Hi George,
In Microsoft Purview Endpoint DLP, you can configure exclusions by targeting specific USB hardware IDs. The way this works is that you first identify the vendor and product IDs of the encrypted tracking keys (you can find these in Device Manager under the device’s properties). Once you have those IDs, you can create a DLP policy exception in the Endpoint DLP settings within the Microsoft Purview compliance portal.
In the policy, you’ll define a rule that blocks removable storage by default, but then add an exception that allows devices matching the approved hardware IDs. This ensures that only the logistics team’s encrypted keys are permitted, while all other USB drives remain blocked. It’s important to test the configuration carefully, since even small differences in firmware or driver versions can change the reported hardware ID.
Best practice is to document the approved devices, monitor usage through audit logs, and periodically revalidate that the hardware IDs haven’t changed. This way, you maintain strong protection for sensitive data while giving your logistics team the flexibility they need.
If you find this answer helpful, kindly hit “accept answer”
Jason