Removable storage file access rules

Prev Next

Removable storage file access rules are used to block executables on plug-in devices from running. They are supported on Microsoft Windows computers only.

Removable storage file access rules block removable storage devices from running applications. You can specify included and excluded devices in the rule. Because some executables, such as encryption applications on encrypted devices, must be allowed to run, the rule includes a File Nameis none of parameter to exempt named files from the blocking rule.

File access rules use true file type and extension to determine which files to block. True file type identifies the file by its internally registered data type, providing accurate identification even if the extension was changed. By default, the rule blocks compressed files (.zip, .gz, .jar, .rar, and .cab) and executables (.bat, .bin, .cgi, .com, .cmd, .dll, .exe, .class, .sys, and .msi). You can customize the file extension definitions to add any file type required.

Note

File access rules also block executable files from being copied to removable storage devices because the file filter driver can’t differentiate between opening and creating an executable.