{"id":3351,"date":"2026-08-13T04:09:27","date_gmt":"2026-08-13T04:09:27","guid":{"rendered":"https:\/\/zecurit.com\/help\/?post_type=docs&#038;p=3351"},"modified":"2026-08-13T07:48:18","modified_gmt":"2026-08-13T07:48:18","slug":"creating-a-windows-policy","status":"publish","type":"docs","link":"https:\/\/zecurit.com\/help\/endpoint-management\/device-access-control\/creating-a-windows-policy\/","title":{"rendered":"Creating a Windows Policy"},"content":{"rendered":"\n<p>A Device Access Control policy is what actually enforces peripheral restrictions on real devices. It sets an action  Allow, Block, or Not Configured  for each USB and peripheral device type, and applies that setting to every endpoint the profile is assigned to.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">What is a Device Access Control Policy?<\/h2>\n\n\n\n<p>A Device Access Control policy is a profile setting that governs which USB and peripheral device types can be used on managed endpoints. Each device type such as Removable Storage Devices or Bluetooth Adapters  is set to Allow, Block, or Not Configured. The same profile can combine strict settings for high-risk devices with permissive settings for everyday peripherals like mice and keyboards.<\/p>\n\n\n\n<p>The same device type can be treated differently across profiles. For example, one profile could block Removable Storage Devices organization-wide, while a separate, narrower profile allows it only for a specific IT support group.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Create Policy<\/h2>\n\n\n\n<figure class=\"wp-block-image size-large\"><img fetchpriority=\"high\" decoding=\"async\" width=\"820\" height=\"1024\" src=\"https:\/\/zecurit.com\/help\/wp-content\/uploads\/2026\/08\/Windows-Policy-820x1024.webp\" alt=\"\" class=\"wp-image-3418\" srcset=\"https:\/\/zecurit.com\/help\/wp-content\/uploads\/2026\/08\/Windows-Policy-820x1024.webp 820w, https:\/\/zecurit.com\/help\/wp-content\/uploads\/2026\/08\/Windows-Policy-240x300.webp 240w, https:\/\/zecurit.com\/help\/wp-content\/uploads\/2026\/08\/Windows-Policy-768x959.webp 768w, https:\/\/zecurit.com\/help\/wp-content\/uploads\/2026\/08\/Windows-Policy-1230x1536.webp 1230w, https:\/\/zecurit.com\/help\/wp-content\/uploads\/2026\/08\/Windows-Policy-1640x2048.webp 1640w\" sizes=\"(max-width: 820px) 100vw, 820px\" \/><\/figure>\n\n\n\n<ol class=\"wp-block-list\">\n<li>Log in to the <strong>Zecurit portal<\/strong>.<\/li>\n\n\n\n<li> Go to <strong>Endpoint Manager \u2192 Manage \u2192 Profiles<\/strong>. <\/li>\n\n\n\n<li>Click <strong>Create Profile<\/strong>. <\/li>\n\n\n\n<li>Select <strong>Device Access Control<\/strong> from the configuration list.<\/li>\n\n\n\n<li> Configure an action (<strong>Allow, Block, or Not Configured<\/strong>) for each device type under <strong>High Risk Devices<\/strong>, <strong>Network &amp; Communication<\/strong>, and <strong>Standard Peripherals<\/strong>. <\/li>\n\n\n\n<li>Click <strong>Save<\/strong>, then click <strong>Publish<\/strong> to activate the profile. Or click <strong>Save as Draft<\/strong> to finish it later.<\/li>\n<\/ol>\n\n\n\n<p>At least one device type must be set to Allow or Block for the policy to take effect. Device types left on Not Configured are not enforced by this profile.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Policy Details<\/h2>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><thead><tr><th><strong>Field<\/strong><\/th><th><strong>Required<\/strong><\/th><th><strong>Description<\/strong><\/th><\/tr><\/thead><tbody><tr><td>Profile Name<\/td><td>Yes<\/td><td>A descriptive name for the profile (e.g., &#8220;Standard Endpoint Security&#8221;). Shown in Inventory to identify which profile is applied to a device.<\/td><\/tr><tr><td>Device Type Actions<\/td><td>Yes<\/td><td>The Allow \/ Block \/ Not Configured setting chosen for each device type listed under the profile&#8217;s categories.<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<p>A single profile can set Block on some device types and Allow on others. There is no requirement to apply the same action across an entire category.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Device Categories and Actions<\/h2>\n\n\n\n<p><strong>Each device type uses one of three actions:<\/strong><\/p>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><thead><tr><th><strong>Action<\/strong><\/th><th><strong>Effect<\/strong><\/th><th><strong>Best For<\/strong><\/th><\/tr><\/thead><tbody><tr><td>Allow<\/td><td>The device is permitted and functions normally.<\/td><td>Everyday peripherals required for business use, such as mice, keyboards, and printers.<\/td><\/tr><tr><td>Block<\/td><td>The device is denied; Windows prevents it from installing or being used.<\/td><td>High-risk device types where there is no legitimate business need, such as removable storage or optical media.<\/td><\/tr><tr><td>Not Configured<\/td><td>No rule is applied by this profile; the device follows local settings or another assigned profile.<\/td><td>Device types intentionally left to a different, more specific profile or to local policy.