公司 IT 管理员面临的最大挑战之一是阻止对组织设备的访问,例如USB、外部硬盘驱动器(External Hard Drive),甚至打印机。为了使这更容易一点,微软(Microsoft)推出了分层组策略功能(Layered Group Policy feature),使管理员能够划分可以在整个组织的机器上安装哪些设备。
什么是Windows 11中的分层组策略(Group Policy)?
该组策略(Group Policy)旨在确保机器减少损坏,减少支持案例的数量,最重要的是减少数据盗窃。该策略确保限制任何安装,即禁止在内部和外部环境中使用设备。IT 管理员可以选择对要使用/安装的设备进行预授权。
在此处可用(Available),该脚本确保并非所有类都被阻止:
Computer Configuration > System > Device Installation > Device Installation Restrictions
这意味着如果您选择阻止USB设备的使用,它只会阻止它。向前迈进了一步,新功能解决了之前需要创建多个集合以避免冲突的问题。相反,您具有分层分层Instance ID > Device ID > Class > Removable设备属性。
如何在Windows 11中应用(Windows 11)分层组策略(Layered Group Policy)
您需要启用的第一个策略是 —在所有设备匹配标准中应用允许和阻止设备安装策略的分层评估顺序(Apply layered order of evaluation for Allow and Prevent device installation policies across all device match criteria)。
完成后,还有一组额外的策略,您需要确保牢记分层顺序(设备(Device)实例IDs > Device IDs > Device设置类> Removable设备)。以下是与每个相关的政策:
设备实例 ID
- 阻止(Prevent)使用与这些设备实例ID匹配的驱动程序安装设备(IDs)
- 允许(Allow)使用与这些设备实例ID(IDs)匹配的驱动程序安装设备。
设备 ID
- 阻止(Prevent)使用与这些设备 ID 匹配的驱动程序安装设备
- 允许(Allow)使用与这些设备 ID 匹配的驱动程序安装设备
设备设置类
- 阻止(Prevent)使用与这些设备安装类匹配的驱动程序安装设备
- 允许(Allow)使用与这些设备安装类匹配的驱动程序安装设备。
可卸除的设备
(Configure)通过添加设备 ID 或类 ID 来配置它们中的每一个并应用更改。
(Microsoft)由于分层结构,Microsoft建议使用此策略而不是“阻止安装其他策略设置未描述的设备”策略设置。(Prevent installation of devices not described by other policy settings)
如何找到硬件 ID(Hardware ID)或兼容 ID?
- 使用Win + X打开设备管理器(Device Manager),然后按 M。
- 找到设备。右键单击它,然后选择属性
- 切换到详细信息选项卡
- 单击(Click)属性(Property)下拉菜单,您可以在此处选择硬件 ID、类 ID 和其他详细信息。确切的值将在值部分中提供。
如何将设备 ID(Device IDs)添加到允许(Allow)列表?
- 打开策略 -允许安装与任何这些设备 ID 匹配的设备(Allow installation of devices that match any of these device IDs)。
- 选择 Enabled(Select Enabled),然后单击Options 下的Show按钮。(Show)
- 将兼容 ID(Add Compatible ID)或硬件 ID(Hardware ID)添加到列表中
- 应用更改。
您还可以使用阻止(Prevent)安装策略阻止安装特定设备。
如何允许管理员覆盖设备安装限制?
您可以启用一个特定于此的策略。启用后,管理员(Administrators)组的成员可以使用添加硬件(Add Hardware)向导或更新驱动程序向导来安装和更新设备。
如何设置超时以强制执行策略更改?
如果要强制执行策略更改,则需要重新启动。设置允许您设置显示给最终用户的重新启动超时(Timeout),以确保没有数据丢失。
我希望这篇文章向您清楚地解释了Windows 11中的(Windows 11)分层组策略(Layered Group Policy)。
该策略(The policy)还作为2021 年 7 月(July 2021)可选“C”客户端版本 的一部分在Windows 10中提供,并将在(Windows 10)2021 年 8 月(August 2021)更新星期二(Update Tuesday)版本开始更广泛地提供。
How to apply Layered Group Policy in Windows 11/10
One of the biggest challenges for аn IT admin in a company іs to block acсess to devices such as USB, External Hard Drive, and even Printers to the organization’s devісes. To makе this a little easier, Microsoft has rolled out the Layered Group Policy feature that gives administrators the ability to divide which devices can be installed on machines across the organization.
What is Layered Group Policy in Windows 11?
This Group Policy aims to ensure the machines get less corruption, the number of support cases drops, and the most important is to reduce data theft. The policy ensures to restrict any installation, i.e., the use of devices both in the internal and external environment is blocked. IT admins can choose to pre-authorized devices to be used/installed.
Available here, the script makes sure not all classes are blocked:
Computer Configuration > System > Device Installation > Device Installation Restrictions
this means that if you chose to block the USB device usage, it only blocks it. Going one step ahead, the new feature resolves the earlier problem where several sets need to be created to avoid conflict. Instead, you have hierarchical layering Instance ID > Device ID > Class > Removable device property.
How to apply Layered Group Policy in Windows 11
The first policy you need to enable is — Apply layered order of evaluation for Allow and Prevent device installation policies across all device match criteria.
Once done, there are an additional set of policies, and you need to ensure to keep the hierarchical order (Device instance IDs > Device IDs > Device setup class > Removable devices) in mind. Here are the policies related to each:
Device instance IDs
- Prevent installation of devices using drivers that match these device instance IDs
- Allow installation of devices using drivers that match these device instance IDs.
Device IDs
- Prevent installation of devices using drivers that match these device IDs
- Allow installation of devices using drivers that match these device IDs
Device setup class
- Prevent installation of devices using drivers that match these device setup classes
- Allow installation of devices using drivers that match these device setup classes.
Removable devices
- Prevent installation of removable devices
Configure each of them by adding the device id or class ID and apply the changes.
Microsoft recommends using this policy over the “Prevent installation of devices not described by other policy settings” policy setting because of the layered structure.
How to find the Hardware ID or Compatible ID?
- Open Device Manager using Win + X, followed by pressing M.
- Locate the device. Right-click on it, and then select Properties
- Switch to the Details tab
- Click on the Property dropdown, and here you can select hardware ID, class ID, and other details. The exact value will be available in the value section.
How to add Device IDs to the Allow list?
- Open the policy— Allow installation of devices that match any of these device IDs.
- Select Enabled, and then click on the Show button under Options.
- Add Compatible ID or Hardware ID to the list
- Apply the changes.
You can also block the installation of specific devices by using the Prevent installation policies.
How to allow administrators to override device installation restrictions?
There is a policy specific to this which you can enable. Once enabled, members of the Administrators group can use the Add Hardware wizard or the update driver wizard to install and update the device.
How to set up a timeout to enforce policy change?
If you want to enforce the policy change, you need to reboot. A setting allows you to set up a Reboot Timeout displayed to the end-user to make sure there is no data loss.
I hope the post explained to you clearly about the Layered Group Policy in Windows 11.
The policy is also available in Windows 10 as part of the July 2021 optional “C” client release and will be made more broadly available beginning in the August 2021 Update Tuesday release.