Approved USB Network Adapter Guide

USB Network Adapter Whitelist for Windows

Keep company-approved USB Wi-Fi and Ethernet adapters working while unknown USB network devices remain unavailable on managed Windows PCs.

  • Register adapters by the displayed device identity
  • Apply a default restriction to unknown hardware
  • Review and remove obsolete whitelist entries
Select an approved USB network adapter for the USB Ethernet whitelist

Select the actual connected adapter before enabling the default restriction.

Allow Known USB Network Hardware, Not Every Adapter

A useful whitelist is based on reviewed physical devices, not a broad promise that every USB Wi-Fi or Ethernet adapter is safe. Record who owns each adapter, why it is required, and which Windows PCs may use it.

Quick answerConnect an approved adapter, open USB Ethernet Lock, click Add, select the correct adapter name, and confirm its USB Ethernet ID. Repeat for all approved hardware, enable Disable USB Ethernet, then test both listed and unlisted adapters.
InventoryRecord the adapter name, owner, business purpose, and assigned PC before approval.
RegisterAdd the connected device to the dedicated USB Ethernet whitelist.
VerifyTest a listed adapter, an unknown adapter, and every required built-in connection.

Decide Which USB Network Adapters to Approve

Your goalRecommended controlWhat remains available
Company-issued USB Ethernet adapterApprove after confirming its device identity and assigned userThe registered adapter remains available.
Temporary service adapterApprove only for the required support period, then remove itThe exception does not remain indefinitely.
Personal or unknown USB Wi-Fi dongleDo not add it to the whitelistThe default USB Ethernet restriction remains active.
Built-in Wi-Fi or EthernetConfirm separately during testingIt is not added as a USB Ethernet whitelist exception.
Create the allow list first
1

Prepare the USB Ethernet Whitelist

Register required adapters before the default restriction is switched on.

  1. List the USB Wi-Fi and Ethernet adapters that have an approved business use.
  2. Install and open GiliSoft USB Lock, then select USB Ethernet Lock.
  3. Connect one approved adapter at a time so its displayed name can be matched to the physical device.
  4. Do not enable Disable USB Ethernet until every required adapter has been registered.
The policy screen keeps the default restriction and approved-adapter list together. Click to enlarge.
Do not whitelist by name alone. Similar adapters can share a model description. Confirm that the selected entry appears for the physical device currently connected and retain its USB Ethernet ID for support records.

Add an Approved Adapter by Device Identity

GiliSoft USB Lock keeps network adapters in a separate USB Ethernet whitelist. This prevents a trusted storage device from being mistaken for an approved network connection.

  1. Connect the approved USB Wi-Fi or USB Ethernet adapter.
  2. Click Add under USB Ethernet Whitelist.
  3. Select the connected adapter and click OK.
  4. Confirm its name and USB Ethernet ID appear in the table, then label the physical adapter for the assigned user or PC.
The selection dialog lists currently detected USB network hardware. Add only the device being reviewed.
Activate the policy
2

Block USB Ethernet After Approved Devices Are Listed

Turn on the default restriction only after the initial whitelist has been checked.

  1. Review every row in the USB Ethernet whitelist and remove entries that were added only for testing.
  2. Select Disable USB Ethernet and save the policy.
  3. Reconnect a whitelisted adapter and confirm the expected network connection works.
  4. Connect a separate unlisted adapter and confirm it cannot provide another network connection.
Inventory approved hardware > Add each adapter > Enable USB Ethernet blocking > Test approved and unknown devices
Test locally first. Do not enable a new adapter restriction through the same USB network connection used to manage a remote PC.
Maintain the approved list
3

Review, Replace, and Remove Adapter Entries

A whitelist should describe current approved hardware, not every device that was ever connected.

Keep an external record of the adapter owner, department, approval reason, physical label, and USB Ethernet ID. When hardware is lost, reassigned, or replaced, remove the old entry and register the replacement as a new device.

Scheduled review

Compare the whitelist against the current hardware inventory and remove entries with no active owner or purpose.

Replacement hardware

Do not assume a replacement of the same model has the same identity. Connect and approve the new physical adapter separately.

A stale whitelist weakens the policy. Remove retired and missing devices promptly instead of leaving unused exceptions available.
Deploy with evidence
4

Record What Was Approved and Where It May Be Used

Device identity is useful only when administrators can connect it to a real owner and business purpose.

Minimum record

Keep the adapter name, USB Ethernet ID, physical asset label, assigned user or PC, and approval date.

Change control

Document additions and removals so another administrator can explain why each exception exists.

Do not treat the whitelist as network authorization. It controls whether the USB adapter is allowed on the PC. Firewall, Wi-Fi credentials, VPN, and network access policy still require their own controls.

Compare USB Network Adapter Approval Methods

MethodDefault blockApproved-device exceptionsAdministration
GiliSoft USB LockYes, for USB network adaptersDedicated USB Ethernet whitelistVisible policy and device list
Disable-NetAdapterOnly adapters selected by commandRequires separate scriptsPowerShell names and scripting
Device ManagerManual per-device actionNo whitelistLocal administrator work
PnPUtilBy instance or hardware IDRequires separate inventory logicCommand-line device management

Test the Whitelist Before Deployment

Approved adapter

Reconnect every listed device and confirm it receives only the network access intended for that PC.

Unknown adapter

Connect a separate unlisted USB Wi-Fi or Ethernet adapter and confirm the default restriction applies.

Required connections

Confirm built-in networking, docks, and unrelated USB peripherals still behave as intended.

A finished whitelist should contain only approved, identifiable adapters that still have an active purpose.

USB Network Adapter Whitelist FAQ

What is a USB network adapter whitelist?

It is a list of approved USB Wi-Fi and Ethernet adapters that remain available while unlisted USB network devices are restricted.

How does USB Lock identify an adapter?

The interface records the selected USB Ethernet name and ID shown for the connected physical device.

Should I add devices before enabling the block?

Yes. Register and verify required adapters first to avoid interrupting approved network access.

Is this the same as the USB storage whitelist?

No. USB network adapters are managed through the separate USB Ethernet whitelist.

Windows Network Adapter References

The Windows command behavior in this article was checked against Microsoft documentation. Microsoft notes that Disable-NetAdapter interrupts connectivity for the selected adapter, and PnPUtil device actions require administrators to identify the intended device carefully.

Allow approved USB network adapters without opening access to every device

Use GiliSoft USB Lock to register company adapters, block unlisted USB network hardware, and maintain clear device exceptions.