Procedure
- Go to .
- Select a desktop or server group.
- Click Configure Policy.The Configure Policy: <group name> screen appears.
- Click Device Control.
- Update the following as required:
-
Enable Device Control
-
Enable USB Autorun Prevention
-
Permissions: Set for both USB devices and network resources.
Device Control Permissions
PermissionsFiles on the DeviceIncoming FilesFull accessPermitted operations: Copy, Move, Open, Save, Delete, ExecutePermitted operations: Save, Move, CopyThis means that a file can be saved, moved, and copied to the device.No accessProhibited operations: All operationsThe device and the files it contains are visible to the user (for example, from Windows Explorer).Prohibited operations: Save, Move, CopyReadPermitted operations: Copy, OpenProhibited operations: Save, Move, Delete, ExecuteProhibited operations: Save, Move, CopyModifyPermitted operations: Copy, Move, Open, Save, DeleteProhibited operations: ExecutePermitted operations: Save, Move, CopyRead and executePermitted operations: Copy, Open, ExecuteProhibited operations: Save, Move, DeleteProhibited operations: Save, Move, Copy -
Exceptions: If a user is not given read permission for a particular device, the user will still be allowed to run or open any file or program in the Approved List.However, if AutoRun prevention is enabled, even if a file is included in the Approved List, it will still not be allowed to run.To add an exception to the Approved List, enter the file name including the path or the digital signature and click Add to the Approved List.
-
- Click Save.