1. Home
  2. Knowledge Base
  3. SureMDM
  4. How to Allow or Block USB Storage devices via Run Script job on macOS
  1. Home
  2. Knowledge Base
  3. macOS Management
  4. How to Allow or Block USB Storage devices via Run Script job on macOS

How to Allow or Block USB Storage devices via Run Script job on macOS

Administrators can now restrict access to USB storage on macOS devices with SureMDM, preventing unwanted data transfers and protecting private data. By configuring a Run Script job, admins can easily allow or block USB storage devices (such as flash drives, external hard drives, and pen drives). This guide provides steps to configure and apply the Job for effective USB management on macOS. 


To enable or disable USB Storage devices on macOS using a Run Script in SureMDM, providing control over the use of USB storage peripherals without affecting other types of connected devices (e.g., keyboards, mice, and smartphones).


  1. Access to the SureMDM account.
  2. Permission to create and apply jobs.
  3. macOS devices are enrolled and managed through SureMDM, and it should be online.
  4. macOS Agent version >=5.8.3


  1. This Script-based approach targets USB Storage devices only (such as flash drives, external hard drives, and pen drives)
  2. This configuration will not affect other peripherals (e.g., keyboards, mice, and smartphones).


  1. Login to SureMDM Console.
  2. Navigate to Jobs, click on New Job, and select macOS as a platform.
  3. Now, click on Run script job.
  1. Enter the Job name and select Allow USB storage Devices/Block USB storage Devices from the USB Media Control section
    →Allow USB Storage Devices: !#suremdm USBMode UnBlock
    →Block USB Storage Devices: !#suremdm USBMode Block
  2. Click Validate to validate the script, and then click on Insert after validation.
    Now the script will be in the script box.

  3. Click Save.
    Now, the newly created job will be listed in the Jobs Section.
  4. Go back to the Home tab and select the macOS device(s) or group(s).
  5. Click Apply to launch the Apply Job/Profile To Device prompt.
  6. In the Apply Job/Profile To Device prompt, select the created job and click on Apply.

Need help? CONTACT US

Was this helpful?
Updated on December 2024
Need Support?
Can't find the answer you're looking for?
Contact Support