Information
This policy setting controls whether users who aren't Administrators can install print drivers on the system.
The recommended state for this setting is: Enabled
Note: On August 10, 2021, Microsoft announced a
Point and Print Default Behavior Change
which modifies the default Point and Print driver installation and update behavior to require Administrator privileges. This is documented in
KB5005652-Manage new Point and Print default driver installation behavior (CVE-2021-34481)
.
Restricting the installation of print drives to Administrators can help mitigate the PrintNightmare vulnerability (
CVE-2021-34527
) and other Print Spooler attacks.
Solution
To establish the recommended configuration via configuration profiles, set the following Settings Catalog path to Enabled
Administrative Templates\Printers\Limits print driver installation to Administrators
Impact:
None - this is the default behavior.