Group Policy Management
body { font-size:68%;font-family:MS Shell Dlg; margin:0px,0px,0px,0px; border: 1px solid #666666; background:#F6F6F6; width:100%; word-break:normal; word-wrap:break-word; } .head { font-weight:bold; font-size:160%; font-family:MS Shell Dlg; width:100%; color:#6587DC; background:#E3EAF9; border:1px solid #5582D2; padding-left:8px; height:24px; } .path { margin-left: 10px; margin-top: 10px; margin-bottom:5px;width:100%; } .info { padding-left:10px;width:100%; } table { font-size:100%; width:100%; border:1px solid #999999; } th { border-bottom:1px solid #999999; text-align:left; padding-left:10px; height:24px; } td { background:#FFFFFF; padding-left:10px; padding-bottom:10px; padding-top:10px; } .btn { width:100%; text-align:right; margin-top:16px; } .hdr { font-weight:bold; border:1px solid #999999; text-align:left; padding-top: 4px; padding-left:10px; height:24px; margin-bottom:-1px; width:100%; } .bdy { width:100%; height:182px; display:block; overflow:scroll; z-index:2; background:#FFFFFF; padding-left:10px; padding-bottom:10px; padding-top:10px; border:1px solid #999999; } button { width:6.9em; height:2.1em; font-size:100%; font-family:MS Shell Dlg; margin-right:15px; } @media print { .bdy { display:block; overflow:visible; } button { display:none; } .head { color:#000000; background:#FFFFFF; border:1px solid #000000; } }
Setting Path:
Explanation
No explanation is available for this setting.
Supported On:
Not available
RU-PO-WIN-C-USB Block
Data collected on: 2-9-2025 08:50:49
General
Details
Domainemea.tpg.ads
OwnerEMEA\efimov.6
Created14-4-2014 09:18:20
Modified19-3-2025 09:54:56
User Revisions50 (AD), 50 (SYSVOL)
Computer Revisions100 (AD), 100 (SYSVOL)
Unique ID{b24c176e-21a9-468a-973b-82cccbe011b4}
GPO StatusUser settings disabled
Links
LocationEnforcedLink StatusPath
AHANoEnabledemea.tpg.ads/RU/Systems/Clients/AHA
Managers WorkstationsNoEnabledemea.tpg.ads/RU/Systems/Clients/KZN/Managers Workstations
Operators WorkstationsNoEnabledemea.tpg.ads/RU/Systems/Clients/KZN/Operators Workstations
Operators WorkstationsNoEnabledemea.tpg.ads/RU/Systems/Clients/MOS/Operators Workstations
Managers WorkstationsNoEnabledemea.tpg.ads/RU/Systems/Clients/REN/Managers Workstations
Operators WorkstationsNoEnabledemea.tpg.ads/RU/Systems/Clients/REN/Operators Workstations
Operators WorkstationsNoEnabledemea.tpg.ads/RU/Systems/Clients/RND/Operators Workstations
Managers WorkstationsNoEnabledemea.tpg.ads/RU/Systems/Clients/TOI/Managers Workstations
Operators WorkstationsNoEnabledemea.tpg.ads/RU/Systems/Clients/TOI/Operators Workstations
Managers WorkstationsNoEnabledemea.tpg.ads/RU/Systems/Clients/TTI/Managers Workstations
Operators WorkstationsNoEnabledemea.tpg.ads/RU/Systems/Clients/TTI/Operators Workstations
Managers WorkstationsNoEnabledemea.tpg.ads/RU/Systems/Clients/VGG/Managers Workstations
Operators WorkstationsNoEnabledemea.tpg.ads/RU/Systems/Clients/VGG/Operators Workstations
Managers WorkstationsNoEnabledemea.tpg.ads/RU/Systems/Clients/VLD/Managers Workstations
Operators WorkstationsNoEnabledemea.tpg.ads/RU/Systems/Clients/VLD/Operators Workstations
Managers WorkstationsNoEnabledemea.tpg.ads/RU/Systems/Clients/VOG/Managers Workstations
Operators WorkstationsNoEnabledemea.tpg.ads/RU/Systems/Clients/VOG/Operators Workstations

This list only includes links in the domain of the GPO.
Security Filtering
The settings in this GPO can only apply to the following groups, users, and computers:
Name
EMEA\Domain Computers
Delegation
These groups and users have the specified permission for this GPO
NameAllowed PermissionsInherited
EMEA\Domain AdminsEdit settings, delete, modify securityNo
EMEA\Domain ComputersRead (from Security Filtering)No
EMEA\efimov.6Edit settings, delete, modify securityNo
EMEA\RU-L-SEC-Delegation Group Policy Objects Modify AccessEdit settings, delete, modify securityNo
NT AUTHORITY\Authenticated UsersReadNo
NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERSReadNo
NT AUTHORITY\SYSTEMEdit settings, delete, modify securityNo
ROOT\Enterprise AdminsEdit settings, delete, modify securityNo
Computer Configuration (Enabled)
Policies
Administrative Templates
Policy definitions (ADMX files) retrieved from the central store.
