Prevent installation of devices that match any of these device instance IDs

This policy setting allows you to specify a list of Plug and Play device instance IDs for devices that Windows is prevented from installing. This policy setting takes precedence over any other policy setting that allows Windows to install a device.

If you enable this policy setting, Windows is prevented from installing a device whose device instance ID appears in the list you create. If you enable this policy setting on a remote desktop server, the policy setting affects redirection of the specified devices from a remote desktop client to the remote desktop server.

If you disable or do not configure this policy setting, devices can be installed and updated as allowed or prevented by other policy settings.

Supported on: At least Windows Server, Windows 10 Version 1909

Registry HiveHKEY_LOCAL_MACHINE
Registry PathSoftware\Policies\Microsoft\Windows\DeviceInstall\Restrictions
Value NameDenyInstanceIDs
Value TypeREG_DWORD
Enabled Value1
Disabled Value0

Prevent installation of devices that match any of these device instance IDs:

Registry HiveHKEY_LOCAL_MACHINE
Registry PathSoftware\Policies\Microsoft\Windows\DeviceInstall\Restrictions\DenyInstanceIDs
Value Name{number}
Value TypeREG_SZ
Default Value

To create a list of devices, click Show. In the Show Contents dialog box, in the Value column,

type a Plug and Play device instance ID

(for example, USB\VID_045E&&PID_0123\01234567890123456789).

Also apply to matching devices that are already installed.
Registry HiveHKEY_LOCAL_MACHINE
Registry PathSoftware\Policies\Microsoft\Windows\DeviceInstall\Restrictions
Value NameDenyInstanceIDsRetroactive
Value TypeREG_DWORD
Default Value0
True Value1
False Value0

deviceinstallation.admx

Administrative Templates (Computers)

Administrative Templates (Users)