Use on kiosks, reception PCs, exam systems, and fixed-purpose workstations where portable storage has no approved business use.
What Counts as Removable Media?
Removable media includes USB flash drives, portable SSDs and hard drives, SD and microSD cards, CD/DVD media, and phones exposed to Windows as a file-transfer device. USB docks and card readers can introduce the same storage paths even when the media is not shaped like a thumb drive.
Choose the Access Level Before Choosing the Tool
Useful when staff must open approved reference files but should not copy company data onto removable media.
Keep named company USB drives available while unknown flash drives, portable disks, and card media remain blocked.
Use encryption when authorized files may leave the PC and must remain protected if the drive is lost or stolen.
Record existing device use first so the policy does not interrupt backup, field service, printing, or equipment-update tasks.
Set distinct rules for USB storage, SD cards, CD/DVD media, phones, tethering, and other device classes instead of treating every connection alike.
Three Practical Ways to Control Removable Media on Windows
Windows Removable Storage Access policy
Windows Group Policy can deny read or write access to removable disks and can deny all access across removable-storage classes. This is suitable for broad rules on managed Windows editions when exceptions and device-level approval are not the main requirement.
Microsoft Defender Device Control
Microsoft's enterprise device-control platform can create reusable allow and deny groups, apply read, write, or execute permissions, add exceptions, and audit device activity. It is the strongest fit for organizations already operating Defender for Endpoint and centralized policy management.
GiliSoft USB Lock
GiliSoft USB Lock gives Windows administrators a dedicated interface for blocking removable storage, allowing trusted USB drives, restricting phone and media-transfer channels, and reviewing access records without building a full enterprise security stack.
Registry edits and Device Manager changes appear in many tutorials, but they are harder to document, easier to apply inconsistently, and less useful when approved-device exceptions or activity records are required.
Control Active Windows Ports with GiliSoft USB Lock
Use GiliSoft USB Lock when the USB port must stay physically available but access should follow a defined company rule. It can keep approved business media working while restricting unknown devices and other transfer paths.
Practical controls in one Windows application
- Block USB and SD storage or restrict reading and writing.
- Add approved company USB drives to a trusted-device whitelist.
- Control CD/DVD media, phone data transfer, selected device classes, and USB tethering.
- Review allowed and denied activity for troubleshooting and policy checks.
- Export a trusted-device list and import it on additional managed computers.
For larger deployments, GiliSoft can discuss custom rules, branding, packaging, and deployment requirements.
Which Windows Removable Media Control Fits the Requirement?
| Requirement | Windows policy | Microsoft Device Control | GiliSoft USB Lock |
|---|---|---|---|
| Broad deny read or write | Yes, through removable-storage policies. | Yes, through device-control rules. | Yes, through USB and media access settings. |
| Approved-device exceptions | Limited for simple class-wide policy. | Detailed reusable device groups and exceptions. | Trusted USB whitelist for approved company drives. |
| Read, write, and execute rules | Read/write policies; options vary by class. | Granular read/write/execute controls. | Task-focused storage access and transfer restrictions. |
| Phones, SD, CD/DVD, and tethering | Requires separate policies and device classes. | Can be modeled through supported device groups. | Presented as dedicated controls in one interface. |
| Administration | Group Policy or MDM knowledge required. | Best with Defender for Endpoint administration. | Direct Windows desktop administration and repeatable whitelist import. |
Deploy Removable Media Rules Without Breaking Daily Work
Inventory real transfer tasks
List backup drives, field-service media, camera cards, photo-printing drives, update media, phones, and specialist equipment before changing access.
Audit or pilot first
Test a small group of representative PCs. Record which device classes are used and confirm the rule does not block keyboards, mice, printers, or required equipment.
Create the approved-device list
Add company-owned storage that has a documented owner and purpose. Avoid approving a drive merely because it happened to be connected during setup.
Apply the narrowest useful restriction
Use read-only access when users need reference files, approved-only access when known media is required, and full blocking where portable storage has no legitimate use.
Verify, document, and review
Test approved and unapproved devices, record the owner of each exception, retain recovery information, and review logs or policy changes on a regular schedule.
Removable Media Test Matrix
| Test item | Expected result | What to verify |
|---|---|---|
| Unknown USB flash drive | Blocked or read-only according to policy. | No unauthorized copy path is available. |
| Approved company USB drive | Works with the assigned permission. | Approval survives reconnect and restart. |
| Portable SSD or hard drive | Handled as removable storage. | Large-capacity external disks do not bypass the rule. |
| SD or microSD card | Blocked, limited, or approved separately. | Built-in and USB card readers behave as intended. |
| Phone in file-transfer mode | Transfer restricted if phone access is disabled. | Charging does not silently enable file copying. |
| Keyboard and mouse | Remain usable. | Storage policy is not disabling required input devices. |
| CD/DVD media | Follows the separate optical-media rule. | Reading and burning permissions match policy. |
Removable Media Access FAQ
Can I block USB storage without disabling the keyboard and mouse?
Yes. Target removable-storage and transfer classes instead of disabling the complete USB controller.
Can users read files from USB but not copy files to it?
Yes. A policy can allow read access while denying write access. Test the exact media class and application behavior before wider deployment.
Should a whitelist use the drive letter?
No. Drive letters can change. Approved-device rules should identify the physical device or its stable identifiers rather than relying only on E:, F:, or another temporary letter.
Does device control encrypt files on the USB drive?
No. Device control governs access on the managed PC. Use USB encryption as a separate layer when authorized files must remain protected after the drive leaves the computer.
Can a trusted USB list be reused on other computers?
GiliSoft USB Lock can export a whitelist and import it on other managed Windows computers, which is useful when the same approved drives are used across a team.
Sources and Further Reading
Keep approved media working and restrict the rest
Use GiliSoft USB Lock to control removable storage, trusted USB drives, phones, optical media, and other transfer channels on Windows PCs.