Kaspersky Embedded Systems Security 3.4 for Windows

Configuring access permissions

This feature is not available for computers running Windows XP and Windows Server 2003 operating systems. For computers running these operating systems, access permissions for a device can be configured without delimitation for users and/or user groups.

To configure access permissions for a device or class of devices described in a Device Control rule:

  1. In the Application Console tree, expand the Computer Control node.
  2. Select the Device Control child node.
  3. In the results pane of the Device Control node, click the Device Control rules link.

    The Device Control rules window opens.

  4. Double-click the name of the Device Control rule to display its settings.
  5. In the Rule properties window that opens, in Access rights for user or user group, click Settings.

    Access permissions cannot be configured in Device Control rules created for Bluetooth devices, USB keyboards, and USB mice, as well as in all Device Control rules created for computers running Windows XP or Windows Server 2003 operating systems. These rules allow full access by all users by default.

    The User's management window opens.

  6. Add rules for accessing the device:
    1. Click the Add button.
    2. In the User or user group access rights window that opens, click Browse.
    3. Select or specify a user or group in any of the suggested ways.
    4. In the Access rights drop-down list, select a level of access to the device:
      • Full control. All operations on the device contents are allowed.
      • Read. You can view files and folders, and run files stored on the device.
    5. Click the OK button.
    6. Repeat steps a through e to add the next device access rule.
    7. Click OK in the User's management window.
  7. Rules for accessing the device will be displayed in the Access control for user or group of users field.
  8. Click the OK button.

The configured access permissions for a device or a class of devices described in the Device Control rule will be saved.

After applying the modified Kaspersky Security Center policy, access to devices is provided as follows.

  • If a user or group has been granted full access in the Device Control rule settings, they can perform any action on files once the device is connected.
  • If a user or group has been granted read access in the Device Control rule settings, they can view files and folders, and open files once the device is connected.
  • If a user or group has no specific access rules set in the Device Control rule settings, they will be able to see the device in File Explorer after connecting it, but they will not be able to view its contents.
  • If a user or group has its access permissions defined across multiple access rules, the most permissive device access rule will be applied.

To control access to SD card readers connected to the PCI bus after applying a Kaspersky Security Center policy, either restart your computer or remove and re-connect the device for the changes to take effect.