Overview
USB removable storage is one of the leading vectors for data exfiltration and malware introduction in enterprise environments. Microsoft Intune's Attack Surface Reduction (ASR) Device Control policies let administrators enforce granular read/write restrictions on removable storage across Windows 10/11 endpoints — without requiring third-party tools.
This guide covers the complete configuration: from creating a Device Control policy in the Intune admin center, selecting the correct ASR profile, configuring Removable Disk deny settings, assigning policies to Entra ID groups, and verifying deployment via PowerShell and the Intune dashboard.



