Build One Trusted USB List and Reuse It
This focused guide covers the whitelist task inside GiliSoft USB Lock. It is intended for administrators who need approved company USB drives to work while unknown or personal storage devices remain restricted.
Before You Start
Add, Export, and Import the USB Whitelist
Open USB & CD Lock
Run GiliSoft USB Lock and open USB & CD Lock, where trusted removable-device rules are managed.
Insert and add each approved USB drive
Connect one trusted USB drive and click Add. Repeat this action until every approved company drive appears in the whitelist.
Export the completed trusted-device list
After checking that the list contains the intended devices, click Export and save the whitelist file in the chosen administrator folder.
Import the whitelist on another Windows PC
Open USB Lock on the target computer, return to the whitelist area, click Import, and select the exported list.
Verify the Imported Whitelist
Do not assume that an imported list is ready until both an approved device and an unknown device have been tested.
Test an approved USB drive
Connect a device included in the whitelist and confirm that the expected read or write access remains available.
Test an unknown USB drive
Connect a device that is not listed and confirm that it follows the restricted USB policy.
Review the device list
Check that the imported entries match the intended department, room, or workstation group.
Review the activity log
Confirm that allowed and blocked device events are recorded as expected after the test.
Deploy Trusted USB Access Across Multiple PCs
A practical USB whitelist starts with a default restriction for unknown storage devices, then makes specific exceptions for hardware that the organization has reviewed and approved.
Restrict unknown storage
Set the removable-device policy so personal or unapproved USB drives do not receive normal access.
Register trusted drives
Insert each approved company USB drive and add it to the trusted-device list.
Export the approved list
Create one controlled deployment file after the whitelist has been reviewed.
Import and verify
Apply the list on other PCs, then test one approved drive and one unknown drive.
Choose the Right USB Whitelisting Approach
USB allowlisting can be implemented in several ways. The right choice depends on how many PCs you manage and how much policy infrastructure you already maintain.
| Approach | Best suited to | What administrators manage |
|---|---|---|
| Windows native device policy | Organizations already using Group Policy, Intune, or Microsoft security administration. | Device identifiers, policy groups, access rules, deployment configuration, and reporting. |
| Enterprise device-control platform | Larger environments that need a central console for many endpoint and peripheral policies. | Agents, trusted-device inventories, user or device groups, policy deployment, and event review. |
| GiliSoft USB Lock | Teams that want a direct Windows interface for approving drives and reusing the same list on other PCs. | Add trusted USB drives, export the completed whitelist, import it on target PCs, and verify access. |
For the workflow shown in this guide: GiliSoft USB Lock keeps the task focused on the approved drives and the Windows PCs that need the same list, without requiring administrators to build policy files manually.
Maintain the Trusted USB List
Use a clear file name
Include the department, location, and revision date so administrators can identify the correct whitelist.
Keep the exported file controlled
Store it in an administrator folder instead of leaving deployment files on shared desktops.
Replace retired devices
Remove obsolete entries, add the replacement drive, and export a fresh version of the list.
Redeploy after changes
Import the updated list on the required PCs, then repeat the approved and unknown-device tests.
USB Whitelisting and USB Encryption Solve Different Jobs
Use USB Lock for endpoint control
Choose USB Lock when the computer should allow approved USB devices and restrict unknown removable devices.
Use USB Encryption for protected storage
Choose USB Encryption when the files stored on the USB drive itself need password-protected access.
USB Device Whitelist FAQ
What does a USB device whitelist do?
It keeps approved USB drives available while unknown USB storage devices follow the configured restriction policy.
Can one whitelist contain many USB drives?
Yes. Insert each approved device and click Add until the trusted-device list is complete.
Can I export and import the USB whitelist?
Yes. Export the completed list and import it on other Windows PCs running GiliSoft USB Lock.
Is this the same as encrypting a USB drive?
No. Whitelisting controls device access on the computer; encryption protects the files stored on the drive.