0 Replies Latest reply on Sep 4, 2014 3:30 PM by keithdrone

    Using HIPS to block phones on PC's

    keithdrone

      While I'm aware that McAfee DLP/Device Control can perform some of these functions, including a few GPO's, I'm asking this from the standpoint that these are not an option in this imaginary scenario

       

       

      Using HIPs, has anyone had any success blocking the mounting/use of phones (Iphone, android, etc.) on Windows 7.    I've tried just blocking device classes, but while it blocked some aspect of registry creation, it still mounted the phones.   i've played around with a few other keys, and it too easily blocks other USB devices like HID, WLAN, etc.  

       

      I'm using the Registry portion for the rule,  been looking at the following key locations.    Has anyone successfully done so, blocking just phones (windows portable devices) and not blocking other devices?

       

      • HKLM\SOFTWARE\Microsoft\WindowsNT\CurrentVersion\EMDMgmt\
      • HKLM\SOFTWARE\Microsoft\Windows Portable Devices\Devices\
      • HKLM\SYSTEM\ControlSet001\Control\DeviceClasses\
      • HKLM\SYSTEM\ControlSet001\Enum\STORAGE\Volume\
      • HKLM\SYSTEM\ControlSet001\Enum\USB\VID_111D&PID_0000\
      • HKLM\SYSTEM\ControlSet001\Enum\USBSTOR\
      • HKLM\SYSTEM\ControlSet001\Enum\WpdBusEnumRoot\UMB\
      • HKLM\SYSTEM\ControlSet002\Control\DeviceClasses\
      • HKLM\SYSTEM\ControlSet002\Enum\STORAGE\Volume\
      • HKLM\SYSTEM\ControlSet002\Enum\USB\VID_111D&PID_0000
      • HKLM\SYSTEM\ControlSet002\Enum\USBSTOR\
      • HKLM\SYSTEM\ControlSet002\Enum\WpdBusEnumRoot\UMB\
      • HKLM\SYSTEM\CurrentControlSet\Control\DeviceClasses\
      • HKLM\SYSTEM\CurrentControlSet\Enum\STORAGE\Volume\
      • HKLM\SYSTEM\CurrentControlSet\Enum\USB\VID_111D&PID_0000\
      • HKLM\SYSTEM\CurrentControlSet\Enum\USBSTOR\
      • HKLM\SYSTEM\ CurrentControlSet\Enum\WpdBusEnumRoot\UMB