Windows has no single desktop switch that disables cut, copy, paste, and delete for selected users everywhere. Use the control that matches the asset and threat: NTFS permissions for deletion in a defined folder, Intune App Protection for work-versus-personal app data, Microsoft Purview Endpoint DLP for sensitive-data transfers, and Application Guard for clipboard exchange across an isolated browser boundary.
Hiding Explorer commands or changing the registry is not a security boundary. Keyboard shortcuts, other programs, PowerShell, network paths, remote sessions, and offline access can still provide alternate routes.
Match the operation to the control
| Requirement | Primary control | What it actually covers |
|---|---|---|
| Stop deletion in one local or shared folder | NTFS ACLs, with share permissions for network access | Delete and related file or folder rights on that location |
| Keep company data out of personal apps | Microsoft Intune App Protection | Cut, copy, and paste boundaries in supported managed applications |
| Stop sensitive text being pasted into websites | Microsoft Purview Endpoint DLP | Content-aware audit, warning, override, or blocking in supported browsers |
| Stop sensitive data going to USB, network shares, Bluetooth, or RDP | Microsoft Purview Endpoint DLP | Device activities involving classified or otherwise matched content |
| Control clipboard between a host and isolated browser | Microsoft Defender Application Guard | Host-to-browser and browser-to-host transfer directions |
| Limit visible folders in a kiosk-style File Explorer | Intune File Explorer policy | The Explorer experience, not underlying authorization |
Windows access control treats operations such as deletion as permissions on securable objects; clipboard behavior is handled separately by applications, device management, isolation, or DLP policies. See Microsoft’s access-control model.
Prevent deletion with NTFS permissions
Use NTFS when the requirement is “users can work in this folder but must not remove its contents.” The volume must be NTFS, and you need permission to change the folder’s security settings. For a network share, both share and NTFS permissions apply; test access over the network as well as locally.
#1 Best Overall
- KEYBOARD: The keyboard works for Windows with hot keys that enable easy access to Media, My Computer, Mute, Volume up/down, and Calculator
- EASY SETUP: Experience simple installation with the USB wired connection
- VERSATILE COMPATIBILITY: This keyboard is designed to work with multiple Windows versions, including Vista, 7, 8, 10 offering broad compatibility across devices.
- SLEEK DESIGN: The elegant black color of the wired keyboard complements your tech and decor, adding a stylish and cohesive look to any setup without sacrificing function.
- FULL-SIZED CONVENIENCE: The standard QWERTY layout of this keyboard set offers a familiar typing experience, ideal for both professional tasks and personal use.
Configure the folder
- Create or select the protected folder. Do not experiment on system folders or user profiles without a recovery plan.
- Right-click it, choose Properties, open Security, then select Advanced.
- Inspect inherited entries. Disable inheritance only when the folder needs a deliberately separate permission design.
- Select the security group to restrict, or add one; groups are easier to audit than individual accounts.
- Grant only the rights required for the job, such as Read, Read & execute, List folder contents, and the required create/write rights.
- Do not grant Delete or Delete subfolders and files to the restricted group. Apply the entry to the intended combination of this folder, subfolders, and files.
- Keep full control for a designated owner or administrators group, then apply the change.
These are separate rights. Delete concerns the object itself; Delete subfolders and files is a right on the parent folder. A design that blocks deletion can also affect rename, move, or creation behavior, so do not assume “edit but never delete” without testing. Microsoft’s NTFS deletion guidance covers ACLs, inheritance, ownership, and recovery: NTFS file and folder deletion troubleshooting.
Validate the result
- Open and edit a permitted file.
- Try Delete and Shift+Delete.
- Test rename, move within the volume, new-file creation, and new-folder creation independently.
- Repeat through the share from a standard account; the effective network result is the more restrictive combination of share and NTFS permissions.
- Confirm that an authorized owner or administrator can recover the intended access.
Local administrators, owners, SYSTEM-level processes, backup operators, and offline tools may take ownership or change ACLs. NTFS is therefore a strong control for ordinary users, not an immutable barrier against administrators.
