Information
This policy setting controls whether users who aren't Administrators can install print drivers on the system.
The recommended state for this setting is: Enabled.
Note: On August 10, 2021, Microsoft announced a Point and Print Default Behavior Change which modifies the default Point and Print driver installation and update behavior to require Administrator privileges. This is documented in KB5005652-Manage new Point and Print default driver installation behavior (CVE-2021-34481).
Rationale:
Restricting the installation of print drives to Administrators can help mitigate the PrintNightmare vulnerability (CVE-2021-34527) and other Print Spooler attacks.
Impact:
None - this is the default behavior.
Solution
To establish the recommended configuration via GP, set the following UI path to Enabled.
Computer Configuration\Policies\Administrative Templates\Printers\Limits print driver installation to Administrators
Note: This Group Policy path is provided by the Group Policy template Printing.admx/adml that is included with the Microsoft Windows 10 Release 21H2 Administrative Templates (and newer).
Default Value:
Enabled. (The system will limit installation of print drivers to Administrators of the computer.)