Device control
Device control is all about protecting your endpoints from devices attached to them. USB attacks continue to be a problem, and you may also have governance needs to restrict access to external storage. We know we need some level of access to devices for productivity and business processes, but that must be balanced with security. In the era of remote work, this is particularly relevant because you are limited in your ability to physically monitor what users are connecting. Device control contributes to endpoint security by giving administrators the ability to control what types of hardware are permitted.
BitLocker and Endpoint DLP can be regarded as device control capabilities but are quite separate from MDE’s scope and aren’t covered in this book. Due to the nature of their access, device control is targeted at client operating systems rather than server operating systems.
Device control is divided into three capabilities:
- Removable storage...