If you use role-based administration:
- You must have the Policy setting -
device control right to edit a device control policy.
- You cannot edit a policy if it is applied
outside your active sub-estate.
For more information, see Managing roles and sub-estates.
- Check which device control policy is used by the group(s) of computers you want to
configure.
- In the Policies pane, double-click Device control. Then double-click the policy you want to change.
- In the Device control policy dialog box, on the Configuration tab, select the Enable device control scanning check box.
- Clear the Detect but do not block devices check box.
-
If you haven’t done so already, change the status of devices you want to block to
“Blocked.” (For details, see Select the applications you want to control.)
-
Click OK.