<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Should users be allowed to run their USB flash sticks? (Reader submission)</title>
	<atom:link href="http://www.asktheadmin.com/2009/05/should-users-be-allowed-to-run-their-usb-flash-sticks-reader-submission.html/feed" rel="self" type="application/rss+xml" />
	<link>http://www.asktheadmin.com/2009/05/should-users-be-allowed-to-run-their-usb-flash-sticks-reader-submission.html</link>
	<description></description>
	<lastBuildDate>Fri, 03 Feb 2012 06:08:50 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3</generator>
	<item>
		<title>By: Karl L. Gechlik &#124; AskTheAdmin.com</title>
		<link>http://www.asktheadmin.com/2009/05/should-users-be-allowed-to-run-their-usb-flash-sticks-reader-submission.html/comment-page-1#comment-10197</link>
		<dc:creator>Karl L. Gechlik &#124; AskTheAdmin.com</dc:creator>
		<pubDate>Tue, 05 May 2009 18:17:40 +0000</pubDate>
		<guid isPermaLink="false">http://www.asktheadmin.com/?p=1938#comment-10197</guid>
		<description>Thanks Aaron - if you are ever itching to blog. We would love to have you write some guest posts on your enviroment! Thanks for reading.</description>
		<content:encoded><![CDATA[<p>Thanks Aaron &#8211; if you are ever itching to blog. We would love to have you write some guest posts on your enviroment! Thanks for reading.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Aaron</title>
		<link>http://www.asktheadmin.com/2009/05/should-users-be-allowed-to-run-their-usb-flash-sticks-reader-submission.html/comment-page-1#comment-10195</link>
		<dc:creator>Aaron</dc:creator>
		<pubDate>Tue, 05 May 2009 14:43:43 +0000</pubDate>
		<guid isPermaLink="false">http://www.asktheadmin.com/?p=1938#comment-10195</guid>
		<description>Sure

Basically the same as you have listed, but with a couple of additions for the overkill feature :)
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\UsbStor
Start = 4
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\StorageDevicePolicies
WriteProtect = 1

Then I also stopped and disabled the &quot;Removable Storage&quot; service.

Also I assigned the deny permission to all users including the system account (since the machine will use system if no user is logged on yet) on the files usbstor.inf and usbstor.pnf in the C:\Windows\INF folder to prevent initial installation.

For removing CD burning features I added group policy &quot;User Config / Admin Temp / Windows Components/Windows Explorer / Remove CD Burning features&quot; and ensured that no burning software such as Nero, etc is installed.

MS also has this KB for group policy template which I have not tried yet.
http://support.microsoft.com/default.aspx?scid=kb;en-us;555324</description>
		<content:encoded><![CDATA[<p>Sure</p>
<p>Basically the same as you have listed, but with a couple of additions for the overkill feature :)<br />
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\UsbStor<br />
Start = 4<br />
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\StorageDevicePolicies<br />
WriteProtect = 1</p>
<p>Then I also stopped and disabled the &#8220;Removable Storage&#8221; service.</p>
<p>Also I assigned the deny permission to all users including the system account (since the machine will use system if no user is logged on yet) on the files usbstor.inf and usbstor.pnf in the C:\Windows\INF folder to prevent initial installation.</p>
<p>For removing CD burning features I added group policy &#8220;User Config / Admin Temp / Windows Components/Windows Explorer / Remove CD Burning features&#8221; and ensured that no burning software such as Nero, etc is installed.</p>
<p>MS also has this KB for group policy template which I have not tried yet.<br />
<a href="http://support.microsoft.com/default.aspx?scid=kb;en-us;555324" rel="nofollow">http://support.microsoft.com/default.aspx?scid=kb;en-us;555324</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Karl Gechlik</title>
		<link>http://www.asktheadmin.com/2009/05/should-users-be-allowed-to-run-their-usb-flash-sticks-reader-submission.html/comment-page-1#comment-10194</link>
		<dc:creator>Karl Gechlik</dc:creator>
		<pubDate>Tue, 05 May 2009 14:13:36 +0000</pubDate>
		<guid isPermaLink="false">http://www.asktheadmin.com/?p=1938#comment-10194</guid>
		<description>Care to share the keys with us you used to block burning?</description>
		<content:encoded><![CDATA[<p>Care to share the keys with us you used to block burning?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Aaron</title>
		<link>http://www.asktheadmin.com/2009/05/should-users-be-allowed-to-run-their-usb-flash-sticks-reader-submission.html/comment-page-1#comment-10193</link>
		<dc:creator>Aaron</dc:creator>
		<pubDate>Tue, 05 May 2009 14:03:29 +0000</pubDate>
		<guid isPermaLink="false">http://www.asktheadmin.com/?p=1938#comment-10193</guid>
		<description>We use the registry to block all USB Memory sticks. Only users with a need such as a camera for work related pictures have it opened. We also disable CD burning, although CD read is still open for all.</description>
		<content:encoded><![CDATA[<p>We use the registry to block all USB Memory sticks. Only users with a need such as a camera for work related pictures have it opened. We also disable CD burning, although CD read is still open for all.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: chugger</title>
		<link>http://www.asktheadmin.com/2009/05/should-users-be-allowed-to-run-their-usb-flash-sticks-reader-submission.html/comment-page-1#comment-8646</link>
		<dc:creator>chugger</dc:creator>
		<pubDate>Mon, 04 May 2009 08:01:14 +0000</pubDate>
		<guid isPermaLink="false">http://www.asktheadmin.com/?p=1938#comment-8646</guid>
		<description>Dude, this is brilliant. Thanks!!</description>
		<content:encoded><![CDATA[<p>Dude, this is brilliant. Thanks!!</p>
]]></content:encoded>
	</item>
</channel>
</rss>

<!-- Performance optimized by W3 Total Cache. Learn more: http://www.w3-edge.com/wordpress-plugins/

Minified using disk
Page Caching using disk (enhanced)

Served from: www.asktheadmin.com @ 2012-02-10 01:38:26 -->
