Endpoint configuration · GraphQL enum

DeviceEnumerationPolicy enum

GPO policy: "Enumeration policy for external devices incompatible with Kernel DMA Protection" under Computer Configuration > Administrative Templates > System > Kernel DMA Protection. Controls when externally connected Thunderbolt/PCIe DMA-capable devices may be enumerated relative to user login state, protecting against DMA attacks from physical access. Registry: HKLM\SOFTWARE\Policies\Microsoft\Windows\Kernel DMAProtection:DeviceEnumerationPolicy (REG_DWORD). Reference: Policy CSP - DmaGuard

Values

Enum Value Description

BLOCK_ALL

Block all external DMA-capable devices (registry value 0). No external DMA devices are enumerated unless they are DMA-remapping compatible. Most restrictive; recommended for high-security environments.

ONLY_WHILE_LOGGED_IN

Allow device enumeration only while a user is logged in (registry value 1). External DMA devices incompatible with Kernel DMA Protection are enumerated only after a user has logged on to the system.

ALLOW_ALL

Allow enumeration of all devices at any time (registry value 2, default). External DMA devices can be enumerated at any time, including at the lock screen. Least restrictive.

Used by

Example

Example

"BLOCK_ALL"