diff --git a/windows/security/threat-protection/device-control/control-usb-devices-using-intune.md b/windows/security/threat-protection/device-control/control-usb-devices-using-intune.md index e19f122d7a..d80c76c2f7 100644 --- a/windows/security/threat-protection/device-control/control-usb-devices-using-intune.md +++ b/windows/security/threat-protection/device-control/control-usb-devices-using-intune.md @@ -136,7 +136,7 @@ These settings require [enabling real-time protection](https://docs.microsoft.co 4. Click **Configure** > **Windows Defender Exploit Guard** > **Attack Surface Reduction**. -5. For **Unsigned and untrusted processes that run from USB**, choose **Audit only**. +5. For **Unsigned and untrusted processes that run from USB**, choose **Block**. ![Block untrusted processes](images/block-untrusted-processes.png) diff --git a/windows/security/threat-protection/device-control/images/block-untrusted-processes.png b/windows/security/threat-protection/device-control/images/block-untrusted-processes.png index c5306ac7f4..3080e0d1f0 100644 Binary files a/windows/security/threat-protection/device-control/images/block-untrusted-processes.png and b/windows/security/threat-protection/device-control/images/block-untrusted-processes.png differ