Restricting Removable Devices on Windows Server 2022

Em 0 Reputation points
2025-10-15T09:48:55.1033333+00:00

Hi,

I have a Windows Server 2022 and i would like to disable the access to removable disks but it doesnt seem to want to work.

Within MMC > Non-administrator policy i have set the pin 'All Removable Storage Classes: Deny all access' to enabled meaning i should not be able to have access to removable devices yet i do. Is there something else i need to set on the server?

I set this same pin on a client PC and it worked fine so I'm not sure why it isn't working on my server.

Any help is appreciated!

Windows for business | Windows Server | Directory services | Deploy group policy objects
{count} votes

2 answers

Sort by: Most helpful
  1. VPHAN 9,355 Reputation points Independent Advisor
    2025-10-15T10:21:49.1666667+00:00

    Hello,

    The policy "All Removable Storage Classes: Deny all access" is working correctly on your client PC because standard users are, by default, subject to these user-based policies. On a Windows Server, however, you are likely logged in as a member of the Administrators group, which can change how these policies are applied.

    The most probable reason the policy isn't taking effect is that administrators are often exempt from these restrictive removable storage policies by design. This is a common security practice to ensure that admins can always perform necessary system recovery or data transfer tasks.

    To resolve this, please follow this two-step verification process:

    Step 1: Confirm Policy Application and Scope

    The policy you configured is located under User Configuration. This means it applies to user accounts, not the computer. Its effectiveness can be overridden by a policy set in Computer Configuration or by your administrative privileges.

    Step 2: Apply the Key "Administrator Exemption" Policy

    To enforce the policy for administrators, you need to explicitly disable the administrator exemption. Here is the official procedure:

    1. In the same Group Policy Object (your "Non-administrator policy"), navigate to: Computer Configuration > Administrative Templates > System > Removable Storage Access
    2. Locate the policy named: "Removable Storage Access: Apply to administrators".
    3. Set this policy to "Disabled". · Enabling it would apply user policies to admins (which you could also do). · Disabling it means the user policies for removable storage do not apply to administrators, which is often the default state. To enforce your rule on admins, you would actually need to Enable this.

    · Start: Goal is to deny removable storage access to all users, including admins.

    · Step 1: Enable "All Removable Storage Classes: Deny all access" in User Configuration.

    · Step 2: Navigate to Computer Configuration and Enable "Removable Storage Access: Apply to administrators".

    · Result: The user policy is now also enforced for administrator accounts.

    After making these changes, run gpupdate /force from an elevated command prompt and log off and back on (or restart) for the policies to take full effect.

    If this solution works for you, please feel free to mark it as "Accept Answer" 🙂

    Best regards,

    VP

    0 comments No comments

  2. VPHAN 9,355 Reputation points Independent Advisor
    2025-10-23T00:55:38.1133333+00:00

    Hi Em,

    Has your issue been solved? If it has, please accept the answer so that others can benefit too. If not, is there anything I can help you with? Please let me know.

    Vivian

    0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.