Device Control in SentinelOne lets you restrict which hardware devices — such as USB storage drives — can be used on endpoints. Enabling it without the right exceptions can block legitimate devices such as card readers, USB hubs, and business peripherals.
Best Practice: Start Strict, Then Add Exceptions
Enable Device Control with a block-all-USB-storage policy as the starting point.
Test on a small set of endpoints first before rolling out to all sites.
Only create exceptions after confirming through testing that a specific device needs one.
Document every exception: include the device name, reason for the exception, who approved it, and a scheduled review date.
Creating Exceptions for USB Devices
When a USB device is blocked and you need to allow it:
Use vendor + product ID exceptions. This is the most precise method — it allows only that specific device, not every device from that vendor.
Scope exceptions to a specific site or device group, not globally. Global allow rules significantly expand your attack surface.
Avoid broad exceptions such as 'allow all USB storage.' Keep exceptions as narrow as possible.
To identify exactly what was blocked and retrieve the vendor and product IDs to use in an exception, log in to the SentinelOne console and use the Device Control activity log. The SentinelOne console Help section includes documentation on creating Device Control rules from activity log events, which walks through this process.
Built-in Card Readers and Devices with No Block Event
Built-in card readers (for example, integrated SD card slots on a laptop) often appear to the operating system as internal devices, not USB storage. Because of this, Device Control may not generate a block event for them even when a policy is active — but the device may still stop working.
If a built-in card reader stops working after enabling Device Control and no block event appears in the activity log, the likely cause is that the USB controller or hub the card reader connects through is being blocked. When the controller is blocked, the downstream device is not recognized at all.
Steps to investigate:
Check the Device Control activity log in the SentinelOne console for any blocked USB controller or hub events around the time the device stopped working.
If a USB hub or controller is showing as blocked, create an exception for that device using its vendor and product ID.
For USB-C card readers: these do appear as USB storage devices and will generate a block event. Create an exception using the device's vendor and product ID — once the exception is in place, whatever card is inserted into it will also be accessible.
