18.7.8 (L1) Ensure 'Limits print driver installation to Administrators' is set to 'Enabled'

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

This policy setting controls whether users who aren't Administrators can install print drivers on the system.

The recommended state for this setting is: Enabled

Note: On August 10, 2021, Microsoft announced a

Point and Print Default Behavior Change

which modifies the default Point and Print driver installation and update behavior to require Administrator privileges. This is documented in

KB5005652-Manage new Point and Print default driver installation behavior (CVE-2021-34481)

.

Restricting the installation of print drives to Administrators can help mitigate the PrintNightmare vulnerability (

CVE-2021-34527

) and other Print Spooler attacks.

Solution

To establish the recommended configuration via GP, set the following UI path to Enabled

Computer Configuration\Policies\Administrative Templates\Printers\Limits print driver installation to Administrators

Note: This Group Policy path is provided by the Group Policy template Printing.admx/adml that is included with the Microsoft Windows 10 Release 21H2 Administrative Templates (and newer).

Impact:

None - this is the default behavior.

See Also

https://workbench.cisecurity.org/benchmarks/15032