In Symantec Endpoint Protection Small Business Edition (SEP SBE) cloud, USB Device Control enables administrators to prevent malicious code injection and intellectual property theft by controlling employee use of USB removable storage devices. USB mice and keyboards are unaffected by USB Device Control because they do not provide data storage. USB Device Control configuration is part of either a new policy or an existing Endpoint Protection policy. Endpoint Protection policies enable you to enforce the following levels of security over USB storage devices based on groups.
The default Endpoint Protection policy setting for device control allows full access to USB storage devices.
By default, small pop-up notifications on the endpoint are disabled.
Device control restrictions do not apply to servers.
When your policy allows USB devices, all computers in the groups to which the policy applies have complete access to USB storage devices. Allow is the default setting. You may specify read-only access for USB storage devices.
When your policy blocks USB devices, you may enable notifications on the endpoint. The notifications appear as small pop-up messages in the bottom, right-side corner of the endpoint computer. Notifications are off by default.
All blocking events are logged for review and reporting. The blocking events are recorded in a number of locations:
As a line item in the Endpoint Protection widget on the Home page.
As line items on the Computer Profile > Services tab
As individual events that are recorded on Computer Profile > History tab
In the USB Device Control portion of the Endpoint Protection Security Overview report
To configure USB device control in an existing Endpoint Protection policy
In SEP SBE Management Console, click Policies.
On the Policies page, locate the Endpoint Protection policy to modify and double-click it.
In the USB Device Control section, use the drop-down to Allow or to Block access to USB devices.
Use the checkboxes to:
Disable or enable read-write access to the USB storage device.
Only active for the Allow option.
Enable or disable user notification of USB blocking.
Only active for the Block option.
When you are done, click Save and Apply.
Overriding USB Device Control on an endpoint
USB Device Control can temporarily prevent the insertion of a USB thumb drive into a computer by setting a password. This capability reduces the risk of malicious code injection or theft of an organization's intellectual property. This security service can thwart the legitimate efforts of network administrators. Many administrators carry USB storage devices containing management software with them to service the computers on their network.
Best practices suggest that the use of USB devices for software installation is a security risk.
To configure an override password for agent administrators
In SEP SBE Management Console, click Settings and then Computer Settings.
Under Agent Administrator Password, select Use this password for features displaying the lock icon.
Enter the new password and confirm the password.
The agent administrator password can now override USB device controls or uninstall password protection on an endpoint.
This feature enables a trusted administrator to insert and use a USB device in endpoint computers.
To override USB Device Controls on an endpoint
From the notification area on the endpoint computer, open Symantec.cloud Agent.
From the main interface page, click Endpoint Protection.
When the main Endpoint Protection page opens, click the Override USB Device Control option in the right side menu.
Enter the administrator password into the USB Device Control password box when it opens and click OK.
The agent Administrator password provides full access to the inserted USB storage device until you restart the computer.
The administrator's password must be entered and confirmed before the USB device is inserted into the computer. If the USB device is inserted before the password is entered, remove the USB device, reenter the administrator password, then reinsert the USB device.
Subscribing will provide email updates when this Article is updated. Login is required.