title | description | ms.date |
---|---|---|
ADMX_RemovableStorage Policy CSP |
Learn more about the ADMX_RemovableStorage Area in Policy CSP. |
08/06/2024 |
[!INCLUDE ADMX-backed CSP tip]
Scope | Editions | Applicable OS |
---|---|---|
❌ Device ✅ User |
✅ Pro ✅ Enterprise ✅ Education ✅ Windows SE ✅ IoT Enterprise / IoT Enterprise LTSC |
✅ Windows 10, version 2004 with KB5005101 [10.0.19041.1202] and later ✅ Windows 10, version 20H2 with KB5005101 [10.0.19042.1202] and later ✅ Windows 10, version 21H1 with KB5005101 [10.0.19043.1202] and later ✅ Windows 11, version 21H2 [10.0.22000] and later |
./User/Vendor/MSFT/Policy/Config/ADMX_RemovableStorage/AccessRights_RebootTime_1
This policy setting configures the amount of time (in seconds) that the operating system waits to reboot in order to enforce a change in access rights to removable storage devices.
-
If you enable this policy setting, you can set the number of seconds you want the system to wait until a reboot.
-
If you disable or don't configure this setting, the operating system doesn't force a reboot.
Note
If no reboot is forced, the access right doesn't take effect until the operating system is restarted.
Description framework properties:
Property name | Property value |
---|---|
Format | chr (string) |
Access Type | Add, Delete, Get, Replace |
[!INCLUDE ADMX-backed policy note]
ADMX mapping:
Name | Value |
---|---|
Name | AccessRights_RebootTime_1 |
Friendly Name | Set time (in seconds) to force reboot |
Location | User Configuration |
Path | System > Removable Storage Access |
Registry Key Name | Software\Policies\Microsoft\Windows\RemovableStorageDevices |
Registry Value Name | RebootTimeinSeconds_state |
ADMX File Name | RemovableStorage.admx |
Scope | Editions | Applicable OS |
---|---|---|
✅ Device ❌ User |
✅ Pro ✅ Enterprise ✅ Education ✅ Windows SE ✅ IoT Enterprise / IoT Enterprise LTSC |
✅ Windows 10, version 2004 with KB5005101 [10.0.19041.1202] and later ✅ Windows 10, version 20H2 with KB5005101 [10.0.19042.1202] and later ✅ Windows 10, version 21H1 with KB5005101 [10.0.19043.1202] and later ✅ Windows 11, version 21H2 [10.0.22000] and later |
./Device/Vendor/MSFT/Policy/Config/ADMX_RemovableStorage/AccessRights_RebootTime_2
This policy setting configures the amount of time (in seconds) that the operating system waits to reboot in order to enforce a change in access rights to removable storage devices.
-
If you enable this policy setting, you can set the number of seconds you want the system to wait until a reboot.
-
If you disable or don't configure this setting, the operating system doesn't force a reboot.
Note
If no reboot is forced, the access right doesn't take effect until the operating system is restarted.
Description framework properties:
Property name | Property value |
---|---|
Format | chr (string) |
Access Type | Add, Delete, Get, Replace |
[!INCLUDE ADMX-backed policy note]
ADMX mapping:
Name | Value |
---|---|
Name | AccessRights_RebootTime_2 |
Friendly Name | Set time (in seconds) to force reboot |
Location | Computer Configuration |
Path | System > Removable Storage Access |
Registry Key Name | Software\Policies\Microsoft\Windows\RemovableStorageDevices |
Registry Value Name | RebootTimeinSeconds_state |
ADMX File Name | RemovableStorage.admx |
Scope | Editions | Applicable OS |
---|---|---|
✅ Device ❌ User |
✅ Pro ✅ Enterprise ✅ Education ✅ Windows SE ✅ IoT Enterprise / IoT Enterprise LTSC |
✅ Windows 10, version 2004 with KB5005101 [10.0.19041.1202] and later ✅ Windows 10, version 20H2 with KB5005101 [10.0.19042.1202] and later ✅ Windows 10, version 21H1 with KB5005101 [10.0.19043.1202] and later ✅ Windows 11, version 21H2 [10.0.22000] and later |
./Device/Vendor/MSFT/Policy/Config/ADMX_RemovableStorage/CDandDVD_DenyExecute_Access_2
This policy setting denies execute access to the CD and DVD removable storage class.
-
If you enable this policy setting, execute access is denied to this removable storage class.
-
If you disable or don't configure this policy setting, execute access is allowed to this removable storage class.
Description framework properties:
Property name | Property value |
---|---|
Format | chr (string) |
Access Type | Add, Delete, Get, Replace |
[!INCLUDE ADMX-backed policy note]
ADMX mapping:
Name | Value |
---|---|
Name | CDandDVD_DenyExecute_Access_2 |
Friendly Name | CD and DVD: Deny execute access |
Location | Computer Configuration |
Path | System > Removable Storage Access |
Registry Key Name | Software\Policies\Microsoft\Windows\RemovableStorageDevices{53f56308-b6bf-11d0-94f2-00a0c91efb8b} |
Registry Value Name | Deny_Execute |
ADMX File Name | RemovableStorage.admx |
Scope | Editions | Applicable OS |
---|---|---|
❌ Device ✅ User |
✅ Pro ✅ Enterprise ✅ Education ✅ Windows SE ✅ IoT Enterprise / IoT Enterprise LTSC |
✅ Windows 10, version 2004 with KB5005101 [10.0.19041.1202] and later ✅ Windows 10, version 20H2 with KB5005101 [10.0.19042.1202] and later ✅ Windows 10, version 21H1 with KB5005101 [10.0.19043.1202] and later ✅ Windows 11, version 21H2 [10.0.22000] and later |
./User/Vendor/MSFT/Policy/Config/ADMX_RemovableStorage/CDandDVD_DenyRead_Access_1
This policy setting denies read access to the CD and DVD removable storage class.
-
If you enable this policy setting, read access is denied to this removable storage class.
-
If you disable or don't configure this policy setting, read access is allowed to this removable storage class.
