Policy
Turn on device control for specific device types
Windows 11 25H2
Policy overview
Key metadata and intent for this policy.
Supported OS tags: Windows10, Windows10RT, Windows11, WindowsServer2016
This policy setting controls which device types, identified by their PrimaryIds, will have device control protection turned on. If you enable this setting for certain device types, device control will regulate access to those devices based on the corresponding custom policy. Device control will be turned off for all other types of supported devices, even if custom protection policies are configured for those devices. This setting currently supports these device types: RemovableMediaDevices, CdRomDevices, WpdDevices, and PrinterDevices. If you enable this policy setting but do not specify any PrimaryIds, device control will be turned off across all supported device types. If you disable or don’t configure this policy setting, device control will be enforced on all supported devicesbased on their corresponding custom policies.
Registry values
How enabled and disabled states update the registry.
No explicit registry values are set for enabled or disabled states.
Policy elements
Inputs and configuration options exposed by this policy.
| Element | Type | Registry mapping | Constraints & behavior |
|---|---|---|---|
Turn on device control for specific device types ID DeviceControl_SecuredDevicesConfiguration | text | HKLM\Software\Policies\Microsoft\Windows Defender\Device Control\SecuredDevicesConfiguration Type REG_SZ | None |
Other policies in this category
Explore related policies at the same level.
- ComputerDefine Device Control evidence data remote locationAt least Windows Server 2016, Windows 10 Version 1607
- ComputerDefine device control policy groupsAt least Windows Server 2016, Windows 10 Version 1607
- ComputerDefine device control policy rulesAt least Windows Server 2016, Windows 10 Version 1607
- ComputerSelect Device Control Default Enforcement PolicyAt least Windows Server 2016, Windows 10 Version 1607
- ComputerSet the Azure AD refresh rateAt least Windows Server 2016, Windows 10 Version 1607
- ComputerSet the data duplication limit (MB)At least Windows Server 2016, Windows 10 Version 1607
- ComputerSet the policy refresh rateAt least Windows Server 2016, Windows 10 Version 1607
- ComputerSet the retention period for files in the local device control cacheAt least Windows Server 2016, Windows 10 Version 1607
- ComputerSet up a support link for device control notificationsAt least Windows Server 2016, Windows 10 Version 1607