Best setup for an offline, USB-scanning kiosk PC
We are working at rolling out USB whitelisting to allow only corporate provided & Bitlocker'd USB sticks. However due to the nature of the org we regularly (maybe weekly) expect to have to get random files from a USB stick provided by the public.
What we're looking at setting up is a couple standalone PCs setup to only accept these untrusted USBs, scan them, and then allow the data transfer to one of the trusted USBs. The problem I'm coming up with is our main AV is Defender for Endpoints and as far as I can see there is no way with Defender to block access to the USB stick until it is scanned. Our staff are not tech-oriented so some sort of progress bar or splash screen while it is working would be an awesome bonus. I know Defender does on-access scanning and would scan it on the transfer but some of the higher-ups aren't confident enough in that and would like access blocked until the full scan is finished.
What are other people doing to solve this? I'm half expecting to need to get a third-party AV (we used to have Kaspersky which could do block-until-scanned) and we'd really like to avoid buying a pre-built kiosk like Tyrex. But we'd love to be able to make it work with our current stack (Defender).
[link] [comments]