How to Enable USB Blocked by Group Policy in Windows 10

To enable USB storage that’s blocked by Group Policy in Windows 10, press Windows + R, type gpedit.msc, and go to Computer Configuration > Administrative Templates > System > Removable Storage Access. Set All Removable Storage classes: Deny all access and any Removable Disks: Deny… policies to Not Configured or Disabled, then run gpupdate /force and reconnect the drive. Check the Device Installation Restrictions policies and the USBSTOR registry value too if the drive still doesn’t appear.

These steps are for a PC you own or administer. If your computer is managed by work or school, USB restrictions usually come from your organization’s domain or device management policies. Local changes will be overwritten and may break company rules, so ask your IT department instead.

Signs that Group Policy is blocking USB

  • A message like “This operation has been cancelled due to restrictions in effect on this computer” or “Access is denied” when you open the drive.
  • The drive shows in File Explorer but you can’t read or write files.
  • The drive doesn’t appear at all, and Device Manager reports that installation of the device is forbidden by system policy.
  • USB keyboards and mice still work. These policies usually target storage, not every USB device.

Before you start

  • You need an administrator account.
  • The Local Group Policy Editor is included in Windows 10 Pro, Enterprise, and Education. On Home, skip to the registry method.
  • Consider creating a restore point first: search for Create a restore point and click Create.

Method 1: Turn off Removable Storage Access policies

  1. Press Windows + R, type gpedit.msc, and press Enter. Click Yes if User Account Control asks.
  2. Go to Computer Configuration > Administrative Templates > System > Removable Storage Access.
  3. Look at the State column for anything set to Enabled.
  4. Double-click All Removable Storage classes: Deny all access, choose Not Configured (or Disabled), and click OK.
  5. Do the same for Removable Disks: Deny read access, Removable Disks: Deny write access, Removable Disks: Deny execute access, and the WPD Devices policies (these cover phones and cameras).
  6. Repeat the check under User Configuration > Administrative Templates > System > Removable Storage Access, since the same policies exist there.
Local Group Policy Editor with the Removable Storage Access folder selected and the All Removable Storage classes Deny all access policy highlighted
(1) Select Removable Storage Access, then (2) set any Enabled deny policies to Not Configured. (Illustration)

Method 2: Check Device Installation Restrictions

If the drive doesn’t show up at all, a device installation policy may be stopping Windows from installing it.

  1. In the Group Policy Editor, go to Computer Configuration > Administrative Templates > System > Device Installation > Device Installation Restrictions.
  2. Set these to Not Configured if they’re enabled: Prevent installation of removable devices, Prevent installation of devices not described by other policy settings, and any Prevent installation of devices that match… policies that list your drive.
  3. Click OK after each change.

Apply the changes

  1. Right-click Start and choose Windows PowerShell (Admin) or Command Prompt (Admin).
  2. Type gpupdate /force and press Enter.
  3. Unplug the USB drive, wait a few seconds, and plug it back in. Restart if it still isn’t accessible.

Method 3: Use the registry (Windows 10 Home or if gpedit changes don’t stick)

Editing the registry incorrectly can cause problems, so back it up first with File > Export in Registry Editor.

  1. Press Windows + R, type regedit, and press Enter.
  2. Go to HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\USBSTOR.
  3. Double-click Start. A value of 4 disables USB storage. Change it to 3 and click OK.
  4. Next, go to HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\RemovableStorageDevices. If it exists, it holds the Removable Storage Access policies. A Deny_All value of 1 blocks all removable storage; set it to 0 or delete it. Subkeys with Deny_Read or Deny_Write values set to 1 block specific device types.
  5. Check HKEY_CURRENT_USER\SOFTWARE\Policies\Microsoft\Windows\RemovableStorageDevices as well.
  6. Restart the PC.

Still blocked? Other causes

  • Organization policies – run gpresult /r in Command Prompt. If you see applied Group Policy objects other than Local Group Policy, a domain policy is in control. Settings > Accounts > Access work or school also shows whether the PC is managed.
  • Security software – some antivirus and endpoint protection tools have their own device control that blocks USB storage.
  • Disabled in Device Manager – right-click Start > Device Manager, expand Universal Serial Bus controllers and Disk drives, and choose Enable device on anything with a down-arrow icon.
  • BIOS or UEFI settings – some PCs can turn off USB ports in firmware setup.
  • Drive problems – test the drive on another computer. If it doesn’t work there either, the issue is the drive, not a policy.
  • Write protection – if you can read but not write, check HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\StorageDevicePolicies for a WriteProtect value of 1, and check for a physical lock switch on SD cards and some drives.

How to block USB storage again

To restore the restriction, set All Removable Storage classes: Deny all access back to Enabled and run gpupdate /force. This is useful on shared or kiosk PCs.

Frequently asked questions

Does this work on Windows 11?

Yes. The policy paths and registry values are the same in Windows 11.

Why do my changes revert after a restart?

A domain Group Policy or device management service is reapplying the setting. Only your administrator can change it.

Will this affect USB keyboards, mice, or printers?

No. Removable Storage Access policies apply to storage devices such as flash drives, external hard drives, memory cards, and phones in file transfer mode.

Can I allow only specific USB drives?

Yes, on Pro and higher editions. Use the Device Installation Restrictions policies to allow devices that match specific device IDs while blocking others. This is more advanced and usually managed by IT.