Project

General

Profile

Actions

Bug #12685

open

New Feature #10636: Windows USB device management

Allowed / denied list of USB devices are not sent in the SyncML payload

Added by Navod Zoysa 4 months ago. Updated 24 days ago.

Status:
QA
Priority:
Critical
Start date:
18/04/2025
Due date:
25/04/2025 (about 2 months late)
% Done:

100%

Estimated time:
20:00 h
Device Type:
Windows
Component:
Type:
Windows
QA Start Time:
QA Due Time:
QA Estimated Time(Hours):

Description

Environment details
6.4.0

Prerequisites
Enrolled Windows device

Steps
  1. Create a Device Installation policy > Device Installation Restrictions > Prevent installation of devices that match any of these device IDs
  2. Add a USB hardware ID (Refer [1] to get the hardware ID) to the deny list and tick Retroactive option
  3. Publish the policy and check if the restriction is applied by inspecting the SyncML payload received on the device or the registry key

Description
When allowing / preventing USB devices the device does not receive the list of inputs added from the policy UI.

A diff of the expected [2] and the actual payload can be viewed here [3]

Result
USB device is not blocked by the policy

[1] - https://techcommunity.microsoft.com/blog/coreinfrastructureandsecurityblog/manage-usb-devices-on-windows-hosts/1691477
[2] - https://learn.microsoft.com/en-us/windows/client-management/mdm/policy-csp-deviceinstallation#preventinstallationofmatchingdeviceids
[3] - https://www.diffchecker.com/fhMymE5M/

Actions #1

Updated by Navod Zoysa 2 months ago

  • Due date set to 25/04/2025
  • Assignee set to Ruwin Dissanayake
  • Start date changed from 27/02/2025 to 18/04/2025
Actions #2

Updated by Ruwin Dissanayake 2 months ago

  • % Done changed from 0 to 80
Actions #3

Updated by Ruwin Dissanayake 2 months ago

  • Status changed from New to QA
  • % Done changed from 80 to 100

https://github.com/entgra-proprietary/emm-proprietary-plugins/pull/168

Please check another admx policy with a list type input and for this policy the registry values can be found here in the windows registry editor "Software\Policies\Microsoft\Windows\DeviceInstall\Restrictions"

Actions #4

Updated by Ruwin Dissanayake about 1 month ago

  • Estimated time set to 20:00 h
Actions #5

Updated by Arshana Atapattu 24 days ago

  • Project changed from product-uem 7.0.0 GA to product-uem 6.5.0 GA
Actions

Also available in: Atom PDF