How to use the group policy to prevent U disk boot under Win7 system

  
                                    

Insert your U disk first, let the system use the U disk normally, then go to the “Control Panel” and open the “Device Manager”. In it, expand “Disk Drive” and you can see it inside. Have your U disk.

Click the right mouse button to select “Properties", click the “details" tab in the pop-up "Properties" window, and then select in the Device"Properties" drop down box “Hardware ID”, the following "value" will appear in the string, this is the hardware ID of your U disk, copy it and save it.

Also need to copy the hardware ID of "Universal Serial Bus Controller" in "Universal Serial Bus Controller", "Under Device Manager" and "Universal Serial Bus Control" "List", find "USB Mass Storage Device", click on the "Details" tab in its "Properties" window, copy its hardware ID and save it.

After finding the hardware ID of the USB flash drive, you can implement it through Group Policy. In the Start menu, search for “Run”, click Run, or directly Win+R to open the “Run” window. Enter “gpedit.msc”.

Expand “Computer Configuration & Rarr;Management Templates & Rarr; System & Rarr; Device Installation & Rarr; Device Installation Restrictions, open the right side of the device to prevent installation of devices not described by other policy settings, In the pop-up window, select “Enabled”, click the “OK" button, and then open “Allow installation of devices that match the following device IDs, set to “Enabled”, in In the "Options" pane, click “Show” to add the copied hardware IDs separately.

The setup is successful and no restart is required. When inserting a new removable storage device (which has never been run on this computer), during the installation of the driver, the following prompt pops up and successfully blocked.

Note

When you need to add a new trusted mobile storage device, just set (1) in the fourth step to “not configured” or “disabled&rdquo ;, then re-insert the new device, you can start, and then add the hardware ID to (2). Finally, the setting is risky and the operation should be cautious.

Copyright © Windows knowledge All Rights Reserved