at my workplace we also use a software to block/allow/read only devices and ports, it's called Endpoint Protector 4