Attack surface reduction

Sam Molyneux 0 Reputation points
2025-10-28T13:56:29.8033333+00:00

Hello

I've set up a new attack surface reduction policy to allow external devices such as USB storage, CD drives and memory card readers. The USB storage has mostly been working apart from a couple here and there, my main concern is the SD card readers.

The HardwareId and Device instance path have been entered into the reusable settings for the memory card readers themselves, however the memory cards when entered do not show in file explorer. When checking device manager the memory card reader will show but the actual memory cards will not. Do I need to somehow get the data from the memory cards to whitelist them separately? As far as I can see there is no way to do this as only the readers show in device manager.

I've attached some screenshots of the memory card showing in storage > Disks and Volume and Device manager.
User's imageUser's image

Microsoft Security | Intune | Security
0 comments No comments
{count} votes

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.