GiliSoft USB Lock User Guide

How to block USB devices and allow trusted drives on Windows

Control USB storage, SD cards, phone data transfer, CD/DVD media, and other endpoint channels. Block unknown devices, prevent copying to removable drives, keep approved company USB drives available, and review policy events from one Windows tool.

USB read and write controlTrusted-device whitelistPhone and media restrictionsActivity logs and alerts
Home > How to Use > USB Lock

Choose the USB control task you need

Choose the USB policy that matches the job

Block read and write

Use this when unknown removable storage must not be opened or used for file transfer.

Block write only

Allow users to read approved material while preventing files from being copied from the PC to USB storage.

Whitelist trusted devices

Keep approved company USB drives working while unknown or personal removable devices remain restricted.

For most company deployments, combine a default block policy with a trusted-device whitelist instead of manually opening USB access whenever an approved drive is needed.

Part 1: Set up USB Lock and apply the core policy

Install and create the administrator password

  • Install GiliSoft USB Lock with administrator permission.
  • Create the master password used to change device-control policies.
  • Add a recovery email before deploying restrictions.
  • Confirm the protection service is running.

Prepare a safe first test

  • Keep one approved USB drive available for whitelist testing.
  • Close files currently open from removable media.
  • Start with one test computer before repeating the policy elsewhere.
  • Record the administrator and recovery information securely.

1. Configure USB storage and transfer rules

Use USB & CD Lock to control the main removable-media channels on the Windows PC.

1Open USB Lock and choose the USB and CD control section.
2Disable USB writing when users may read approved drives but must not copy company files out.
3Disable USB reading when unknown storage must not open on the PC.
4Apply the required SD card and phone data-transfer restrictions.

2. Add approved USB drives to the whitelist

Whitelist known company devices so they remain available while the default restriction continues to block unknown storage.

1Insert an approved USB drive.
2Open the trusted-device list and click Add.
3Repeat the process for every approved company drive.
4Export the completed whitelist and import it on other managed computers when needed.
For a focused multi-PC walkthrough, see USB Lock whitelisting instructions.

Part 2: Control phones, SD cards, CD/DVD media, and other devices

Apply the device controls required by the PC

USB Lock can extend the removable-media policy beyond ordinary flash drives.

1Restrict SD card and card-reader access where removable camera media is not approved.
2Block Android or iPhone data transfer while leaving ordinary charging behavior available where supported.
3Disable CD/DVD reading or disc burning according to the workstation policy.
4Review printer, Bluetooth, infrared, modem, COM/LPT, and 1394 controls only when those channels matter.

CD/DVD reading and burning

Control whether users can read optical media or write files to recordable discs. Apply only the restrictions required for that workstation.

Printers and other endpoint ports

Use the additional device controls for printers, Bluetooth, modem, COM/LPT, infrared, and 1394 channels when removable-media policy must cover more than USB storage.

Part 3: Review activity and protect administrator settings

Review allowed, blocked, and whitelist events

Use the logs to understand when a device was connected and how the current policy handled it.

1Open the activity or monitoring section.
2Filter for denied USB access, allowed trusted devices, and policy changes.
3Record the time, device, user context, and result when an event needs investigation.
4Export or retain logs according to the organization's support process.

Configure self-protection and alarm notifications

Protect the policy from casual changes and make repeated unauthorized access attempts easier to notice.

1Open the security or self-protection settings.
2Enable the appropriate password and policy protection options.
3Configure alarm email notifications where administrators need them.
4Test the alert process without exposing the administrator password.

Recover or change the administrator password

Set the recovery email before the password is lost, then use the supported recovery process when administrator access is needed.

1Confirm a valid recovery email is configured.
2Use the password recovery option from the USB Lock login interface.
3Complete the recovery steps sent to the authorized email address.
4Create a new administrator password and store it securely.

Additional endpoint controls

Website and network restrictions

Block selected websites and manage IP or network-adapter changes when the workstation policy also covers network access.

Program blocking

Restrict selected programs from running on shared or managed Windows PCs when application use is part of the same endpoint policy.

Allow only approved encrypted USB drives

Use trusted-device rules when approved encrypted company USB drives should remain available while other removable storage stays blocked. Add each approved device to the whitelist and test it under the active policy.

Keep the USB policy understandable

Enable only the endpoint controls the organization actually uses. A focused USB, whitelist, phone, media, and logging policy is easier to test and support than an unexplained blanket configuration.

USB Lock troubleshooting

An approved USB drive is still blocked

  • Confirm the correct physical device was added to the whitelist.
  • Reconnect the drive after the policy is saved.
  • Check whether read access, write access, or both are restricted.
  • Review the activity log for the exact deny event.

A phone charges but cannot transfer files

  • This can be expected when phone data access is blocked.
  • Check the Android/iPhone transfer policy separately from charging.
  • Reconnect the phone after changing the rule.
  • Review the log to confirm which policy was applied.

An imported whitelist does not work

  • Confirm the list was exported after all devices were added.
  • Import it with administrator permission.
  • Save or apply the policy before testing.
  • Compare the imported device identity with the connected USB drive.

The administrator password is unavailable

  • Use the configured recovery email process.
  • Check that the protection service is running normally.
  • Do not uninstall or alter policy files as a recovery shortcut.
  • Contact GiliSoft support when authorized recovery cannot be completed.

USB Lock FAQ

Can I block copying files to USB without blocking reading?

Yes. Disable USB writing while leaving the permitted read behavior available.

Can approved company USB drives remain usable?

Yes. Add them to the trusted-device whitelist while unknown removable devices stay restricted.

Can I export and import the whitelist?

Yes. Build the list on one PC, export it, and import it on other managed computers.

Can USB Lock control phone data transfer?

Yes. Android and iPhone data access can be restricted separately from ordinary USB storage policy.

Can I review blocked USB attempts?

Yes. Activity logs help administrators review denied access, allowed trusted devices, and policy events.

Can CD/DVD reading and burning be controlled?

Yes. Optical-media reading and disc-burning restrictions can be applied according to the workstation policy.

More USB control guides

Control removable devices without blocking approved work

Apply USB read and write rules, keep trusted company drives available, restrict phone and media channels, and review device activity from one Windows policy tool.

View GiliSoft USB Lock