Create a new Port Protection rule

  1. In the Data Protection policy, go to the right pane, Capabilities & Exclusions > Port Protection.
  2. From the Port Protection Policy list, select one of the following:
    • To allow all the devices, select Allow all.

    • To allow only essential devices, select Allow essential.

      The essential ports for Windows are:

      • Smart Card Readers

      • Keyboard

      • Network Adaptors

      • Modems

      • Mouse

      The essential ports for macOS are:

      Note:

      The device names of macOS ports are prefixed with "MAC_".

      • USB Network

      • USB Video

      • USB HID

      • USB Health

      • USB Audio

      • USB Wireless controller

      • USB SmartCard (Supported only with the Endpoint Security Client version E86.20 and higher.)

      • Bluetooth Audio

      • Bluetooth Computer

      • Bluetooth Health

      • Bluetooth HID

      • Bluetooth Imaging

      • Bluetooth Phone

      • Bluetooth Toy

      • Bluetooth Wearable

      • Printers

    • To customize device settings, click Custom and then click Edit.

  3. Click New.

    The New Port Protection Rule window opens.

  4. Select a device from the list or click New to create a new device (see Managing Devices for details on how to create a new device).
  5. Select the Access Type from the list:
    • Accept - Allow connecting the peripheral device.

    • Block - Do not allow connecting the peripheral device.

  6. In the Log Type field, select the log settings:
    • Log - Create log entries when a peripheral device is connected to an endpoint computer (Action IDs 11 and 20).

    • None - Do not create log entries.

  7. Click Create.