×
×
×
×

Device Control Temporary Access

Grant a specific user time-limited permission to use a blocked peripheral device.

Setup

Create and target temporary access

Name the policy, choose the user and computer, and define when the access is valid.

Create the policy

  1. Navigate to Policies → Temporary Access → Create.
  2. Enter the policy Name.
  3. Optionally add a Description that explains the purpose or key details.
Temporary Access policy creation form
Create and describe a temporary-access policy.

Define the target and duration

  1. Select the computer and the specific user who should receive temporary access.
  2. Duration:
    • Fixed — set an access duration and an expiry date and time. Access begins when the policy is deployed to the computer.
    • Window — set From and To dates and times. The user can access the selected device only within that period.

Devices

Choose the allowed device

Grant access to every instance of a device type or limit access to one identified device.

Select the device scope

Allowed Device settings for a temporary-access policy
Select the device type and permitted instance scope.

Select the device type that should receive temporary access, then choose how the device is identified:

  • All Instances — grants access to every instance of the selected device type.
  • Specific Instance — grants access only to the device identified by its device path.

Control removable storage

When the selected type is Removable Storage Device, advanced settings provide additional file-transfer controls.

Advanced removable-storage settings for temporary access
Configure file-transfer behavior for removable storage.
  • Restrict transfers from a connected removable storage device to the computer.
  • Restrict changes to files on the removable device and transfers from the computer to the device.
  • Allow transfers to removable storage according to specific file extensions and their corresponding file sizes.

Deployment

Deliver temporary access

Apply the policy directly or give the user a code file that activates it from the endpoint.

Choose the deployment method

  • Deploy Immediately — applies the policy directly to the target user.
  • Generate a Code — creates a .tac file that the user can activate.
    1. Right-click the agent tray icon.
    2. Select View Device Temporary Access Portal.
    3. Select the .tac file.
    4. Select Apply.

Requests

Handle user access requests

Users can request access from their computers and administrators can review, approve, code, or decline each request.

Submit a request from the endpoint

  1. Right-click the agent tray icon and select View Device Temporary Access Portal → Temporary Access Request.
  2. Select the device and access duration, enter the reason, and select Request.
Temporary Access Request interface on an endpoint
Request temporary device access from the endpoint portal.

Review the request

Open the policy to review the requested device and the reason supplied by the user.

Temporary-access request details for administrator review
Review the requested device and the user's reason.

Respond to the request

Select Modify, then choose an administrator action:

  • Deploy Immediately — accepts the request and deploys the policy.
  • Generate Code — creates a .tac file that the user can apply to activate the policy.
  • Decline — rejects the temporary-access request.
Administrator actions for a temporary-access request
Deploy, generate a code, or decline the request.

Related