<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<p><strong>Device types are grouped into three categories to make large policies easier to review:<\/strong><\/p>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><thead><tr><th><strong>Category<\/strong><\/th><th><strong>Includes<\/strong><\/th><\/tr><\/thead><tbody><tr><td>High Risk Devices<\/td><td>Removable Storage Devices, CD ROM, Windows Portal Devices, TapeDrivers, Apple Devices, Imaging Devices, Floppy Disks<\/td><\/tr><tr><td>Network &amp; Communication<\/td><td>Wireless Adapters, Bluetooth Adapters, Modems, Infrared Devices<\/td><\/tr><tr><td>Standard Peripherals<\/td><td>Mice, Keyboards, Printers, Biometric Devices, Smart Card Readers, Serial Ports, Parallel Ports<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<p>A typical rollout pattern is to leave a new device type on Not Configured while confirming which endpoints actually use it, then move to Block once you&#8217;ve confirmed it has no legitimate business use in your environment.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Publishing vs. Saving as Draft<\/h2>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><thead><tr><th><strong>Option<\/strong><\/th><th><strong>Effect<\/strong><\/th><\/tr><\/thead><tbody><tr><td><br>Save<\/td><td>Saves the profile configuration. You can publish it later.<\/td><\/tr><tr><td>Publish<\/td><td>Activates the policy immediately; enforcement begins on all endpoints the profile is assigned to.<\/td><\/tr><tr><td>Save as Draft<\/td><td>Stores the profile configuration without activating it, so it can be reviewed or completed later.<\/td><\/tr><tr><td>Cancel<\/td><td>Discards changes and exits without saving.<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<h2 class=\"wp-block-heading\">Example Policies<\/h2>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><thead><tr><th><strong>Profile Name<\/strong><\/th><th><strong>Category Focus<\/strong><\/th><th><strong>Action<\/strong><\/th><th><strong>Notes<\/strong><\/th><\/tr><\/thead><tbody><tr><td>Standard Endpoint Security<\/td><td>High Risk Devices<\/td><td>Block<\/td><td>Applied to all corporate laptops and desktops.<\/td><\/tr><tr><td>Kiosk Lockdown<\/td><td>High Risk + Network &amp; Communication<\/td><td>Block<\/td><td>Applied to shared\/kiosk device group only.<\/td><\/tr><tr><td>IT Support Exception<\/td><td>High Risk Devices<\/td><td>Allow<\/td><td>Scoped to the IT support device group only.<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<h2 class=\"wp-block-heading\">Best Practices<\/h2>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Name profiles clearly enough that they&#8217;re identifiable later in Inventory without opening them.<\/li>\n\n\n\n<li>Set high-risk device types (removable storage, optical media, portable devices) to Block by default.<\/li>\n\n\n\n<li>Keep everyday peripherals mice, keyboards, printers, biometric devices  on Allow.<\/li>\n\n\n\n<li>Use a separate, narrowly scoped profile for exceptions rather than loosening the base policy.<\/li>\n\n\n\n<li>Review published profiles periodically, since device usage and risk levels change over time.<\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\">Troubleshooting Tips<\/h2>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><thead><tr><th><strong>Issue<\/strong><\/th><th><strong>Resolution<\/strong><\/th><\/tr><\/thead><tbody><tr><td>Publish button is disabled<\/td><td>Confirm a Profile Name is entered and at least one device type has an action set.<\/td><\/tr><tr><td>Device blocked unexpectedly<\/td><td>Check whether another assigned profile also sets a policy for that device type; Block generally takes precedence over Allow.<\/td><\/tr><tr><td>User reports device still works after Block<\/td><td>Confirm the profile was Published, not left as a draft, and that the device has synced with the endpoint.<\/td><\/tr><tr><td>Draft profile not enforcing<\/td><td>Draft profiles are inactive by design; open the profile and click Publish to activate it.<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<h1 class=\"wp-block-heading\"><\/h1>\n","protected":false},"featured_media":0,"parent":3334,"menu_order":0,"comment_status":"open","ping_status":"closed","template":"","meta":{"_is_vendor_doc":"0","footnotes":""},"doc_tag":[],"class_list":["post-3351","docs","type-docs","status-publish","hentry"],"comment_count":0,"_links":{"self":[{"href":"https:\/\/zecurit.com\/help\/wp-json\/wp\/v2\/docs\/3351","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/zecurit.com\/help\/wp-json\/wp\/v2\/docs"}],"about":[{"href":"https:\/\/zecurit.com\/help\/wp-json\/wp\/v2\/types\/docs"}],"replies":[{"embeddable":true,"href":"https:\/\/zecurit.com\/help\/wp-json\/wp\/v2\/comments?post=3351"}],"version-history":[{"count":17,"href":"https:\/\/zecurit.com\/help\/wp-json\/wp\/v2\/docs\/3351\/revisions"}],"predecessor-version":[{"id":3424,"href":"https:\/\/zecurit.com\/help\/wp-json\/wp\/v2\/docs\/3351\/revisions\/3424"}],"up":[{"embeddable":true,"href":"https:\/\/zecurit.com\/help\/wp-json\/wp\/v2\/docs\/3334"}],"next":[{"title":"Creating a Linux Policy","link":"https:\/\/zecurit.com\/help\/endpoint-management\/device-access-control\/creating-a-linux-policy\/","href":"https:\/\/zecurit.com\/help\/wp-json\/wp\/v2\/docs\/3383"}],"wp:attachment":[{"href":"https:\/\/zecurit.com\/help\/wp-json\/wp\/v2\/media?parent=3351"}],"wp:term":[{"taxonomy":"doc_tag","embeddable":true,"href":"https:\/\/zecurit.com\/help\/wp-json\/wp\/v2\/doc_tag?post=3351"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}