Thanks a lots, bull eyes . I hope that you will create a complete playlist for the Intune!!
@parfeit1Күн бұрын
Merci Jonathan pour vos tutos. Vous explications sont claires et la démo facile à suivre. Vous faites un excellent travail.
@georgiosstratigos433410 күн бұрын
excellent ,my only concern is this subject policy don't block whole docking stations ,but only usb mass storage
@ACrispiels11 күн бұрын
Honestly, Jonathan, when I see the relative complexity of the thing, I am happy to manage hybrid environments and therefore to be able to continue easily with gpo's to manage this !
@bearded365guy10 күн бұрын
Oh no!
@MN-wy6me11 күн бұрын
I love it and I'll looking forward for how to block removable storage on macOS via Intune as well. Thanks for good content guy.
@bearded365guy11 күн бұрын
Yes, that will come soon from me!
@NiCo2005lost5 күн бұрын
Saved the day mate! Thanks!
@NajiyaParween-gv8ke2 күн бұрын
Thanks ❤❤❤
@kaleidoscopeon11 күн бұрын
Love your videos. Simple and friendly.
@bearded365guy11 күн бұрын
Glad you like them!
@matheusferrari16138 күн бұрын
Hey Jonathan, I did all the process, on the first one to deny write access, everything got ok, but when I did th rest of the process, exactly like the video, the usb wasn´t get the blocked like before
@bearded365guy8 күн бұрын
All devices in Intune? And enrolled in Defender for Business?
@matheusferrari16138 күн бұрын
@@bearded365guy They are all on Intune. I believe they are enrolled in Defender for Business, got a lot of politics on there that are working well. But on this matter, just on the part to deny write access it´s fine. When I go to reusable settings, I can create normally, but when I do like your video, I put the informations of a External HD, the instance path, the politcs go successful but it does not come like a whitelist device like it should
@abualghoul11 күн бұрын
Excellent and timely! Could you please assist with blocking the computer and laptop cameras while allowing them to work in Microsoft Teams? Additionally, I need to stop Microsoft Teams from launching at Windows startup. I’ve tried various methods, but it still starts automatically.
10 күн бұрын
excellent video again.
@patrick__00711 күн бұрын
Awesome one. I've created the (almost) same policy last week. I am running this as a pilot. One thing about the Allowed USB from your video. I would assume you would assign this Allowed USB to a new ASR rule which is assigned to the CEOs device, right? Now this USB is allowed on every device.
@bearded365guy11 күн бұрын
Yes, you could further tie it down. But what if the CEO has multiple devices?
@patrick__00711 күн бұрын
@@bearded365guyYour are right. Have a nice weekend. Can't wait for your next video.
@BRALVisuals11 күн бұрын
Thank you sir for your work for our community
@bearded365guy10 күн бұрын
Thank you 🙏
@vmsystemsch7 күн бұрын
Hi Jon @bearded365guy Thanks for the great video! Are only USB storage devices affected here or also USB-A/USB-C devices such as USB-C monitors or USB-C/Thunderbolt docking stations or Logitech USB-A Receiver for Keyboards & Mouses or USB-A/C Cameras? In "Option 1 - Block write access", is the transfer from the USB storage device to the device itself is also blocked here, i.e. as you show in the video, you create a document on the USB storage device and open it, what if you now drag this file to the laptop/PC is this prevented by the Intune policy? If not, option 2 would be the right policy to prevent this
@DivyaAnevakar5 күн бұрын
Thanks for this video Jonathan. Are you aware of any solution to block USB for MAC?
@bearded365guy5 күн бұрын
Watch out in a few weeks there will be some content that includes this.
@SonnyLearnsToRock11 күн бұрын
Thanks for explaining alot of things in 365 and making it easier to understand! U the best 👌
@bearded365guy11 күн бұрын
Glad you think so!
@qusaialhaddad141511 күн бұрын
Thanks , very helpful
@bearded365guy11 күн бұрын
You're welcome!
@steve_main6 күн бұрын
Any idea why this policy does apply to a machine I can see the setting in the registry but they can still read and write to USB drives. I only have this policy applied to 1 machine just FYI
@magnuscarlsson50679 күн бұрын
Is it possible to just allow read for some filetypes on USB?
@bearded365guy8 күн бұрын
I don’t think so…
@AJJACKAU11 күн бұрын
Does a phone count as a USB storage device? I want to block thumb drives completely, but allow people to copy photos from their phones.
@thelongbacker4 күн бұрын
You are looking for a very similar setting in the policy from this video, there is a section for removable storage access and that incorporates those settings
@mattiasolsson605611 күн бұрын
For the ones with "old" on-prem environments it could also be done with gpo:s 😊 but great video as usual! To get "all" gpos to m365 before all computers gets migrated could be a video for you, if you don't have it already 😇
@bearded365guy10 күн бұрын
Thanks for the tips!
@remku11 күн бұрын
Hi Jonathan, We have blocked the USB devices from Device Configuration, General, Removable Storage. Is there any advantage of doing the new way that you showed in-the video?
@bearded365guy10 күн бұрын
Both ways will work. I prefer this because our devices all run Defender for Business. If you use 3rd party AV, you’d need to use your way
@remku7 күн бұрын
Thanks, Jonathan, for the clarification. We are not using Defender for Business.
@bearded365guy6 күн бұрын
@@remku that will be why…. You can block using config in Intune
@y4sting11 күн бұрын
Thanks a lot for this video!!! will this also block FIDO keys?
@bearded365guy11 күн бұрын
No, it won’t block other USB devices.
@gouthamvishal00712 сағат бұрын
If I do this will it affect wireless keyboard dongle?
@vrodriguezgomez7 күн бұрын
My devices are in intune and running defender for busines but full blocking not working. Two different Tenants not working
@vrodriguezgomez6 күн бұрын
It's working after remove reusable settings from Included ID on USB Storage Device Policy. Both Tenants working OK
@Yquegsyeir11 күн бұрын
How can I use the exception in this case? Block for a user, but enable access on request.
@bearded365guy11 күн бұрын
You’d have to maybe create some Entra groups called Allowed and Denied then move the user between them on request.
@AliManzoor-i5d10 күн бұрын
I have tried , ready only works, but step to full blocking not working.
@bearded365guy10 күн бұрын
Are your devices in Intune? Running Defender for Endpoint/Business?
@AliManzoor-i5d10 күн бұрын
@bearded365guy using Microsoft Premium lics
@andrewenglish38107 күн бұрын
I am trying this in Hybrid mode, haven't fully tested it but I have excluded a couple of people.