GiliSoft USB Lock Deployment Guide

How to Whitelist USB Devices on Windows

Add approved USB drives to a trusted-device list, export the whitelist once, and import the same policy on other Windows PCs without registering every company drive again.

Allow trusted USB drivesBlock unknown devicesExport and import
GiliSoft USB Lock trusted USB device whitelist interface

Add approved USB drives, then export or import the trusted-device list.

Build One Trusted USB List and Reuse It

This focused guide covers the whitelist task inside GiliSoft USB Lock. It is intended for administrators who need approved company USB drives to work while unknown or personal storage devices remain restricted.

Quick answerOpen USB & CD Lock, insert each approved USB drive and click Add, click Export when the list is complete, then use Import on the other managed PCs.

Before You Start

Collect approved drivesHave every company USB drive available because each one must be connected and added.
Prepare the target PCsInstall USB Lock on the Windows computers that will receive the same trusted-device list.
Choose an admin locationDecide where the exported whitelist file will be stored, named, and backed up.

Add, Export, and Import the USB Whitelist

1

Open USB & CD Lock

Run GiliSoft USB Lock and open USB & CD Lock, where trusted removable-device rules are managed.

2

Insert and add each approved USB drive

Connect one trusted USB drive and click Add. Repeat this action until every approved company drive appears in the whitelist.

3

Export the completed trusted-device list

After checking that the list contains the intended devices, click Export and save the whitelist file in the chosen administrator folder.

4

Import the whitelist on another Windows PC

Open USB Lock on the target computer, return to the whitelist area, click Import, and select the exported list.

Click the interface to enlarge it. Button placement can vary slightly between builds, but the workflow remains Add, Export, and Import.
AddRegister the USB drive that is currently connected.
ExportSave the finished trusted-device list for backup or deployment.
ImportApply an existing trusted-device list on another managed PC.

Verify the Imported Whitelist

Do not assume that an imported list is ready until both an approved device and an unknown device have been tested.

Test an approved USB drive

Connect a device included in the whitelist and confirm that the expected read or write access remains available.

Test an unknown USB drive

Connect a device that is not listed and confirm that it follows the restricted USB policy.

Review the device list

Check that the imported entries match the intended department, room, or workstation group.

Review the activity log

Confirm that allowed and blocked device events are recorded as expected after the test.

Deploy Trusted USB Access Across Multiple PCs

A practical USB whitelist starts with a default restriction for unknown storage devices, then makes specific exceptions for hardware that the organization has reviewed and approved.

Restrict unknown storage

Set the removable-device policy so personal or unapproved USB drives do not receive normal access.

Register trusted drives

Insert each approved company USB drive and add it to the trusted-device list.

Export the approved list

Create one controlled deployment file after the whitelist has been reviewed.

Import and verify

Apply the list on other PCs, then test one approved drive and one unknown drive.

Why identify individual devices? A trusted-device list is more precise than opening every USB port: approved hardware remains usable while unknown removable storage continues to follow the restriction policy.

Choose the Right USB Whitelisting Approach

USB allowlisting can be implemented in several ways. The right choice depends on how many PCs you manage and how much policy infrastructure you already maintain.

ApproachBest suited toWhat administrators manage
Windows native device policyOrganizations already using Group Policy, Intune, or Microsoft security administration.Device identifiers, policy groups, access rules, deployment configuration, and reporting.
Enterprise device-control platformLarger environments that need a central console for many endpoint and peripheral policies.Agents, trusted-device inventories, user or device groups, policy deployment, and event review.
GiliSoft USB LockTeams that want a direct Windows interface for approving drives and reusing the same list on other PCs.Add trusted USB drives, export the completed whitelist, import it on target PCs, and verify access.

For the workflow shown in this guide: GiliSoft USB Lock keeps the task focused on the approved drives and the Windows PCs that need the same list, without requiring administrators to build policy files manually.

Maintain the Trusted USB List

Use a clear file name

Include the department, location, and revision date so administrators can identify the correct whitelist.

Keep the exported file controlled

Store it in an administrator folder instead of leaving deployment files on shared desktops.

Replace retired devices

Remove obsolete entries, add the replacement drive, and export a fresh version of the list.

Redeploy after changes

Import the updated list on the required PCs, then repeat the approved and unknown-device tests.

USB Whitelisting and USB Encryption Solve Different Jobs

Use USB Lock for endpoint control

Choose USB Lock when the computer should allow approved USB devices and restrict unknown removable devices.

Use USB Encryption for protected storage

Choose USB Encryption when the files stored on the USB drive itself need password-protected access.

USB Device Whitelist FAQ

What does a USB device whitelist do?

It keeps approved USB drives available while unknown USB storage devices follow the configured restriction policy.

Can one whitelist contain many USB drives?

Yes. Insert each approved device and click Add until the trusted-device list is complete.

Can I export and import the USB whitelist?

Yes. Export the completed list and import it on other Windows PCs running GiliSoft USB Lock.

Is this the same as encrypting a USB drive?

No. Whitelisting controls device access on the computer; encryption protects the files stored on the drive.

Allow trusted USB drives without opening every PC to unknown devices

Build a reusable trusted-device list, deploy it to managed Windows computers, and keep removable-device policy consistent.

Buy GiliSoft USB Lock