logo
search
Security Policy Errors

Fix Intune ASR Policy Not Blocking USB Storage on Windows

Maira MehtabMaira Mehtab Sep 27, 2026 869 views

Question details

Users need to resolve an issue where an Intune Attack Surface Reduction policy is successfully applied, but USB storage remains accessible.

Product
Microsoft Intune
Device & OS
Windows
Scenario
Enforcing USB storage blocking via Intune ASR policies on hybrid Microsoft Entra devices.
Observed behavior
The policy reports as applied in the Intune portal, but users can still access USB storage despite the configured Windows Portable Devices restrictions.
Before you start

Ensure you have administrator access to the Microsoft Endpoint Manager admin center and gather the affected device's synchronization logs before proceeding.

Solution 1Recommended

Gather Diagnostics and Consult Microsoft Q&A Specialists

Because this involves complex ASR rules in a hybrid Entra environment, escalating to Microsoft Intune specialists with detailed diagnostics is the most effective approach.

In hybrid environments, overlapping Group Policy Objects (GPOs) or hidden configuration conflicts can cause Intune policies to report as applied while failing to enforce locally.

1
Document the Policy Details

Log into the Microsoft Endpoint Manager admin center, navigate to the specific ASR policy, and document the configured Windows Portable Devices rule, policy targeting, and licensing.

2
Gather Device Information

Note the affected machine's exact Windows version, device sync status in Intune, and confirm its hybrid Microsoft Entra join state.

3
Navigate to Microsoft Q&A

Go to the Microsoft Q&A website and log in with your administrator Microsoft account.

4
Post in the Intune Topic

Click 'Ask a question', apply the 'Microsoft Intune' tag, and provide all gathered details so specialists can investigate why the policy has no effect and advise on creating a proper allowlist.

Free Microsoft Office alternative

Need a Lightweight Office Suite for Managed Devices?

While troubleshooting Intune and Windows device management policies, consider deploying WPS Office. It's a comprehensive, free, and highly compatible Office suite that integrates seamlessly into corporate environments, saving on licensing costs while keeping your teams productive.

  1. 1. Visit the official website: Go to the official WPS Office website to access the standard or enterprise installers.
  2. 2. Download the package: Click 'Download' to get the lightweight installation file suitable for your Windows environment.
  3. 3. Deploy to devices: Use your endpoint management tool, such as Microsoft Intune, to deploy the package to your managed corporate devices.
Fully compatible with Microsoft Office formats (.docx, .xlsx, .pptx).Lightweight installation ideal for devices with strict storage or ASR security policies.Cost-effective alternative to expensive enterprise Office subscriptions.Familiar user interface requiring zero learning curve for seamless migration.
microsoft office alternative - wps office

Frequently Asked Questions

Why does my Intune ASR policy show as 'Applied' but doesn't block USB storage?

The 'Applied' status indicates that the policy successfully reached the device, but it might fail to enforce locally due to conflicting Device Control profiles, overlapping on-premises GPOs, or unsupported OS versions for that specific rule.

How do I block USB storage access using Microsoft Intune?

You can block USB storage by configuring an Attack Surface Reduction (ASR) policy or a Device Control profile in the Microsoft Endpoint Manager admin center, setting the 'Windows Portable Devices' restrictions to block read and write access.

What details should I provide when asking for help on Microsoft Q&A regarding Intune?

Always include your tenant's licensing level, your admin permissions, policy targeting groups, device sync status, OS build, and the specific Windows Portable Devices rule configuration.

Can hybrid Microsoft Entra joins cause Intune policy conflicts?

Yes, hybrid setups synchronize both on-premises Active Directory Group Policy Objects (GPOs) and Intune MDM policies. If they conflict over USB permissions, it can lead to unexpected behaviors or enforcement failures.