Defender USB Events Report

This guide will show an administrator how to view information about USB connections that have been established on Intune joined devices.

Role Requirements

Procedure Scope: Administrators

Required Group Membership: Admin.Security

Handbook Reference

Package: TBD

Domain: TBD

Modifies: TBD

Defender USB Events Reporting

  1. Navigate to the Device Control Report – Microsoft Defender portal, this page provides information about media usage, such as the use of removable storage devices on Intune joined devices. This report can provide insight about possible IOCs that could have occurred from connecting malicious media to a device or provide an audit of possible data exfiltration that could have occurred via USB.

Need Assistance?

Reach out to your Customer Success Manager to discuss how a Sittadel cybersecurity analyst can assist in managing these tasks for you. New to our services? Inquire about arranging a consultation to explore optimizing your Azure environment for painless management.