Skip to main content

🧱πŸͺŸπŸ’»πŸ”“ES - DMA Guard - Allow

The deliberate exception to the block. It reopens external DMA for the specific device that genuinely needs a non-remapping peripheral, and nobody else.

🧱Type Endpoint Security (inverse)πŸͺŸPlatform WindowsπŸ”“Action Reopen, exception group
reference-build Β· es-dma-guard-allowGolden Master reference
License tier
Business Premium (Intune)
Control plane
Intune Settings Catalog
Scope
Assigned exception group only
Reversibility
clean-revert

What this policy is about πŸ”“β€‹

This is the counter-policy to 🧱πŸͺŸπŸ’»ES - DMA Guard. The block refuses DMA to peripherals that do not support memory remapping, which is the right default. But some legitimate hardware, older docks, external GPUs, and capture cards, is exactly that: DMA-capable and remapping-incapable. On those devices the block does its job a little too well and the peripheral simply stops working.

For that narrow case, this policy sets the Device Enumeration Policy to Allow all, reopening DMA, and it is assigned only to the exception group. Everyone else stays protected by the block.

πŸ€” A named exception, not a retreat

This does not weaken DMA Guard for the tenant. It lifts it for a documented list of devices that have a hardware reason and an accepted risk. Aim it at one dock model; never aim it at "all laptops".

πŸ› οΈ Configuration​

Where: Intune admin center β†’ Devices β†’ Configuration β†’ Create β†’ Windows β†’ Settings catalog β†’ DMA Guard.

SettingValue
Device Enumeration PolicyAllow all (Least restrictive)
Assignment, includeπŸ›‘οΈπŸͺŸπŸ’»πŸ‘ˆπŸ”“βš™οΈGroup - DMA Guard Allowed
Assignment, excludeNone (only the approved exception group receives this)

Setting it to Allow all overrides the block for the assigned devices, which is the only thing that reopens DMA for them.

Caveats βš οΈβ€‹

Assign it narrowly or you have disarmed the fleet. This belongs on the approved exception group only. Point it any wider and you have reopened the DMA attack surface for everyone.

It is only half the pair. It has no purpose without the DMA Guard block; the two are designed and reviewed together.

Every member needs a reason and a compensating control. A device in this group is more exposed to physical DMA attacks, so the peripheral requirement should be documented, the risk accepted in writing, and the device ideally physically controlled (not left in hotel rooms).

License and reversibility. Included in Business Premium. Clean-revert: unassign and those devices fall back under the block.


Reopen the port for the one device that needs it, with the paperwork to back it up, and keep the block for everyone else. πŸ”“