How do you open USB blocking monitoring?
Open the view from the application menu: Menu -> Monitoring -> USB - blocked. It shows USB policy decisions saved by the agent, meaning whether connected USB storage was allowed, blocked, recognized as whitelisted or required policy enforcement. In the table and panel you can find Unique USB Devices, USB Decisions, USB Allow Decisions, USB Block Decisions, Failed USB Blocks, USB Block Success, Whitelisted USB Decisions, computers and employees.
Open this view after enabling USB Storage Blocking, after changing the allowed device list or whenever you want to verify whether removable media are used according to the monitoring profile. USB blocking monitoring helps separate normal use of a known device from a situation where the agent had to enforce a block or could not complete it.
The view combines the Analytics Panel, a daily records table and a details section. The panel groups decision counts, device rankings, action and result distributions, trends, comparisons, anomalies, hourly presence and data quality. One list record describes one monitored day on a specific computer. After it is opened, the application shows details for the workstation and employee, aggregated mainly by USB device, volume, decision, policy status and blocking success.
Daily table in USB blocking monitoring
The daily table quickly shows whether USB devices appeared on a computer and how policy handled those media. Start with the number of decisions and devices, then move to blocks, allowed decisions and failed enforcement attempts.
In the basic table layout you see:
- Unique USB Devices - the number of recognized media or devices aggregated in the record.
- USB Decisions - the sum of allow and block decisions saved for the day.
- Allowed - decisions where USB storage use was permitted.
- Blocked - decisions where the policy indicated that the medium should be blocked.
After expanding columns, you can inspect Failed USB Blocks, Last Decision, Block Attempts, Successful Blocks, Block Success, Required Blocks, whitelisted devices, Allowed Share and Blocked Share, last action, mode, Policy Status, Volume, Drive, Serial Number, Device ID and whether the last medium was Whitelisted. Search also covers Active Hours, actions, modes, statuses, volumes, serial numbers, drive names and ItemsJson details.
Analytics panel in USB policy monitoring
The analytics panel summarizes USB policy decisions from the selected period. Total shows the full number of events and decisions, while Daily Average helps compare periods of different length or ranges with a different number of active computers.
The key metrics are Unique USB Devices, USB Decisions, USB Allow Decisions, USB Block Decisions, Failed USB Blocks, USB Block Success and Whitelisted USB Decisions. If blocks increase, check blocking success at the same time. More blocks with high success usually means active policy enforcement, while growth in failed blocks requires opening device details.
In USB blocking monitoring, the panel separates two subjects: detecting the medium and executing the decision. This lets you see not only that a device appeared in the system, but also whether the agent recognized it as allowed, whether it should be blocked and whether the block was completed.
Device rankings in USB policy monitoring
Rankings help identify which devices and computers generated the most USB policy decisions. They are a good starting point when the panel shows more blocks, but it is not yet clear whether the issue concerns one medium, one workstation or a broader pattern of removable storage use.
The rankings panel includes, among others:
- Top USB Devices - media or devices with the largest number of policy events.
- USB Policy Actions - the distribution of actions the agent attempted.
- USB Policy Results - statuses showing how decision handling ended.
- USB Policy Modes - modes in which the blocking policy operated.
- Top Computers and Top Employees - places and users with the highest number of USB events.
If the device ranking is dominated by one item, open details and compare model, Serial Number, Volume and Decision. With USB, the volume name can be misleading, so Device ID and Serial Number are often more useful than the drive label.
USB decision trends in blocking monitoring
Trends show how USB policy decisions changed across consecutive days. You can analyze charts for Unique USB Devices, USB Decisions, USB Allow Decisions, USB Block Decisions and Failed USB Blocks.
When reading trends, check:
- whether decision growth appeared after a profile change or allowed USB storage list update,
- whether the number of blocks grows together with the number of unique devices,
- whether failed blocks are isolated or form a series on the same computer,
- whether allow decisions dominate after adding new devices to the allowed list,
- whether the number of USB decisions matches the number of monitored computers.
The Hourly USB Policy Presence chart shows in which local hours the agent noticed USB policy activity during the analyzed days. It is not a decision counter or USB usage duration. A marked hour only means that a policy event was present in that interval.
