How to Block Mobile Phones (iPhone/Android) via USB Using Device Control

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements

How to Block Mobile Phones (iPhone/Android) via USB Using Device Control

L0 Member

Hi everyone,

 

I'm currently working on a Device Control policy in Cortex XDR and I need to block mobile phones (iPhones, Android devices, etc.) when they are connected via USB — similar to how USB drives and external disks can be blocked.

I understand that Cortex XDR uses ClassGuid to identify device types (https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-4.x-Documentation/Device-control and https://learn.microsoft.com/en-us/windows-hardware/drivers/install/system-defined-device-setup-class... )

 

My goal is to block phones used for file transfer.

 

Questions:

  1. Is there a recommended way to block mobile phones specifically, without impacting other USB peripherals?
  2. Are there ClassGuids or USB class codes I should be aware of for iPhones and Android devices?
  3. Has anyone successfully implemented this kind of policy and could share best practices?

I am kind of surprise to not find this feature by default.

Thanks in advance for your help!

 

Best regards

1 REPLY 1

L5 Sessionator

Hi @HaddadSteve 

 

You can create your own custom devices using the unique  ClassGuid  for every device. 

Here is how to:

Add a custom device class

(Windows only) You can include custom USB-connected device classes beyond Disk Drive, CD-ROM, Windows Portable Devices, and Floppy Disk Drives, such as USB connected network adapters. When you create a custom device class, you must supply Cortex XDR the official ClassGuid identifier used by Microsoft. Alternatively, if you configured a GUID value to a specific USB connected device, you must use this value for the new device class. After you add a custom device class, you can view it in Device Management and enforce any device control rules and exceptions on this device class.

  1. Go to Endpoints  Policy Management  Settings  Device Management.

    This is the list of all your custom USB-connected devices.

  2. Create the new device class.

    Select +New Device. Set a Name for the new device class, and supply a valid and unique GUID Identifier. For each GUID value, you can define one class type only.

  3. Save.

    The new device class is now available in Cortex XDR as all other device classes.

You can read further at the doc:
https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-3.x-Documentation/Device-control#

 

If you feel this has answered your query, please let us know by clicking like and on "mark this as a Solution". Thank you.

 

KR,

Luis

  • 95 Views
  • 1 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!