# Block USB Storage Group Policy: 5 Methods for Windows 11

Source: https://srvscripts.com/guides/block-usb-storage-group-policy-intune/
Updated: 2026-10-03
Publisher: srvScripts (https://srvscripts.com/)

A block USB storage Group Policy setup on Windows 11 and Windows Server 2025 uses two native tools: the Removable Storage Access policies, which deny read or write access to drives that are already installed, and the Device Installation Restrictions, which stop Windows from installing the device at all. This guide covers both, plus the USBSTOR registry value, BitLocker To Go and Intune, with an allow-list for approved drives and an exception for the IT team.

**Short answer:** Create a GPO linked to the workstation OU and enable `Computer Configuration » Policies » Administrative Templates » System » Removable Storage Access » "All Removable Storage classes: Deny all access"`. Run `gpupdate /force` and reconnect the drive: it appears but cannot be opened. For an allow-list of approved drives, use Device Installation Restrictions instead.

In short: Create a GPO linked to the workstation OU and enable Computer Configuration » Policies » Administrative Templates » System » Removable Storage Access » “All Removable Storage classes: Deny all access”.

## Which method to use

Each block USB storage Group Policy option works at a different layer. Removable Storage Access acts after the driver loads; Device Installation Restrictions act before it, so the device never gets a drive letter.

| Method | What it blocks | Scope | Pros | Cons |
| --- | --- | --- | --- | --- |
| Removable Storage Access (GPO) | Read, write or all access per storage class (disks, CD/DVD, WPD phones, floppy, tape) | Computer or user | Simple; no device IDs; per-user exceptions | No per-device allow-list |
| Device Installation Restrictions (GPO) | Device installation by class GUID, device ID or instance ID | Computer | Allow-list by model or serial number | Can lock out hubs, keyboards or disks if misconfigured |
| USBSTOR Start=4 via GPP | The USB mass storage driver (USBSTOR) | Computer | Works on any edition, one registry value | Misses UAS drives and phones; no allow-list; persists |
| BitLocker To Go write protection | Writes to removable drives not protected by BitLocker | Computer | Encrypted company drives stay usable | Reading still allowed |
| Intune (Device control / Settings catalog) | Same settings as the GPOs, plus Defender device control rules | Device or user | Covers cloud-only devices | Defender rules need a licence; no servers |

For most domains, the best combination is Removable Storage Access to deny everything by default, plus Device Installation Restrictions only where a team needs specific approved drives.

## Prerequisites

- Windows 11 Pro, Enterprise or Education joined to the domain, or Windows Server 2016 to 2025. Windows 11 Home cannot process domain Group Policy.

- Rights to create and link GPOs, and the Group Policy Management Console.

- Current ADMX files in the Central Store (`\\contoso.com\SYSVOL\contoso.com\Policies\PolicyDefinitions`). The layered evaluation setting needs a recent `DeviceInstallation.admx`.

- A test OU with a spare flash drive, a USB phone and, for an allow-list, the approved drive model.

## Method 1: Removable Storage Access policies

This is the main block USB storage Group Policy method and the one we recommend starting with. Windows installs the device, then denies the access type you choose to that storage class.

### Computer vs user configuration

Each setting exists twice:

- `Computer Configuration » Policies » Administrative Templates » System » Removable Storage Access` applies to every user who signs in to the machine, including administrators.

- `User Configuration » Policies » Administrative Templates » System » Removable Storage Access` applies to the user wherever they sign in, and needs a GPO linked to the OU that holds the user accounts (or loopback processing on the computer OU).

Use the computer side for kiosks, shared PCs and servers. Use the user side when IT staff must keep USB access on the same machines, because user-side settings can be filtered per user group.

### Steps: deny all removable storage

- Open **Group Policy Management** (`gpmc.msc`), right-click the workstation OU and choose **Create a GPO in this domain, and Link it here**. Name it, for example, SEC – Block USB Storage.

- Edit the GPO and go to `Computer Configuration » Policies » Administrative Templates » System » Removable Storage Access`.

- Open **“All Removable Storage classes: Deny all access”**, set it to **Enabled** and click **OK**.

- On a test machine, run `gpupdate /force`, unplug the drive and plug it in again. Explorer shows the drive letter, but opening it returns an access denied error.

This single setting covers every class in the node, including WPD devices. It writes the value `Deny_All = 1` (REG_DWORD) under `HKLM\SOFTWARE\Policies\Microsoft\Windows\RemovableStorageDevices` (or the same path under HKCU for the user-side policy).

