Endpoint configuration · GraphQL enum

UpdatePromptSettings enum

Point and Print Restrictions — behavior when updating drivers for an existing printer connection. Controls whether users see a warning and/or an elevation (UAC) prompt when Windows Installer updates a printer driver via Point and Print. Stored in HKLM\Software\Policies\Microsoft\WindowsNT\Printers\PointAndPrint:UpdatePromptSettings. CIS Benchmark (L1) requires WARN_AND_ELEVATE_ON_UPDATE to mitigate PrintNightmare (CVE-2021-34527). Reference: Point and Print Restrictions policies are ignored in Windows

Values

Enum Value Description

WARN_AND_ELEVATE_ON_UPDATE

Show warning and elevation prompt (registry value 0). Most secure. The user sees a warning dialog and must supply administrator credentials before the updated printer driver is installed. CIS L1 recommended value.

WARNING_NO_ELEVATION_ON_UPDATE

Show warning only (registry value 1). A warning dialog is shown when the driver is updated, but no elevation prompt is displayed. The driver installs without requiring administrator credentials.

NO_WARNING_NO_ELEVATION_ON_UPDATE

Do not show warning or elevation prompt (registry value 2). Least secure. Driver updates are applied silently with no user notification and no credential check. Exposes the host to PrintNightmare-class privilege escalation attacks (CVE-2021-34527).

Used by

Example

Example

"WARN_AND_ELEVATE_ON_UPDATE"