Rank #2
- Reliable Plug and Play: The USB receiver provides a reliable wireless connection up to 33 ft (1), so you can forget about drop-outs and delays and you can take it wherever you use your computer
- Type in Comfort: The design of this keyboard creates a comfortable typing experience thanks to the low-profile, quiet keys and standard layout with full-size F-keys, number pad, and arrow keys
- Durable and Resilient: This full-size wireless keyboard features a spill-resistant design (2), durable keys and sturdy tilt legs with adjustable height
- Long Battery Life: MK270 combo features a 36-month keyboard and 12-month mouse battery life (3), along with on/off switches allowing you to go months without the hassle of changing batteries
- Easy to Use: This wireless keyboard and mouse combo features 8 multimedia hotkeys for instant access to the Internet, email, play/pause, and volume so you can easily check out your favorite sites
Restrict work-data cut, copy, and paste with Intune
Choose Intune App Protection when the data boundary is organizational versus personal—for example, allowing normal work inside approved apps while preventing company content from moving into personal storage. It is not a universal clipboard lock and requires supported enrollment, licensing, and applications.
Configure a Windows App Protection policy
- In the Intune admin center, open Apps > App protection policies > Windows.
- Create or edit a policy and open Data protection.
- Set the cut, copy, and paste control to the boundary your organization needs: unrestricted, organization-only, organization-to-organization destinations, or blocked movement between organizational and external contexts.
- Assign the policy to a pilot group.
- Test work-to-personal copy, personal-to-work paste, work-to-work copy, and content copied from browsers and Office applications.
- Review exceptions and user impact before expanding deployment.
See the documented Windows App Protection settings and App Protection overview. Edge for Business can apply protected-clipboard behavior to its work profile, but that behavior remains scoped to the managed profile rather than the whole Windows clipboard: Edge data-loss-prevention features.
The Tool Desk
Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →Rank #3
- All-day Comfort: The design of this standard keyboard creates a comfortable typing experience thanks to the deep-profile keys and full-size standard layout with F-keys and number pad
- Easy to Set-up and Use: Set-up couldn't be easier, you simply plug in this corded keyboard via USB on your desktop or laptop and start using right away without any software installation
- Compatibility: This full-size keyboard is compatible with Windows 7, 8, 10 or later, plus it's a reliable and durable partner for your desk at home, or at work
- Spill-proof: This durable keyboard features a spill-resistant design (1), anti-fade keys and sturdy tilt legs with adjustable height, meaning this keyboard is built to last
- Plastic parts in K120 include 51% certified post-consumer recycled plastic*
Expect workflow trade-offs. Developers, help-desk staff, password-manager users, and employees who copy ticket numbers or customer data may need documented exceptions. Users can still photograph a screen, retype information, or use an unmanaged application unless additional controls address those paths.
Block sensitive paste actions with Purview Endpoint DLP
Use Purview when the rule is about what the content is, not every paste. Endpoint DLP can audit, block with override, or block sensitive information pasted into supported browser destinations.
Rank #4
- Fluid Typing Experience: Laptop-like profile with spherically-dished keys shaped for your fingertips delivers a fast, fluid, precise and quieter typing experience
- Automate Repetitive Tasks: Easily create and share time-saving Smart Actions shortcuts to perform multiple actions with a single keystroke with the Logi Options+ app (1)
- Smarter Illumination: Backlit keyboard keys light up as your hands approach and adapt to the environment; Now with more lighting customizations on Logi Options+ (1)
- More Comfort, Deeper Focus: Work for longer with a solid build, low-profile design and an optimum keyboard angle that is better for your wrist posture
- Multi-Device, Multi OS Bluetooth Keyboard: Pair with up to 3 devices on nearly any operating system (Windows, macOS, Linux, Googlebook OS) via Bluetooth Low Energy or included Logi Bolt USB receiver (2)
Set a browser-paste rule
- In the Microsoft Purview portal, open Data loss prevention > Settings.
- Under endpoint settings, create sensitive service-domain groups for destinations needing stricter treatment.
- Open Data loss prevention > Policies, create or edit a policy scoped to devices, and choose Create or customize advanced DLP rules.
- Add the relevant sensitive-information type, sensitivity label, or other condition.
- Under device activities, select Audit or restrict activities on devices and choose Paste to supported browsers.
- Start with Audit, then use Block with override or Block after reviewing alerts and false positives.