Description framework properties:
Property name | Property value |
---|---|
Format | chr (string) |
Access Type | Add, Delete, Get, Replace |
[!INCLUDE ADMX-backed policy note]
ADMX mapping:
Name | Value |
---|---|
Name | CDandDVD_DenyRead_Access_1 |
Friendly Name | CD and DVD: Deny read access |
Location | User Configuration |
Path | System > Removable Storage Access |
Registry Key Name | Software\Policies\Microsoft\Windows\RemovableStorageDevices{53f56308-b6bf-11d0-94f2-00a0c91efb8b} |
Registry Value Name | Deny_Read |
ADMX File Name | RemovableStorage.admx |
Scope | Editions | Applicable OS |
---|---|---|
✅ Device ❌ User |
✅ Pro ✅ Enterprise ✅ Education ✅ Windows SE ✅ IoT Enterprise / IoT Enterprise LTSC |
✅ Windows 10, version 2004 with KB5005101 [10.0.19041.1202] and later ✅ Windows 10, version 20H2 with KB5005101 [10.0.19042.1202] and later ✅ Windows 10, version 21H1 with KB5005101 [10.0.19043.1202] and later ✅ Windows 11, version 21H2 [10.0.22000] and later |
./Device/Vendor/MSFT/Policy/Config/ADMX_RemovableStorage/CDandDVD_DenyRead_Access_2
This policy setting denies read access to the CD and DVD removable storage class.
-
If you enable this policy setting, read access is denied to this removable storage class.
-
If you disable or don't configure this policy setting, read access is allowed to this removable storage class.
Description framework properties:
Property name | Property value |
---|---|
Format | chr (string) |
Access Type | Add, Delete, Get, Replace |
[!INCLUDE ADMX-backed policy note]
ADMX mapping:
Name | Value |
---|---|
Name | CDandDVD_DenyRead_Access_2 |
Friendly Name | CD and DVD: Deny read access |
Location | Computer Configuration |
Path | System > Removable Storage Access |
Registry Key Name | Software\Policies\Microsoft\Windows\RemovableStorageDevices{53f56308-b6bf-11d0-94f2-00a0c91efb8b} |
Registry Value Name | Deny_Read |
ADMX File Name | RemovableStorage.admx |
Scope | Editions | Applicable OS |
---|---|---|
❌ Device ✅ User |
✅ Pro ✅ Enterprise ✅ Education ✅ Windows SE ✅ IoT Enterprise / IoT Enterprise LTSC |
✅ Windows 10, version 2004 with KB5005101 [10.0.19041.1202] and later ✅ Windows 10, version 20H2 with KB5005101 [10.0.19042.1202] and later ✅ Windows 10, version 21H1 with KB5005101 [10.0.19043.1202] and later ✅ Windows 11, version 21H2 [10.0.22000] and later |
./User/Vendor/MSFT/Policy/Config/ADMX_RemovableStorage/CDandDVD_DenyWrite_Access_1
This policy setting denies write access to the CD and DVD removable storage class.
-
If you enable this policy setting, write access is denied to this removable storage class.
-
If you disable or don't configure this policy setting, write access is allowed to this removable storage class.
Description framework properties:
Property name | Property value |
---|---|
Format | chr (string) |
Access Type | Add, Delete, Get, Replace |
[!INCLUDE ADMX-backed policy note]
ADMX mapping:
Name | Value |
---|---|
Name | CDandDVD_DenyWrite_Access_1 |
Friendly Name | CD and DVD: Deny write access |
Location | User Configuration |
Path | System > Removable Storage Access |
Registry Key Name | Software\Policies\Microsoft\Windows\RemovableStorageDevices{53f56308-b6bf-11d0-94f2-00a0c91efb8b} |
Registry Value Name | Deny_Write |
ADMX File Name | RemovableStorage.admx |
Scope | Editions | Applicable OS |
---|---|---|
✅ Device ❌ User |
✅ Pro ✅ Enterprise ✅ Education ✅ Windows SE ✅ IoT Enterprise / IoT Enterprise LTSC |
✅ Windows 10, version 2004 with KB5005101 [10.0.19041.1202] and later ✅ Windows 10, version 20H2 with KB5005101 [10.0.19042.1202] and later ✅ Windows 10, version 21H1 with KB5005101 [10.0.19043.1202] and later ✅ Windows 11, version 21H2 [10.0.22000] and later |
./Device/Vendor/MSFT/Policy/Config/ADMX_RemovableStorage/CDandDVD_DenyWrite_Access_2
This policy setting denies write access to the CD and DVD removable storage class.
-
If you enable this policy setting, write access is denied to this removable storage class.
-
If you disable or don't configure this policy setting, write access is allowed to this removable storage class.
Description framework properties:
Property name | Property value |
---|---|
Format | chr (string) |
Access Type | Add, Delete, Get, Replace |
[!INCLUDE ADMX-backed policy note]
ADMX mapping:
Name | Value |
---|---|
Name | CDandDVD_DenyWrite_Access_2 |
Friendly Name | CD and DVD: Deny write access |
Location | Computer Configuration |
Path | System > Removable Storage Access |
Registry Key Name | Software\Policies\Microsoft\Windows\RemovableStorageDevices{53f56308-b6bf-11d0-94f2-00a0c91efb8b} |
Registry Value Name | Deny_Write |
ADMX File Name | RemovableStorage.admx |
Scope | Editions | Applicable OS |
---|---|---|
❌ Device ✅ User |
✅ Pro ✅ Enterprise ✅ Education ✅ Windows SE ✅ IoT Enterprise / IoT Enterprise LTSC |
✅ Windows 10, version 2004 with KB5005101 [10.0.19041.1202] and later ✅ Windows 10, version 20H2 with KB5005101 [10.0.19042.1202] and later ✅ Windows 10, version 21H1 with KB5005101 [10.0.19043.1202] and later ✅ Windows 11, version 21H2 [10.0.22000] and later |
./User/Vendor/MSFT/Policy/Config/ADMX_RemovableStorage/CustomClasses_DenyRead_Access_1
This policy setting denies read access to custom removable storage classes.
-
If you enable this policy setting, read access is denied to these removable storage classes.
-
If you disable or don't configure this policy setting, read access is allowed to these removable storage classes.
