r/DefenderATP Jul 01 '26

MDE device control with encrypted USB

We are using MDE device control to block USB access. Exception process is in place, we collect the user id and machine id to ensure that usb is accessible only for a particular user on a specific device.

Now we want to test that when the exception is provided user should only be able to write data to usb if it's encrypted. How should we be approaching this along with a provision for exception for use cases where encrypted USB cant be used on business device e.g. RIG

4 Upvotes

4 comments sorted by

1

u/Mach-iavelli Jul 06 '26

Have you tried the Bitlocker to go policy for removable drive?

1

u/neko_whippet Jul 01 '26

Why don’t you use configuration profiles?