Forums on Intune, SCCM, and Windows 11

Welcome to the forums. Register a free account today to become a member! Once signed in, you'll be able to participate on this site by adding your topics and posts, as well as connect with other members through your own private inbox!

PENDING intune - allow list usb in a surface reduction policy- allow list not working

  • Thread starter Thread starter berta87
  • Start date Start date
  • Replies Replies 3
  • Views Views 2K

berta87

New Member
Messages
3
Reaction score
0
Points
1
Hi all,
we have deployed a new surface attack reduction policy to block all removable media storage.
we have to allow some kind of usb device.
the allowlist is not working, alla device are denied?
any suggestions?

thanks

Davide
 
1671106407673.png



the policy is under attack surface reduction.
we have to block all type of device mass storage and allow few USB pendrives or hdd, or other few devices.
the policy is blocking all type of mass storage device and it's correct
for test we allow only 1 pen drive ( device id, device instance path, setup class) butit seems not working the allowlist.
can u help me?
 
When I utilise the Allow and Block lists in the same profile, I always have issues with Intune. Sometimes Intune will advise that the only choice to take effect is to Allow or Block.
Have you tried GPO in Intune?
1671199752378.png
 

Forum statistics

Threads
7,135
Messages
27,868
Members
18,159
Latest member
jordysmits
Back
Top