18.3.7 Ensure 'Limits print driver installation to Administrators' is set to 'Enabled'

Information

This policy setting controls whether users who aren't Administrators can install print drivers on the system.

The recommended state for this setting is: Enabled.

Note: On August 10, 2021, Microsoft announced a Point and Print Default Behavior Change which modifies the default Point and Print driver installation and update behavior to require Administrator privileges. This is documented in KB5005652-Manage new Point and Print default driver installation behavior (CVE-2021-34481).

Rationale:

Restricting the installation of print drives to Administrators can help mitigate the PrintNightmare vulnerability (CVE-2021-34527) and other Print Spooler attacks.

Impact:

None - this is the default behavior.

Solution

To establish the recommended configuration via GP, set the following UI path to Enabled.

Computer Configuration\Policies\Administrative Templates\MS Security Guide\Limits print driver installation to Administrators

Note: This Group Policy path does not exist by default. An additional Group Policy template SecGuide.admx/adml is required - it is available from Microsoft at this link.

Default Value:

Enabled. (The system will limit installation of print drivers to Administrators of the computer.)

See Also

https://workbench.cisecurity.org/files/4022

Item Details

Category: IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|IA-5(1), 800-53|SC-28, 800-53|SC-28(1), CSCv6|16.14, CSCv7|16.4

Plugin: Windows

Control ID: 04ced794f30dafa232cc8bd686dcaa9c3334e7f4214d1264becd53b26239b1ae