Disable: 'Prevent installation of devices that match any of these device IDs' for DenyDeviceIDs This policy setting allows you to specify a list of Plug and Play hardware IDs and compatible IDs for devices that Windows is prevented from installing. This policy setting takes precedence over any other policy setting that allows Windows to install a device. If you enable this policy setting, Windows is prevented from installing a device whose hardware ID or compatible ID appears in the list you create. If you enable this policy setting on a remote desktop server, the policy setting affects redirection of the specified devices from a remote desktop client to the remote desktop server. If you disable or do not configure this policy setting, devices can be installed and updated as allowed or prevented by other policy settings. Counter Measure: Configure this setting depending on your organization's requirements. Potential Impact: Users are unable to install devices specified by the Plug and Play hardware IDs and compatible IDS in this policy setting. (1) GPO: Computer Configuration\Administrative Templates\System\Device Installation\Device Installation Restrictions\Prevent installation of devices that match any of these device IDs (2) REG: HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\DeviceInstall\Restrictions\DenyDeviceIDs,DenyDeviceIDsRetroactive oval:org.secpod.oval:def:34974 oval:org.secpod.oval:def:34974 oval:org.secpod.oval:def:34974 SCAP Repo OVAL Definition 2016-06-10