×
×
×
×

Comprehensive Guide to Device Control

Build a device control strategy around your organization's risks while preserving legitimate access to peripheral devices.

Baseline

Establish a secure access baseline

Start with broad restrictions, then account for endpoints and users that require wider access.

Block peripheral access by default

New endpoints entering your network are more exposed to unauthorized peripheral devices. Apply a block policy across all endpoints to shut off peripheral access and protect the organization.

Preserve access for privileged endpoints

Create a separate policy for endpoints used by managers, C-level executives, and other highly privileged users. The policy can allow access to all peripheral devices so these users remain productive.

Exclude administrators from a block policy

Use User Group exclusion to give administrators full peripheral access without maintaining an additional policy.

  1. Create a user group that contains the administrators.
  2. Map the block-all policy to the custom group containing all users in the organization.
  3. Select the administrator user group for exclusion.

After deployment, only the administrators retain complete access to all peripheral devices.

Exceptions

Approve trusted and temporary use

Handle authorized hardware and short-term business needs without weakening the broader policy.

Maintain a trusted devices list

Add enterprise-authorized peripherals to the Trusted Devices list. A supporting policy then allows these approved devices to remain active on the network.

  1. Create a CSV file containing the enterprise-approved devices.
  2. Upload the CSV file to the Trusted Devices list instead of adding every device manually.

Enable temporary device access

A business requirement may occasionally justify access to a blocked peripheral. Configure a Temporary Access policy so the end user can request limited access to a specific device without compromising security or productivity.

Protection

Protect data and surface unauthorized activity

Limit removable storage to encrypted devices and notify the right people when restricted activity occurs.

Allow only encrypted peripherals

Configure your policy to allow only BitLocker-encrypted devices. Blocking unencrypted removable storage reduces endpoint exposure during data transmission and helps keep potential keyloggers out.

Configure alerts and notifications

Send email alerts when a restricted device attempts to enter the network, and notify technicians when a user requests temporary access.

Prerequisites
Configure the mail server settings and add the intended recipients before relying on alert and notification emails.

Compliance

Audit file activity and retain evidence

Align file controls and reporting with the organization's compliance requirements.

Configure auditing and data mirroring reports

Customize file actions according to your organization's compliance policies, then configure the audit data settings for the reports you need.

  • Device audit report
  • File audit report
  • File shadowing report
  • File archive report

Specify how long the daily logs generated for auditing must be retained.

Related