Device control
By default, all external USB and Bluetooth devices are allowed to connect to your Windows and macOS-based Cortex Cloud endpoints, and all print jobs are allowed. To protect endpoints from connecting to removable devices, such as disk drives, CD-ROM drives, floppy disk drives, Bluetooth devices, and other portable devices, that can contain malicious files, Cortex Cloud provides device control. Different types of print jobs can also be blocked.
Using device control, you can:
(Windows and macOS) Block all supported USB-connected devices for an endpoint group.
(Windows and macOS) Block a USB device type but add to your allow list a specific vendor from that list that will be accessible from the endpoint.
(Windows and macOS) Block connections to Classic Bluetooth devices or Low Energy Bluetooth services. These are two different Bluetooth protocols used for short-range wireless connections.
Some examples of Classic Bluetooth devices include: laptop computers, tablets, telephones, audio/video devices, wearables, peripherals, imaging devices, health devices, toys, and so on.
Some examples of Low Energy Bluetooth devices include: telephone alert status, microphone control, health sensors, insulin delivery, location and navigation, object transfer, and so on.
Temporarily block only some device types on an endpoint.
USB devices (Windows and macOS)
Bluetooth devices (Windows and macOS)
(Windows and macOS from agent 9.2 and later) Block or allow SD Cards connected on the PCI/PCIe bus.
(Windows and macOS) Block some, or all, print jobs to local or network printers, or to file.
Operating systems report on devices in different ways. Sometimes, the same BLE device will report different services and interfaces, depending on the host's operating system. This may have an effect on the specific BLE services that are blocked for each operating system.
Depending on your defined user scope permissions, creating device profiles, policies, exceptions, and violations may be disabled.
The following are prerequisites to enforce device control policy rules on your endpoints:
Windows
For VDI:
For VMware Horizon, you must disable Sharing → Allow access to removable storage in your VMware Horizon client settings.
Mac
No prerequisites
Linux
Not supported
Android
Not supported
iOS
Not supported
The following limitations apply to device control on your endpoints:
Windows
VDI
Virtual environments leverage different stacks that might not be subject to the Device Control policy rules that are enforced by the Cortex XDR agent and, therefore, could lead to USB devices that are allowed to connect to the VDI instance in contrast to the configured policy rules.
The Cortex XDR agent provides best-effort enforcement of the Device Control policy rules on VDI instances that are running on physical endpoints where a Cortex XDR agent is not deployed.
For Citrix Virtual Apps and Desktops, Cortex Cloud Device Control is supported on generic virtual channels only.
Windows
Bluetooth
Serial number queries are not supported.
If a profile is set to block specific Bluetooth Low Energy (BLE) services, Cortex Cloud only blocks the services set to Block, and not the functionality of the entire device. This means that if a device has multiple services, some of them might still be accessible, while others are blocked.
Cortex Cloud attempts to aggregate all related BLE services so that they appear under a single logical Bluetooth device control violation report. However, some Bluetooth devices might be reported in a separate violation report due to the way these devices are paired in the Windows operating system and because they reside outside the device container.
Cortex Cloud cannot block low energy services or report device control violations on devices that do not report any LE services. The devices can, however, be blocked completely by setting the entire Bluetooth device to Block.
Exceptions can only be created when the Vendor field for the device is available in a violation report.
Exceptions for specific BLE devices cannot be created from a violation report. Exceptions for such devices can only be created by disabling the the blocked LE services in the policy.
If a Bluetooth device vendor is registered as a Vendor (with ID) in the regulatory organization that supervises USB devices, but is not registered as a Bluetooth device, exceptions cannot be created from a violation report. An alternate method for creating an exception is to create a separate profile for the endpoints using the BLE devices, and allow use of specific major and minor classes for these devices.
macOS
Bluetooth
Cortex Cloud cannot block low energy services or report device control violations on devices that do not report any LE services. The devices can, however, be blocked completely by setting the entire Bluetooth device to Block.
Exceptions can only be created when the Vendor field for the device is available in a violation report.
Exceptions for specific BLE devices cannot be created from a violation report. Exceptions for such devices can only be created by disabling the the blocked LE services in the policy.
If a Bluetooth device vendor is registered as a Vendor (with ID) in the regulatory organization that supervises USB devices, but is not registered as a Bluetooth device, exceptions cannot be created from a violation report. An alternate method for creating an exception is to create a separate profile for the endpoints using the BLE devices, and allow use of specific major and minor classes for these devices.
In some cases, when LE devices are blocked by XDR, the host's user interface might not reflect this, and they might appear as connected, when in fact they are blocked. In such cases, these devices retain their pairing status, even though they are blocked.
Some Apple devices, such as iPhones or iPads, might not be blocked because they employ protocols other than Bluetooth for inter-device communication.
Some complex Bluetooth and BLE devices, such as earphones with pre-paired charging cases, may not be blocked.
Linux
-
Not supported
Android
-
Not supported
iOS
-
Not supported
Device control profiles
To apply device control in your organization, define device control profiles that determine which device types Cortex Cloud blocks, and which it permits. There are two types of profiles:
Configuration Profile
Allow or block these device type groups:
Disk Drives (USB-connected)
CD-Rom Drives (USB-connected)
Floppy Disk Drives (USB-connected)
(Windows only) Windows Portable Devices (USB-connected)
(Windows only) Bluetooth Devices (block, allow, or custom types)
The Custom option includes configuration options for specific Bluetooth Classes (Bluetooth Classic) device types, and for Low Energy Services (Bluetooth Low Energy).
When you select an option in Bluetooth Classes, the right pane of the dialog box provides a detailed list of device types that belong to the selected class. You can choose all, or some of the items in this list.
SD Cards connected on the PCI/PCIe bus (Windows and macOS from agent 9.2 and later)
Print Jobs (all, or custom types)
When set to Block, all print jobs sent from the endpoint will be blocked.
When set to Custom, the following options are available:
Network printer jobs only when outside Corp. network blocks print jobs sent to network printers while the endpoint is not on the corporate network.
Network printer jobs (internal/VPN) blocks print jobs sent to network printers while the endpoint is connected to the network via VPN or an internal connection.
Local printer jobs blocks print jobs sent to a printer which is directly connected to an endpoint.
Printing to file (Windows only) blocks print jobs that are saved as a file. This option only blocks the print driver.
For network printer print jobs, ensure that you also configure the Agent Settings profile, Network Location Configuration option. This setting must be set to Enabled, and configured.
If you do not enable and configure this setting, all network printer operations will be treated as internal network print jobs.
The Print Job option does not block connections to a printer, but blocks print jobs according to the type of print job. You cannot block use of a specific printer with this feature.
Any print job that is not sent via the endpoint's printer spooler, such as a file uploaded to a remote software based printing service, will not be blocked.
Cortex XDR relies on the device class assigned by the operating system.
The Cortex XDR agent relies on the device class assigned by the operating system. For Windows endpoints only, you can configure additional device classes.
Exceptions Profile
Allow specific devices according to device types and vendor. You can further specify a specific product and/or product serial number.
Device Configuration and Device Exceptions profiles are configured for each operating system separately. After you configure a device control profile, apply device control profiles to your endpoints.
Last updated
Was this helpful?
