per-device actionNo whitelistLocal administrator work
PnPUtilBy instance or hardware IDRequires separate inventory logicCommand-line device management

Verify the Approved-Only Result

Approved adapter

Reconnect every listed device and confirm it receives only the network access intended for that PC.

Unknown adapter

Connect a separate unlisted USB Wi-Fi or Ethernet adapter and confirm the default restriction applies.

Required connections

Confirm built-in networking, docks, and unrelated USB peripherals still behave as intended.

A finished whitelist should contain only approved, identifiable adapters that still have an active purpose.

Approved USB Network Adapter FAQ

Can I allow only approved USB network adapters?

Yes. Register approved physical devices and activate USB Ethernet blocking for everything not on the list.

What happens to a new unknown adapter?

It remains unavailable until an administrator reviews and adds that specific device.

Can a temporary adapter be approved?

Yes. Record the reason and end date, then remove the entry when the temporary work is complete.

Does approval transfer to replacement hardware?

No. Connect and register the replacement device, then remove the retired adapter entry.

Windows Network Adapter References

The Windows command behavior in this article was checked against Microsoft documentation. Microsoft notes that Disable-NetAdapter interrupts connectivity for the selected adapter, and PnPUtil device actions require administrators to identify the intended device carefully.

Keep approved USB network adapters working and block everything unlisted

Use GiliSoft USB Lock to register required hardware, enforce the approved-only rule, and control temporary or replacement exceptions.