18.7.14 Ensure 'Require IPPS for IPP printers' is set to 'Enabled'

Information

This policy setting determines whether communication with printers using the Microsoft Internet Printing Protocol (IPP) Class Driver uses IPPS. IPPS uses TLS for secure communication.

The recommended state for this setting is: Enabled.

To prevent interception or tampering with printer data, IPPS encrypts all communication between the client and the printer.

Solution

To establish the recommended configuration via GP, set the following UI path to Enabled.

Computer Configuration\Policies\Administrative Templates\Printers\Require IPPS for IPP printers

Note: This Group Policy path is provided by the Group Policy template Printing.admx/adml that is included with the Microsoft Windows 11 Release 25H2 Administrative Templates (or newer).

Impact:

IPP printers which use self-signed or locally issued certificates will be affected and may not function properly. Any attempts to install non-compliant IPP printers will fail and generate an event in the Application log.

Warning: It is recommended that all printers are assessed, and if they meet the requirements, then enable this policy.

See Also

https://workbench.cisecurity.org/benchmarks/25708

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-8

Plugin: Windows

Control ID: 80da955a947880212318de5eefa9f55e887887a7eb107c9f4b5f1e533c027bcb