Description framework properties:
Property name | Property value |
---|---|
Format | chr (string) |
Access Type | Add, Delete, Get, Replace |
[!INCLUDE ADMX-backed policy note]
ADMX mapping:
Name | Value |
---|---|
Name | CustomClasses_DenyRead_Access_1 |
Friendly Name | Custom Classes: Deny read access |
Location | User Configuration |
Path | System > Removable Storage Access |
Registry Key Name | Software\Policies\Microsoft\Windows\RemovableStorageDevices\Custom\Deny_Read |
Registry Value Name | Deny_Read |
ADMX File Name | RemovableStorage.admx |
Scope | Editions | Applicable OS |
---|---|---|
✅ Device ❌ User |
✅ Pro ✅ Enterprise ✅ Education ✅ Windows SE ✅ IoT Enterprise / IoT Enterprise LTSC |
✅ Windows 10, version 2004 with KB5005101 [10.0.19041.1202] and later ✅ Windows 10, version 20H2 with KB5005101 [10.0.19042.1202] and later ✅ Windows 10, version 21H1 with KB5005101 [10.0.19043.1202] and later ✅ Windows 11, version 21H2 [10.0.22000] and later |
./Device/Vendor/MSFT/Policy/Config/ADMX_RemovableStorage/CustomClasses_DenyRead_Access_2
This policy setting denies read access to custom removable storage classes.
-
If you enable this policy setting, read access is denied to these removable storage classes.
-
If you disable or don't configure this policy setting, read access is allowed to these removable storage classes.
Description framework properties:
Property name | Property value |
---|---|
Format | chr (string) |
Access Type | Add, Delete, Get, Replace |
[!INCLUDE ADMX-backed policy note]
ADMX mapping:
Name | Value |
---|---|
Name | CustomClasses_DenyRead_Access_2 |
Friendly Name | Custom Classes: Deny read access |
Location | Computer Configuration |
Path | System > Removable Storage Access |
Registry Key Name | Software\Policies\Microsoft\Windows\RemovableStorageDevices\Custom\Deny_Read |
Registry Value Name | Deny_Read |
ADMX File Name | RemovableStorage.admx |
Scope | Editions | Applicable OS |
---|---|---|
❌ Device ✅ User |
✅ Pro ✅ Enterprise ✅ Education ✅ Windows SE ✅ IoT Enterprise / IoT Enterprise LTSC |
✅ Windows 10, version 2004 with KB5005101 [10.0.19041.1202] and later ✅ Windows 10, version 20H2 with KB5005101 [10.0.19042.1202] and later ✅ Windows 10, version 21H1 with KB5005101 [10.0.19043.1202] and later ✅ Windows 11, version 21H2 [10.0.22000] and later |
./User/Vendor/MSFT/Policy/Config/ADMX_RemovableStorage/CustomClasses_DenyWrite_Access_1
This policy setting denies write access to custom removable storage classes.
-
If you enable this policy setting, write access is denied to these removable storage classes.
-
If you disable or don't configure this policy setting, write access is allowed to these removable storage classes.
Description framework properties:
Property name | Property value |
---|---|
Format | chr (string) |
Access Type | Add, Delete, Get, Replace |
[!INCLUDE ADMX-backed policy note]
ADMX mapping:
Name | Value |
---|---|
Name | CustomClasses_DenyWrite_Access_1 |
Friendly Name | Custom Classes: Deny write access |
Location | User Configuration |
Path | System > Removable Storage Access |
Registry Key Name | Software\Policies\Microsoft\Windows\RemovableStorageDevices\Custom\Deny_Write |
Registry Value Name | Deny_Write |
ADMX File Name | RemovableStorage.admx |
Scope | Editions | Applicable OS |
---|---|---|
✅ Device ❌ User |
✅ Pro ✅ Enterprise ✅ Education ✅ Windows SE ✅ IoT Enterprise / IoT Enterprise LTSC |
✅ Windows 10, version 2004 with KB5005101 [10.0.19041.1202] and later ✅ Windows 10, version 20H2 with KB5005101 [10.0.19042.1202] and later ✅ Windows 10, version 21H1 with KB5005101 [10.0.19043.1202] and later ✅ Windows 11, version 21H2 [10.0.22000] and later |
./Device/Vendor/MSFT/Policy/Config/ADMX_RemovableStorage/CustomClasses_DenyWrite_Access_2
This policy setting denies write access to custom removable storage classes.
-
If you enable this policy setting, write access is denied to these removable storage classes.
-
If you disable or don't configure this policy setting, write access is allowed to these removable storage classes.
Description framework properties:
Property name | Property value |
---|---|
Format | chr (string) |
Access Type | Add, Delete, Get, Replace |
[!INCLUDE ADMX-backed policy note]
ADMX mapping:
Name | Value |
---|---|
Name | CustomClasses_DenyWrite_Access_2 |
Friendly Name | Custom Classes: Deny write access |
Location | Computer Configuration |
Path | System > Removable Storage Access |
Registry Key Name | Software\Policies\Microsoft\Windows\RemovableStorageDevices\Custom\Deny_Write |
Registry Value Name | Deny_Write |
ADMX File Name | RemovableStorage.admx |
Scope | Editions | Applicable OS |
---|---|---|
✅ Device ❌ User |
✅ Pro ✅ Enterprise ✅ Education ✅ Windows SE ✅ IoT Enterprise / IoT Enterprise LTSC |
✅ Windows 10, version 2004 with KB5005101 [10.0.19041.1202] and later ✅ Windows 10, version 20H2 with KB5005101 [10.0.19042.1202] and later ✅ Windows 10, version 21H1 with KB5005101 [10.0.19043.1202] and later ✅ Windows 11, version 21H2 [10.0.22000] and later |
./Device/Vendor/MSFT/Policy/Config/ADMX_RemovableStorage/FloppyDrives_DenyExecute_Access_2
This policy setting denies execute access to the Floppy Drives removable storage class, including USB Floppy Drives.
-
If you enable this policy setting, execute access is denied to this removable storage class.
-
If you disable or don't configure this policy setting, execute access is allowed to this removable storage class.
