7.7 Configuring access permissions for a specific device GFI EndPointSecurity allows you to assign access, read and write privileges for a specific device, listed in the devices database, to any user and user group that is a member of the Active Directory (AD) or local users and groups schema. You can do this on a protection policy by policy basis. For example, you can assign read-only privileges for a specific company approved USB pen drive. Attempts to use any other non-approved USB pen drive will be blocked. To configure users and privileges for a specific device in a protection policy: 1. Click on the Configuration tab. 2. Click Protection Policies. 3. From the left pane, select the protection policy to configure. 4. Click on the Security sub-node. 5. From the left pane, click Add new permission(s). Screenshot 67 - Selecting the specific devices option 6. Select the Specific Devices option and click Next to continue. Screenshot 68 - Selecting the devices 7. Select the device(s), from the devices database, for which to configure permissions and click Next to continue. Screenshot 69 - Add users or groups 8. Click Add to specify the user(s)/group(s) which will have access to the device(s) you specified. Screenshot 70 - Add permissions 9. Assign read/write privileges for each user/group you specified. Click Finish to finalize your settings. 10. Deploy the protection policy updates on to the computers included in the policy. From the left pane, right-click on the protection policy you configured and select Deployment ► Deploy agent(s). NOTE: You can also use the keyboard shortcut CTRL + D to perform this step.