Windows 11/10 USB Storage Guide

How to Block USB Storage Devices on Windows

Block flash drives and external USB storage without disabling the keyboards, mice, printers, and other peripherals Windows users still need.

  • Block USB disk reading, writing, or both
  • Keep approved company drives available
  • Review allowed and blocked device activity
Windows USB device control showing an approved flash drive and restricted external storage

Control removable storage by device type and policy instead of switching off every USB port.

Block Storage Access, Not Every USB Peripheral

USB storage control should focus on removable data channels. Disabling every USB controller can also interrupt keyboards, mice, webcams, printers, and other devices that are unrelated to file copying.

Quick answerFor the clearest Windows workflow, open USB & CD Lock in GiliSoft USB Lock and disable USB disk reading, writing, or both. Add approved company drives to the trusted-device whitelist when selected storage still needs access.
Block readingStop users from opening or copying files from removable USB storage.
Block writingStop files from being copied from the PC to flash drives and external USB disks.
Allow approved drivesKeep reviewed company USB devices usable through trusted-device rules.

Choose the Right Blocking Level

Your goalRecommended controlWhat remains available
Prevent data from leaving the PCDisable writing to USB disksUSB storage may remain readable, depending on policy.
Prevent any USB storage useDisable reading and writingKeyboard, mouse, and unrelated peripherals can remain available.
Block personal drives but allow company drivesDefault restriction plus trusted-device whitelistOnly approved USB storage remains usable.
Apply the same rule to managed Windows PCsGroup Policy, MDM, or endpoint device controlBehavior depends on Windows edition, licensing, and policy scope.
Recommended for direct control
1

Block USB Storage with GiliSoft USB Lock

Use a visible policy screen instead of editing device identifiers or registry values by hand.

  1. Install and open GiliSoft USB Lock, then enter the administrator password.
  2. Open USB & CD Lock from the Control Center.
  3. Select Disable Reading USB Disk, Disable Writing to USB Disk, or both, according to the required policy.
  4. Apply the policy, reconnect a test flash drive, and verify the expected read and write behavior.
USB & CD Lock separates storage controls from broader device controls. Click the screenshot to enlarge it.
Do not select more channels than the policy requires. If the concern is copying files to removable media, disabling USB writing may be enough. Add phone transfer, SD card, or tethering restrictions only when those channels also need control.

Allow Trusted USB Drives While Unknown Storage Stays Blocked

A blanket ban is not practical when staff still use approved encrypted drives, service media, or company-issued storage. In that case, keep the restriction active and add reviewed devices to the trusted-device whitelist.

  1. Connect one approved company USB drive.
  2. Click Add in the Trusted Devices White-list area.
  3. Repeat for each approved drive, then test an unknown drive.
  4. Use Export and Import when the same list is needed on other PCs.
Approved USB devices can be recorded once and reused as a controlled list on other managed Windows PCs.
Windows Pro and Enterprise
2

Block Removable Storage with Windows Group Policy

Use Windows policies when administrators already manage Pro, Enterprise, or Education PCs and need a class-wide rule.

  1. Press Windows + R, enter gpedit.msc, and open the Local Group Policy Editor.
  2. Go to the Removable Storage Access policy location shown below.
  3. Choose Removable Disks: Deny read access, Deny write access, or All Removable Storage classes: Deny all access.
  4. Enable only the required rule, run gpupdate /force when appropriate, reconnect the drive, and test the exact operation.
Computer Configuration > Administrative Templates > System > Removable Storage Access
Windows edition matters: Local Group Policy Editor is generally available in Pro, Enterprise, and Education editions, not standard Windows Home installations. Domain or Intune environments should test policy scope before broad deployment.
For managed organizations
3

Use Microsoft Defender Device Control for Managed Endpoints

Defender Device Control can apply allow or deny policies to removable media and distinguish read, write, and execute access.

This route is relevant when the organization already uses Microsoft Defender for Endpoint and has staff who can maintain device groups, policy XML, deployment scope, and audit data. A default-deny policy needs carefully defined allow rules so required printers, phones, optical devices, and approved storage do not become collateral damage.

Useful controls

Allow or deny removable-media groups and control read, write, and execute operations.

Operational cost

Requires compatible licensing, deployment tooling, policy maintenance, testing, and incident review.

For a smaller Windows deployment: GiliSoft USB Lock exposes the common storage, phone, whitelist, and log controls in one desktop interface without requiring policy XML.
Control new device installation
4

Restrict USB Device Installation by Hardware ID

Windows Device Installation Restrictions can block new devices or allow only approved device IDs on managed machines.

What it controls

Whether Windows may install devices that match specified instance IDs, device IDs, setup classes, or the removable-device category.

What it does not replace

An installation rule is not the same as an access rule for devices already installed. Test existing hardware as well as a newly introduced drive.

Avoid disabling the USB host controller. That can interrupt keyboards, mice, webcams, printers, docks, and other peripherals unrelated to storage.

Compare USB Storage Blocking Methods

MethodSeparate read/write rulesTrusted-device listBest fit
GiliSoft USB LockYesYesOffice, school, shared, and managed Windows PCs
Group PolicyYes, by storage classRequires additional device policiesWindows Pro/Enterprise policy administration
Defender Device ControlYesYes, through device groupsOrganizations already using Defender for Endpoint
Device Installation RestrictionsNoYes, by device identifiersControlling which new devices Windows may install

Verify the USB Storage Policy

Test reading

Open a file on an unapproved USB drive and confirm the configured read restriction.

Test writing

Copy a harmless test file to the USB drive and confirm the configured write restriction.

Test trusted devices

Connect an approved drive and confirm it receives only the intended permissions.

Review USB activity after testing so administrators can confirm when access was allowed or denied.

USB Storage Blocking FAQ

Can I block USB storage without disabling my keyboard and mouse?

Yes. Use storage-specific read/write controls instead of disabling USB controllers or hubs.

Can I block copying files to USB but still read the drive?

Yes. A write restriction targets copy-out activity while read access can remain available.

Can approved company USB drives remain usable?

Yes. Add reviewed drives to the trusted-device whitelist and test both approved and unknown devices.

Does USB storage blocking encrypt the files on a drive?

No. Blocking controls access on the PC. Use USB Encryption when files on the drive itself need password protection.

Windows Policy References

The Windows methods in this guide were checked against Microsoft documentation for Removable Storage Access, Device Installation Restrictions, and Defender Device Control. These references explain the policy scope; the GiliSoft steps and screenshots describe the USB Lock workflow.

Block unknown USB storage while approved work continues

Control USB disk reading and writing, keep trusted devices available, and review access activity from one Windows application.

Buy GiliSoft USB Lock