QNova Client · Device classes

USB device control that blocks the drive, not the keyboard

USB device control lets you decide which kinds of USB device a Windows machine will accept. Mass storage and imaging get blocked while keyboards, mice, audio, network adapters and Bluetooth keep working. The rule arrives as signed company policy, and every connection attempt is written back as a signed audit record.

What it is

The port does not know what you are worried about

A USB port supplies power and speaks a protocol. It has no opinion about whether the thing on the end is a mouse or a copy of your customer list. So USB policy usually ends up as one switch with two bad settings. Leave it on, and a stick from a conference goodie bag can carry a database out of the building in a coat pocket. Turn it off, and you have also turned off the keyboard, the headset and the dock, and the list of approved exceptions starts growing the same afternoon.

It blocks by device class, not by port

Windows already tags every device with a class identifier, and the client works from those tags. Mass storage and imaging get restricted; keyboard, mouse, audio, network and Bluetooth carry on as normal. The person keeps their desk. The drive does not mount.

It takes a snapshot before it changes anything

The client records the device state it found before applying the rule, so there is a written account of what the machine looked like going in.

It survives a reboot

A watch thread keeps re-asserting the rule against devices that show up after the policy landed, which is the case that actually matters. Unplugging and plugging back in at six in the evening is not a way around it.

That is the real reason USB stays open in most organisations. It is not that nobody thought about it. It is that the cure was worse than the disease.

The mechanism

Plug in the keyboard. Then plug in the drive.

Same rule, same port, two different answers, because the rule is about the class of device and not about the socket. Switch between the three mandates and watch what Soft does here, which is not what Soft does anywhere else.

plug something inKeyboardHIDMouseHIDHeadsetAudioNetwork adapterCDCUSB drive, 64 GBMass storageDocument scannerImagingWindows deviceSoft mandateblocks by device class,never by portnothing plugged ina watch thread re-assertsSigned audit recordwritten whether it mounted or notvendor id-product id-class-description-serial-timestamp window-
then click a device on the leftsoft means blocked here, and that is on purpose

Six USB devices on the left: a keyboard and a mouse on the HID class, a headset on the audio class, a network adapter on the CDC class, a 64 GB drive on the mass storage class and a document scanner on the imaging class. In the middle a Windows device carrying the mandate, which blocks by device class and never by port. On Unmanaged, everything mounts. On a Soft mandate the drive and the scanner are refused while the keyboard, mouse, headset and network adapter keep working, because for this one rule Soft is inverted on purpose and means blocked. An Enforced mandate does the same and the device cannot loosen it. Whatever happens, the attempt is written to a signed audit record carrying the vendor id, the product id, the class, the description and the serial number, inside a timestamp window of plus or minus 30 seconds.

Why this exists

Four things that go wrong without it

One switch, two bad settings

On means a database can leave in a coat pocket. Off means the keyboard, the headset and the dock stop working, and the exception list starts the same afternoon.

The exception list becomes the policy

Once people are queuing for exceptions, the rule is whatever the busiest person approved last, and nobody can say what it is any more.

Unplug and plug back in at six in the evening

A rule applied once, at policy time, is a rule with an obvious way around it. What matters is what happens to the device that appears afterwards.

We do not allow USB drives is a sentence, not evidence

When somebody checks, a line in a policy document is worth very little next to a dated list with serial numbers on it.

What you get

One rule, and the two complaints it usually causes

The person who runs the fleet is thinking about the support queue a USB policy normally creates. The person who signs for it is thinking about the week somebody asks for evidence.

For the fleet

Nobody loses their keyboard

Blocking by class means the restriction lands on storage and imaging and nothing else. The support queue that normally follows a USB policy does not form.

The rule holds after a reboot

A watch thread re-asserts it against devices that appear later, so the obvious way around it is closed before anybody tries.

The safe state is the one you land on

For this rule, Soft means blocked. It is inverted on purpose, so not paying attention leaves you protected rather than open.

For the business

A dated list instead of a sentence

Every attempt is a signed record with the vendor id, the product id, the class, the description and the serial number. That is a different kind of answer when somebody is checking.

No settings file to argue with

The client passes the signed policy through byte for byte and the checking happens in a system service, so there is nowhere on the laptop to write yourself an exception.

You will know the gaps before you buy

The allowlist is stored and carried down but not yet enforced, and this control is enforced on Windows. Both are on this page on purpose.

How it works

Three steps, and the last one is the one you will be asked for

The rule is signed in the console before it goes anywhere

It travels as signed company policy from QS-WAN, and the client verifies that signature in a system service against a pinned key. The app is transport, not authority: it passes the policy through exactly as it arrived, byte for byte, and there is no settings file on the laptop where a determined person can write themselves an exception.

