Explore all features first-hand.
Get full access to every Device Control Plus feature with a free 30-day trial. No credit card required.
Device Control Plus brings granular policies, Just-in-Time access, and real-time audit visibility, across 17+ peripheral device types connected to your endpoints.
Regulate and manage peripheral device access across every endpoint in the organization. Enforce stringent device policies to restrict unauthorized access to critical enterprise data, governing which devices can connect, what they can access, and what data they can transfer.
Allow or block entire categories of peripheral devices, including removable storage, CD drives, Windows portable devices, Apple devices, printers, and Bluetooth adapters, all from a single console. Every connection attempt is evaluated against admin-defined policies, and blocked devices are instantly flagged to administrators.
Learn MoreGet a real-time inventory of all peripheral devices connected across managed endpoints. View device types, vendors, models, and connection status to spot unrecognized or unauthorized peripherals before they pose a risk.
Learn MoreOnce policies are deployed, enforcement is automated and continues even when the endpoint is disconnected from the network, ensuring device control is never switched off for remote workers or machines operating outside the corporate network.
Learn MoreControl how users interact with files on connected peripheral devices and regulate what can be transferred out. Assign access permissions by role, restrict transfers by file type and size, and maintain a complete log of all transfer activity.
Control which file operations (read, copy, modify, or delete) users can perform on files accessed through connected peripheral devices. Assign permissions by role so each user group automatically gets the access appropriate to their position. Set read-only access for roles that need visibility without copy access, or restrict operations selectively by user group. Specific user groups can be excluded from policies enforced on the endpoints.
Learn MoreDefine which file types and extensions can be transferred to removable storage, like blocking executables, batch scripts, and other sensitive formats while allow-listing permitted extensions. Set maximum file size limits so transfers that exceed the threshold are blocked outright and the user is notified immediately.
Learn MoreAny attempt to copy a restricted file type or transfer a file beyond the size limit is logged automatically. The dashboard shows which file extensions are attempted most frequently, providing the data needed to refine policies over time.
Learn MoreAdmins can configure device control policies to permit only encrypted USB devices to access organizational data for viewing or performing file transfer operations.
Configure policies so that files can only be transferred to BitLocker-encrypted USB devices. Users can still view files on unencrypted devices, but any attempt to copy files is blocked outright.
Learn MorePrompt users to encrypt USB when they copy files to an unencrypted USB drive. Files can only be transferred once encryption is complete.
Learn MoreCentrally manage and retrieve recovery keys for BitLocker-encrypted USB drives that were encrypted through Device Control Plus, directly from the console.
Learn MoreGet full access to every Device Control Plus feature with a free 30-day trial. No credit card required.

Temporary access allows the admin to grant users permission to use a specific blocked peripheral device for a limited time.
Grant device access only for the duration it is necessary. Permissions expire automatically when the window closes.
Learn MoreGenerate and email an access code to users that are offline or outside the network, letting them connect a device for a defined period. Set an exact start and end time, or grant access in advance.
Learn MoreUsers can request temporary device access directly from their computers, sending the request to the admin for approval.
Learn MoreTrusted devices contain a list of approved peripherals considered safe and secure for accessing sensitive data.
Maintain a list of approved peripherals, each identified by its device instance path, which gives the device type, vendor name, model, and unique device ID. Devices not on the list are blocked by default, based on the policy.
Learn MoreUse wildcard patterns to add devices from the same vendor to the trusted list in one go.
Learn MoreMaintain trusted lists of peripherals for individual endpoints or groups of endpoints. Approved peripherals are available only on the machines that need them, not across the entire network.
Learn MoreKeep a copy of every file transferred to a USB device and track every file action regardless of size or extension, with detailed audit logs generated in real time.
Store a remote copy of every file transferred to USB devices. Set size limits and extension filters to determine which transfers get shadowed, with logs capturing each shadowed file in real time.
Learn MoreRecord a detailed trail of every file action—which file, where it was transferred to, who moved it, and when—regardless of size or extension. When a breach occurs, pinpoint the exact files affected and trace their path.
Learn MoreMaintain records of devices, users and computers that are managed. View all device actions and data usage activities.
Capture every device connection attempt, logging which device connected, who connected it, which computer it was plugged into, and when. Use the device summary view to spot behavioural patterns and flag suspicious activity.
Learn MoreSchedule reports on managed peripherals and device activity for daily, weekly, or monthly email delivery. Get instant email alerts the moment a blocked device attempts to connect to any endpoint.
Learn MoreDefine how long device logs, file tracing records, and file shadowing audits are retained. Reports beyond that window can be archived to a designated share path and retrieved when needed.
Learn More