Enabling write protection for USB devices on Windows 10

Sometimes it is required to write-protect the USB port so that no data can be transferred on to USB-based storage devices. Big organizations use specialized apps to control this. But you can also do this on your Windows OS based systems easily through the Windows Registry or Group Policy.

How to enable USB write protection using the Registry

Important: Editing the registry is risky, and it can cause irreversible damage to your installation if you don’t do it correctly. It’s recommended to make a full backup of your PC before proceeding.

  1. Use the Windows key + R keyboard shortcut to open the Run command.
  2. Type regedit, and click OK to open the registry.
  3. Browse the following path:HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control
  4. Right-click the Control (folder) key, select New, and click on Key.
  5. Name the new key StorageDevicePolicies and press Enter.


  6. Select the newly created key, and right-click on the right side, select New, and click on DWORD (32-bit) Value.


  7. Name the new DWORD WriteProtect and press Enter.
  8. Double-click the newly created DWORD and change its value from 0 to 1.
  9. Click OK.


  10. Close the Registry to complete the task.

Once you completed the steps, anyone who connects a USB drive to your computer will be denied copy privileges, and they’ll get a “This disk is write-protected” message.

How to enable USB write protection using the Group Policy

Alternatively, if you don’t feel comfortable modifying the Registry, and you’re running Windows 10 Pro, Enterprise, or Education, you can access the Group Policy editor to deny write permissions to removable storage devices.

To enable write protection using Group Policy, do the following:

  1. Use the Windows key + R keyboard shortcut to open the Run command.
  2. Type gpedit.msc and click OK to open the Local Group Policy Editor.
  3. Browse the following path:Computer Configuration > Administrative Templates > System > Removable Storage Access
  4. On the right side, double-click the Removable Disks: Deny write access policy.


  5. On the top-left, select the Enabled option to activate the policy.
  6. Click Apply.
  7. Click OK.


  8. Close the Group Policy editor.
  9. Restart your computer to complete the task.

Once your computer reboots, anyone who connects a USB drive will be denied access to save, edit, or delete any content from the removable storage. However, unlike the enabling write protection using the Registry, users will get the “You’ll need to provide administrator permission to copy to this folder” message, but even with administrator privileges no one will be able to export data to the USB drive.

It’s worth pointing out that inside of Removable Storage Access, you’ll also get a number of other storage policies. For example, “All Removable Storage classes: Deny all access,” which doesn’t enable write protection, but it will prevent anyone from accessing any removable storage, which achieves the same result.

f you need to revert the changes, just follow the same steps, but on step 5 make sure to select the Not Configured option.

End-Note

While you can enable the write protection feature on your computer to protect your data from falling on to the wrong hands, there a number of other scenarios where something like this will be useful.

For example, this feature can add an extra layer of security when implementing a kiosk machine, or when you work with sensitive data on your business, just to name a few.

Although we’re focusing this guide on Windows 10, it’s worth pointing out that the same concept should work on previous versions of the operating system, including Windows 8.1 and Windows 7.

Leave a Reply