Você pode seguir os links aqui para desativá-lo via GPO
Detalhes:
In GPEdit.msc (or any other GPO Editor window you're using) click on View > Filtering.
Click to un-select the "Only show policy settings that can be fully managed" check-box. Click Ok.
Now you will be able to see the new settings in the right pane:
An additional step that needs to be performed before the above tip will work has to do with modifying the file access permissions for 2 files. You need to remove the SYSTEM access permissions from the usbstor.sys and usbstor.inf files.
You can do so by right clicking these files > Properties, then going to the Security tab. There you need to remove the line for the SYSTEM account.
Note: Under some circumstances, the SYSTEM should have write access to these files during Service Pack installation. For example, when the SP is installed via GPO or SMS, the installation runs under the SYSTEM Account.
Service Pack needs to replace the files to a new version and without proper write access to the file, installation will fail... Therefore, before each SP deployment we need to allow access to the SYSTEM account for these files.