Regarding the device control function of XDR

Showing results for 
Show  only  | Search instead for 
Did you mean: 

Regarding the device control function of XDR

L1 Bithead

Hi everyone,


I configured profile to block all types of devices, and called in profile, it works fine.


Now due to work needs, I want to allow specific USB sticks. I know it's possible to configure a global exception to allow a specific USB device, but after I added a USB device to Device Permanent Exceptions, it wasn't allowed.


A pop-up message pops up on the PC that the device is blocked, but I can't find information in Device Control Violations that the USB device is blocked.


Why didn't Device Permanent Exceptions work?


L5 Sessionator

Hi @yuyangab ,


Thank you for reaching out to live community.


Technically, there are multiple mechanisms for whitelisting USB devices. When you are creating device exceptions in temporary and permanent exceptions, you can add exceptions only after the violations as you can create exceptions from violations page only. 

Alternatively, you can create device exceptions profile for specific hosts and add the exceptions to the profiles. 


Assuming, you have configured the policy rules and the exception correctly. Please note that once done, the agent needs to soak the policy rule or even the exception in the policy rule, to allow the exception and it can take upto 5-10 minutes as the agent syncs upto the heartbeat to take the policy rules. As a result, there must have been a delay. Because you did not have the violation and exception working, you might want to check if the agent is connected to the cloud or not.


If it still does not work, you might want to open a support case and get it investigated by our support team. Hope this helps!


Please mark the response as "Accept as Solution" if it answers your query.



  • 1 replies
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!