    What procedure to allow one device on one PC for one user?

      


      I have tested DLP to block mass storage devices and it works really fine. What I want to do is to generally block mass storage devices for all users except domain admins and allow specific devices on specific PCs for specific users only, for example the BlackBerry on the laptop of the CIO only for the CIO.


      The base rule to block all devices was no problem, it works. I also can make exceptions in this rule to allow specific devices on all hosts and for specific users or groups on all hosts, that is no problem. I also can allow specific devices only on one PC for all users.


      But what is a possible procedure to let this base rule take place an additionally allow a specific device for a specific user on a specific PC? Can anyone help me with that?


      Best regards, Jochen