Description framework properties:
Property name | Property value |
---|---|
Format | chr (string) |
Access Type | Add, Delete, Get, Replace |
[!INCLUDE ADMX-backed policy note]
ADMX mapping:
Name | Value |
---|---|
Name | FloppyDrives_DenyExecute_Access_2 |
Friendly Name | Floppy Drives: Deny execute access |
Location | Computer Configuration |
Path | System > Removable Storage Access |
Registry Key Name | Software\Policies\Microsoft\Windows\RemovableStorageDevices{53f56311-b6bf-11d0-94f2-00a0c91efb8b} |
Registry Value Name | Deny_Execute |
ADMX File Name | RemovableStorage.admx |
Scope | Editions | Applicable OS |
---|---|---|
❌ Device ✅ User |
✅ Pro ✅ Enterprise ✅ Education ✅ Windows SE ✅ IoT Enterprise / IoT Enterprise LTSC |
✅ Windows 10, version 2004 with KB5005101 [10.0.19041.1202] and later ✅ Windows 10, version 20H2 with KB5005101 [10.0.19042.1202] and later ✅ Windows 10, version 21H1 with KB5005101 [10.0.19043.1202] and later ✅ Windows 11, version 21H2 [10.0.22000] and later |
./User/Vendor/MSFT/Policy/Config/ADMX_RemovableStorage/FloppyDrives_DenyRead_Access_1
This policy setting denies read access to the Floppy Drives removable storage class, including USB Floppy Drives.
-
If you enable this policy setting, read access is denied to this removable storage class.
-
If you disable or don't configure this policy setting, read access is allowed to this removable storage class.
Description framework properties:
Property name | Property value |
---|---|
Format | chr (string) |
Access Type | Add, Delete, Get, Replace |
[!INCLUDE ADMX-backed policy note]
ADMX mapping:
Name | Value |
---|---|
Name | FloppyDrives_DenyRead_Access_1 |
Friendly Name | Floppy Drives: Deny read access |
Location | User Configuration |
Path | System > Removable Storage Access |
Registry Key Name | Software\Policies\Microsoft\Windows\RemovableStorageDevices{53f56311-b6bf-11d0-94f2-00a0c91efb8b} |
Registry Value Name | Deny_Read |
ADMX File Name | RemovableStorage.admx |
Scope | Editions | Applicable OS |
---|---|---|
✅ Device ❌ User |
✅ Pro ✅ Enterprise ✅ Education ✅ Windows SE ✅ IoT Enterprise / IoT Enterprise LTSC |
✅ Windows 10, version 2004 with KB5005101 [10.0.19041.1202] and later ✅ Windows 10, version 20H2 with KB5005101 [10.0.19042.1202] and later ✅ Windows 10, version 21H1 with KB5005101 [10.0.19043.1202] and later ✅ Windows 11, version 21H2 [10.0.22000] and later |
./Device/Vendor/MSFT/Policy/Config/ADMX_RemovableStorage/FloppyDrives_DenyRead_Access_2
This policy setting denies read access to the Floppy Drives removable storage class, including USB Floppy Drives.
-
If you enable this policy setting, read access is denied to this removable storage class.
-
If you disable or don't configure this policy setting, read access is allowed to this removable storage class.
Description framework properties:
Property name | Property value |
---|---|
Format | chr (string) |
Access Type | Add, Delete, Get, Replace |
[!INCLUDE ADMX-backed policy note]
ADMX mapping:
Name | Value |
---|---|
Name | FloppyDrives_DenyRead_Access_2 |
Friendly Name | Floppy Drives: Deny read access |
Location | Computer Configuration |
Path | System > Removable Storage Access |
Registry Key Name | Software\Policies\Microsoft\Windows\RemovableStorageDevices{53f56311-b6bf-11d0-94f2-00a0c91efb8b} |
Registry Value Name | Deny_Read |
ADMX File Name | RemovableStorage.admx |
Scope | Editions | Applicable OS |
---|---|---|
❌ Device ✅ User |
✅ Pro ✅ Enterprise ✅ Education ✅ Windows SE ✅ IoT Enterprise / IoT Enterprise LTSC |
✅ Windows 10, version 2004 with KB5005101 [10.0.19041.1202] and later ✅ Windows 10, version 20H2 with KB5005101 [10.0.19042.1202] and later ✅ Windows 10, version 21H1 with KB5005101 [10.0.19043.1202] and later ✅ Windows 11, version 21H2 [10.0.22000] and later |
./User/Vendor/MSFT/Policy/Config/ADMX_RemovableStorage/FloppyDrives_DenyWrite_Access_1
This policy setting denies write access to the Floppy Drives removable storage class, including USB Floppy Drives.
-
If you enable this policy setting, write access is denied to this removable storage class.
-
If you disable or don't configure this policy setting, write access is allowed to this removable storage class.
Description framework properties:
Property name | Property value |
---|---|
Format | chr (string) |
Access Type | Add, Delete, Get, Replace |
[!INCLUDE ADMX-backed policy note]
ADMX mapping:
Name | Value |
---|---|
Name | FloppyDrives_DenyWrite_Access_1 |
Friendly Name | Floppy Drives: Deny write access |
Location | User Configuration |
Path | System > Removable Storage Access |
Registry Key Name | Software\Policies\Microsoft\Windows\RemovableStorageDevices{53f56311-b6bf-11d0-94f2-00a0c91efb8b} |
Registry Value Name | Deny_Write |
ADMX File Name | RemovableStorage.admx |
Scope | Editions | Applicable OS |
---|---|---|
✅ Device ❌ User |
✅ Pro ✅ Enterprise ✅ Education ✅ Windows SE ✅ IoT Enterprise / IoT Enterprise LTSC |
✅ Windows 10, version 2004 with KB5005101 [10.0.19041.1202] and later ✅ Windows 10, version 20H2 with KB5005101 [10.0.19042.1202] and later ✅ Windows 10, version 21H1 with KB5005101 [10.0.19043.1202] and later ✅ Windows 11, version 21H2 [10.0.22000] and later |
./Device/Vendor/MSFT/Policy/Config/ADMX_RemovableStorage/FloppyDrives_DenyWrite_Access_2
This policy setting denies write access to the Floppy Drives removable storage class, including USB Floppy Drives.
-
If you enable this policy setting, write access is denied to this removable storage class.
-
If you disable or don't configure this policy setting, write access is allowed to this removable storage class.
