4.7.3 (L1) Ensure 'Configure RPC connection settings: Protocol to use for outgoing RPC connections' is set to 'Enabled: RPC over TCP'

Information

This policy setting controls which protocol and protocol settings to use for outgoing Remote Procedure Call (RPC) connections to a remote print spooler.

The recommended state for this setting is: Enabled: RPC over TCP

This setting prevents the use of named pipes for RPC connections to the print spooler and forces the use of TCP which is a more secure communication method.

Solution

To establish the recommended configuration via configuration profiles, set the following Settings Catalog path to Enabled: RPC over TCP :

Administrative Templates\Printers\Configure RPC connection settings: Protocol to use for outgoing RPC connections

Impact:

Warning: Many existing print configurations may be using the older named pipes protocol and therefore will cease to function.

See Also

https://workbench.cisecurity.org/benchmarks/21719

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6b.

Plugin: Windows

Control ID: 414d3c25535d6b453997ab8460dcc8727a3e29660c760ee6f8e62c89ac4910c3