### Steps: deny read or write per class

If you want to allow reading but not writing, leave the “Deny all access” setting as **Not Configured** and enable the class settings instead:

| Policy setting | Blocks | Registry subkey under RemovableStorageDevices |
| --- | --- | --- |
| “Removable Disks: Deny read access” / “Removable Disks: Deny write access” | USB flash drives, external USB disks, SD cards presented as removable disks | {53f5630d-b6bf-11d0-94f2-00a0c91efb8b} |
| “CD and DVD: Deny read access” / “CD and DVD: Deny write access” | Internal and USB optical drives, including burning | {53f56308-b6bf-11d0-94f2-00a0c91efb8b} |
| “WPD Devices: Deny read access” / “WPD Devices: Deny write access” | Phones, tablets and media players connected over MTP/PTP | {6AC27878-A6FA-4155-BA85-F98F491D4F33} |
| “Floppy Drives: Deny read/write access” | Floppy drives, including USB floppy | {53f56311-b6bf-11d0-94f2-00a0c91efb8b} |
| “Tape Drives: Deny read/write access” | Tape drives | {53f5630b-b6bf-11d0-94f2-00a0c91efb8b} |

Each class subkey receives `Deny_Read = 1` or `Deny_Write = 1`. A common data-loss setup is “Removable Disks: Deny write access” plus “WPD Devices: Deny write access”: staff can still read files a vendor hands them, but cannot copy anything out.

Leave **“Set time (in seconds) to force reboot”** off unless you control the restart window: some access changes need a restart, and this setting forces one after the given delay. Drives mapped into Remote Desktop sessions are controlled by the RDP redirection settings, not by this node.

## Method 2: USBSTOR registry value via Group Policy Preferences

The USB mass storage driver is a service at `HKLM\SYSTEM\CurrentControlSet\Services\USBSTOR`. Its `Start` value is `3` (load on demand) by default; setting it to `4` (disabled) stops the driver from loading, so flash drives and most external disks get no drive letter.

- In the GPO, go to `Computer Configuration » Preferences » Windows Settings » Registry`, right-click and choose **New » Registry Item**.

- Set **Action** to Update, **Hive** to HKEY_LOCAL_MACHINE, **Key Path** to `SYSTEM\CurrentControlSet\Services\USBSTOR`, **Value name** to `Start`, **Value type** to REG_DWORD and **Value data** to `4` (decimal).

- Do **not** tick “Remove this item when it is no longer applied” on the Common tab. That option deletes the `Start` value when the GPO stops applying, which leaves the service without a start type.

The same change for a single machine, from an elevated prompt:

```
reg add "HKLM\SYSTEM\CurrentControlSet\Services\USBSTOR" /v Start /t REG_DWORD /d 4 /f
reg query "HKLM\SYSTEM\CurrentControlSet\Services\USBSTOR" /v Start
```

Limits you must accept with this method:

- USB Attached SCSI (UAS) drives, common for fast external SSDs, load the `UASPStor` driver instead of `USBSTOR` and are not blocked.

- Phones and cameras using MTP/PTP are not affected.

- It is a preference: the value stays after you unlink the GPO, and a local administrator can change it back. There is no allow-list.

Treat USBSTOR as an extra layer, not as your main block USB storage Group Policy control.

## Method 3: Device Installation Restrictions

These settings live in `Computer Configuration » Policies » Administrative Templates » System » Device Installation » Device Installation Restrictions` and write to `HKLM\SOFTWARE\Policies\Microsoft\Windows\DeviceInstall\Restrictions`. A block USB storage Group Policy built here stops the driver install, so a blocked device shows an error in Device Manager and gets no drive letter.

### The settings you will use

| Setting | Registry value | Matches |
| --- | --- | --- |
| “Prevent installation of devices using drivers that match these device setup classes” | DenyDeviceClasses | Setup class GUIDs |
| “Prevent installation of devices that match any of these device IDs” | DenyDeviceIDs | Hardware IDs and compatible IDs |
| “Prevent installation of devices that match any of these device instance IDs” | DenyInstanceIDs | One physical device (Windows 10 2004 and later) |
| “Prevent installation of removable devices” | n/a | Any device its bus driver reports as removable |
| “Allow installation of devices that match any of these device IDs” | AllowDeviceIDs | Hardware IDs and compatible IDs |
| “Allow installation of devices that match any of these device instance IDs” | AllowInstanceIDs | One physical device |
| “Apply layered order of evaluation for Allow and Prevent device installation policies across all device match criteria” | AllowDenyLayered | Changes precedence (see below) |

The Prevent settings have a checkbox named **“Also apply to matching devices that are already installed”**. With it ticked, Windows removes matching devices that are already present, not only new ones.