Description framework properties:
Property name | Property value |
---|---|
Format | chr (string) |
Access Type | Add, Delete, Get, Replace |
[!INCLUDE ADMX-backed policy note]
ADMX mapping:
Name | Value |
---|---|
Name | FloppyDrives_DenyWrite_Access_2 |
Friendly Name | Floppy Drives: Deny write access |
Location | Computer Configuration |
Path | System > Removable Storage Access |
Registry Key Name | Software\Policies\Microsoft\Windows\RemovableStorageDevices{53f56311-b6bf-11d0-94f2-00a0c91efb8b} |
Registry Value Name | Deny_Write |
ADMX File Name | RemovableStorage.admx |
Scope | Editions | Applicable OS |
---|---|---|
✅ Device ❌ User |
✅ Pro ✅ Enterprise ✅ Education ✅ Windows SE ✅ IoT Enterprise / IoT Enterprise LTSC |
✅ Windows 10, version 2004 with KB5005101 [10.0.19041.1202] and later ✅ Windows 10, version 20H2 with KB5005101 [10.0.19042.1202] and later ✅ Windows 10, version 21H1 with KB5005101 [10.0.19043.1202] and later ✅ Windows 11, version 21H2 [10.0.22000] and later |
./Device/Vendor/MSFT/Policy/Config/ADMX_RemovableStorage/Removable_Remote_Allow_Access
This policy setting grants normal users direct access to removable storage devices in remote sessions.
-
If you enable this policy setting, remote users can open direct handles to removable storage devices in remote sessions.
-
If you disable or don't configure this policy setting, remote users can't open direct handles to removable storage devices in remote sessions.
Description framework properties:
Property name | Property value |
---|---|
Format | chr (string) |
Access Type | Add, Delete, Get, Replace |
[!INCLUDE ADMX-backed policy note]
ADMX mapping:
Name | Value |
---|---|
Name | Removable_Remote_Allow_Access |
Friendly Name | All Removable Storage: Allow direct access in remote sessions |
Location | Computer Configuration |
Path | System > Removable Storage Access |
Registry Key Name | Software\Policies\Microsoft\Windows\RemovableStorageDevices |
Registry Value Name | AllowRemoteDASD |
ADMX File Name | RemovableStorage.admx |
Scope | Editions | Applicable OS |
---|---|---|
✅ Device ❌ User |
✅ Pro ✅ Enterprise ✅ Education ✅ Windows SE ✅ IoT Enterprise / IoT Enterprise LTSC |
✅ Windows 10, version 2004 with KB5005101 [10.0.19041.1202] and later ✅ Windows 10, version 20H2 with KB5005101 [10.0.19042.1202] and later ✅ Windows 10, version 21H1 with KB5005101 [10.0.19043.1202] and later ✅ Windows 11, version 21H2 [10.0.22000] and later |
./Device/Vendor/MSFT/Policy/Config/ADMX_RemovableStorage/RemovableDisks_DenyExecute_Access_2
This policy setting denies execute access to removable disks.
-
If you enable this policy setting, execute access is denied to this removable storage class.
-
If you disable or don't configure this policy setting, execute access is allowed to this removable storage class.
Description framework properties:
Property name | Property value |
---|---|
Format | chr (string) |
Access Type | Add, Delete, Get, Replace |
[!INCLUDE ADMX-backed policy note]
ADMX mapping:
Name | Value |
---|---|
Name | RemovableDisks_DenyExecute_Access_2 |
Friendly Name | Removable Disks: Deny execute access |
Location | Computer Configuration |
Path | System > Removable Storage Access |
Registry Key Name | Software\Policies\Microsoft\Windows\RemovableStorageDevices{53f5630d-b6bf-11d0-94f2-00a0c91efb8b} |
Registry Value Name | Deny_Execute |
ADMX File Name | RemovableStorage.admx |
Scope | Editions | Applicable OS |
---|---|---|
❌ Device ✅ User |
✅ Pro ✅ Enterprise ✅ Education ✅ Windows SE ✅ IoT Enterprise / IoT Enterprise LTSC |
✅ Windows 10, version 2004 with KB5005101 [10.0.19041.1202] and later ✅ Windows 10, version 20H2 with KB5005101 [10.0.19042.1202] and later ✅ Windows 10, version 21H1 with KB5005101 [10.0.19043.1202] and later ✅ Windows 11, version 21H2 [10.0.22000] and later |
./User/Vendor/MSFT/Policy/Config/ADMX_RemovableStorage/RemovableDisks_DenyRead_Access_1
This policy setting denies read access to removable disks.
-
If you enable this policy setting, read access is denied to this removable storage class.
-
If you disable or don't configure this policy setting, read access is allowed to this removable storage class.
Description framework properties:
Property name | Property value |
---|---|
Format | chr (string) |
Access Type | Add, Delete, Get, Replace |
[!INCLUDE ADMX-backed policy note]
ADMX mapping:
Name | Value |
---|---|
Name | RemovableDisks_DenyRead_Access_1 |
Friendly Name | Removable Disks: Deny read access |
Location | User Configuration |
Path | System > Removable Storage Access |
Registry Key Name | Software\Policies\Microsoft\Windows\RemovableStorageDevices{53f5630d-b6bf-11d0-94f2-00a0c91efb8b} |
Registry Value Name | Deny_Read |
ADMX File Name | RemovableStorage.admx |
Scope | Editions | Applicable OS |
---|---|---|
✅ Device ❌ User |
✅ Pro ✅ Enterprise ✅ Education ✅ Windows SE ✅ IoT Enterprise / IoT Enterprise LTSC |
✅ Windows 10, version 2004 with KB5005101 [10.0.19041.1202] and later ✅ Windows 10, version 20H2 with KB5005101 [10.0.19042.1202] and later ✅ Windows 10, version 21H1 with KB5005101 [10.0.19043.1202] and later ✅ Windows 11, version 21H2 [10.0.22000] and later |
./Device/Vendor/MSFT/Policy/Config/ADMX_RemovableStorage/RemovableDisks_DenyRead_Access_2
This policy setting denies read access to removable disks.
-
If you enable this policy setting, read access is denied to this removable storage class.
-
If you disable or don't configure this policy setting, read access is allowed to this removable storage class.
Description framework properties:
Property name | Property value |
---|---|
Format | chr (string) |
Access Type | Add, Delete, Get, Replace |
[!INCLUDE ADMX-backed policy note]
ADMX mapping:
Name | Value |
---|---|
Name | RemovableDisks_DenyRead_Access_2 |
Friendly Name | Removable Disks: Deny read access |
Location | Computer Configuration |
Path | System > Removable Storage Access |
Registry Key Name | Software\Policies\Microsoft\Windows\RemovableStorageDevices{53f5630d-b6bf-11d0-94f2-00a0c91efb8b} |
Registry Value Name | Deny_Read |
ADMX File Name | RemovableStorage.admx |
Scope | Editions | Applicable OS |
---|---|---|
❌ Device ✅ User |
✅ Pro ✅ Enterprise ✅ Education ✅ Windows SE ✅ IoT Enterprise / IoT Enterprise LTSC |
✅ Windows 10, version 2004 with KB5005101 [10.0.19041.1202] and later ✅ Windows 10, version 20H2 with KB5005101 [10.0.19042.1202] and later ✅ Windows 10, version 21H1 with KB5005101 [10.0.19043.1202] and later ✅ Windows 11, version 21H2 [10.0.22000] and later |
./User/Vendor/MSFT/Policy/Config/ADMX_RemovableStorage/RemovableDisks_DenyWrite_Access_1
This policy setting denies write access to removable disks.
