Skip to content
Enable WebUsb Ask for Urls Policy in Microsoft Edge to Control USB Device Access using Intune

Enable WebUsb Ask for Urls Policy in Microsoft Edge to Control USB Device Access using Intune

Written By Anoop C Nair
Last Updated September 23, 2025
Posted In Intune
SHARE

Hey, let’s learn how to Enable WebUsb Ask for Urls Policy in Microsoft Edge to Control USB Device Access Using Intune. The WebUsbAskForUrls policy in Microsoft Edge is designed to control which websites can request access to USB devices. By defining specific URL patterns, organizations can allow only trusted sites to ask users for USB access.

If this policy is not configured, the browser defaults to global settings or user preferences, which may not always align with organizational security standards.This policy is important because it helps ensure that sensitive USB devices are only accessed by secure and approved websites.

For users, this policy simplifies security management by removing the burden of deciding which sites can access USB devices. For organizations, it provides peace of mind knowing that data flow between browsers and USB devices is restricted to vetted platforms. This balance improves both usability and safety within the workplace.

An example of using this policy would be in a university or research lab where only specific websites, such as trusted educational portals or research databases, are allowed to communicate with lab equipment via USB. Similarly, a company may permit only its internal web applications, like device management tools, to connect with specialized hardware.

Patch My PC

What are the Advantages of Enabling this Policy using Intune?

Enabling the WebUsbAskForUrls policy gives both users and organizations better control and protection. It reduces the risk of unsafe sites using USB devices, ensures only approved websites have access, and helps maintain smooth workflows without security issues. This balance makes work safer and easier for everyone.

1. Prevents unsafe or malicious websites from using USB devices
2. Ensures only trusted sites can request USB access
3. Protects sensitive data and devices from misuse
4. Reduces user mistakes by setting clear rules
5. Supports safe and efficient work in schools, labs, and companies

Enable WebUsb Ask for Urls Policy in Microsoft Edge to Control USB Device Access using Intune

When the WebUsbAskForUrls policy is not enabled, any website can ask to use USB devices. This can confuse users, and they might allow unsafe sites by mistake. As a result, both devices and data face higher security risks.

When the policy is enabled, only trusted websites chosen by the organization can request USB access. This removes guesswork for users and keeps workflows safe. It also gives the organization stronger security and better control over device usage.

Create a Profile

To start deploying a policy in Intune, sign in to the Microsoft Intune Admin Center. Then go to Devices> Configuration under the Manage devices> Policies> Create> New policy. In the create a profile window, add the platform Windows and later, profile type is Settings Catalog. Then click the create button.

Enable WebUsb Ask for Urls Policy in Microsoft Edge to Control USB Device Access using Intune - Fig.1
Enable WebUsb Ask for Urls Policy in Microsoft Edge to Control USB Device Access using Intune – Fig.1

First Step

To configure a policy in Intune, start with the Basics step, where you enter the policy name (e.g Allow WebUSB on specific sites), provide a short description (such as To Allow WebUSB on specific sites) and the platform is Windows.

Enable WebUsb Ask for Urls Policy in Microsoft Edge to Control USB Device Access using Intune - Fig.2
Enable WebUsb Ask for Urls Policy in Microsoft Edge to Control USB Device Access using Intune – Fig.2

Configuration Settings

In the Configuration settings, you can see the Add settings button. Click the Add Settings to browse or search the catalog for the settings you want to configure. In the Settings picker, you can search for the Settings quickly. Here, I choose the Microsoft Edge\Content settings category, select Allow WebUSB on specific sites.

Enable WebUsb Ask for Urls Policy in Microsoft Edge to Control USB Device Access using Intune - Fig.3
Enable WebUsb Ask for Urls Policy in Microsoft Edge to Control USB Device Access using Intune – Fig.3

Once you have selected Allow WebUSB on specific sites and closed the Settings picker. You will see it on the Configuration page. Here we have only two settings: Enable or Disable. By default, it will be set to Disable. If you want to disable these settings, click on the Next button.

