Additional Microsoft Defender tools and services that provide security across various platforms and environments
Microsoft Defender for Endpoint blocking of USB Storage devices using GPO and XML files do not work
Hi Everybody
I'm trying to implement Device Control using Microsoft Defender for Endpoint P2 with managing based on XML files and GPO, I enabled Device Control and set the Default Enforcement to deny, I'm trying to manage the whitelist using XML file, working with Copilot create both XML files (groups and rules) but the behavior isn't what expected. All devices in PCs in the test OU block the USB Storage Devices but the Whitelist part fails to enable exceptions. Other thing noted was that it is supposed that Device Control should be visible in the logs under Applications and Services Logs └ Microsoft └ Windows └ DeviceControl └ Operational and it doesn't.
Can anybody help?