Allow Installation of a Device by Device Setup Class
Applies To: Windows Server 2008
You can use this procedure to create a list of devices that users are allowed to install. The allowed devices are identified by the device setup class assigned to them by the manufacturer and referenced in the device driver package's .inf file.
This policy setting only has affect when the Prevent installation of devices not described by other policy settings policy setting is enabled. See Prevent Installation of All Devices By Default.
Membership in the local Administrators group, or equivalent, is the minimum required to complete this procedure.
To allow installation of a device by device setup class
Open the Group Policy Management Editor. To do so, click Start, and then in the Start Search box, type
In the navigation pane, open the following folders: Local Computer Policy, Computer Configuration, Administrative Templates, System, Device Installation, and Device Installation Restrictions.
In the details pane, double-click Allow installation of devices that match any of these device setup classes.
Click Enabled, and then click Show.
In the Show Contents dialog box, click Add.
In the Add Item dialog box, type the GUID for the device setup class that applies to your device. Ensure that you include the curly brace characters on either side of the value.
Click OK to save your changes. You can repeat steps 5 and 6 for other devices.
Click OK to save the completed list, and then click OK to save the policy setting.
To determine the device setup class GUID for your device, see Determine the Device Setup Class for Your Device, or for a list of system defined setup classes, see "System-Supplied Device Setup Classes" at http://go.microsoft.com/fwlink/?LinkId=82268.
This setting does not take precedence over any of the policy settings that would prevent this device from being installed.
These policy settings affect all devices, even if the device driver is staged in the driver store. This is different from the policy setting described in Allow Standard Users to Install Drivers For Devices from Specified Setup Classes, which controls whether or not a user can place a device driver package in the driver store. The policy settings in this topic work by allowing (or preventing) the Plug and Play system to enumerate and construct the necessary memory structures for the device to operate.
If you edit policy settings locally on a computer, you will affect the settings on only that one computer. If you configure the settings in a Group Policy object (GPO) hosted in an Active Directory domain, then the settings apply to all computers that are subject to that GPO. For more information about Group Policy in an Active Directory domain, see Group Policy (http://go.microsoft.com/fwlink/?LinkId=55625).