Microsoft documents Edge, Chrome, and Firefox support on Windows; Chrome and Firefox require the documented browser extensions. Coverage is not universal across every browser. Classification can introduce a short evaluation delay and a policy notification. Details and prerequisites are in Purview’s browser-paste guidance.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Control copying to USB, shares, Bluetooth, RDP, and the clipboard
If the concern is exfiltration, configure Purview Endpoint DLP device activities rather than trying to remove Explorer buttons. After onboarding supported Windows devices, define the sensitive content condition and select activities such as:
Best Value
- All-day Comfort: This USB keyboard creates a comfortable and familiar typing experience thanks to the deep-profile keys and standard full-size layout with all F-keys, number pad and arrow keys
- Built to Last: The spill-proof (2) design and durable print characters keep you on track for years to come despite any on-the-job mishaps; it’s a reliable partner for your desk at home, or at work
- Long-lasting Battery Life: A 24-month battery life (4) means you can go for 2 years without the hassle of changing batteries of your wireless full-size keyboard
- Simply plug the USB receiver into a USB port on your desktop, laptop or netbook computer and start using the keyboard right away without any software installation
- Simply Wireless: Forget about drop-outs and delays thanks to a strong, reliable wireless connection with up to 33 ft range (5); K270 is compatible with Windows 7, 8, 10 or later
- Copy to clipboard
- Copy to a removable USB device
- Copy to a network share
- Copy or move using an unallowed Bluetooth application
- Copy or move using RDP
Microsoft’s activity reference is Endpoint DLP controls for device activities. The default device policy audits several activities initially; use that audit period to identify legitimate workflows before enforcement. A broad USB or clipboard block can disrupt accessibility software, password managers, remote support, printers, scanners, and line-of-business applications.
If the requirement is simply to deny removable storage rather than inspect content, the RemovableStorage policy can deny supported removable-storage classes on applicable Windows editions. That is device access control, not content-aware DLP.
Control clipboard across an isolated browser boundary
Application Guard is appropriate when untrusted browsing must be isolated from the host. Intune endpoint-protection settings can allow copy and paste from the PC to the protected browser, from the browser to the PC, in both directions, or in neither direction; when an allow mode is selected, the permitted data can be limited to text, images, or both. Configure it through the documented Intune Application Guard settings. This does not disable clipboard use among ordinary desktop applications.
Limit File Explorer locations in managed environments
The Intune File Explorer policy can define allowed folder locations for supported Windows 10 and Windows 11 editions, including documented Pro, Enterprise, Education, and IoT Enterprise coverage. See the FileExplorer policy CSP for version details. It narrows the Explorer interface; it does not grant file authorization or stop another application with access from reading the same path.
Do these 3 things before closing this tab:
1Fix the driver behind crashes, sound loss and screen glitches2Repair Windows errors before they cause bigger problems3Scan for outdated or missing drivers - takes under a minuteQuick Recap
Approaches that do not provide reliable protection
- Hidden context-menu commands: cosmetic only; shortcuts, drag-and-drop, alternate file managers, shells, archive tools, sync clients, and network paths remain.
- Registry-only Explorer hacks: they change a user interface, not the underlying authorization or data-transfer path.
- NTFS for clipboard control: ACLs understand files and folders, not ordinary text or images copied from an application.
- AppLocker as a copy blocker: AppLocker controls whether applications run; it does not itself define a general clipboard or file-copy rule. See AppLocker overview.
- Restricting administrators as though they were standard users: administrators can often take ownership, change policy, install alternate tools, or access data offline. Use separate daily standard accounts and controlled administrative accounts.
Validation matrix
| Test | Expected result |
|---|---|
| Open protected file | Allowed or denied as designed |
| Edit protected file | Allowed or denied as designed |
| Delete and Shift+Delete | Denied for the restricted group |
| Rename and move | Tested separately; neither is implied by the delete result |
| Copy to another local folder | Verified against the intended data boundary |
| Paste into a personal application | Intune result verified |
| Paste into a supported browser | Purview audit, override, or block verified |
| Copy to USB, share, Bluetooth, or RDP | Endpoint DLP result verified |
| Repeat as an administrator | Bypass risk documented and accepted or separately controlled |
Choose the least invasive effective layer
- Folder integrity: design and test NTFS ACLs, plus share permissions where applicable.
- Work/personal application separation: use Intune App Protection in supported managed contexts.
- Sensitive information: use Purview Endpoint DLP with audit-first deployment and narrowly defined conditions.
- Browser isolation: use Application Guard for the specific host/browser boundary.
- Broader bypass resistance: combine standard-user accounts, application control, endpoint management, monitoring, and organizational procedures.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




