Earlier quoted context omitted.
I used to do the other way around, and disable all my ports until I knew I needed to use one. Of course, there's always the possibility that I unlock my port and plug in some infected USB of my own volition and it's much more likely than some random person plugging something in. But, anyway, this thing presents as a keyboard, not a storage device.
I thought about disabling ports, and on some machines I do, but for the most part there would be mutiny if people couldn't charge their phones or use USB sticks for legitimate purposes. I try instead to make sure everyone is skeptical and weary of everything technology related+the corporate network. I'm in the process of creating a USB drop-test script for employee training purposes. Awareness and preparedness traini…
If the corporate network you're talking about is Windows Active Directory based then I believe that there are Group Policy settings to only allow connection of encrypted external drives. I'm not sure when this was introduced, and it might only be on Windows 10, but hopefully at this point most businesses are either already there or moving in that direction.