18.7.8 (L1) Ensure 'Limits print driver installation to Administrators' is set to 'Enabled'

Information

This policy setting controls whether users who aren't Administrators can install print drivers on the system.

The recommended state for this setting is: Enabled

Note: On August 10, 2021, Microsoft announced a

Point and Print Default Behavior Change

which modifies the default Point and Print driver installation and update behavior to require Administrator privileges. This is documented in

KB5005652-Manage new Point and Print default driver installation behavior (CVE-2021-34481)

.

Restricting the installation of print drives to Administrators can help mitigate the PrintNightmare vulnerability (

CVE-2021-34527

) and other Print Spooler attacks.

Solution

To establish the recommended configuration via GP, set the following UI path to Enabled

Computer Configuration\Policies\Administrative Templates\Printers\Limits print driver installation to Administrators

Note: This Group Policy path is provided by the Group Policy template Printing.admx/adml that is included with the Microsoft Windows 10 Release 21H2 Administrative Templates (or newer).

Impact:

None - this is the default behavior.

See Also

https://workbench.cisecurity.org/benchmarks/17096

Item Details

Category: SYSTEM AND INFORMATION INTEGRITY

References: 800-53|SI-4

Plugin: Windows

Control ID: adb35f999df6d1276f92b33c77d079c24f3e7a72e2ba313cdd29ef6d16f3d585