Skip to main content

USB Media Control

This section allows you to customize the operations related to your USB devices. You can define preferences for allowing or blocking the installation of USB devices and set other parameters for various USB operations.

To enforce USB Media Control Policy on the enrolled device(s), follow these steps:

  1. Navigate to SureMDM Web Console > Profiles > Linux > Add > USB Media Control > Configure.
  2. Enter a Profile Name.
  3. Configure the following USB Media Control Policy settings and click Save:

Allow / Block Installation of USB Devices:

  • Allow / Block USB Device(s): Allow/Block all the USB Devices
  • USB devices to be Allowed (if any, blocks unspecified): Enter the Serial Number or DeviceClassID of allowed USB devices. Only the specified devices with provided Serial Numbers or DeviceClassID will have access; others will be blocked.
note

Supported only on SureMDM Agent version > 3.11.1

Other USB Device Configuration:

  • Block Unencrypted USB Drive: If enabled, unencrypted USB Drives will be blocked. This feature is supported from "Agent v3.5.4" and above.
  • Encrypt USB Drive: If enabled, USB Drives will be encrypted. This feature is supported from "Agent v3.5.4" and above.
    note

    If both the options (Block Unencrypted USB Drive and Encrypt USB Drive) are enabled, then priority will be given to encryption to block.

  • USB Write Block: Restricts the writing capability of USB devices while maintaining read access.
note

'USB Write Block' feature is supported from the SureMDM Agent Version 3.8.0 onwards.

  1. Go back to the Home tab and select the Linux device(s) or group(s).
  2. Click Apply to launch the Apply Job/Profile To Device prompt.
  3. Select the profile under All Jobs/Profiles.
  4. Click Apply in the Apply/Profile To Device prompt.