Configure Device Control (Windows Computers)

Applies To: WatchGuard EPDR, WatchGuard EPP

In the Device Control settings of a workstations and servers settings profile, you can control the behavior of protected Windows computers when they connect to a removable or mass storage device. You can select the device or devices you want to authorize or block, and specify their usage.

Screen shot of WatchGuard Endpoint Security, Device Control settings

To configure device control:

  1. From the top navigation bar, select Settings.
  2. From the left pane, select Workstations and Servers.
  3. Select an existing security settings profile to edit, copy an existing profile, or in the upper-right corner of the window, click Add to create a new profile.

    The Add Settings or Edit Settings page opens.
  4. Enter a Name and Description for the profile, if required.
  5. Select Device Control.
  6. Enable the Enable Device Control toggle.
  7. For each type of device, specify the authorized use.
  8. Screen shot of WatchGuard Endpoint Security, Device Control authorized usage 

    • Removable Storage Drives and CD/DVD Drives:
      • Block – Computer cannot connect to the drive.
      • Allow read access – Computer can read the drive.
      • Allow read & write access – Computer and read and write to the drive.
    • Bluetooth Devices, Mobile Devices, Imaging Devices, and Modems:
      • Allow – Computer can connect to the device.
      • Block – Computer cannot connect to the device.
  9. In the Allowed Devices section, add devices that you want to allow usage of with no restrictions.
    1. Click .
      The Add Devices dialog box opens.
    2. Select the devices and computers you want to add to the allowlist.
    3. Click Add.
  10. To import a list of computers, click the options menu, and select Import.
    For information on how to create a list of device IDs to import, see Determine the Device Unique ID.
  11. To prevent confusion, you can assign a custom name for a device.
    1. In the Allowed Devices list, select the computer or device.
    2. Click .
    3. Type a new name and click OK.
  12. Click Save.
  13. Select the profile and assign recipients, if required.
    For more information, see Assign a Settings Profile.

See Also

Manage Settings Profiles