How to block USB devices in Mac from Intune.

Omkar Parthe 20 Reputation points
2024-03-11T12:19:49.4066667+00:00

Hi tried to block USB devices from Intune was creating the policy and getting the below error.

MAC Usb policy .png

Microsoft Intune Security
Microsoft Intune Security
Microsoft Intune: A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.Security: The precautions taken to guard against crime, attack, sabotage, espionage, or another threat.
339 questions
Microsoft Intune Configuration
Microsoft Intune Configuration
Microsoft Intune: A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.Configuration: The process of arranging or setting up computer systems, hardware, or software.
1,725 questions
0 comments No comments
{count} votes

Accepted answer
  1. ZhoumingDuan-MSFT 8,060 Reputation points Microsoft Vendor
    2024-03-12T01:55:34.4033333+00:00

    @Omkar Parthe, Thanks for posting in Q&A.

    From your description, I know you want to block USB devices in Mac from Intune policy.

    Based on my research, we can create a device control policy for mac to block USB devices.

    Here are some links you can refer.

    https://learn.microsoft.com/en-us/microsoft-365/security/defender-endpoint/mac-device-control-intune?view=o365-worldwide

    https://github.com/MicrosoftDocs/microsoft-365-docs/blob/8f06eeece74af5c98ab0b453d821ed0b0161f998/microsoft-365/security/defender-endpoint/mac-device-control-intune.md

    Non-official, just for reference.

    https://learn.microsoft.com/en-us/microsoft-365/security/defender-endpoint/mac-device-control-overview?view=o365-worldwide

    Hope above information can help you.

    If the answer is helpful, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment".

    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.

    1 person found this answer helpful.

1 additional answer

Sort by: Most helpful
  1. glebgreenspan 1,290 Reputation points
    2024-03-11T14:31:48.0533333+00:00

    Hello Omkar

    Here is step for your request

    1.     Sign in to the Microsoft Endpoint Manager admin center (https://endpoint.microsoft.com/).

    2.     In the admin center, navigate to "Devices" and select "Configuration profiles."

    3.     Click on "Create profile" and choose the platform as macOS.

    4.     Under the settings catalog, select "Device restrictions."

    5.     Click on "USB device restrictions" to configure the settings related to USB devices.

    6.     To block USB devices, you can set the policy to disable USB storage devices and other USB devices based on your organization's requirements.

    7.     Once you have configured the USB device restrictions settings as desired, click on "Create" to create the Device Configuration profile.

    8.     Assign the newly created profile to the desired user group or device group by clicking on "Assignments" and selecting the appropriate assignment type.

    9.     After assigning the profile, the restrictions will be enforced on the Mac devices within the targeted group, effectively blocking USB devices according to the configured policy.