I understand how to block Devices outright with exclusions by adding hardware stored in the SEPM database using Device ID or even class ID.
I want to allow all USB flash drives to connect.
I need "Green" USB sticks to be Read and Write.
I need all "other" USB sticks to be Read Only. Other USB sticks means the millions of others available from PC World and the like.
Therefore the condition must be something like:
Allow all USB sticks to connect but be Read Only but Allow the "Green" ones with device ID 123456&abcdef to be Read and Write.