Enable WebUsb Ask for Urls Policy in Microsoft Edge to Control USB Device Access using Intune - Fig.4
Enable WebUsb Ask for Urls Policy in Microsoft Edge to Control USB Device Access using Intune – Fig.4

Enable WebUSB Policy

If we enable or configure this policy, you can enable the WebUSB policy by toggling the switch. After reviewing or adding more settings, you can click the Next button to proceed.

Enable WebUsb Ask for Urls Policy in Microsoft Edge to Control USB Device Access using Intune - Fig.5
Enable WebUsb Ask for Urls Policy in Microsoft Edge to Control USB Device Access using Intune – Fig.5

Scope Tags

In Intune, Scope Tags are used to control who can view and modify a policy. The scope tag is not mandatory, so you can skip this section. It functions as a tool for organisation and access management, but assigning it is optional. Click Next if they’re not required for your setup.

Enable WebUsb Ask for Urls Policy in Microsoft Edge to Control USB Device Access using Intune - Fig.6
Enable WebUsb Ask for Urls Policy in Microsoft Edge to Control USB Device Access using Intune – Fig.6

Assignments

In the Assignments tab, you choose the users or devices that will receive the policy by clicking Add Group under Include Group, select the group that you want to target (e.g Test_HTMD_Policy) and then click Next to continue.

Enable WebUsb Ask for Urls Policy in Microsoft Edge to Control USB Device Access using Intune - Fig.7
Enable WebUsb Ask for Urls Policy in Microsoft Edge to Control USB Device Access using Intune – Fig.7

Last Step

At the final Review + Create step, we see a summary of all configured settings for the new profile; after reviewing the details and making any necessary changes by clicking Previous. We click Create to finish, and a notification confirms that the “Allow WebUSB on specific sites created successfully”.

Enable WebUsb Ask for Urls Policy in Microsoft Edge to Control USB Device Access using Intune - Fig.8
Enable WebUsb Ask for Urls Policy in Microsoft Edge to Control USB Device Access using Intune – Fig.8

Device and User Check-in Status

To view a policy’s status, go to Devices > Configuration in the Intune portal, select the policy (like Allow WebUSB on specific sites ), and check that the status shows Succeeded (1). Use manual sync in the Company Portal to speed up the process.

Enable WebUsb Ask for Urls Policy in Microsoft Edge to Control USB Device Access using Intune - Fig.9
Enable WebUsb Ask for Urls Policy in Microsoft Edge to Control USB Device Access using Intune – Fig.9

Client Side Verification

To confirm if a policy has been applied, use the Event Viewer on the client device. Go to Applications and Services Logs > Microsoft > Windows > Device Management > Enterprise Diagnostic Provider > Admin. From the list of policies, use the Filter Current Log option and search for Intune event 814.

Event Details
MDM PolicyManager: Set policy string, Policy (WebUsbAskForUrls)Area:
(microsoft_edqe~Policy~microsoft_edqe~ContentSettinqs), EnrollmentID requestinq merqe:
(EB427D85-802F-46D9-A3E2-D5B414587F63), Current User: (Device), Strinq: (), Enrollment Type: (0x6), Scope:
(0x0).
Enable WebUsb Ask for Urls Policy in Microsoft Edge to Control USB Device Access using Intune – Table.1
Enable WebUsb Ask for Urls Policy in Microsoft Edge to Control USB Device Access using Intune - Fig.10
Enable WebUsb Ask for Urls Policy in Microsoft Edge to Control USB Device Access using Intune – Fig.10

How to Remove Assigned groups from WebUSB Policy

After creating the policy, if you want to remove the specific group that you previously selected, you can easily do that. First, go to Devices > Configuration policies. In the Configuration policy section, search and select the policy. In the Assignment section, you will find an Edit option and click on it. Then, click the Remove option and Review+ save button.

For detailed information, you can refer to our previous post – Learn How to Delete or Remove App Assignment from Intune using by Step-by-Step Guide.

