Follow
Windows

Deny Write Access to Unprotected Removable Drives in Windows 11

Richard
Written by
Richard
Feb 1, 2026 Updated Apr 2, 2026 3 min read
Deny Write Access to Unprotected Removable Drives in Windows 11
Deny Write Access to Unprotected Removable Drives in Windows 11

You can prevent Windows 11 from writing to unprotected removable drives by configuring the Group Policy Editor.

This setting ensures that sensitive data is only saved to drives that meet your security standards, like those encrypted with BitLocker.

By default, Windows 11 allows writing to any connected USB drive, which can pose a risk if those drives are lost or stolen.

This tutorial focuses on using the Local Group Policy Editor, available in Windows 11 Pro, Enterprise, and Education editions, to enforce this policy.

⚡ Quick Answer

Deny write access by opening Local Group Policy Editor, navigating to the BitLocker settings for removable drives, and enabling “Deny write access to removable drives not protected by BitLocker.” This restricts writing to BitLocker-encrypted drives only.

What is BitLocker?

BitLocker helps protect your files so only you or people you trust can access them. It works by encrypting your drive. This means it scrambles the data to keep it safe.

You can use BitLocker to protect:

  • USB drives and other removable drives
  • Fixed drives inside your PC
  • Your Windows operating system drive

When BitLocker is turned on for your Windows system drive, your PC can unlock it automatically when it starts up.

Why Deny Write Access to Unprotected Drives?

Sometimes you want to make sure files can only be saved to drives protected by BitLocker. This keeps your data more secure. It also prevents accidentally saving data to unsafe drives.

How to Deny Write Access Using Local Group Policy Editor

Follow these simple steps:

Step 1Open the Local Group Policy Editor

  1. Click the Start button
  2. Type Edit group policy and press Enter

Step 2Navigate to the BitLocker Settings

In the window that opens, go to this location:

Computer Configuration → Administrative Templates → Windows Components → BitLocker Drive Encryption → Removable Data Drives

Step 3Find and Change the Setting

Look for the setting named “Deny write access to removable drives not protected by BitLocker” and double-click it.

Deny write access to removable drive not protected with BitLocker
Deny write access to removable drive not protected with BitLocker

Step 4Choose Your Option

You will see these options:

  • Not Configured (default) – Same as disabled. No restrictions.
  • Enabled – You can only write to drives protected by BitLocker. Unprotected drives become read-only (you can view files, but not save new ones).
  • Disabled – You can write to all removable drives, whether protected or not.

Select Enabled to protect your data.

Step 5Save and Restart

Click OK to save your changes.

Restart your PC to apply the changes.

Options for denying write access in BitLocker policy
Options for denying write access in BitLocker policy

Extra option: When you enable this setting, you can also choose to allow write access only to devices set up by your organization. This is useful for work computers.

How to Deny Write Access Using Windows Registry Editor

You can also do this by changing settings in the Windows Registry. Be careful when editing the registry — it’s best to back it up first. ⚠️ Admin privileges required.

Step 1Open the Registry Editor

  1. Press Windows + R keys to open the Run box
  2. Type regedit and press Enter

Step 2Go to the First Registry Path

Navigate to this path:

🗝️Registry
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\FVE

Step 3Create or Edit RDVDenyCrossOrg

Look for a value named RDVDenyCrossOrg. If it’s not there, create it:

  1. Right-click the right side of the window
  2. Click NewDWORD (32-bit) Value
  3. Name it RDVDenyCrossOrg

Double-click RDVDenyCrossOrg and set the value to 0 (zero) to deny write access to unprotected drives.

Step 4Go to the Second Registry Path

Next, navigate to this path:

🗝️Registry
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Policies\Microsoft\FVE

Step 5Create or Edit RDVDenyWriteAccess

Look for RDVDenyWriteAccess. If it’s missing, create it the same way.

Double-click RDVDenyWriteAccess and set the value to 1 to deny write access.

Step 6Close and Restart

Close Registry Editor and restart your PC.

Registry settings to deny write access
Registry settings to deny write access

Note: If you want to only allow write access to devices from your organization, set both RDVDenyCrossOrg and RDVDenyWriteAccess to 1.

To go back to normal and allow writing to all drives, just delete these two values from the Registry.

Summary

You can protect your data by making sure Windows only allows writing to removable drives that have BitLocker encryption enabled.

You can set this up easily using the Local Group Policy Editor or by editing the Registry if you’re comfortable with it.

This helps keep your files safe and reduces the risk of data being saved to unprotected drives.

If you want to learn more about BitLocker, check out this helpful guide: How to Turn On BitLocker in Windows 11.

Was this guide helpful?

Tags: #Windows 11
Was this helpful?
Richard

About the Author

Richard

Tech Writer, IT Professional

Richard, a writer for Geek Rewind, is a tech enthusiast who loves breaking down complex IT topics into simple, easy-to-understand ideas. With years of hands-on experience in system administration and enterprise IT operations, he’s developed a knack for offering practical tips and solutions. Richard aims to make technology more accessible and actionable. He's deeply committed to the Geek Rewind community, always ready to answer questions and engage in discussions.

📚 Related Tutorials

How to Turn On BitLocker to Protect a Data Drive in Windows 11
Windows How to Turn On BitLocker to Protect a Data Drive in Windows 11
How to Turn On BitLocker for Your Windows 11 Operating System Drive
Windows How to Turn On BitLocker for Your Windows 11 Operating System Drive
How to Enable or Disable BitLocker to Unlock OS Drive with PIN or USB at Startup in Windows 11
Windows How to Enable or Disable BitLocker to Unlock OS Drive with PIN or USB at Startup in Windows 11
How to View Local Group Policies that are Configured in Windows 11
Windows How to View Local Group Policies that are Configured in Windows 11

No comments yet — be the first to share your thoughts!

Leave a Comment

Your email address will not be published. Required fields are marked *