-
If you enable this policy setting, write access is denied to this removable storage class.
-
If you disable or don't configure this policy setting, write access is allowed to this removable storage class.
Note
To require that users write data to BitLocker-protected storage, enable the policy setting "Deny write access to drives not protected by BitLocker," which is located in "Computer Configuration\Administrative Templates\Windows Components\BitLocker Drive Encryption\Removable Data Drives".
Description framework properties:
Property name | Property value |
---|---|
Format | chr (string) |
Access Type | Add, Delete, Get, Replace |
[!INCLUDE ADMX-backed policy note]
ADMX mapping:
Name | Value |
---|---|
Name | RemovableDisks_DenyWrite_Access_1 |
Friendly Name | Removable Disks: Deny write access |
Location | User Configuration |
Path | System > Removable Storage Access |
Registry Key Name | Software\Policies\Microsoft\Windows\RemovableStorageDevices{53f5630d-b6bf-11d0-94f2-00a0c91efb8b} |
Registry Value Name | Deny_Write |
ADMX File Name | RemovableStorage.admx |
Scope | Editions | Applicable OS |
---|---|---|
❌ Device ✅ User |
✅ Pro ✅ Enterprise ✅ Education ✅ Windows SE ✅ IoT Enterprise / IoT Enterprise LTSC |
✅ Windows 10, version 2004 with KB5005101 [10.0.19041.1202] and later ✅ Windows 10, version 20H2 with KB5005101 [10.0.19042.1202] and later ✅ Windows 10, version 21H1 with KB5005101 [10.0.19043.1202] and later ✅ Windows 11, version 21H2 [10.0.22000] and later |
./User/Vendor/MSFT/Policy/Config/ADMX_RemovableStorage/RemovableStorageClasses_DenyAll_Access_1
Configure access to all removable storage classes.
This policy setting takes precedence over any individual removable storage policy settings. To manage individual classes, use the policy settings available for each class.
-
If you enable this policy setting, no access is allowed to any removable storage class.
-
If you disable or don't configure this policy setting, write and read accesses are allowed to all removable storage classes.
Description framework properties:
Property name | Property value |
---|---|
Format | chr (string) |
Access Type | Add, Delete, Get, Replace |
[!INCLUDE ADMX-backed policy note]
ADMX mapping:
Name | Value |
---|---|
Name | RemovableStorageClasses_DenyAll_Access_1 |
Friendly Name | All Removable Storage classes: Deny all access |
Location | User Configuration |
Path | System > Removable Storage Access |
Registry Key Name | Software\Policies\Microsoft\Windows\RemovableStorageDevices |
Registry Value Name | Deny_All |
ADMX File Name | RemovableStorage.admx |
Scope | Editions | Applicable OS |
---|---|---|
✅ Device ❌ User |
✅ Pro ✅ Enterprise ✅ Education ✅ Windows SE ✅ IoT Enterprise / IoT Enterprise LTSC |
✅ Windows 10, version 2004 with KB5005101 [10.0.19041.1202] and later ✅ Windows 10, version 20H2 with KB5005101 [10.0.19042.1202] and later ✅ Windows 10, version 21H1 with KB5005101 [10.0.19043.1202] and later ✅ Windows 11, version 21H2 [10.0.22000] and later |
./Device/Vendor/MSFT/Policy/Config/ADMX_RemovableStorage/RemovableStorageClasses_DenyAll_Access_2
Configure access to all removable storage classes.
This policy setting takes precedence over any individual removable storage policy settings. To manage individual classes, use the policy settings available for each class.
-
If you enable this policy setting, no access is allowed to any removable storage class.
-
If you disable or don't configure this policy setting, write and read accesses are allowed to all removable storage classes.
Description framework properties:
Property name | Property value |
---|---|
Format | chr (string) |
Access Type | Add, Delete, Get, Replace |
[!INCLUDE ADMX-backed policy note]
ADMX mapping:
Name | Value |
---|---|
Name | RemovableStorageClasses_DenyAll_Access_2 |
Friendly Name | All Removable Storage classes: Deny all access |
Location | Computer Configuration |
Path | System > Removable Storage Access |
Registry Key Name | Software\Policies\Microsoft\Windows\RemovableStorageDevices |
Registry Value Name | Deny_All |
ADMX File Name | RemovableStorage.admx |
Scope | Editions | Applicable OS |
---|---|---|
✅ Device ❌ User |
✅ Pro ✅ Enterprise ✅ Education ✅ Windows SE ✅ IoT Enterprise / IoT Enterprise LTSC |
✅ Windows 10, version 2004 with KB5005101 [10.0.19041.1202] and later ✅ Windows 10, version 20H2 with KB5005101 [10.0.19042.1202] and later ✅ Windows 10, version 21H1 with KB5005101 [10.0.19043.1202] and later ✅ Windows 11, version 21H2 [10.0.22000] and later |
./Device/Vendor/MSFT/Policy/Config/ADMX_RemovableStorage/TapeDrives_DenyExecute_Access_2
This policy setting denies execute access to the Tape Drive removable storage class.
-
If you enable this policy setting, execute access is denied to this removable storage class.
-
If you disable or don't configure this policy setting, execute access is allowed to this removable storage class.
