Endpoint configuration · GraphQL enum

RedirectionGuardPolicy enum

GPO policy: "Configure Redirection Guard" under Computer Configuration > Administrative Templates

Printers. Determines whether Redirection Guard is enabled for the print spooler process, which prevents file-redirect attacks against the spooler (e.g. symlink/junction abuse via CopyFiles). Registry: HKLM\SOFTWARE\Policies\Microsoft\Windows NT\Printers:RedirectionguardPolicy (REG_DWORD). Default when policy is unconfigured is Enabled (value 1). Reference: Printer driver security guidance

Values

Enum Value Description

DISABLED

Redirection Guard disabled (registry value 0). File redirections may be followed by the spooler process. Less secure; not recommended.

ENABLED

Redirection Guard enabled (registry value 1, default). Prevents any file redirections from being followed within the spooler process.

AUDIT_ONLY

Audit-only mode (registry value 2). Redirection Guard logs events as though enforced but does not actually block file redirections. Use to assess impact before enforcing.

Used by

Example

Example

"DISABLED"