18.7.15 Ensure 'Set TLS/SSL security policy for IPP printers: Disallow invalid certificate authority' is set to 'Enabled: Checked'

Information

This policy setting determines the TLS/SSL security policy (WINHTTP_OPTION_SECURITY_FLAGS) for printers using the Microsoft Internet Printing Protocol (IPP) Class Driver.

The recommended state for this setting is: Enabled: Checked.

Certificate validation helps prevent spoofed or unauthorized printers, reduces the risk of credential theft, and protects sensitive print jobs from being redirected.

Solution

To establish the recommended configuration via GP, set the following UI path to Enabled: Checked.

Computer Configuration\Policies\Administrative Templates\Printers\Set TLS/SSL security policy for IPP printers: Disallow invalid certificate authority

Note: This Group Policy path is provided by the Group Policy template Printing.admx/adml that is included with the Microsoft Windows 11 Release 25H2 Administrative Templates (or newer).

Impact:

The system enforces certificate validation and blocks printing whenever certificate errors are detected.

Warning: It is recommended that all printers are assessed, and if they meet the requirements, then enable this policy.

See Also

https://workbench.cisecurity.org/benchmarks/26061

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-12, 800-53|SC-13

Plugin: Windows

Control ID: b1984654382a51a46cf320d3c1f406da20349117ee79cbc20945346a029af56e