logo
search
Security Policy Errors

Fix Intune USB Control Policy Blocking Allowed Devices

Maira MehtabMaira Mehtab Sep 20, 2026 869 views

Question details

An Intune USB control policy is unexpectedly blocking previously allowed and newly excluded USB removable devices without any recent modifications to the policy.

Product
Microsoft Intune
Device & OS
Windows
Scenario
Managing removable storage access via Microsoft Intune and Microsoft Defender Attack Surface Reduction settings in an enterprise environment.
Observed behavior
Removable devices that were explicitly approved in the exclusion list are now being blocked by default, potentially due to missing GUIDs or a Defender update.
Before you start

Ensure you have administrative access to the Microsoft Endpoint Manager admin center and the Microsoft 365 Defender portal to review device installation logs and modify security policies.

Solution 1Recommended

Review Exclusion Lists and Add Missing Class GUIDs

Verify that the affected device identifiers are still correctly listed in the allow list and update the policy with any missing device class GUIDs found in the logs.

Sometimes the Intune Attack Surface Reduction rules fail to recognize hardware IDs if the specific device class GUID is missing from the configuration.

1
Check the Device Installation Logs

Open the Event Viewer on the affected Windows endpoint, navigate to the device installation logs, and look for entries generated when the blocked USB device is plugged in to identify missing class GUIDs.

2
Review the Removable-Storage Policy

Log in to the Microsoft Endpoint Manager admin center, navigate to Endpoint security, and open your Attack Surface Reduction removable-storage policy.

3
Update the Exclusion List

Confirm that the hardware IDs of the affected devices are present in the exclusion list and add the required class GUIDs identified from the endpoint logs.

4
Save and Sync

Save the updated policy and force a device sync on the affected endpoint to apply the new configuration immediately.

Free Microsoft Office alternative

Looking for a Reliable and Secure Office Suite?

While you manage endpoint security and device access policies, ensure your team has a highly compatible and efficient office suite. WPS Office is a powerful, free alternative to Microsoft Office that is fully compatible with Word, Excel, and PowerPoint files.

  1. 1. Download the Installer: Visit the official WPS Office website and download the free installation package for your operating system.
  2. 2. Deploy on Managed Endpoints: Distribute the lightweight installer across your network without heavily impacting endpoint storage.
  3. 3. Open Existing Documents: Launch WPS Office and open your existing Microsoft Office files with perfect formatting retention.
Seamless format compatibility with Microsoft Office (DOCX, XLSX, PPTX).Lightweight application footprint that performs perfectly on securely managed endpoints.Free to use with a familiar tabbed user interface, requiring zero learning curve.Comprehensive PDF editing tools integrated directly into the suite.
microsoft office alternative - wps office

Frequently Asked Questions

Why are approved USB devices suddenly being blocked by my Intune policy?

This can happen if a recent Microsoft Defender for Endpoint update modified how Attack Surface Reduction rules process removable storage, or if specific device class GUIDs are missing from your Intune exclusion list.

How do I find missing class GUIDs for blocked USB devices?

You can locate missing class GUIDs by reviewing the Windows device installation logs in the Event Viewer on the affected endpoint immediately after plugging in the blocked USB device.

Can I bypass Intune Attack Surface Reduction policies locally for troubleshooting?

Locally bypassing these policies is generally restricted by tamper protection and centralized management. You must modify the policy in the Microsoft Endpoint Manager admin center or place the endpoint in a temporary exclusion group for troubleshooting.