### Block USB storage by device ID

Blocking by compatible ID is the safest way to target USB mass storage without touching internal disks:

- Open **“Prevent installation of devices that match any of these device IDs”**, set it to **Enabled** and click **Show…**.

- Add `USBSTOR\Disk` and `USBSTOR\RAW` (compatible IDs that `usbstor.sys` reports for USB disks) and `USB\Class_08` (the USB mass storage interface class, which also catches UAS drives).

- Tick **“Also apply to matching devices that are already installed”** if drives were used before, then click **OK**.

### Block by setup class GUID

To block phones and media players at install time, add the WPD setup class `{eec5ad98-8080-425f-922a-dabf3de3f69a}` to **“Prevent installation of devices using drivers that match these device setup classes”**. Avoid the Disk drives class `{4d36e967-e325-11ce-bfc1-08002be10318}`: internal SATA and NVMe disks belong to it, and Microsoft warns that a retroactive block on all disk drives can cut access to the boot disk. Use the device ID method above instead.

### Allow-list approved drives

By default every Prevent setting wins over every Allow setting, so an allow entry cannot punch a hole in a broad block. Windows 11 (21H2 and later) and Windows Server 2022 and later support the setting **“Apply layered order of evaluation for Allow and Prevent device installation policies across all device match criteria”**. When enabled, more specific criteria win, in this order: device instance IDs, then device IDs, then device setup class, then removable devices.

- Plug the approved drive into a test PC and collect its IDs:

```
$d = Get-PnpDevice -PresentOnly | Where-Object InstanceId -like 'USBSTOR*'$d | Format-List FriendlyName, InstanceIdGet-PnpDeviceProperty -InstanceId $d[0].InstanceId -KeyName DEVPKEY_Device_HardwareIds | Select-Object -ExpandProperty Datapnputil /enum-devices /connected /class DiskDrive /ids
```

The instance ID ends with the drive’s serial number, so it matches one physical drive. The most detailed hardware ID (Microsoft’s example is `USBSTOR\DiskGeneric_Flash_Disk______8.07`) matches every drive of that model.

- Enable **“Apply layered order of evaluation for Allow and Prevent device installation policies across all device match criteria”**.

- Keep the Prevent entries from the previous section. If you added `USB\Class_08`, also allow the drive’s parent USB device (its instance ID starts with `USB\VID_`), because a blocked parent device hides everything below it in the device tree.

- Enable **“Allow installation of devices that match any of these device IDs”** and add the model hardware ID, or enable **“Allow installation of devices that match any of these device instance IDs”** and add each issued drive’s instance ID.

- Run `gpupdate /force`, plug in an approved drive and an unapproved one, and confirm only the approved drive installs.

Because instance IDs outrank device IDs, an allowed instance ID beats the `USBSTOR\Disk` prevent entry. Remember that Removable Storage Access applies after installation: if “All Removable Storage classes: Deny all access” is also enabled on the same machine, the approved drive installs but still cannot be opened. Use one approach per machine, or exclude the allow-list machines from the deny GPO.

### Keep keyboards and mice working

- Removable Storage Access and the storage device IDs above do not affect keyboards, mice, headsets or webcams.

- **“Prevent installation of removable devices”** blocks every new removable device, including a replacement USB keyboard or mouse. Avoid it unless you pair it with allow entries.

- Blocking the USB (`{36fc9e60-c465-11cf-8056-444553540000}`) or USBDevice (`{88BAE032-5A81-49f0-BC3D-A4FF138216D6}`) classes blocks hubs and host controllers, and everything connected below them. If you must, allow host controllers and hubs first (Microsoft’s example uses `PCI\CC_0C03`, `USB\ROOT_HUB30`, `USB\ROOT_HUB20` and `USB\USB20_HUB`).

- **“Allow administrators to override Device Installation Restriction policies”** lets members of the local Administrators group install and update drivers for any device through the Add Hardware and Update Driver wizards.

