Policy
Turn on device control for specific device types
This policy setting controls which device types, identified by their PrimaryIds, will have device control protection turned on. If you enable this setting for certain device types, device control will regulate access to those devices based on the corresponding custom policy. Device control will be turned off for all other types of supported devices, even if custom protection policies are configured for those devices. This setting currently supports these device types: RemovableMediaDevices, CdRomDevices, WpdDevices, and PrinterDevices. If you enable this policy setting but do not specify any PrimaryIds, device control will be turned off across all supported device types. If you disable or don’t configure this policy setting, device control will be enforced on all supported devicesbased on their corresponding custom policies.
d3466c3b930e DeviceControl_SecuredDevicesConfiguration Registry
Copy registry mappings
HKLM\Software\Policies\Microsoft\Windows Defender\Device Control\SecuredDevicesConfiguration Policy notes
This policy setting controls which device types, identified by their PrimaryIds, will have device control protection turned on. If you enable this setting for certain device types, device control will regulate access to those devices based on the corresponding custom policy. Device control will be turned off for all other types of supported devices, even if custom protection policies are configured for those devices. This setting currently supports these device types: RemovableMediaDevices, CdRomDevices, WpdDevices, and PrinterDevices. If you enable this policy setting but do not specify any PrimaryIds, device control will be turned off across all supported device types. If you disable or don’t configure this policy setting, device control will be enforced on all supported devicesbased on their corresponding custom policies.