> ## Documentation Index
> Fetch the complete documentation index at: https://syteca.com/docs/llms.txt
> Use this file to discover all available pages before exploring further.

# USB Monitoring Rules

> Add, edit, and delete USB monitoring rules in Syteca, define exceptions for individual devices by Hardware ID or VID/PID, and find a device's Hardware ID.

USB monitoring rules let you alert on, block, or gate-by-approval specific USB device classes on Windows and macOS Clients. This page covers the full rule lifecycle — adding, editing, deleting — plus the two related tasks you'll use frequently: defining exceptions for individual devices, and finding a device's Hardware ID.

For the conceptual overview, the list of device classes available, and the difference between automatic and rule-based monitoring, see [USB Device Monitoring & Blocking](/docs/session-monitoring/usb-devices/overview).

<Note>
  Rules can only be added, edited, or deleted by a user with the [administrative Client Installation and Management permission](/docs/administration/users/administrative-permissions).
</Note>

## Add a USB monitoring rule

<Steps>
  <Step title="Open the USB Devices page">
    Sign in to the Management Tool, click **USB Devices** in the left navigation, then click **Add** in the top right.
  </Step>

  <Step title="Set the rule properties">
    On the **USB Rule Properties** tab:

    * Select **Enable USB rule** to enable the rule.
    * Enter a unique **Name** for the rule.
    * Optionally enter a **Description**.
    * Select the required **Risk Level**.

    Click **Next**.
  </Step>

  <Step title="Choose the device classes and exceptions">
    On the **Rule Conditions** tab, select the device classes to monitor in the **Monitored Devices** list. See [the device class reference](/docs/session-monitoring/usb-devices/overview#usb-device-classes-available-for-rule-based-monitoring) for what each class covers.

    <Note>
      Only **Mass storage devices** and **Vendor-specific devices** are currently supported for macOS Clients.
    </Note>

    Then add [exceptions](#define-exceptions) for any individual devices that should remain usable, and click **Next**.
  </Step>

  <Step title="Choose what happens when a device is detected">
    On the **Additional Actions** tab, configure what the rule does:

    **In the Notifications section:**

    * **Send email notification to** — receive an email when a device is detected.
          <Note>
            Email notifications require the [Email Sending Settings](/docs/administration/configuration/email-sending-settings) to be configured correctly.
          </Note>

    * **Show warnings in Tray Notifications application** — show a notification in the [Syteca Tray Notifications application](/docs/administration/deployment/tray-notifications) on the user's computer.

    **In the Actions section** *(only one blocking action can be selected; Windows only):*

    * **Block access to mass storage device until administrator's approval** — block the device until a trusted user (Approver) grants access. See [USB access approval](/docs/session-monitoring/usb-devices/usb-access-approval) for the user-side workflow. Optionally enter a custom message to show when the device is connected.

          <Note>
            By default, access requests expire if not processed within 30 minutes. Change this in [System Settings](/docs/administration/configuration/system-settings) on the Configuration page. Approvers must have valid email addresses on their [user account](/docs/administration/users/users#edit-a-user) to receive email requests.
          </Note>

    * **Block USB device** — block the device unconditionally on all assigned Clients. Affects all users regardless of user filtering.

    * **Notify user on the target computer about device blocking** — show a custom message (max 250 characters) as a balloon notification when a blocked device is plugged in.

    <Note>
      If no action is selected, devices detected by the rule only appear in the Session Viewer (no alerts, no blocking).
    </Note>

    Click **Next**.
  </Step>

  <Step title="Assign the rule to Clients">
    On the **Assigned Clients** tab, click **Add** in the **Clients** or **Client Groups** section and pick the Clients or groups the rule applies to.

    <Note>
      Use the **Search** box to find specific Clients or Client groups.
    </Note>
  </Step>

  <Step title="Save">
    Click **Finish** in the bottom right. The rule appears in the grid on the USB Devices page.
  </Step>
</Steps>

<Warning>
  If a rule is created **while a target device is already plugged in**, blocking will not take effect on that device until the user unplugs and re-plugs it.
</Warning>

<Frame caption="The Add USB Rule page with the four-tab wizard.">
  <img src="https://mintcdn.com/syteca/FKrkO8bEqEQ6WSgs/images/administration/usb-devices/add-usb-rule.png?fit=max&auto=format&n=FKrkO8bEqEQ6WSgs&q=85&s=cb5cca9e7d79f48a08e7fd6da1d67e8c" alt="Add USB Rule page showing USB Rule Properties, Rule Conditions, Additional Actions, and Assigned Clients tabs" width="1632" height="395" data-path="images/administration/usb-devices/add-usb-rule.png" />
</Frame>

