Prevent any new devices from being installed

Written by on Tuesday, January 1, 2008 10:05 - 0 Comments

Vista can be configured to prevent any new devices from being installed.

While Vista includes new Group Policy settings that let you prevent device installation based on device setup class GUID or PnP device ID, this may not be sufficient in a highly secure environment. If you want to prevent Vista from installing *any* new devices, you can do this using local Group Policy as follows:
1. Type gpedit.msc in the Start Search box and hit Enter.

2. Click Continue when the UAC prompt appears.

3. Navigate to the following policy location:

Computer ConfigurationAdministrative TemplatesSystemDevice Installation Restrictions

4. Enable the following policy setting:

Prevent installation of devices not described by other policy settings

Note that when this policy setting is enabled it will also prevent existing devices from having their drivers updated. Note also that you can selectively override this policy for specific device setup class GUIDs and PnP device IDs by enabling and configuring the following two policy settings which are found in the same location:

Allow installation of devices using drivers for these device classes

Allow installation of devices that match any of these device IDs.

Article written by

Comments are closed.

Ad Sponsor


2003 server - Sep 30, 2008 22:34 - 0 Comments

instant messaging srv records

More In Computers & PC

Microsoft Outlook - Mar 22, 2009 11:22 - 0 Comments

Outlook: Duplicates in Mailbox

More In Computers & PC

Microsoft Desktop, Web browsers and Internet, Windows 2000, Windows 7, Windows 98, Windows Firewall and networking, Windows Vista, Windows XP - Feb 8, 2010 18:09 - 0 Comments

Disable Proxy settings in IE

More In Computers & PC