USB Control – Recommended Deployment Workflow
1.Description
2.Recommendation
3.Procedure
4.Troubleshooting
Description
This article describes the recommended deployment workflow for the USB Control module in Heimdal. Following this approach helps ensure full device visibility and prevents unintended blocking caused by incomplete device whitelisting.
Recommendation
It is recommended to initially configure USB Control in Reporting Mode before enabling restrictions. This allows all USB device instances to be discovered and reviewed prior to enforcement.
Procedure
Step 1 – Enable Reporting Mode
Go to:
Endpoint Settings → Group Policies → [Select Policy] → USB Settings
Set USB Mode to Reporting Mode
Click Save on the Group Policy
Expected behavior:
All connected USB devices are detected
The system enumerates all device entries and iterations (including different instances generated by ports, drivers, or connection contexts)
Device data is reported to the Heimdal Dashboard
Step 2 – Review Device Entries
After a monitoring period:
Access the Heimdal Dashboard
Navigate to the USB Control Management section:
Review all detected device entries
Important:
A single physical USB device may generate multiple entries (enumerations) in the system.
Each of these entries represents a different instance of the same device.
Step 3 – Whitelist Required Device Entries
Identify all required USB devices
Add all associated entries (enumerations) of each device to the Allowed Devices (Whitelist)
Key point:
If not all related entries of a device are whitelisted, the device may be partially or fully blocked when restrictions are applied.
Step 4 – Enable Restrictive Mode
Once the whitelist is complete:
Change USB Mode to Restrictive Mode
Click Save on the Group Policy
Result:
Only whitelisted device entries are allowed
All other USB devices are blocked
Important Notes
Reporting Mode is recommended to ensure complete device discovery before enforcing restrictions
When Restrictive Mode is enabled, Reporting Mode is no longer available (option is greyed out)
Incomplete whitelisting of device entries may lead to unintended blocking of otherwise valid devices
For a controlled deployment:
Reporting Mode → Full Device Enumeration → Complete Whitelisting (all entries) → Restrictive Mode
Troubleshooting – Device still blocked after whitelisting
If a USB device is still blocked after being added to the Allowed Devices (Whitelist), consider the following:
1. Incomplete Device Enumeration
The most common cause is that not all device entries (enumerations) were whitelisted.
Explanation:
A single physical USB device may generate multiple entries in the system (different ports, drivers, or connection contexts).
Action:
Go to the USB reporting section in the Dashboard
Identify all entries related to the device
Ensure all associated entries are added to the Allowed Devices (Whitelist)
2. Policy Not Applied on Endpoint
The updated Group Policy may not yet be applied on the endpoint.
Action:
Verify the endpoint is online
Check if the policy was successfully updated
Trigger a policy refresh if needed
3. Device Reconnected on Different Port
Reconnecting the device to a different USB port may generate a new enumeration.
Action:
Recheck the device in Reporting data
Whitelist any newly generated entries
4. Reporting Mode Not Used Before Restrictive Mode
If Restrictive Mode was enabled without prior use of Reporting Mode, some device entries may not have been discovered.
Action:
Temporarily switch back to Reporting Mode (if operationally possible)
Allow time for full device enumeration
Update the whitelist accordingly
Re-enable Restrictive Mode
5. Policy Configuration Review
Ensure no conflicting settings are impacting USB behavior.
Action:
Review USB Settings in the Group Policy
Confirm the correct policy is assigned to the endpoint
Additional Recommendation
Always allow sufficient time in Reporting Mode to capture all device variations before enabling restrictions.