In a network environment, you enable some group policies in the following location:
User Configuration\Administrative Template\System\Removable Storage Access
However, if you add the removable storage drive to a client computer that is running Windows Vista or Windows Server 2008 during the period between the system start and the user logon, you find that you can still perform related operations to the removable storage drive.
For example, consider the following scenario:
- You enable the policy “Removable Disks: Deny write access”
- You start a client computer that is running Windows Vista
- You insert a USB storage drive into the computer
- You log on to the system
In this scenario, you can still write files to the USB, or create files on the USB storage drive. However, you expect to see an “Access is denied” message.