Fix Intune USB Control Policy Blocking Allowed Devices
Question details
An Intune USB control policy is unexpectedly blocking previously allowed and newly excluded USB removable devices without any recent modifications to the policy.
- Product
- Microsoft Intune
- Device & OS
- Windows
- Scenario
- Managing removable storage access via Microsoft Intune and Microsoft Defender Attack Surface Reduction settings in an enterprise environment.
- Observed behavior
- Removable devices that were explicitly approved in the exclusion list are now being blocked by default, potentially due to missing GUIDs or a Defender update.
Ensure you have administrative access to the Microsoft Endpoint Manager admin center and the Microsoft 365 Defender portal to review device installation logs and modify security policies.
Review Exclusion Lists and Add Missing Class GUIDs
Verify that the affected device identifiers are still correctly listed in the allow list and update the policy with any missing device class GUIDs found in the logs.
Sometimes the Intune Attack Surface Reduction rules fail to recognize hardware IDs if the specific device class GUID is missing from the configuration.
Open the Event Viewer on the affected Windows endpoint, navigate to the device installation logs, and look for entries generated when the blocked USB device is plugged in to identify missing class GUIDs.
Log in to the Microsoft Endpoint Manager admin center, navigate to Endpoint security, and open your Attack Surface Reduction removable-storage policy.
Confirm that the hardware IDs of the affected devices are present in the exclusion list and add the required class GUIDs identified from the endpoint logs.
Save the updated policy and force a device sync on the affected endpoint to apply the new configuration immediately.
Investigate Microsoft Defender Updates
Check if a recent Microsoft Defender for Endpoint update altered the behavior of removable storage blocking.
Looking for a Reliable and Secure Office Suite?
While you manage endpoint security and device access policies, ensure your team has a highly compatible and efficient office suite. WPS Office is a powerful, free alternative to Microsoft Office that is fully compatible with Word, Excel, and PowerPoint files.
- 1. Download the Installer: Visit the official WPS Office website and download the free installation package for your operating system.
- 2. Deploy on Managed Endpoints: Distribute the lightweight installer across your network without heavily impacting endpoint storage.
- 3. Open Existing Documents: Launch WPS Office and open your existing Microsoft Office files with perfect formatting retention.

Frequently Asked Questions
Why are approved USB devices suddenly being blocked by my Intune policy?
This can happen if a recent Microsoft Defender for Endpoint update modified how Attack Surface Reduction rules process removable storage, or if specific device class GUIDs are missing from your Intune exclusion list.
How do I find missing class GUIDs for blocked USB devices?
You can locate missing class GUIDs by reviewing the Windows device installation logs in the Event Viewer on the affected endpoint immediately after plugging in the blocked USB device.
Can I bypass Intune Attack Surface Reduction policies locally for troubleshooting?
Locally bypassing these policies is generally restricted by tamper protection and centralized management. You must modify the policy in the Microsoft Endpoint Manager admin center or place the endpoint in a temporary exclusion group for troubleshooting.