USB blocking comparisons in computer monitoring
The comparisons tab places the current range against a reference period. This shows whether device count, blocks, allowed decisions or enforcement issues increased after policy changes.
In comparisons, pay attention to:
- the change in USB Decisions, because it shows overall policy activity.
- growth in USB Block Decisions, especially when it appears after a stricter mode is enabled.
- the difference in Failed USB Blocks, because it points to technical problems with policy execution.
- movement in USB Block Success, because a drop in this value matters more than the number of attempts alone.
- Unique USB Devices and Whitelisted USB Decisions, to separate new media from already accepted devices.
If the current period differs strongly from the baseline, start with USB Policy Modes and USB Policy Results, then move to specific computers. In USB blocking, the source of change is often profile configuration rather than a single connected medium.
Anomalies in USB storage blocking monitoring
Anomalies draw attention to USB policy behavior that is higher than expected or clearly different from the reference range. In this view they mainly cover block growth, enforcement failures and new devices that were blocked.
The panel may show, among others:
- USB blocking activity increased significantly - when the number of blocks is clearly higher than in the baseline period.
- USB blocking failed - when devices that should have been blocked were not successfully enforced.
- New USB device was blocked - when a medium appears in the current period but was not present before.
- USB drive resolution is pending - when the agent needs to determine the drive path or name before full enforcement.
In anomaly evidence, review Current Blocked Count, Baseline Blocked Count, Blocked Count Increase, Failed USB Blocks, Should Block Count, Failure Share, Device, Policy Status, Pending Drive Resolution, Drive Resolution Attempts and Reason. These fields help separate a configuration issue from a problem with resolving a specific medium.
Record details in USB decision monitoring
After clicking a record, the application shows USB devices aggregated for one day and one computer. Details are grouped by stable device identity, using model, Serial Number, Device ID, PnP Device ID, drive name, volume and other data that help distinguish similar media.
The details table contains fields such as USB Device, Volume, Model, Serial Number, Drive, Decision, Policy Result, USB Decisions, USB Allow Decisions, USB Block Decisions, Failed USB Blocks and Whitelisted information. Additional columns may show USB Events, Activity Share, Action, Mode, Drive Type, Drive Format, Required Blocks, Block Attempts, Successful Blocks, Block Success, first and last detection, Active Hours, device identifiers, Block Message and Repair Message.
Start by sorting by USB Block Decisions or Failed USB Blocks. Then check Policy Status, mode and Block Message. If a device is marked as allowed, compare Serial Number, Device ID and volume label with the Allowed USB Storage Devices list in the profile.
Data quality in USB policy monitoring
The data quality section tells you whether device details are available and whether they fit the daily summary. This matters because the table shows aggregated values, while USB blocking analysis requires the device, decision, status and enforcement counters.
The quality panel may signal missing details despite existing decisions, invalid JSON structure, items with timestamps outside the day range, a mismatch between summary and device list, current-day aggregation still in progress or a closed record without USB details.
If the warning concerns today's data, wait until aggregation is closed. For older records, check agent operation, the sending queue, ItemsJson presence and whether decision, block, allow and failed-block counts match detail rows. Only after that check is it useful to assess USB policy effectiveness.
USB blocking monitoring settings
The data presented in this view depends on editable profile configuration responsible for USB Storage Blocking. These options decide whether the agent only observes devices, blocks unknown media or allows only storage devices saved on the allowed list.
The most important options connected with this view are:
- USB Storage Blocking - enables enforcement of USB storage blocking rules.
- USB Storage Blocking Mode - lets you choose policy behavior, including Block unknown devices or Block all except allowed devices.
- Allowed USB Storage Devices - the exception list where you can add Device ID, Serial Number, volume label or drive name.
After changing these settings, observe USB Decisions, USB Block Decisions, Whitelisted USB Decisions, Failed USB Blocks and USB Block Success. In Block all except allowed devices mode, complete device identifiers are especially important, because an entry that is too general may not recognize the medium, while an overly broad exception can allow more devices than intended.
