GPO policy: "Enumeration policy for external devices incompatible with Kernel DMA Protection" under Computer Configuration > Administrative Templates > System > Kernel DMA Protection. Controls when externally connected Thunderbolt/PCIe DMA-capable devices may be enumerated relative to user login state, protecting against DMA attacks from physical access. Registry: HKLM\SOFTWARE\Policies\Microsoft\Windows\Kernel DMAProtection:DeviceEnumerationPolicy (REG_DWORD). Reference: Policy CSP - DmaGuard
Values
| Enum Value | Description |
|---|---|
|
|
Block all external DMA-capable devices (registry value 0). No external DMA devices are enumerated unless they are DMA-remapping compatible. Most restrictive; recommended for high-security environments. |
|
|
Allow device enumeration only while a user is logged in (registry value 1). External DMA devices incompatible with Kernel DMA Protection are enumerated only after a user has logged on to the system. |
|
|
Allow enumeration of all devices at any time (registry value 2, default). External DMA devices can be enumerated at any time, including at the lock screen. Least restrictive. |
Used by
ComputerAdministrativeTemplatestype: Computer-specific Administrative Templates (ADMX) settings on an Endpoint.
Example
Example
"BLOCK_ALL"