Thursday, March 23, 2017

Device installation restrictions only work on not-yet-installed devices

I was helping someone tweak the Registry to configure device installation restrictions and we hit a snag. Even though the Registry settings were exactly as they should have been, the restricted devices were not disallowed, even on Pro editions where the Group Policy infrastructure is definitely there.

Eventually I found this Microsoft guide that mentions that devices should be uninstalled for these restrictions to work reliably. As the question author discovered, the devices' drivers don't have to be removed, but the devices themselves definitely should. The restrictions only take effect at install time, not plug-in time.

No comments:

Post a Comment