Every peripheral governed. Every file transfer controlled.

Device Control Plus brings granular policies, Just-in-Time access, and real-time audit visibility, across 17+ peripheral device types connected to your endpoints.

Device control

Regulate and manage peripheral device access across every endpoint in the organization. Enforce stringent device policies to restrict unauthorized access to critical enterprise data, governing which devices can connect, what they can access, and what data they can transfer.

background

Device access control

Allow or block entire categories of peripheral devices, including removable storage, CD drives, Windows portable devices, Apple devices, printers, and Bluetooth adapters, all from a single console. Every connection attempt is evaluated against admin-defined policies, and blocked devices are instantly flagged to administrators.

Learn More
background

Peripheral device discovery

Get a real-time inventory of all peripheral devices connected across managed endpoints. View device types, vendors, models, and connection status to spot unrecognized or unauthorized peripherals before they pose a risk.

Learn More
background

Always-on offline enforcement

Once policies are deployed, enforcement is automated and continues even when the endpoint is disconnected from the network, ensuring device control is never switched off for remote workers or machines operating outside the corporate network.

Learn More

File access and transfer control

Control how users interact with files on connected peripheral devices and regulate what can be transferred out. Assign access permissions by role, restrict transfers by file type and size, and maintain a complete log of all transfer activity.

background

File access permissions

Control which file operations (read, copy, modify, or delete) users can perform on files accessed through connected peripheral devices. Assign permissions by role so each user group automatically gets the access appropriate to their position. Set read-only access for roles that need visibility without copy access, or restrict operations selectively by user group. Specific user groups can be excluded from policies enforced on the endpoints.

Learn More
background

File transfer control

Define which file types and extensions can be transferred to removable storage, like blocking executables, batch scripts, and other sensitive formats while allow-listing permitted extensions. Set maximum file size limits so transfers that exceed the threshold are blocked outright and the user is notified immediately.

Learn More
background

File transfer monitoring

Any attempt to copy a restricted file type or transfer a file beyond the size limit is logged automatically. The dashboard shows which file extensions are attempted most frequently, providing the data needed to refine policies over time.

Learn More

USB encryption

Admins can configure device control policies to permit only encrypted USB devices to access organizational data for viewing or performing file transfer operations.

background

Allow file transfers to encrypted USB devices only

Configure policies so that files can only be transferred to BitLocker-encrypted USB devices. Users can still view files on unencrypted devices, but any attempt to copy files is blocked outright.

Learn More
background

Prompt to enforce encryption

Prompt users to encrypt USB when they copy files to an unencrypted USB drive. Files can only be transferred once encryption is complete.

Learn More
background

Retrieve recovery keys

Centrally manage and retrieve recovery keys for BitLocker-encrypted USB drives that were encrypted through Device Control Plus, directly from the console.

Learn More

Explore all features first-hand.

Get full access to every Device Control Plus feature with a free 30-day trial. No credit card required.

ecnew-fea-card-person-1

Just-in-Time (JIT) access

Temporary access allows the admin to grant users permission to use a specific blocked peripheral device for a limited time.

background

Time-bound access with auto-revocation

Grant device access only for the duration it is necessary. Permissions expire automatically when the window closes.

Learn More
background

Access codes for offline devices

Generate and email an access code to users that are offline or outside the network, letting them connect a device for a defined period. Set an exact start and end time, or grant access in advance.

Learn More
background

Approval-based access workflow

Users can request temporary device access directly from their computers, sending the request to the admin for approval.

Learn More

Trusted device management

Trusted devices contain a list of approved peripherals considered safe and secure for accessing sensitive data.

background

Hardware-verified device allowlisting

Maintain a list of approved peripherals, each identified by its device instance path, which gives the device type, vendor name, model, and unique device ID. Devices not on the list are blocked by default, based on the policy.

Learn More
background

Wildcard-based bulk device addition

Use wildcard patterns to add devices from the same vendor to the trusted list in one go.

Learn More
background

Endpoint-specific device allowlisting

Maintain trusted lists of peripherals for individual endpoints or groups of endpoints. Approved peripherals are available only on the machines that need them, not across the entire network.

Learn More

File shadowing and file tracing

Keep a copy of every file transferred to a USB device and track every file action regardless of size or extension, with detailed audit logs generated in real time.

background

File shadowing

Store a remote copy of every file transferred to USB devices. Set size limits and extension filters to determine which transfers get shadowed, with logs capturing each shadowed file in real time.

Learn More
background

File tracing and breach investigation

Record a detailed trail of every file action—which file, where it was transferred to, who moved it, and when—regardless of size or extension. When a breach occurs, pinpoint the exact files affected and trace their path.

Learn More

Reports and audits

Maintain records of devices, users and computers that are managed. View all device actions and data usage activities.

background

Comprehensive device audit reports

Capture every device connection attempt, logging which device connected, who connected it, which computer it was plugged into, and when. Use the device summary view to spot behavioural patterns and flag suspicious activity.

Learn More
background

Scheduled delivery and real-time alerts

Schedule reports on managed peripherals and device activity for daily, weekly, or monthly email delivery. Get instant email alerts the moment a blocked device attempts to connect to any endpoint.

Learn More
background

Audit log archive

Define how long device logs, file tracing records, and file shadowing audits are retained. Reports beyond that window can be archived to a designated share path and retrieved when needed.

Learn More

Every peripheral controlled. Every file transfer accounted for.