|
In our school we have USB drives publicly accessible because we must (don't ask me why, it wasn't my choice to make). Here is what we did to allow MOST USB drives to work in MOST computers (note it's very rare we have problems with USB sticks that may require a special driver).
Go into Group Policy Management (whatever you use to edit GPOs), then go to the following place : Under Computer Configuration -> Windows Settings -> Security Settings -> Local Policies -> User Rights Assignment. Look for a setting called 'load and unload device drivers'. Set this to whichever group/users you want to have that right. This allows USB sticks to work happily but it also opens up other possibilities, our desktops are locked right down so our users cannot use anything to exploit the right above. Your situation may be different. Just out of interest, what custom ADM templates do you have and why do you have them? I ask because I use custom templates for our site and am always curious to see what other people have done when they customise their GPOs with their own templates. Sorry that this is waaay OT.
|