## Method 4: BitLocker To Go write protection

If staff need removable drives for legitimate work, allow only encrypted ones. Go to `Computer Configuration » Policies » Administrative Templates » Windows Components » BitLocker Drive Encryption » Removable Data Drives` and enable **“Deny write access to removable drives not protected by BitLocker”**. Unencrypted drives mount read-only; BitLocker-protected drives mount read-write. The setting writes `RDVDenyWriteAccess` under `HKLM\SYSTEM\CurrentControlSet\Policies\Microsoft\FVE`.

The option **“Deny write access to devices configured in another organization”** restricts writes to drives whose identification field matches your organisation. Set the field in **“Provide the unique identifiers for your organization”** under `BitLocker Drive Encryption`. Do not combine this method with “Removable Disks: Deny write access”, which would block the encrypted drives as well.

## Method 5: Intune equivalents

### Endpoint security Device control profile

- In the Intune admin center, go to **Endpoint security » Attack surface reduction » Create policy**, choose platform **Windows** and profile **Device Control**.

- The profile groups the Windows **Device Installation Restrictions** settings, **Removable Storage Access**, **Storage » Removable Disk Deny Write Access** and Defender device control rules.

- For Defender device control, add reusable settings groups for included and excluded devices (vendor ID, product ID, serial number or instance ID), then an Allow, Deny or Audit entry. **Default Enforcement** (`DefaultEnforcementAllow` or `DefaultEnforcementDeny`) applies when no rule matches.

Defender device control needs Defender for Endpoint Plan 1, Plan 2 or Defender for Business, runs on Windows 10 and Windows 11 only, and does not support servers. For Windows Server 2025, stay with Group Policy.

### Settings catalog

Without Defender licences, create **Devices » Configuration » Create » New policy » Windows 10 and later » Settings catalog** and search for:

- **Device Installation**: for example `PreventInstallationOfMatchingDeviceIDs`, `AllowInstallationOfMatchingDeviceInstanceIDs` and `EnableInstallationPolicyLayering`.

- **Administrative Templates » System » Removable Storage Access**: the same “Deny all access” and per-class settings as the GPO.

Assign to device groups, and use a separate excluded group for IT staff devices.

## Exceptions for IT and admin groups

A block USB storage Group Policy object has no per-setting exception, so exclude the whole GPO with security filtering.

- Create a security group such as SEC-USB-Exempt. For computer-side settings add **computer accounts**; for user-side settings add **user accounts**. A computer policy is evaluated against the computer account, so putting IT users in the group does not exempt a computer-side block.

- In GPMC, select the GPO, open the **Delegation** tab and click **Advanced**.

- Add the group, leave **Read** allowed and tick **Deny** for **Apply group policy**.

- Keep **Authenticated Users** with Read and Apply group policy so everyone else still receives the block.

- Restart members (computer groups) or have them sign in again (user groups).

A cleaner pattern for mixed desks is to put “All Removable Storage classes: Deny all access” in User Configuration, deny Apply to the IT user group, and keep only the Device Installation allow-list on the computer side.

## Verify it works

- Confirm the block USB storage Group Policy object applies:

```
gpupdate /forcegpresult /scope computer /rgpresult /h C:\Temp\gp-report.html
```

The GPO must be listed under Applied Group Policy Objects, not under filtered out.

- Check the policy registry keys:

```
reg query "HKLM\SOFTWARE\Policies\Microsoft\Windows\RemovableStorageDevices" /sreg query "HKCU\SOFTWARE\Policies\Microsoft\Windows\RemovableStorageDevices" /sreg query "HKLM\SOFTWARE\Policies\Microsoft\Windows\DeviceInstall\Restrictions" /s
```

You should see `Deny_All`, `Deny_Read` or `Deny_Write` set to 1, and values such as `DenyDeviceIDs`, `AllowInstanceIDs` and `AllowDenyLayered` with their list subkeys.

- Check the device state: `Get-PnpDevice -Class DiskDrive | Format-Table Status, FriendlyName, InstanceId`. A blocked drive shows a status other than OK.

- Read the logs. Enable **Audit PNP Activity** under `Advanced Audit Policy Configuration » System Audit Policies » Detailed Tracking`; Security event **6423** (“The installation of this device is forbidden by system policy”) then records each blocked device with its hardware and class IDs. The `Microsoft-Windows-Kernel-PnP/Configuration` log (event 400) shows devices that did configure, and `C:\Windows\INF\setupapi.dev.log` contains a Device Installation Restrictions Policy Check section for each install attempt.

