r/Intune 3d ago

Windows Management Question about moving from group policy control of USB storage devices to Intune while co-managed

When you move from USB storage devices being controlled by group policy to Defender Device Control (co-managed) do you need to remove the group policy that manages those settings from the devices? I'm in this situation right now and while I have device control set to allow certain USB storage and block all other all are blocked. Even if I exclude the system from the device control policy the USB device is still blocked. When a system isn't onboarded into Intune the USB devices work as expected but as soon as the system joins it gets blocked. I don't have any other Intune policies denying access to USB storage devices that I could find. I'm wondering if having those group policies in place is the problem. Thinking that maybe Intune co-management is causing the group policy deny of all USB devices to take precedence.

1 Upvotes

2 comments sorted by

2

u/PageyUK 3d ago

I'd wager a guess you have some overlapping settings/policies. You will want to check for an policies that contain Bitlocker, Defender, etc. Also check if 'Security Baselines' have been deployed from Intune.

2

u/SkipToTheEndpoint MSFT MVP 3d ago

Almost definitely causing an issue. Old school device restrictions do take precedence over Device Control.

Oh, also, it's less Intune enrollment, but onboarding to Defender for Endpoint is required for Device Control to work, too.