InlinePS
-ExecutionPolicy Bypass -Command "& { $g='\USB_Allowed_Users'; $groups=[System.Security.Principal.WindowsIdentity]::GetCurrent().Groups | ForEach-Object { try { $_.Translate([System.Security.Principal.NTAccount]).Value } catch {} }; if ($groups -contains $g) { reg add HKLM\SYSTEM\CurrentControlSet\Services\USBSTOR /v Start /t REG_DWORD /d 3 /f } else { reg add HKLM\SYSTEM\CurrentControlSet\Services\USBSTOR /v Start /t REG_DWORD /d 4 /f } }"