Windows USB Write-Control Guide

How to Prevent Copying Files to a USB Drive

Stop files leaving a Windows PC through unknown USB drives while keeping read access, approved company media, and everyday USB peripherals available.

  • Block creating, editing, deleting, and copying files on USB storage
  • Keep USB reading or approved writable drives when required
  • Control phone transfer, SD cards, and other removable media separately
GiliSoft USB Lock settings for preventing files from being copied to USB drives
GiliSoft USB Lock

Block USB Writing, Not Every USB Device

Quick answerTo prevent PC-to-USB copying, deny write access to removable disks. Users can still open files already stored on the drive, while Windows blocks new files, edits, renames, deletions, and other write operations.

Disabling USB ports is usually broader than the job requires. Keyboards, mice, printers, security keys, and other peripherals also use USB. A write-control rule targets removable storage instead, so the computer can keep its required peripherals and, when appropriate, continue reading approved material from a drive.

Read-only USBUsers may open existing files but cannot place company files on the drive.
Unknown drives blockedUnregistered storage cannot receive files; approved company drives remain writable.
No removable storageUse a broader read-and-write block only where USB storage has no approved purpose.

Confirm the Copy Direction Before Applying a Rule

What you need to stopCorrect controlExpected result
USB to PCDeny read accessUsers cannot open, import, or copy files from the removable drive.
Both directionsDeny all removable-storage accessThe drive may remain visible, but file access is rejected.
Only named company drivesTrusted-device whitelistApproved media works while unknown drives remain restricted.
Write access covers more than drag-and-drop. Test Save As, application exports, archive creation, file synchronization, rename, modify, and delete operations. Each writes data or metadata to the USB drive.

Compare Ways to Stop PC-to-USB File Copying

OptionBest fitApproved-drive supportAdministration
Removable Disks: Deny write accessA uniform read-only rule on supported Windows editionsNot by itselfLocal or domain Group Policy; MDM policy is also available
Microsoft Defender Device ControlManaged fleets needing device groups, user conditions, and granular permissionsYesRequires eligible licensing and policy administration
BitLocker-protected removable drivesOrganizations that allow writing only to encrypted company mediaBy encryption status rather than a simple whitelistUseful with managed encryption and recovery-key procedures
Method 1: GiliSoft USB Lock

Prevent File Copying and Keep Approved USB Drives Writable

  1. Install USB Lock, create the administrator password, and set password-recovery information.
  2. Open the USB and CD/DVD controls and apply the USB storage write restriction required by the PC.
  3. Insert each verified company drive that must remain writable and add it to the trusted-device whitelist.
  4. Reconnect an unknown drive and try drag-and-drop, Save As, rename, delete, archive output, and command-line copying.
  5. Open an existing file from the unknown drive to confirm read access still works when a read-only policy is intended.
  6. Reconnect an approved drive, verify normal writing, and review the access log for allowed and blocked attempts.
  7. Export the tested whitelist before applying the same device list to additional computers.
GiliSoft USB Lock USB storage write-control settings
Apply storage restrictions without disabling keyboards, mice, printers, and other non-storage USB peripherals.
GiliSoft USB Lock trusted USB drive whitelist
Register verified company drives that are allowed to receive files.
GiliSoft USB Lock access log
Review blocked and allowed device activity after testing the policy.
Method 2: Windows Group Policy

Set Removable Disks to Deny Write Access

On supported Windows editions, open gpedit.msc and navigate to Computer Configuration > Administrative Templates > System > Removable Storage Access. Enable Removable Disks: Deny write access.

  1. Open Local Group Policy Editor with administrator rights.
  2. Open the Removable Storage Access policy folder.
  3. Enable Removable Disks: Deny write access and apply the change.
  4. Run gpupdate /force, reconnect the drive, and test the full set of write operations.
  5. On managed PCs, use gpresult when the rule is missing or another domain policy overrides it.
This method is best for one consistent rule. If selected company drives must remain writable while unknown drives become read-only, use a trusted-device workflow or enterprise device-control policy.
Method 3: enterprise device policy

Allow Write Access Only to Approved USB Drives

Microsoft Defender Device Control can organize devices into groups and apply read, write, or execute permissions by device, user, or machine. A common company design is to make unknown removable storage read-only, then create an allow rule for registered corporate drives that need write access.

  • Identify approved drives by stable device properties rather than a drive letter.
  • Apply the broad read-only rule before adding the narrower writable-device exception.
  • Test the rule as a normal employee account, not only as an administrator.
  • Manage phones, SD cards, cameras, and optical media as separate transfer channels.
  • Document the owner, purpose, and review date for every writable-device exception.
GiliSoft recommendation

Stop USB Copying Without Building Complex Policy Files

GiliSoft USB Lock combines USB and SD storage control, trusted-drive whitelisting, Android and iPhone transfer rules, tethering restrictions, CD/DVD controls, password-protected settings, and access records in one Windows application. It is well suited to offices, shared computers, front-desk PCs, classrooms, and other environments where unknown drives should not receive files.

GiliSoft USB Lock software box

GiliSoft USB Lock

Use the trial on a representative PC and verify unknown media, approved drives, required peripherals, phones, and SD cards before wider deployment.

Need rollout support?

GiliSoft provides volume licensing, OEM options, and custom development for organizations with specific USB-control or deployment requirements.

Contact sales@gilisoft.com

Test More Than Drag-and-Drop

Related USB Copy-Control Guides

Prevent Copying Files to USB FAQ

Can I stop users copying files to USB but still let them read the drive?

Yes. Deny write access while leaving read access enabled. Users can open existing USB files, but cannot save new files or changes to the drive.

Does deny write access also block deleting or editing files on the USB drive?

Yes. Editing, renaming, overwriting, and deleting all change data or metadata on the drive and should be rejected by a working write restriction.

Can selected company USB drives remain writable?

Yes. Add verified company drives to a trusted-device whitelist, or use enterprise device groups to create a narrower write-allow exception.

Will USB write blocking disable keyboards, mice, or printers?

No, not when the rule targets removable storage rather than the USB host controller. Test all required peripherals after deployment.

Is the Removable Disks: Deny write access policy available on Windows Home?

The Local Group Policy Editor is normally available on Pro, Enterprise, and Education editions, not Windows Home. USB Lock provides a direct interface across supported Windows editions.

Can phone transfer and SD cards bypass a USB flash-drive rule?

They may use different device or transfer classes. Set and test separate controls for phones, SD cards, cameras, tethering, and optical media.

Official References

Stop unknown USB drives from receiving company files

Keep the Windows peripherals and approved storage your work requires, while blocking unapproved PC-to-USB copying.