Application Delivery Management
Application Modernization & Connectivity
CyberRes by OpenText
IT Operations Management
Author: Ravella Raghunadh
Reviewer: Anju Dagliya
An Administrator can choose to restrict the usage of removable media devices such as USB flash drives, CD-ROM, and Floppy Disks within the organization by using one of the following ZENworks Configuration Management features:
################################################################################################################################################
CLASS MACHINE
CATEGORY !!category
CATEGORY !!categoryname
POLICY !!policynameusb
KEYNAME "SYSTEM\CurrentControlSet\Services\USBSTOR"
EXPLAIN !!explaintextusb
PART !!labeltextusb DROPDOWNLIST REQUIRED
VALUENAME "Start"
ITEMLIST
NAME !!Disabled VALUE NUMERIC 3 DEFAULT
NAME !!Enabled VALUE NUMERIC 4
END ITEMLIST
END PART
END POLICY
POLICY !!policynamecd
KEYNAME "SYSTEM\CurrentControlSet\Services\Cdrom"
EXPLAIN !!explaintextcd
PART !!labeltextcd DROPDOWNLIST REQUIRED
VALUENAME "Start"
ITEMLIST
NAME !!Disabled VALUE NUMERIC 1 DEFAULT
NAME !!Enabled VALUE NUMERIC 4
END ITEMLIST
END PART
END POLICY
POLICY !!policynameflpy
KEYNAME "SYSTEM\CurrentControlSet\Services\Flpydisk"
EXPLAIN !!explaintextflpy
PART !!labeltextflpy DROPDOWNLIST REQUIRED
VALUENAME "Start"
ITEMLIST
NAME !!Disabled VALUE NUMERIC 3 DEFAULT
NAME !!Enabled VALUE NUMERIC 4
END ITEMLIST
END PART
END POLICY
POLICY !!policynamels120
KEYNAME "SYSTEM\CurrentControlSet\Services\Sfloppy"
EXPLAIN !!explaintextls120
PART !!labeltextls120 DROPDOWNLIST REQUIRED
VALUENAME "Start"
ITEMLIST
NAME !!Disabled VALUE NUMERIC 3 DEFAULT
NAME !!Enabled VALUE NUMERIC 4
END ITEMLIST
END PART
END POLICY
END CATEGORY
END CATEGORY
[strings]
category="Custom Policy Settings"
categoryname="Restrict Drives"
policynameusb="Disable USB Removable Drives"
policynamecd="Disable CD-ROM"
policynameflpy="Disable Floppy"
policynamels120="Disable High Capacity Floppy"
explaintextusb="Disables the USB Removable Drives capability by disabling the usbstor.sys driver. \n\nSelect the ENABLED radiobox, then select STOPPED for the usbstore.sys driver status in the drop-down list. \n\nNote that this will only prevent usage of newly plugged-in USB Removable Drives or Flash Drives, devices that were plugged-in while this option was not configured will continue to function normally. Also, devices that use the same device or hardware ID (for example - 2 identical Flash Disks made by the same manufacturer) will still function if one of them was plugged-in prior to the configuration of this setting. In order to successfully block them you will need to make sure no USB Removable Drive is plugged-in while you set this option. \n\nIn order to re-enable the usage of USB Removable Drives select STARTED for the usbstore.sys driver status in the drop-down list."
explaintextcd="Disables the CD-ROM Drive by disabling the cdrom.sys driver. \n\nSelect the ENABLED radiobox, then select STOPPED for the cdrom.sys driver status in the drop-down list. \n\nIn order to re-enable the usage of CD-ROM Drives select STARTED for the cdrom.sys driver status in the drop-down list."
explaintextflpy="Disables the Floppy Drive by disabling the flpydisk.sys driver. \n\nSelect the ENABLED radiobox, then select STOPPED for the flpydisk.sys driver status in the drop-down list. \n\nIn order to re-enable the usage of Floppy Drives select STARTED for the flpydisk.sys driver status in the drop-down list."
explaintextls120="Disables the High Capacity Floppy Drive by disabling the sfloppy.sys driver. \n\nSelect the ENABLED radiobox, then select STOPPED for the sfloppy.sys driver status in the drop-down list. \n\nIn order to re-enable the usage of High Capacity Floppy Drives select STARTED for the sfloppy.sys driver status in the drop-down list."
labeltextusb="usbstore.sys driver status"
labeltextcd="cdrom.sys driver status"
labeltextflpy="flpydisk.sys driver status"
labeltextls120="sfloppy.sys driver status"
Enabled="Stopped"
Disabled="Started"
################################################################################################################################################
Create a new Windows Group Policy
For more information on creating Windows Group Policy, see the Novell ZENworks 10 Configuration Management Documentation: Windows Group Policy
Click Add/Remove Templates.
Click on View > Filtering
Deselect the Only show policy settings that can be fully managed option.
In the usbstore.sys driver status option, select Stopped.
Assign the created Group Policy to ZENworks Configuration Management device or users to block the usage of removable media for the assigned users and devices.
For more information on assigning Policies to the devices, see Assigning a Policy to Devices
For more information on assigning Policies to the users, see Assigning a Policy to Users
################################################################################################################################################
Windows Registry Editor Version 5.00
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\USBSTOR]
"Start"=dword:00000004
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom]
"Start"=dword:00000004
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Flpydisk]
"Start"=dword:00000004
################################################################################################################################################
Log in to ZENworks Control Center
Create a new Directive Bundle
For more information on Creating Directive Bundles, see the Novell ZENworks 10 Configuration Management Documentation: Creating Directive Bundles
Add Registry Edit Action to the bundle
For more information on adding the Registry Edit Action, see the Novell ZENworks 10 Configuration Management Documentation: Action - Registry Edit
Browse and import the registry file created in Step 1.
Assign the bundle to ZENworks Configuration Management devices or users to block the usage of removable media for them.
For more information on assigning bundles to the devices, see the Novell ZENworks 10 Configuration Management Documentation: Assigning Existing Bundles to Devices.
For more information on assigning bundles to the users, see the Novell ZENworks 10 Configuration Management Documentation: Assigning Existing Bundles to Users
Launch the bundle. You can choose to configure a distribution or launch schedule for the bundle.
For more information on Bundle Schedules, see the Novell ZENworks 10 Configuration Management Documentation: Bundle Schedules Types
I would like to thank Anju Dagliya for reviewing this cool solution and providing valuable feedback.