20.37 Ensure 'Non-administrative accounts or groups only have print permissions on printer shares'

Information

This policy setting ensures that non-administrative accounts or groups only have print permissions on printer shares.

Windows shares are a means by which files, folders, printers, and other resources can be published for network users to access. Improper configuration can permit access to devices and data beyond a user's need.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

Configure the permissions on shared printers to restrict standard users to only have Print permissions.

Open

Printers & scanners

in

Settings

.

For each printer:

- Select the

printer

- Select

Manage

- Select

Printer Properties

- Select the

Sharing

tab

If Share this printer is checked, select the

Security

tab and change the permissions.

Impact:

Standard user accounts will only have print permissions on printer shares.

See Also

https://workbench.cisecurity.org/benchmarks/15301

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-3

Plugin: Windows

Control ID: 34a25baad9be0cab249853acbda4efb7503b9341510f8557ab1b2f64f9a5e6db