Description framework properties:
Property name | Property value |
---|---|
Format | chr (string) |
Access Type | Add, Delete, Get, Replace |
[!INCLUDE ADMX-backed policy note]
ADMX mapping:
Name | Value |
---|---|
Name | TapeDrives_DenyExecute_Access_2 |
Friendly Name | Tape Drives: Deny execute access |
Location | Computer Configuration |
Path | System > Removable Storage Access |
Registry Key Name | Software\Policies\Microsoft\Windows\RemovableStorageDevices{53f5630b-b6bf-11d0-94f2-00a0c91efb8b} |
Registry Value Name | Deny_Execute |
ADMX File Name | RemovableStorage.admx |
Scope | Editions | Applicable OS |
---|---|---|
❌ Device ✅ User |
✅ Pro ✅ Enterprise ✅ Education ✅ Windows SE ✅ IoT Enterprise / IoT Enterprise LTSC |
✅ Windows 10, version 2004 with KB5005101 [10.0.19041.1202] and later ✅ Windows 10, version 20H2 with KB5005101 [10.0.19042.1202] and later ✅ Windows 10, version 21H1 with KB5005101 [10.0.19043.1202] and later ✅ Windows 11, version 21H2 [10.0.22000] and later |
./User/Vendor/MSFT/Policy/Config/ADMX_RemovableStorage/TapeDrives_DenyRead_Access_1
This policy setting denies read access to the Tape Drive removable storage class.
-
If you enable this policy setting, read access is denied to this removable storage class.
-
If you disable or don't configure this policy setting, read access is allowed to this removable storage class.
Description framework properties:
Property name | Property value |
---|---|
Format | chr (string) |
Access Type | Add, Delete, Get, Replace |
[!INCLUDE ADMX-backed policy note]
ADMX mapping:
Name | Value |
---|---|
Name | TapeDrives_DenyRead_Access_1 |
Friendly Name | Tape Drives: Deny read access |
Location | User Configuration |
Path | System > Removable Storage Access |
Registry Key Name | Software\Policies\Microsoft\Windows\RemovableStorageDevices{53f5630b-b6bf-11d0-94f2-00a0c91efb8b} |
Registry Value Name | Deny_Read |
ADMX File Name | RemovableStorage.admx |
Scope | Editions | Applicable OS |
---|---|---|
✅ Device ❌ User |
✅ Pro ✅ Enterprise ✅ Education ✅ Windows SE ✅ IoT Enterprise / IoT Enterprise LTSC |
✅ Windows 10, version 2004 with KB5005101 [10.0.19041.1202] and later ✅ Windows 10, version 20H2 with KB5005101 [10.0.19042.1202] and later ✅ Windows 10, version 21H1 with KB5005101 [10.0.19043.1202] and later ✅ Windows 11, version 21H2 [10.0.22000] and later |
./Device/Vendor/MSFT/Policy/Config/ADMX_RemovableStorage/TapeDrives_DenyRead_Access_2
This policy setting denies read access to the Tape Drive removable storage class.
-
If you enable this policy setting, read access is denied to this removable storage class.
-
If you disable or don't configure this policy setting, read access is allowed to this removable storage class.
Description framework properties:
Property name | Property value |
---|---|
Format | chr (string) |
Access Type | Add, Delete, Get, Replace |
[!INCLUDE ADMX-backed policy note]
ADMX mapping:
Name | Value |
---|---|
Name | TapeDrives_DenyRead_Access_2 |
Friendly Name | Tape Drives: Deny read access |
Location | Computer Configuration |
Path | System > Removable Storage Access |
Registry Key Name | Software\Policies\Microsoft\Windows\RemovableStorageDevices{53f5630b-b6bf-11d0-94f2-00a0c91efb8b} |
Registry Value Name | Deny_Read |
ADMX File Name | RemovableStorage.admx |
Scope | Editions | Applicable OS |
---|---|---|
❌ Device ✅ User |
✅ Pro ✅ Enterprise ✅ Education ✅ Windows SE ✅ IoT Enterprise / IoT Enterprise LTSC |
✅ Windows 10, version 2004 with KB5005101 [10.0.19041.1202] and later ✅ Windows 10, version 20H2 with KB5005101 [10.0.19042.1202] and later ✅ Windows 10, version 21H1 with KB5005101 [10.0.19043.1202] and later ✅ Windows 11, version 21H2 [10.0.22000] and later |
./User/Vendor/MSFT/Policy/Config/ADMX_RemovableStorage/TapeDrives_DenyWrite_Access_1
This policy setting denies write access to the Tape Drive removable storage class.
-
If you enable this policy setting, write access is denied to this removable storage class.
-
If you disable or don't configure this policy setting, write access is allowed to this removable storage class.
Description framework properties:
Property name | Property value |
---|---|
Format | chr (string) |
Access Type | Add, Delete, Get, Replace |
[!INCLUDE ADMX-backed policy note]
ADMX mapping:
Name | Value |
---|---|
Name | TapeDrives_DenyWrite_Access_1 |
Friendly Name | Tape Drives: Deny write access |
Location | User Configuration |
Path | System > Removable Storage Access |
Registry Key Name | Software\Policies\Microsoft\Windows\RemovableStorageDevices{53f5630b-b6bf-11d0-94f2-00a0c91efb8b} |
Registry Value Name | Deny_Write |
ADMX File Name | RemovableStorage.admx |
Scope | Editions | Applicable OS |
---|---|---|
✅ Device ❌ User |
✅ Pro ✅ Enterprise ✅ Education ✅ Windows SE ✅ IoT Enterprise / IoT Enterprise LTSC |
✅ Windows 10, version 2004 with KB5005101 [10.0.19041.1202] and later ✅ Windows 10, version 20H2 with KB5005101 [10.0.19042.1202] and later ✅ Windows 10, version 21H1 with KB5005101 [10.0.19043.1202] and later ✅ Windows 11, version 21H2 [10.0.22000] and later |
./Device/Vendor/MSFT/Policy/Config/ADMX_RemovableStorage/TapeDrives_DenyWrite_Access_2
This policy setting denies write access to the Tape Drive removable storage class.
-
If you enable this policy setting, write access is denied to this removable storage class.
-
If you disable or don't configure this policy setting, write access is allowed to this removable storage class.