System/Device Installation/Device Installation Restrictions
PolicySettingComment
Allow administrators to override Device Installation Restriction policiesEnabled
Allow installation of devices that match any of these device IDsEnabled
Allow installation of devices that match any of these Device IDs:
USB\VID_0951&PID_1656&REV_0110
USB\Class_03
USB\Class_01
USB\Class_02
USB\Class_04
USB\Class_05
USB\Class_06
USB\Class_07
USB\Class_09
GenDisk
USB\Class_0a
USB\Class_0b
USB\Class_0d
USB\Class_0e
USB\Class_0f
USB\Class_10
USB\Class_11
USB\Class_e0
USB\VID_04C5&PID_2028
USB\VID_0781&PID_5576
USB\VID_046D&PID_0848
USB\VID_1C4F&PID_0026
USB\VID_0951&PID_1666
USB\VID_046D&PID_C31C
USB\VID_04D9&PID_1603
HID\VID_046D&PID_C315
USB\VID_04D9&PID_1702
USB\VID_0951&PID_1643\001CC07CEAD9FAC02925130A
USB\VID_0951&PID_1642\001CC0EC3509BAA105FA0049
USB\VID_0930&PID_6544\001CC0C61232C0A0C4250764
USB\VID_0930&PID_6544\0014780D8CF1C0B0354463AC
USB\VID_0930&PID_6544\001CC0C440A7C021341E074D
USB\VID_125F&PID_C82A\8791b207bca4a6
USB\VID_8564&PID_1000\T2O1SMRI
USB\VID_8564&PID_1000\99KG0Z76
USB\VID_0930&PID_6544
USB\VID_8564&PID_1000
USB\VID_0951&PID_1643
USB\VID_125F&PID_C82A
USB\VID_0951&PID_1642
USB\VID_0A89&PID_0030&REV_0100
SCFILTER\CID_5275746f6b656e20445320
HDAUDIO\FUNC_01&VEN_10EC&DEV_0887&SUBSYS_10438576&REV_1003
PCI\VEN_8086&DEV_8C22&SUBSYS_85341043&REV_05
STORAGE\Volume
Root\Spaceport
MONITOR\PHLC0B1
vms_mp
*VMWVAUDIOIN
tapoas
MMDEVAPI\AudioEndpoints
{990a2bd7-e738-46c7-b26f-1cf8fb9f1391}
SCFILTER\CID_8073c021c057597562694b6579
PCI\VEN_5853&DEV_1003
root\vbdenum
To create a list of devices, click Show. In the Show Contents dialog box, in the Value column,
type a Plug and Play hardware ID or compatible ID
(for example, gendisk, USB\COMPOSITE, USB\Class_ff).
PolicySettingComment
Allow installation of devices using drivers that match these device setup classesEnabled
Allow installation of devices using drivers for these device classes:
{4d36e96f-e325-11ce-bfc1-08002be10318}
{4d36e96b-e325-11ce-bfc1-08002be10318}
{1ed2bbf9-11f0-4084-b21f-ad83a8e6dcdc}
{36fc9e60-c465-11cf-8056-444553540000}
{4d36e968-e325-11ce-bfc1-08002be10318}
{c166523c-fe0c-4a94-a586-f1a80cfbbf3e}
{745a17a0-74d3-11d0-b6fe-00a0c90f57da}
{50dd5230-ba8a-11d1-bf5d-0000f805f530}
{990a2bd7-e738-46c7-b26f-1cf8fb9f1391}
{4d36e967-e325-11ce-bfc1-08002be10318}
{06d10322-7de0-4cef-8e25-197d0e7442e2}
{eec5ad98-8080-425f-922a-dabf3de3f69a}
{4d36e97b-e325-11ce-bfc1-08002be10318}
{4d36e96a-e325-11ce-bfc1-08002be10318}
{4d36e96c-e325-11ce-bfc1-08002be10318}
{4d36e972-e325-11ce-bfc1-08002be10318}
To create a list of device classes, click Show. In the Show Contents dialog box, in the Value column,
type a GUID that represents a device setup class
(for example, {25DBCE51-6C8F-4A72-8A6D-B54C2B4FC835}).
PolicySettingComment
Display a custom message title when device installation is prevented by a policy settingEnabled
Enter the text you wish users to see (Max 63 chars)
Main TextTP Policy warning
PolicySettingComment
Display a custom message when installation is prevented by a policy settingEnabled
Enter the text you wish users to see (Max 128 chars)
Detail TextUSB device blocked by TP Policy
PolicySettingComment
Prevent installation of devices not described by other policy settingsEnabled
Prevent installation of devices that match any of these device IDsDisabled
Prevent installation of devices using drivers that match these device setup classesDisabled
Prevent installation of removable devicesDisabled
System/Removable Storage Access
PolicySettingComment
All Removable Storage classes: Deny all accessEnabled
CD and DVD: Deny execute accessEnabled
CD and DVD: Deny read accessEnabled
CD and DVD: Deny write accessEnabled
Floppy Drives: Deny execute accessEnabled
Floppy Drives: Deny read accessEnabled
Floppy Drives: Deny write accessEnabled
Removable Disks: Deny execute accessEnabled
Removable Disks: Deny read accessEnabled
Removable Disks: Deny write accessEnabled
Tape Drives: Deny execute accessEnabled
Tape Drives: Deny read accessEnabled
Tape Drives: Deny write accessEnabled
WPD Devices: Deny read accessEnabled
WPD Devices: Deny write accessEnabled
Preferences
Windows Settings
Registry
UpperFilters (Order: 1)
General
ActionDelete
Properties
HiveHKEY_LOCAL_MACHINE
Key pathSYSTEM\CurrentControlSet\Control\Class\{36fc9e60-c465-11cf-8056-444553540000}
Value nameUpperFilters
Lines
LineValue
1CsDeviceControl
Common
Options
Stop processing items on this extension if an error occurs on this itemNo
Apply once and do not reapplyNo
LowerFilters (Order: 2)
General
ActionDelete
Properties
HiveHKEY_LOCAL_MACHINE
Key pathSYSTEM\CurrentControlSet\Control\Class\{36fc9e60-c465-11cf-8056-444553540000}
Value nameLowerFilters
Lines
LineValue
1CsDeviceControl
Common
Options
Stop processing items on this extension if an error occurs on this itemNo
Apply once and do not reapplyNo
User Configuration (Disabled)
No settings defined.