## Edit a USB monitoring rule

<Steps>
  <Step title="Open the rule">
    On the **USB Devices** page, click the **Edit Rule** icon next to the rule you want to change.
  </Step>

  <Step title="Make your changes">
    Edit the rule on each tab the same way as when [adding a rule](#add-a-usb-monitoring-rule), then click **Finish**.
  </Step>
</Steps>

## Delete a USB monitoring rule

<Steps>
  <Step title="Open the rule">
    On the **USB Devices** page, click the **Edit Rule** icon next to the rule.
  </Step>

  <Step title="Delete">
    On the **USB Rule Properties** tab, click **Delete Rule** at the bottom of the page, then click **Delete** in the confirmation message.
  </Step>
</Steps>

<Warning>
  If the rule was blocking any plugged-in devices, users will need to unplug and re-plug those devices before they can be used.
</Warning>

## Define exceptions

The **exceptions list** contains the individual USB devices that the rule will **not** monitor or block — even though they match one of the monitored device classes. Unlike the Monitored Devices list (which is by *class*), exceptions are added one device at a time.

<Warning>
  Add all permitted USB devices to the exceptions list **before** enabling a blocking rule. A blocking rule with no exceptions can lock out keyboards, mice, license dongles, and other peripherals your users depend on.
</Warning>

Exceptions are added on the **Rule Conditions** tab while adding or editing a rule.

<Steps>
  <Step title="Open the Exceptions section">
    On the **Rule Conditions** tab, scroll down to **Exceptions** and click **Add**.
  </Step>

  <Step title="Identify the device">
    In **Add Exception**, choose how to identify the device:

    <Tabs>
      <Tab title="Quick selection (Hardware ID)">
        Enter the [Device Hardware ID](#find-a-device’s-hardware-id) of the device.
      </Tab>

      <Tab title="Custom selection (VID/PID)">
        Enter the **Vendor ID (VID)**, **Product ID (PID)**, **Revision**, and **Serial** number in the respective fields.

        * **VID and PID are required.** Revision and Serial are optional.
        * You can use the `*` **wildcard** as the *entire* value in any one of the four fields (but not combined with other characters). This is also useful when a Hardware ID contains characters the system won't accept, such as `?`.
      </Tab>
    </Tabs>
  </Step>

  <Step title="Describe the exception (optional)">
    Enter a **Description** so future admins know why the exception exists (e.g. *"Engineering team Yubikeys"*, *"CFO laptop USB-C dock"*).
  </Step>

  <Step title="Save the exception">
    Click **Add** in the bottom right. The device joins the list of exceptions for this rule.
  </Step>

  <Step title="Save the rule">
    Click **Finish** to save the rule with the new exception applied.
  </Step>
</Steps>

## Find a device's Hardware ID

The Hardware ID is the most specific way to identify a single USB device in an exception. To view it on Windows:

<Steps>
  <Step title="Plug the device in">
    Plug the USB device into your Windows computer.
  </Step>

  <Step title="Open Computer Management">
    Right-click **This PC** and select **Manage**.
  </Step>

  <Step title="Open Device Manager">
    Expand the **Device Manager** node.
  </Step>

  <Step title="Expand the USB controllers">
    Expand the node with the computer's name in the central pane, then expand **Universal Serial Bus Controllers**.
  </Step>

  <Step title="View the Hardware ID">
    Right-click the device, choose **Properties**, select the **Details** tab, then select **Hardware Ids** in the **Property** drop-down. The Hardware ID appears in the **Value** field — copy it into the exception's **Quick selection** field.
  </Step>
</Steps>

## Related

<CardGroup cols={2}>
  <Card title="USB Devices overview" icon="usb" href="/docs/session-monitoring/usb-devices/overview">
    The conceptual overview, device class reference, and how automatic vs rule-based monitoring differ.
  </Card>

  <Card title="USB access approval" icon="user-check" href="/docs/session-monitoring/usb-devices/usb-access-approval">
    The Approver and user-side workflow for "block until approved" rules.
  </Card>

  <Card title="Alerts" icon="bell" href="/docs/session-monitoring/alerts">
    Where rule-triggered USB events appear alongside other endpoint alerts.
  </Card>

  <Card title="Access requests" icon="inbox" href="/docs/pam/access/access-requests">
    Process USB and PAM access requests in one place.
  </Card>
</CardGroup>