## Troubleshooting

| Symptom | Likely cause | Fix |
| --- | --- | --- |
| Drive still opens after gpupdate | GPO linked to the user OU for a computer setting, or filtered out | Check gpresult /scope computer /r; link to the OU that holds the computer objects |
| Access policy set but mounted drive still writable | Change needs a re-plug or restart | Unplug and reconnect, or restart once |
| Fast external SSD not blocked by USBSTOR | Drive uses UAS (UASPStor) | Use Removable Storage Access or block USB\Class_08 |
| Phone can still copy photos | MTP is the WPD class, not removable disks | Enable “WPD Devices: Deny read/write access” or block class {eec5ad98-8080-425f-922a-dabf3de3f69a} |
| Approved drive blocked | Layered evaluation off, or Deny all access still applies | Enable the layered setting; exclude the machine from the access GPO |
| New keyboard or mouse will not install | “Prevent installation of removable devices” or USB class block | Disable it, or allow hubs and HID IDs with layered evaluation |
| IT staff also blocked | Deny ACE on a user group for a computer-side setting | Use a computer group, or move the block to User Configuration |

If the block USB storage Group Policy object does not appear in `gpresult` at all, check replication, security filtering, WMI filters and events 1058/1030 first.

## Roll back or undo

- **Removable Storage Access and Device Installation Restrictions:** set each setting to **Not Configured** (or unlink the GPO), then run `gpupdate /force`. The policy values under `SOFTWARE\Policies` are removed on the next refresh.

- **Devices removed retroactively:** after the restriction is gone, reconnect the device or rescan with `pnputil /scan-devices`.

- **USBSTOR:** change the GPP item’s value to `3` and let it apply before you delete the item, or on one machine run `reg add "HKLM\SYSTEM\CurrentControlSet\Services\USBSTOR" /v Start /t REG_DWORD /d 3 /f`.

- **BitLocker To Go:** set “Deny write access to removable drives not protected by BitLocker” to Not Configured; drives mount read-write after re-plugging.

- **Intune:** unassign or delete the profile and sync the device. If a device keeps the block, assign a profile that sets the same settings to Disabled.

Roll out any block USB storage Group Policy change to a pilot OU first, keep one exempt admin workstation per site, and document the allow-list so the service desk can add new drives.

## Block USB storage Group Policy at a glance

**Official documentation:** [Manage device installation with Group Policy](https://learn.microsoft.com/en-us/windows/client-management/client-tools/manage-device-installation-with-group-policy), [ADMX_RemovableStorage Policy CSP](https://learn.microsoft.com/en-us/windows/client-management/mdm/policy-csp-admx-removablestorage), [Device control in Microsoft Defender for Endpoint](https://learn.microsoft.com/en-us/defender-endpoint/device-control-overview).

**Related guides:** [Disable RDP Drive Redirection with GPO: Secure Clipboard and USB](/guides/disable-rdp-drive-redirection-gpo/) · [Troubleshoot Group Policy not applying: gpresult, RSoP and Events 1058/1030](/guides/group-policy-not-applying/) · [Group Policy loopback processing: merge vs replace for RDS hosts and kiosks](/guides/group-policy-loopback-processing/).

## Frequently asked questions

### Does blocking USB storage with Group Policy also block USB keyboards and mice?

No. The Removable Storage Access policies and the USB storage device IDs only affect storage classes. Keyboards and mice are only at risk if you enable “Prevent installation of removable devices” or block the USB hub and USBDevice setup classes.

### Should I use the computer or user Removable Storage Access policy?

Use Computer Configuration for kiosks, shared PCs and servers, because it applies to everyone who signs in. Use User Configuration when IT staff need USB access on the same machines, because user-side settings can be excluded per user group with security filtering.

### How do I allow one approved USB drive when everything else is blocked?

Block USB storage with “Prevent installation of devices that match any of these device IDs”, enable “Apply layered order of evaluation for Allow and Prevent device installation policies across all device match criteria”, then add the approved drive’s instance ID or hardware ID to the matching Allow policy.

### Is setting USBSTOR Start to 4 enough to block USB drives?

Not on its own. It stops the USBSTOR driver only, so UAS drives that use UASPStor and MTP phones still work, and the value stays after the GPO is removed. Use it as an extra layer next to the policy settings.

### Can I block USB storage on Windows Server 2025 with Intune device control?

Defender device control does not support servers. On Windows Server 2025, use the Group Policy Removable Storage Access and Device Installation Restrictions settings instead.
