Information
This policy setting determines the TLS/SSL security policy (WINHTTP_OPTION_SECURITY_FLAGS) for printers using the Microsoft Internet Printing Protocol (IPP) Class Driver.
The recommended state for this setting is: Enabled: Checked.
Certificate validation helps prevent spoofed or unauthorized printers, reduces the risk of credential theft, and protects sensitive print jobs from being redirected.
Solution
To establish the recommended configuration via GP, set the following UI path to Enabled: Checked.
Computer Configuration\Policies\Administrative Templates\Printers\Set TLS/SSL security policy for IPP printers: Disallow invalid certificate common name
Note: This Group Policy path is provided by the Group Policy template Printing.admx/adml that is included with the Microsoft Windows 11 Release 25H2 Administrative Templates (or newer).
Impact:
The system enforces certificate validation and blocks printing whenever certificate errors are detected.
Warning: It is recommended that all printers are assessed, and if they meet the requirements, then enable this policy.