Microsoft Defender for Endpoint blocking of USB Storage devices using GPO and XML files do not work

Huain Gomez 20 Reputation points
2026-04-09T15:28:00.71+00:00

Hi Everybody

I'm trying to implement Device Control using Microsoft Defender for Endpoint P2 with managing based on XML files and GPO, I enabled Device Control and set the Default Enforcement to deny, I'm trying to manage the whitelist using XML file, working with Copilot create both XML files (groups and rules) but the behavior isn't what expected. All devices in PCs in the test OU block the USB Storage Devices but the Whitelist part fails to enable exceptions. Other thing noted was that it is supposed that Device Control should be visible in the logs under Applications and Services Logs └ Microsoft └ Windows └ DeviceControl └ Operational and it doesn't.

Can anybody help?

Microsoft Security | Microsoft Defender | Other
0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.