18.7.9 (L2) Ensure 'Configure Windows protected print' is set to 'Enabled'

Information

This policy setting controls whether Windows protected print is enabled on the system. Windows protected print uses the modern print platform and Windows protected print mode. Modern print is designed to work only with Mopria-certified printers. Mopria is a collection of printer manufacturers and software vendors that define standards for IPP printing and eSCL scanning.

The recommended state for this setting is: Enabled

Note: Windows protected print will not prohibit administrators or users from installing third-party print drivers through an installation package provided by the print device manufacturer.

In September of 2023, Microsoft announced an end of servicing plan for legacy third-party printer drivers. In July of 2025, Microsoft will not publish new printer drivers to Windows Update, and by July 2027 (except for security-related fixes), third-party printer driver updates will no longer be deployed.

Windows protected print also hardens the entire print stack against attacks.

According to Microsoft

, Windows protected print can mitigate over half of past reported security issues for Windows print.

Solution

To establish the recommended configuration via GP, set the following UI path to Enabled

Computer Configuration\Policies\Administrative Templates\Printers\Configure Windows protected print

Note: This Group Policy path is provided by the Group Policy template Printing.admx/adml that is included with the Microsoft Windows 11 Release 24H2 Administrative Templates (or newer).

Impact:

Only Mopria-certified print drivers will continue to be deployed via Widows Update.

See Also

https://workbench.cisecurity.org/benchmarks/21344

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-11b.

Plugin: Windows

Control ID: af9b97804d383643648885f8e0653283b08efdfda997d72a9376958ef750891d