Intune USB Block unable to reverse change

Kevin Halstead 26 Reputation points
2020-11-09T08:59:39.123+00:00

Hi,

We are having issues reverse a USB block to a device, we have a requirement for this user to use USB. We usually block all USB access on all devices.
We added the user and device to the exception for the device profile for USB blocking but the user is still unable to use USB.

We have identified it changes the following registry key:
HKLM\SOFTWARE\Microsoft\PolicyManager\current\device\System
Name: AllowStorageCard

We can set this and USB now works, however on reboot the settings reverse again again.

Is there anyway we can reverse this setting? I really do not want to have to rebuild the machine just for this?

Thanks.

Microsoft Intune Configuration
Microsoft Intune Configuration
Microsoft Intune: A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.Configuration: The process of arranging or setting up computer systems, hardware, or software.
1,728 questions
Microsoft Intune
Microsoft Intune
A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.
4,362 questions
{count} votes

6 answers

Sort by: Most helpful
  1. Mohamed Abdulmoez 6 Reputation points
    2023-10-26T06:57:19.34+00:00

    this happened to me yesterday. the solution depends on how you created the policy.

    For me I have created the policy as are follows:

    Endpoint Manager Intune portal https://endpoint.microsoft.com/

    • Select Devices > Windows > Configuration profiles > Create profile
    • In Create Profile, Select Platform, Windows 10, and later and Profile, Select Profile Type as Settings catalog. Click on Create button.
    • On the Basics tab, enter a descriptive name, such as Disable Removable Storage Write Access. Optionally, enter a Description for the policy, then select Next.
    • In Configuration settings, click Add settings to browse or search the catalog for the settings you want to configure.
    • On the Settings Picker windows, Select Storage to see all the settings in this category. Select Removable Disk Deny Write Access below. After adding your settings, click the cross mark at the right-hand corner to close the settings picker.
    • The setting is shown and configured with a default value Disabled. Set Removable Disk Deny Write Access to Enabled. Click Next.

    so, to reverse the change: I selected "Disable".

    and then I have created a new profile with "Removable Disk Deny Write Access" enabled, and selected a device group that I want to block USB from.

    and I have created another profile with "Removable Disk Deny Write Access" disabled for those I want to allow them to use USB.

    It is complicated, but it works!

    0 comments No comments