Prevent any new devices from being installed

  • Section(s): Administration
  • Published on Aug 09, 2006.
  • Last Modified on Aug 09, 2006.
  • Last Modified by Mitch Tulloch.
  • Rated 5 out of 5 based on 1 votes.
Vista can be configured to prevent any new devices from being installed.
While Vista includes new Group Policy settings that let you prevent device installation based on device setup class GUID or PnP device ID, this may not be sufficient in a highly secure environment. If you want to prevent Vista from installing *any* new devices, you can do this using local Group Policy as follows:

1. Type gpedit.msc in the Start Search box and hit Enter.

2. Click Continue when the UAC prompt appears.

3. Navigate to the following policy location:

Computer Configuration\Administrative Templates\System\Device Installation Restrictions

4. Enable the following policy setting:

Prevent installation of devices not described by other policy settings

Note that when this policy setting is enabled it will also prevent existing devices from having their drivers updated. Note also that you can selectively override this policy for specific device setup class GUIDs and PnP device IDs by enabling and configuring the following two policy settings which are found in the same location:

Allow installation of devices using drivers for these device classes

Allow installation of devices that match any of these device IDs.

Cheers,
Mitch Tulloch, MVP
http://www.mtit.com

About Mitch Tulloch

Mitch Tulloch was lead author for the Windows Vista Resource Kit from Microsoft Press, which is the book for IT pros who want to deploy, maintain and support Windows Vista in mid- and large-sized network environments. Mitch was also the author of Introducing Windows Server 2008 and technical project lead for the Microsoft Office Communications Server 2007 Resource Kit, both books also from Microsoft Press. For more information on these and other books by Mitch, see www.mtit.com .

Share this article


Article not looking right or info is missing? Let us know so that we can fix it: .


Receive all the latest articles by email!

Receive Real-Time & Monthly WindowsNetworking.com article updates in your mailbox. Enter your email below!
Click for Real-Time sample & Monthly sample

Become a WindowsNetworking.com member!

Discuss your network issues with thousands of other network administrators. Click here to join!

Community Area

Log in | Register

Readers' Choice

Which is your preferred network administration tool?