mirror of
https://github.com/MicrosoftDocs/windows-itpro-docs.git
synced 2025-06-21 13:23:36 +00:00
added images
This commit is contained in:
@ -28,19 +28,17 @@ You can also [run a PowerShell script to perform a custom scan](https://aka.ms/s
|
|||||||
|
|
||||||
## Completely block removable storage or USB connections
|
## Completely block removable storage or USB connections
|
||||||
|
|
||||||
1. Sign in to the Microsoft Azure portal.
|
1. Sign in to the [Microsoft Azure portal](https://portal.azure.com/).
|
||||||
2. Click **Intune** > **Device configuration** > **Profiles** > **Create profile**.
|
2. Click **Intune** > **Device configuration** > **Profiles** > **Create profile**.
|
||||||
|
|
||||||

|

|
||||||
|
|
||||||
3. Use the following settings.
|
3. Use the following settings:
|
||||||
|
|
||||||
│ Setting │ Value │
|
- Name: Type a name for the profile
|
||||||
│---------│-------│
|
- Description: Type a description
|
||||||
│ Name │ Type a name for the profile │
|
- Platform: Windows 10 or later
|
||||||
│ Description │ Type a description │
|
- Profile type: Device restrictions
|
||||||
│ Platform │ Windows 10 or later │
|
|
||||||
│ Profile type │ Device restrictions │
|
|
||||||
|
|
||||||

|

|
||||||
|
|
||||||
@ -55,3 +53,27 @@ You can also [run a PowerShell script to perform a custom scan](https://aka.ms/s
|
|||||||
7. Click **Create** to save the profile.
|
7. Click **Create** to save the profile.
|
||||||
|
|
||||||
## Allow removable storage or USB connections but block unsigned or untrusted processes from running
|
## Allow removable storage or USB connections but block unsigned or untrusted processes from running
|
||||||
|
|
||||||
|
1. Sign in to the [Microsoft Azure portal](https://portal.azure.com/).
|
||||||
|
2. Click **Intune** > **Device configuration** > **Profiles** > **Create profile**.
|
||||||
|
|
||||||
|

|
||||||
|
|
||||||
|
3. Use the following settings:
|
||||||
|
|
||||||
|
- Name: Type a name for the profile
|
||||||
|
- Description: Type a description
|
||||||
|
- Platform: Windows 10 or later
|
||||||
|
- Profile type: Endpoint protection
|
||||||
|
|
||||||
|

|
||||||
|
|
||||||
|
4. Click **Configure** > **Windows Defender Exploit Guard** > **Attack Surface Reduction**.
|
||||||
|
|
||||||
|
5. For **Unsigned and untrusted processes that run from USB**, choose **Block**.
|
||||||
|
|
||||||
|

|
||||||
|
|
||||||
|
6. Click **OK** to close **Attack Surface Reduction**, **Windows Defender Exploit Guard**, and **Endpoint protection**.
|
||||||
|
|
||||||
|
7. Click **Create** to save the profile.
|
Binary file not shown.
After Width: | Height: | Size: 98 KiB |
Binary file not shown.
After Width: | Height: | Size: 15 KiB |
Reference in New Issue
Block a user