Enable WebUsb Ask for Urls Policy in Microsoft Edge to Control USB Device Access using Intune - Fig.11
Enable WebUsb Ask for Urls Policy in Microsoft Edge to Control USB Device Access using Intune – Fig.11

How to Delete WebUSB Policy from Intune Portal

If you want to delete this policy for any reason, you can easily do so. First, search for the policy name(Allow WebUSB on specific sites) in the configuration section. When you find the policy name, you will see a 3-dot menu next to it. Click on the 3 dots, then click the Delete button.

For detailed information, you can refer to our previous post How to Delete Allow Clipboard History Policy in Intune Step by Step Guide.

Enable WebUsb Ask for Urls Policy in Microsoft Edge to Control USB Device Access using Intune - Fig.12
Enable WebUsb Ask for Urls Policy in Microsoft Edge to Control USB Device Access using Intune – Fig.12

Need Further Assistance or Have Technical Questions?

Join the LinkedIn Page and Telegram group to get the latest step-by-step guides and news updates. Join our Meetup Page to participate in User group meetings. Also, Join the WhatsApp Community to get the latest news on Microsoft Technologies. We are there on Reddit as well.

Author

Anoop C Nair has been Microsoft MVP from 2015 onwards for 10 consecutive years! He is a Workplace Solution Architect with more than 22+ years of experience in Workplace technologies. He is also a Blogger, Speaker, and Local User Group Community leader. His primary focus is on Device Management technologies like SCCM and Intune. He writes about technologies like Intune, SCCM, Windows, Cloud PC, Windows, Entra, Microsoft Security, Career, etc.

Written by

Anoop C Nair is Workplace Technology solution architect with 25+ years of experience in global enterprise organizations such as JP Morgan, Capgemini, etc. Microsoft Certified Trainer. Microsoft MVP from 2015 onwards for consecutive 11+ years! He also conducts Intune and modern workplace tech training for enterprise organizations. He is Blogger, Speaker, and Founder of HTMD Community and HTMD Conference. His main focus is on Device Management technologies like Intune, Windows, Cloud PC. He writes about technologies like Intune, SCCM, Windows, Cloud PC, Windows, Entra, Microsoft Security.

Discussion

Join the discussion

Your email address will not be published. Required fields are marked *

Related guides

Intune

Simplify Windows Devices to Run Only the Required Applications using Intune

Key Takeaways Hey, let’s learn about Simplify Windows Devices to Run Only the Required Applications using Intune. This policy lets administrators replace the default windows shell with a custom or lightweight shell. it improves performance by using system resources and is useful for devices that run a dedicated application. If the policy is disabled or […]

AC Anoop C Nair 8 min read
Intune

Enhance macOS Compliance with Custom Security and Compliance Checks to Improve Device Security using Microsoft Intune

Key Takeaways In this post we are discussing about Enhance macOS Compliance with Custom Security and Compliance Checks to Improve Device Security using Microsoft Intune. Microsoft has announced the general availability of Custom Compliance Settings for macOS in Microsoft Intune. The feature helps organizations strengthen security controls while supporting many types of macOS management scenarios. […]

AC Anoop C Nair 4 min read
Intune

Manage Samsung Galaxy Firmware Versions to Improve Security and Compliance using Microsoft Intune

Key Takeaways In this post we are discussing Manage Samsung Galaxy Firmware Versions to Improve Security and Compliance using Microsoft Intune. Microsoft Intune has received a new update that expands firmware management capabilities for Samsung Galaxy devices through Firmware Versionsintegration. This enhancement gives IT administrators more control over firmware and operating system updates, helping them […]

AC Anoop C Nair 4 min read
Intune

MS Intune Adds Windows Registry Data Collection to Device Inventory for Single Values All Key Values and Subkeys

Key Takeaways Microsoft Intune 2607 introduces Windows Registry Data collection in Device Inventory, allowing IT admins to verify actual device configurations without relying on custom discovery or remediation scripts. Using the Properties Catalog, admins can collect registry information through Single Value, All Values Under a Key (Non-Recursive), or Same Value Across Subkeys. MS Intune Adds […]

AC Anoop C Nair 5 min read