Information
This policy setting determines whether communication with printers using the Microsoft Internet Printing Protocol (IPP) Class Driver uses IPPS. IPPS uses TLS for secure communication.
The recommended state for this setting is: Enabled.
To prevent interception or tampering with printer data, IPPS encrypts all communication between the client and the printer.
Solution
To establish the recommended configuration via GP, set the following UI path to Enabled.
Computer Configuration\Policies\Administrative Templates\Printers\Require IPPS for IPP printers
Note: This Group Policy path is provided by the Group Policy template Printing.admx/adml that is included with the Microsoft Windows 11 Release 25H2 Administrative Templates (or newer).
Impact:
IPP printers which use self-signed or locally issued certificates will be affected and may not function properly. Any attempts to install non-compliant IPP printers will fail and generate an event in the Application log.
Warning: It is recommended that all printers are assessed, and if they meet the requirements, then enable this policy.