Applying it needs administrator rights and a reboot, and it says so

The QNova Client puts that on screen rather than failing quietly and leaving somebody to work it out. It is a worse first impression than a progress bar and a much better second one. After that there is very little to see, which is the intention.

Every attempt comes back as a record

Blocking is half of it. The other half is answering the question three months later. Each connection attempt is sent to the console as a signed audit record carrying the vendor id, the product id, the USB class, the device description and the serial number, inside a timestamp window of plus or minus 30 seconds.

Before you start

You need the client on Windows machines, administrator rights on them, and one reboot per machine. Decide the mandate before you roll it out, because Soft is not the gentle option on this rule.

In detail

The inverted mandate, and the record it leaves either way

Mandates

Soft means blocked, and that one catches people out

Everywhere else in the policy catalogue a soft mandate is the gentle setting. For USB it is inverted on purpose, and you need to know that before you touch it.

Unmanaged: no USB mandate reaches the device, and local settings decide. Enforced: the rule comes down from company policy and the device cannot loosen it. Soft: blocked by default. That is the inversion, and it is deliberate: for this rule, the safe state is the one you land on when you are not paying attention. A device can always be stricter than its mandate, never looser.

Records

What a refusal actually leaves behind

Every connection attempt is sent to the console as a signed audit record. It carries the vendor id, the product id, the USB class, the device description and the serial number, inside a timestamp window of plus or minus 30 seconds.

So the claim that you do not allow USB drives stops being a sentence in a policy document and becomes a list of dated, signed entries with serial numbers on them. The records are written whether the device mounted or not, which is the half people forget to ask for.

Where this earns its place

Four mornings this changes

A stick arrives from a conference goodie bag

It does not mount, and the attempt is written down with its serial number. Nobody had to notice it happening.

The finance team still needs their docks and headsets

They keep them. The restriction is on the storage and imaging classes, so the desk carries on working exactly as it did.

Somebody asks for evidence covering the last quarter

The answer is a dated list with vendor ids, product ids and serial numbers, not a paragraph from a policy document.

A laptop is rebooted to get around the rule

The watch thread re-asserts it against whatever appears afterwards, so the reboot changes nothing except the time on the record.

Works better with

What carries the rule, and what covers the other routes

The envelope this rule travels in: three scopes merged, signed once, and a version that only ever goes up.

What happens to a file on a drive you did allow. Scanning on access refuses an infected file the moment something touches it.

The other routes out. This page covers the USB path and nothing else, and pretending otherwise would fall apart in the first technical call.

The problem this gets bought for, with the rest of what happens on a machine sitting in somebody living room.

What this does not do

The limits, because they are what make the rest believable

The allowlist is not enforced yet

You cannot currently say to block everything except three approved encrypted drives and have the device honour it. The allowlist is stored and carried down with the policy today, and the enforcement is not built. That is partial, and it is better written here than discovered in your second week.

This control is enforced on Windows

The client itself runs on Windows, Linux, macOS and Android. This particular control is enforced on Windows: Linux enforcement is on the roadmap and macOS is planned, assisted by MDM. You will not get a matrix from us with a tick in every column, because you would find out anyway.

A green result is not proof a sleeping laptop complied

What the console stores is authoritative about the decision you made. Getting it to a device that has been offline for a week is best effort, and it converges when the device comes back. Worth knowing before you quote a number to a board.

It does not stop data leaving by another route

This is the USB path. Webmail, cloud upload and the photo somebody takes of a screen are each their own problem, and pretending otherwise would be the sort of claim that falls apart in the first technical call.

Questions people ask

The ones that come up first

What is USB device control here?

It decides which kinds of USB device a Windows machine will accept, by device class rather than by port. Mass storage and imaging get restricted while keyboard, mouse, audio, network and Bluetooth carry on as normal.

Does blocking USB drives also disable the keyboard?

No, and that is the entire point. Windows tags every device with a class identifier, and the rule works from those tags, so the person keeps their desk and the drive does not mount.

Why does Soft mean blocked?

Because for this one rule the safe state should be the one you land on when you are not paying attention. Everywhere else in the catalogue Soft is the gentle setting; here it is inverted on purpose, and you should know that before you touch it.

Can somebody get around it by rebooting?

No. A watch thread keeps re-asserting the rule against devices that show up after the policy landed, so unplugging and plugging back in at six in the evening changes nothing except the time on the record.

What is in the audit record?

The vendor id, the product id, the USB class, the device description and the serial number, inside a timestamp window of plus or minus 30 seconds. It is written whether the device mounted or not.

Can I allow three specific approved drives?

Not yet. The allowlist is stored and carried down with the policy today, and the enforcement is not built. We would rather say that here than let you plan a rollout around it.

Bring a memory stick and a keyboard to the call.

We put the mandate on a real machine, plug both in while you watch, and then open the record each attempt left behind. It is free, it lasts as long as you want, and there is nothing to sign.

Scroll to Top