Comprehensive Guide to Device Control
Build a device control strategy around your organization's risks while preserving legitimate access to peripheral devices.
Baseline
Establish a secure access baseline
Start with broad restrictions, then account for endpoints and users that require wider access.
Block peripheral access by default
New endpoints entering your network are more exposed to unauthorized peripheral devices. Apply a block policy across all endpoints to shut off peripheral access and protect the organization.
Preserve access for privileged endpoints
Create a separate policy for endpoints used by managers, C-level executives, and other highly privileged users. The policy can allow access to all peripheral devices so these users remain productive.
Exclude administrators from a block policy
Use User Group exclusion to give administrators full peripheral access without maintaining an additional policy.
- Create a user group that contains the administrators.
- Map the block-all policy to the custom group containing all users in the organization.
- Select the administrator user group for exclusion.
After deployment, only the administrators retain complete access to all peripheral devices.
Exceptions
Approve trusted and temporary use
Handle authorized hardware and short-term business needs without weakening the broader policy.
Maintain a trusted devices list
Add enterprise-authorized peripherals to the Trusted Devices list. A supporting policy then allows these approved devices to remain active on the network.
- Create a CSV file containing the enterprise-approved devices.
- Upload the CSV file to the Trusted Devices list instead of adding every device manually.
Enable temporary device access
A business requirement may occasionally justify access to a blocked peripheral. Configure a Temporary Access policy so the end user can request limited access to a specific device without compromising security or productivity.
Compliance
Audit file activity and retain evidence
Align file controls and reporting with the organization's compliance requirements.
Configure auditing and data mirroring reports
Customize file actions according to your organization's compliance policies, then configure the audit data settings for the reports you need.
- Device audit report
- File audit report
- File shadowing report
- File archive report
Specify how long the daily logs generated for auditing must be retained.