USB Storage Device Policies (Allow, Read-Only, Block)

Edit Article

Protect corporate data by controlling removable USB flash drives and external hard drives.

Sentinel Operations Team
5 min read
Updated August 28, 2026
v3.2

USB thumb drives are one of the most common vectors for data leaks and malware infections. Sentinel gives administrators three distinct policy modes to protect corporate endpoints.

USB Policy ModeWhat Happens When USB InsertedBest For
Audit & Log (Default)USB drive mounts normally. Sentinel logs drive model, serial number, and files copied.Standard corporate environments wanting visibility.
Enforce Read-OnlyUser can read/open files from USB, but cannot write or copy corporate files TO the USB.Protecting against data leaks while allowing employees to view presentations.
Block CompletelyUSB storage drives are instantly ejected and unmounted. A desktop warning is shown.High-security environments (Finance, Healthcare, R&D).
Policy Configuration — Application & USB Monitoring
Policy Engine
Policy:Global Corporate Standard v2
Enforced
USB Storage Enforcement
Policy Mode: Read-Only Enforced
Prompt User Alert: Enabled
Log File Copies: Enabled (All Sizes)
Directory Watch Patterns
✓ C:\Users\*\Documents\**
✓ C:\CompanyData\**
✗ Exclude: C:\Windows\**
1USB Storage Control Mode
2Directory Watch Patterns

Figure 2.1: Policy management screen for configuring process whitelists, browser telemetry, and USB block rules.

Tags:#USB Control#DLP#Data Protection#Removable Media

Was this documentation page helpful?

Your technician feedback helps our team continuously improve Sentinel guides.