USB Whitelisting
Allow specific USB devices while blocking all others.
Overview
By default, the USB Guard blocks all USB mass storage devices. You can whitelist trusted devices by their serial number, vendor ID, or product ID.
Adding a Whitelisted Device
From the Dashboard
- Navigate to USB Devices in the admin dashboard
- Click Add Device
- Enter the device details:
- Vendor ID — USB vendor identifier
- Product ID — USB product identifier
- Serial Number — Unique device serial
- Description — Human-readable label (e.g., "IT Department Backup Drive")
- Save — the device is immediately whitelisted across all endpoints in the tenant
From Alert Data
When a USB device is blocked, the alert includes the device's vendor ID, product ID, and serial number. You can whitelist it directly from the alert.
How Whitelisting Works
When a USB storage device is inserted:
- The USB Guard detects the new device
- It checks the device's serial number against the whitelist
- If whitelisted: device is allowed, an INFO alert is logged
- If not whitelisted: device is blocked/ejected, a CRITICAL alert is generated
Tenant-Scoped Whitelists
USB whitelists are scoped to the tenant. Each organization manages its own list of approved devices. Super admins can view and manage whitelists across all tenants.
Policy-Level Whitelisting
You can also add whitelisted USB serial numbers directly in the policy's USB Guard configuration. This is useful for group-specific whitelists.