Restrict USB Mass Storage Policy Issue

Bionic

Expert Member
Joined
Nov 15, 2009
Messages
1,075
Reaction score
105
Location
Deep in the valley, Midrand
Hi. We are trying to implement a policy to block USB removal storage on our domain. It works however it doesnt for our 3G cards. It seems the 3G cards need its built in storage to start its native application. According to our ISP, there is no workaround for this. I have even given them the PID to allow the device but it doesn't work. Has anyone implemented it successfully with 3G cards in the mix?
 
What's a 3G card?
One of those 3G/LTE USB sticks. The device has got mass storage on board which is typically read only. Some of them allow you to install an SD card and you get a flash drive for general use. This guy is trying to prevent people from plugging in any forms of mass storage because we now truly live in the age of the employee cannot be trusted one bit.
 
We abandoned group policy in favour of using a Endpoint Protection (AV + other stuff) to protect against disallowed USB mass storage

The last time I personally dealt with the Vodacom and MTN sticks you could pre-install the relevant client application to prevent the need to access the Mass Storage component to run the software
 
One of those 3G/LTE USB sticks. The device has got mass storage on board which is typically read only. Some of them allow you to install an SD card and you get a flash drive for general use. This guy is trying to prevent people from plugging in any forms of mass storage because we now truly live in the age of the employee cannot be trusted one bit.
Absolutely Paul. POPIA as well as DLP is the reason for this policy however the 3G card issue is now a show stopper
 
Absolutely Paul. POPIA as well as DLP is the reason for this policy however the 3G card issue is now a show stopper
It isn't about POPIA and you know it. This is why I am so glad I left SA... this crap can stay in SA and 'Murica
Good luck anyway, because you're not going to win this battle. Perhaps when you have no employees left and nobody wants to work for your little sweatshop then you shall reflect on your actions.
 
Another d00s baas... SA is full of them... As I said earlier, he needs good luck on his side because he won't have employees for long. People are over taking schitt from the boss, they will l
Easy there. Why so agro? seems you left SA based on a d00s baas or maybe you the d00s. Good riddens. We have a company and want to protect our data, its easy as that. Ever heard of zero trust policy???
 
Easy there. Why so agro? seems you left SA based on a d00s baas or maybe you the d00s. Good riddens. We have a company and want to protect our data, its easy as that. Ever heard of zero trust policy???
Good riddance indeed... it reinforces points made though.
Riddens... Its "riddance" my bra... Jy kan doen met 'n bietjie meer Engels lesse.

Data protection goes both ways, and clearly you've no clue about POPIA or GDPR either. I do know more than you though, because I sat through all those courses, twice.
What you are doing is trying to make for a very difficult working environment, block everything, and probably have a camera on each employee. Your L. Ron. Hubbard manual should tell you how to block these USB devices. The fact that you have the gall to ask this on a public forum is because you won't ask the professionals either, because you're going DIY here, saving lots of bucks because there's a new Mercedes you have your eye on.

TLDR? Ek ken jou soort, lank vir d0se soos jy gewerk...
 
We abandoned group policy in favour of using a Endpoint Protection (AV + other stuff) to protect against disallowed USB mass storage

The last time I personally dealt with the Vodacom and MTN sticks you could pre-install the relevant client application to prevent the need to access the Mass Storage component to run the software
This is how it is done. Endpoint Protection is the current industry standard. I am speaking from my experience here in the EU and the American offices. It also allows for scale, and allows for situations where employees must have flash drives to do their job.
 
I feel as though I need to help you out @Bionic. Zero trust is about establishing trust through authentication and authorisation exactly opposite to what you are doing.

This method of restriction is literally draconian when it comes to the tech. I am guessing you have an exchange server in the broom cupboard too as an example.

Enforce zero-trust security and increase your business' agility.​

With today's businesses operating at warp speed, port-based security controls can be stagnant when compared. Blocking USB ports in case of malicious intrusion can cause productivity loss; instead, utilize a zero trust security model to ensure smooth operation of your business as it seamlessly runs in the background without interference.
 
The USB is just serving to deliver the files. There is no connectivity through the mass storage device interface so just copy the files off the device and then you can copy it onto the corresponding laptops.

You could package the software into an installer and then deploy via Group Policy or SCCM - that will make it easier to update it later if required.
 
Top
Sign up to the MyBroadband newsletter
X