I'm looking for practical ways to manage removable USB storage in an environment where most devices are locked down. We currently block USB storage through Intune on roughly 95% of our endpoints, but one part of the business needs to transfer diagnostic data from vehicles and aircraft to customers. Personal devices cannot access our Microsoft 365 environment, so having staff use their own computers is not a realistic solution.
We have about five approved USB drives whitelisted by serial number, but that still worries me. A drive could be taken off-site, have malicious or inappropriate files added to it, and then be connected to a corporate endpoint. I'd like to find a reliable way to sanitize or inspect the drives after use, although that creates its own challenge because the process would need to be consistently followed.
Ideally, I would block removable storage entirely, but management needs the business function to continue. How do you handle this balance? I'm especially interested in controls such as dedicated transfer workstations, scanning procedures, encryption, check-in/check-out processes, or temporary approvals.
5 Answers
The safest approach is to block removable storage by default and make exceptions tightly controlled. Use company-owned drives, preferably encrypted models with built-in PIN entry, and maintain a register of who has each device. Drives should be checked in and out, audited regularly, and immediately removed from the allow list if they are lost or their custody is uncertain. Reformatting them on return can reduce data retention, but it does not replace malware scanning or proper process controls.
For a recurring operational need, consider one or more dedicated transfer workstations. Keep them isolated from the main network, restrict what users can do, scan removable media before opening files, copy only the required data to an approved storage location, and then wipe or reformat the drive. A restricted VLAN or an otherwise isolated system can limit the impact if a contaminated drive gets through.
This is often more realistic than trying to make every approved USB drive trustworthy. It gives the business a defined way to transfer files while containing the risk.
Some organizations allow only a very small number of exceptions, with manager approval and periodic recertification. Removable media is scanned automatically where possible, file transfers are monitored, and the exception is removed when the business need ends. Longer term, it is worth working with the equipment or software vendors to find a secure network-based transfer method so USB is no longer required.
This needs to be treated as a business risk decision rather than something IT can solve alone. Present management with the operational requirement, the realistic threats, and the remaining risk after the proposed controls. Then have the appropriate business or security owner formally approve the exception. Training and clear procedures matter because staff may not understand that plugging a work drive into a third-party computer can compromise it.
That makes sense. The drives are already checked in and out, but I’m mainly concerned about what happens when someone uses one on an external system. I’ll focus on a documented transfer process and formal risk acceptance instead of assuming the whitelist alone is enough.
There probably isn’t a perfect technical solution once a drive is allowed to move between unknown systems. Use serial-number allowlisting, visible asset labels, check-in/check-out through the stores or operations team, limited approval periods, and regular reviews. Make the permitted use very specific and document the risks. If a drive is taken home, used in an untrusted system, or cannot be accounted for, revoke it immediately and replace or wipe it.

Encryption protects the data if the drive is lost, but it does not stop someone from adding malicious files. The custody and inspection process is still important.