| GR-PO-SEC-C-Enable USB Storage | |
| Data collected on: 2-9-2025 08:59:25 | |
| Domain | emea.tpg.ads |
| Owner | EMEA\tentolouris.5 |
| Created | 8-9-2016 12:04:18 |
| Modified | 27-1-2025 14:16:44 |
| User Revisions | 0 (AD), 0 (SYSVOL) |
| Computer Revisions | 58 (AD), 58 (SYSVOL) |
| Unique ID | {3a3d9701-15c6-4755-ab02-1b06421d56bf} |
| GPO Status | Enabled |
| Location | Enforced | Link Status | Path |
|---|---|---|---|
| Clients | Yes | Enabled | emea.tpg.ads/GR/Systems/Clients |
| Name |
|---|
| EMEA\GR-L-SEC-Usb Storage Devices ENABLE |
| Name | Allowed Permissions | Inherited |
|---|---|---|
| EMEA\Domain Admins | Edit settings, delete, modify security | No |
| EMEA\Domain Computers | Read | No |
| EMEA\GR-G-ORG-OU Admins | Edit settings, delete, modify security | No |
| EMEA\GR-L-SEC-Usb Storage Devices ENABLE | Read (from Security Filtering) | No |
| EMEA\tentolouris.5 | Edit settings, delete, modify security | No |
| NT AUTHORITY\Authenticated Users | Read | No |
| NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS | Read | No |
| NT AUTHORITY\SYSTEM | Edit settings, delete, modify security | No |
| ROOT\Enterprise Admins | Edit settings, delete, modify security | No |
| Policy | Setting |
|---|---|
| Devices: Allowed to format and eject removable media | Administrators and Interactive Users |
| Devices: Restrict CD-ROM access to locally logged-on user only | Disabled |
| Owner |
| Type | Name | Permission | Apply To |
|---|---|---|---|
| Allow | APPLICATION PACKAGE AUTHORITY\ALL APPLICATION PACKAGES | Read and Execute | This folder, subfolders and files |
| Allow | CREATOR OWNER | Full Control | This folder, subfolders and files |
| Allow | NT AUTHORITY\SYSTEM | Full Control | This folder, subfolders and files |
| Allow | BUILTIN\Administrators | Full Control | This folder, subfolders and files |
| Allow | BUILTIN\Users | Read and Execute | This folder, subfolders and files |
| Allow inheritable permissions from the parent to propagate to this object and all child objects | Disabled |
| Owner |
| Type | Name | Permission | Apply To |
|---|---|---|---|
| Allow | APPLICATION PACKAGE AUTHORITY\ALL APPLICATION PACKAGES | Read and Execute | This folder, subfolders and files |
| Allow | CREATOR OWNER | Full Control | This folder, subfolders and files |
| Allow | NT AUTHORITY\SYSTEM | Full Control | This folder, subfolders and files |
| Allow | BUILTIN\Administrators | Full Control | This folder, subfolders and files |
| Allow | BUILTIN\Users | Read and Execute | This folder, subfolders and files |
| Allow inheritable permissions from the parent to propagate to this object and all child objects | Disabled |
| Policy | Setting | Comment |
|---|---|---|
| All Removable Storage classes: Deny all access | Disabled | |
| All Removable Storage: Allow direct access in remote sessions | Enabled | |
| CD and DVD: Deny execute access | Disabled | |
| CD and DVD: Deny read access | Disabled | |
| CD and DVD: Deny write access | Disabled | |
| Removable Disks: Deny execute access | Disabled | |
| Removable Disks: Deny read access | Disabled | |
| Removable Disks: Deny write access | Disabled | |
| WPD Devices: Deny read access | Disabled | |
| WPD Devices: Deny write access | Disabled |
| Action | Update |
| Source file(s) | \\grkalfs01\netconfigfiles\GlobalSettings\USBdenyallreset.bat |
| Destination file | C:\TPSTUF\USBdenyallreset.bat |
| Suppress errors on individual file actions | Disabled |
| Read-only | Disabled |
| Hidden | Disabled |
| Archive | Enabled |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Update |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SYSTEM\CurrentControlSet\services\USBSTOR |
| Value name | Start |
| Value type | REG_DWORD |
| Value data | 0x3 (3) |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |
| Action | Update |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SOFTWARE\Policies\Microsoft\Windows\RemovableStorageDevices |
| Value name | Deny_All |
| Value type | REG_DWORD |
| Value data | 0x0 (0) |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |