Why a Shared PC Needs Clear USB Rules
Simply telling users not to connect personal drives is difficult to enforce. Disabling every USB controller is also too broad when the PC still needs a keyboard, mouse, printer, license key, or approved company drive. The practical goal is to restrict removable storage and phone data channels while preserving the devices the computer genuinely needs.
What to Control on a Shared Windows PC
- USB and SD storage: block unknown flash drives, portable disks, and memory cards.
- Trusted work media: allow the company drives that staff actually need.
- Phone file transfer: restrict Android and iPhone data access when it is not part of the job.
- USB tethering: prevent unmanaged phone-based internet connections.
- Settings access: keep policy changes behind an administrator password.
- Access records: review allowed and blocked attempts after testing or an incident.
Compare Shared-PC USB Control Options
| Option | Good for | User experience | Important consideration |
|---|---|---|---|
| Device Manager | Temporary change on one computer | A selected device or controller is disabled | A broad controller change may also interrupt required peripherals |
| Windows removable-storage policy | Repeatable read, write, or all-access rules on supported editions | Storage access is denied according to policy | Configuration depends on Windows edition and administrative setup |
| Microsoft Defender Device Control | Managed enterprise device groups, allow/deny rules, and auditing | Rules are applied through the organization's security management | Requires eligible Microsoft licensing and administration |
| GiliSoft USB Lock Recommended here | A local shared PC that needs a whitelist, phone controls, and readable logs | Unknown media is blocked while approved drives continue to work | Commercial software; download is a trial |
How to Block USB Drives on a Shared PC
- List every device that must remain usable, including keyboards, mice, printers, scanners, license keys, and approved company drives.
- Install GiliSoft USB Lock, set the administrator password, and configure recovery details before applying restrictions.
- Open the USB and CD/DVD controls and enable the required USB/SD storage restriction.
- Insert each approved company drive and add it to the trusted-device whitelist.
- Test an unknown USB drive, an approved drive, and phone transfer or tethering if those channels also need control.
- Review the access log, then export the tested whitelist for backup or use on similar shared computers.



Shared-PC Deployment Examples
- Front-desk computer: allow a company backup drive while blocking personal flash drives.
- Training room: prevent attendees from copying course folders or introducing unknown media.
- Workshop terminal: retain approved diagnostic media and restrict unregistered storage.
- Shift workstation: keep the same removable-media rules active for every operator.
- Family computer: reduce accidental transfers from personal drives and phones.
- Media handoff station: permit designated delivery drives while rejecting everything else.
Block Unknown Drives Without Disabling Approved Work Devices
GiliSoft USB Lock combines USB/SD storage control, trusted-device whitelisting, phone transfer and tethering restrictions, password-protected settings, and activity records in one local Windows interface. It is a practical fit when a shared PC needs more than an all-or-nothing port switch.

GiliSoft USB Lock
Download the trial, test the exact peripherals and workflows used on the shared computer, then keep the verified whitelist as part of the PC's setup record.
Managing many shared PCs?
GiliSoft can discuss volume licensing, OEM requirements, and custom development for larger deployments with specific device-control needs.
Contact sales@gilisoft.comShared-PC Deployment Checklist
- Required peripherals and approved drives are documented.
- The administrator password and recovery email are recorded securely.
- An unknown USB drive is blocked as expected.
- Every approved work drive still opens normally.
- Phone transfer and tethering rules have been tested.
- Access logs are readable and reviewed periodically.
- The whitelist has been exported and backed up.
- A standard user cannot change the USB policy.
Related USB Control Guides
- Export and import a USB whitelist
- Allow only approved USB devices
- Block files from being copied to USB
- Block phone and USB transfer on a PC
- Control removable-media access
- USB Lock help by topic
Shared PC USB Lock FAQ
Can I block USB drives without disabling the keyboard and mouse?
Yes. Apply storage-specific controls instead of disabling an entire USB controller. Test the keyboard, mouse, printer, and every required peripheral before handing the PC back to users.
Can approved USB drives still work on a shared PC?
Yes. Add the designated company drives to the trusted-device whitelist while unknown removable storage remains restricted.
Can standard users change the USB restrictions?
USB Lock settings can be protected with an administrator password so ordinary shared-PC users cannot casually change the configured rules.
Can I block phone file transfer as well as USB drives?
Yes. USB Lock includes controls for Android and iPhone data access and can also restrict USB tethering when those channels are not permitted.
Is blocking USB drives the same as encrypting them?
No. USB control decides which devices can be used on a computer. USB Encryption protects files stored on the removable drive.
Can I reuse a tested whitelist on other shared PCs?
Yes. Export the trusted-device list after testing and import it on similar computers, then verify required devices on each PC before wider use.
Official Windows References
- Microsoft Learn: removable-storage access policies
- Microsoft Learn: Defender for Endpoint device-control policies
- Microsoft Learn: device-control events and reports
Protect a shared PC without blocking approved work devices
Test unknown USB drives, trusted company media, phone-transfer controls, and access logs before applying the setup to daily users.