Skip to main content

Device Control

Device Control is the hub for the policies that lock down and standardise your Windows endpoints- disk encryption, USB and device access, allowed applications, firewall rules, web filtering, and more. It's a launch page: each card opens a module where you build policies and then deploy them to a scope of endpoints.

Edition

Device Control is available on the EndpointOps edition. Each module is also permission-gated, so you only see the cards you're allowed to manage.

How to get here

  1. In the left sidebar, click Device Control.

Navigate to: Device Control

URL path: /device-control

The Device Control hub

The Device Control hub with a card per moduleThe Device Control hub with a card per module

Each card is one module. Use the search box at the top to filter the cards by name or description, then click a card to open that module.

ModuleWhat it does
Disk EncryptionBitLocker encryption status, policies, deployments, and recovery keys.
Browser ManagementControl browser extensions and permissions.
Device Access ControlAllow, block, or restrict USB and other removable/external devices.
Application ControlBlock applications and grant time-bound temporary access.
Appearance ManagementEnforce wallpaper, screensaver, resolution, and DPI.
Firewall ManagementManage firewall profiles and inbound/outbound rules.
Power ManagementConfigure power plans and sleep/hibernate behaviour.
Prohibited SoftwareDetect and auto-uninstall unapproved software.
File Access ControlControl access to files, folders, and registry keys.
Certificate ManagementInstall or remove certificates across endpoints.
Security PoliciesApply Windows GPO-style security controls.
URL FilteringBlock or restrict web content by category.

The shape of every module

Almost every Device Control module follows the same two-step pattern, shown as tabs down the left:

  1. Policies- define what the rule is (the encryption settings, the device rules, the firewall profile, and so on).
  2. Deployments- push a policy to a scope of endpoints on a schedule.

Some modules add extra tabs- a read-only Status view, a Temporary Access grant, Trusted Devices, Recovery Keys, and so on. Those are covered on each module's pages.

Deploying a policy

Every Deployment form is the same: name it, choose Apply or Remove, pick the policy, choose a Scope of endpoints, pick a Deployment Policy (the schedule/window), and optionally set who to notify.

  • Endpoints- the machines you deploy to.
  • Automation- deploy software and configuration the same way.
  • Deployment Policies- the schedule/window every Deployment form's Deployment Policy field points to.