Skip to main content

πŸ›‘οΈπŸͺŸπŸ’»πŸ‘ˆπŸ”“βš™οΈGroup - DMA Guard Allowed

What this group is for​

This is a static assigned device group that carves an exception out of the tenant-wide block on external DMA.

It works only as a pair with:

A device in this group is dropped from the block and actively allowed external DMA again. Membership is an exception with a hardware reason, not a convenience.

πŸ› οΈ Group Configuration​

SettingValue
Group nameπŸ›‘οΈπŸͺŸπŸ’»πŸ‘ˆπŸ”“βš™οΈGroup - DMA Guard Allowed
Group descriptionDevices explicitly allowed external DMA, overriding the DMA Guard block, because they run a peripheral that lacks memory remapping. Membership requires documented, approved justification.
Group typeSecurity
Membership typeAssigned (Device Group)

⚠️ Governance​

Excluding a device from the block is only half the job; the inverse policy is what actually reopens DMA, so both assignments must be in place. And because you are reopening a physical attack surface, the bar is high:

  • A documented peripheral requirement per device (which dock, which card, why).
  • Written risk acceptance from the customer.
  • A regular membership review (quarterly at least), and ideally physical control of the device.

Good reason: a fixed workstation with an older capture card that has no remapping support. Bad reason: "the dock was acting up, so I allowed everything." If you cannot defend a device's place here in an audit, it does not belong here.


Keep it small. An exception group the size of the fleet is not an exception, it is a disarmed defense wearing a disguise. πŸ”“