Adding Override Rules to Removable Storage Controls

Jamf Protect Documentation

Solution
Application
Content Type
Technical Documentation
Utilities & Services
ft:locale
en-US

You can add override rules to a removable storage control set. These rules provide additional flexibility to prevent or allow eligible storage devices based on the following criteria:

  • Encrypted DevicesThe removable storage device's encryption status
  • Product IDThe removable storage device's identifier for an individual product
  • Vendor IDThe removable storage device's identifier for a specific company
  • Serial NumberThe removable storage device's unique identifier

When a removable storage device matches more than one override, the most restrictive override applies.

Important:
  • If you do not configure override rules, the default policy of the removable storage control set is applied to any supported removable storage devices that attempt to mount.

  • Override rules are not supported for SD cards used with internal SDXC card slots or external SD card reader adapters. The default permission configured in the removable storage control set is enforced.

  1. In Jamf Protect, click Device Controls.
  2. Select a Removable Storage Control Set.
  3. In the Total Overrides section, click Add.
  4. Choose a Removable Storage Override Type from the menu.
  5. Click Add.
  6. Configure the Override Details section:
    1. Select a Permission from the menu.
    2. Choose a device encryption option from the pop-up menu to determine which removable storage devices Jamf Protect applies the override permission to:
      • All devices

      • Encrypted devices

      • Unencrypted devices

    3. (Optional) Edit the Local Notification Message.
      Note:

      Local notification messages apply to Prevent and Read Only permission settings based on the selected configuration. If you do not edit the Local Notification Message, one of the following default notification messages is displayed when a user mounts a removable storage device:

      • PreventThis removable storage device is not allowed.
      • Read OnlyThis removable storage device is limited to read-only.
  7. Add list data for storage devices by doing one of the following:
    • Upload CSV FileUpload Vendor IDs and Serial Numbers by a CSV file with one column containing the identifying values. You can upload Product IDs by CSV file with one column containing Vendor IDs and a second column containing Product IDs.
    • Add Text InputAdd Vendor IDs and Serial Numbers by a list of comma separated values. You can add Product IDs one at a time by entering the Vendor ID and Product ID.

    Removable storage devices must be provided in the following formats:

    • Product ID0x1d00
    • Vendor ID0x13fe
    • Serial Number5B6B0B88D431
    Example:

    You can find a USB device's details from the System Report view on your macOS computer.

  8. Click Save.