Description framework properties:
Property name | Property value |
---|---|
Format | chr (string) |
Access Type | Add, Delete, Get, Replace |
[!INCLUDE ADMX-backed policy note]
ADMX mapping:
Name | Value |
---|---|
Name | TapeDrives_DenyWrite_Access_2 |
Friendly Name | Tape Drives: Deny write access |
Location | Computer Configuration |
Path | System > Removable Storage Access |
Registry Key Name | Software\Policies\Microsoft\Windows\RemovableStorageDevices{53f5630b-b6bf-11d0-94f2-00a0c91efb8b} |
Registry Value Name | Deny_Write |
ADMX File Name | RemovableStorage.admx |
Scope | Editions | Applicable OS |
---|---|---|
❌ Device ✅ User |
✅ Pro ✅ Enterprise ✅ Education ✅ Windows SE ✅ IoT Enterprise / IoT Enterprise LTSC |
✅ Windows 10, version 2004 with KB5005101 [10.0.19041.1202] and later ✅ Windows 10, version 20H2 with KB5005101 [10.0.19042.1202] and later ✅ Windows 10, version 21H1 with KB5005101 [10.0.19043.1202] and later ✅ Windows 11, version 21H2 [10.0.22000] and later |
./User/Vendor/MSFT/Policy/Config/ADMX_RemovableStorage/WPDDevices_DenyRead_Access_1
This policy setting denies read access to removable disks, which may include media players, cellular phones, auxiliary displays, and CE devices.
-
If you enable this policy setting, read access is denied to this removable storage class.
-
If you disable or don't configure this policy setting, read access is allowed to this removable storage class.
Description framework properties:
Property name | Property value |
---|---|
Format | chr (string) |
Access Type | Add, Delete, Get, Replace |
[!INCLUDE ADMX-backed policy note]
ADMX mapping:
Name | Value |
---|---|
Name | WPDDevices_DenyRead_Access_1 |
Friendly Name | WPD Devices: Deny read access |
Location | User Configuration |
Path | System > Removable Storage Access |
Registry Key Name | Software\Policies\Microsoft\Windows\RemovableStorageDevices{6AC27878-A6FA-4155-BA85-F98F491D4F33} |
Registry Value Name | Deny_Read |
ADMX File Name | RemovableStorage.admx |
Scope | Editions | Applicable OS |
---|---|---|
✅ Device ❌ User |
✅ Pro ✅ Enterprise ✅ Education ✅ Windows SE ✅ IoT Enterprise / IoT Enterprise LTSC |
✅ Windows 10, version 2004 with KB5005101 [10.0.19041.1202] and later ✅ Windows 10, version 20H2 with KB5005101 [10.0.19042.1202] and later ✅ Windows 10, version 21H1 with KB5005101 [10.0.19043.1202] and later ✅ Windows 11, version 21H2 [10.0.22000] and later |
./Device/Vendor/MSFT/Policy/Config/ADMX_RemovableStorage/WPDDevices_DenyRead_Access_2
This policy setting denies read access to removable disks, which may include media players, cellular phones, auxiliary displays, and CE devices.
-
If you enable this policy setting, read access is denied to this removable storage class.
-
If you disable or don't configure this policy setting, read access is allowed to this removable storage class.
Description framework properties:
Property name | Property value |
---|---|
Format | chr (string) |
Access Type | Add, Delete, Get, Replace |
[!INCLUDE ADMX-backed policy note]
ADMX mapping:
Name | Value |
---|---|
Name | WPDDevices_DenyRead_Access_2 |
Friendly Name | WPD Devices: Deny read access |
Location | Computer Configuration |
Path | System > Removable Storage Access |
Registry Key Name | Software\Policies\Microsoft\Windows\RemovableStorageDevices{6AC27878-A6FA-4155-BA85-F98F491D4F33} |
Registry Value Name | Deny_Read |
ADMX File Name | RemovableStorage.admx |
Scope | Editions | Applicable OS |
---|---|---|
❌ Device ✅ User |
✅ Pro ✅ Enterprise ✅ Education ✅ Windows SE ✅ IoT Enterprise / IoT Enterprise LTSC |
✅ Windows 10, version 2004 with KB5005101 [10.0.19041.1202] and later ✅ Windows 10, version 20H2 with KB5005101 [10.0.19042.1202] and later ✅ Windows 10, version 21H1 with KB5005101 [10.0.19043.1202] and later ✅ Windows 11, version 21H2 [10.0.22000] and later |
./User/Vendor/MSFT/Policy/Config/ADMX_RemovableStorage/WPDDevices_DenyWrite_Access_1
This policy setting denies write access to removable disks, which may include media players, cellular phones, auxiliary displays, and CE devices.
-
If you enable this policy setting, write access is denied to this removable storage class.
-
If you disable or don't configure this policy setting, write access is allowed to this removable storage class.
Description framework properties:
Property name | Property value |
---|---|
Format | chr (string) |
Access Type | Add, Delete, Get, Replace |
[!INCLUDE ADMX-backed policy note]
ADMX mapping:
Name | Value |
---|---|
Name | WPDDevices_DenyWrite_Access_1 |
Friendly Name | WPD Devices: Deny write access |
Location | User Configuration |
Path | System > Removable Storage Access |
Registry Key Name | Software\Policies\Microsoft\Windows\RemovableStorageDevices{6AC27878-A6FA-4155-BA85-F98F491D4F33} |
Registry Value Name | Deny_Write |
ADMX File Name | RemovableStorage.admx |
Scope | Editions | Applicable OS |
---|---|---|
✅ Device ❌ User |
✅ Pro ✅ Enterprise ✅ Education ✅ Windows SE ✅ IoT Enterprise / IoT Enterprise LTSC |
✅ Windows 10, version 2004 with KB5005101 [10.0.19041.1202] and later ✅ Windows 10, version 20H2 with KB5005101 [10.0.19042.1202] and later ✅ Windows 10, version 21H1 with KB5005101 [10.0.19043.1202] and later ✅ Windows 11, version 21H2 [10.0.22000] and later |
./Device/Vendor/MSFT/Policy/Config/ADMX_RemovableStorage/WPDDevices_DenyWrite_Access_2
This policy setting denies write access to removable disks, which may include media players, cellular phones, auxiliary displays, and CE devices.
-
If you enable this policy setting, write access is denied to this removable storage class.
-
If you disable or don't configure this policy setting, write access is allowed to this removable storage class.
Description framework properties:
Property name | Property value |
---|---|
Format | chr (string) |
Access Type | Add, Delete, Get, Replace |
[!INCLUDE ADMX-backed policy note]
ADMX mapping:
Name | Value |
---|---|
Name | WPDDevices_DenyWrite_Access_2 |
Friendly Name | WPD Devices: Deny write access |
Location | Computer Configuration |
Path | System > Removable Storage Access |
Registry Key Name | Software\Policies\Microsoft\Windows\RemovableStorageDevices{6AC27878-A6FA-4155-BA85-F98F491D4F33} |
Registry Value Name | Deny_Write |
ADMX File Name | RemovableStorage.admx |