Skip to main content
USB monitoring rules let you alert on, block, or gate-by-approval specific USB device classes on Windows and macOS Clients. This page covers the full rule lifecycle — adding, editing, deleting — plus the two related tasks you’ll use frequently: defining exceptions for individual devices, and finding a device’s Hardware ID. For the conceptual overview, the list of device classes available, and the difference between automatic and rule-based monitoring, see USB Device Monitoring & Blocking.
Rules can only be added, edited, or deleted by a user with the administrative Client Installation and Management permission.

Add a USB monitoring rule

1

Open the USB Devices page

Sign in to the Management Tool, click USB Devices in the left navigation, then click Add in the top right.
2

Set the rule properties

On the USB Rule Properties tab:
  • Select Enable USB rule to enable the rule.
  • Enter a unique Name for the rule.
  • Optionally enter a Description.
  • Select the required Risk Level.
Click Next.
3

Choose the device classes and exceptions

On the Rule Conditions tab, select the device classes to monitor in the Monitored Devices list. See the device class reference for what each class covers.
Only Mass storage devices and Vendor-specific devices are currently supported for macOS Clients.
Then add exceptions for any individual devices that should remain usable, and click Next.
4

Choose what happens when a device is detected

On the Additional Actions tab, configure what the rule does:In the Notifications section:
  • Send email notification to — receive an email when a device is detected.
    Email notifications require the Email Sending Settings to be configured correctly.
  • Show warnings in Tray Notifications application — show a notification in the Syteca Tray Notifications application on the user’s computer.
In the Actions section (only one blocking action can be selected; Windows only):
  • Block access to mass storage device until administrator’s approval — block the device until a trusted user (Approver) grants access. See USB access approval for the user-side workflow. Optionally enter a custom message to show when the device is connected.
    By default, access requests expire if not processed within 30 minutes. Change this in System Settings on the Configuration page. Approvers must have valid email addresses on their user account to receive email requests.
  • Block USB device — block the device unconditionally on all assigned Clients. Affects all users regardless of user filtering.
  • Notify user on the target computer about device blocking — show a custom message (max 250 characters) as a balloon notification when a blocked device is plugged in.
If no action is selected, devices detected by the rule only appear in the Session Viewer (no alerts, no blocking).
Click Next.
5

Assign the rule to Clients

On the Assigned Clients tab, click Add in the Clients or Client Groups section and pick the Clients or groups the rule applies to.
Use the Search box to find specific Clients or Client groups.
6

Save

Click Finish in the bottom right. The rule appears in the grid on the USB Devices page.
If a rule is created while a target device is already plugged in, blocking will not take effect on that device until the user unplugs and re-plugs it.
Add USB Rule page showing USB Rule Properties, Rule Conditions, Additional Actions, and Assigned Clients tabs

The Add USB Rule page with the four-tab wizard.

Edit a USB monitoring rule

1

Open the rule

On the USB Devices page, click the Edit Rule icon next to the rule you want to change.
2

Make your changes

Edit the rule on each tab the same way as when adding a rule, then click Finish.

Delete a USB monitoring rule

1

Open the rule

On the USB Devices page, click the Edit Rule icon next to the rule.
2

Delete

On the USB Rule Properties tab, click Delete Rule at the bottom of the page, then click Delete in the confirmation message.
If the rule was blocking any plugged-in devices, users will need to unplug and re-plug those devices before they can be used.

Define exceptions

The exceptions list contains the individual USB devices that the rule will not monitor or block — even though they match one of the monitored device classes. Unlike the Monitored Devices list (which is by class), exceptions are added one device at a time.
Add all permitted USB devices to the exceptions list before enabling a blocking rule. A blocking rule with no exceptions can lock out keyboards, mice, license dongles, and other peripherals your users depend on.
Exceptions are added on the Rule Conditions tab while adding or editing a rule.
1

Open the Exceptions section

On the Rule Conditions tab, scroll down to Exceptions and click Add.
2

Identify the device

In Add Exception, choose how to identify the device:
Enter the Device Hardware ID of the device.
3

Describe the exception (optional)

Enter a Description so future admins know why the exception exists (e.g. “Engineering team Yubikeys”, “CFO laptop USB-C dock”).
4

Save the exception

Click Add in the bottom right. The device joins the list of exceptions for this rule.
5

Save the rule

Click Finish to save the rule with the new exception applied.

Find a device’s Hardware ID

The Hardware ID is the most specific way to identify a single USB device in an exception. To view it on Windows:
1

Plug the device in

Plug the USB device into your Windows computer.
2

Open Computer Management

Right-click This PC and select Manage.
3

Open Device Manager

Expand the Device Manager node.
4

Expand the USB controllers

Expand the node with the computer’s name in the central pane, then expand Universal Serial Bus Controllers.
5

View the Hardware ID

Right-click the device, choose Properties, select the Details tab, then select Hardware Ids in the Property drop-down. The Hardware ID appears in the Value field — copy it into the exception’s Quick selection field.

USB Devices overview

The conceptual overview, device class reference, and how automatic vs rule-based monitoring differ.

USB access approval

The Approver and user-side workflow for “block until approved” rules.

Alerts

Where rule-triggered USB events appear alongside other endpoint alerts.

Access requests

Process USB and PAM access requests in one place.