Wartiva evaluates these checks on its cloud mirror every time an endpoint changes, with zero endpoint load, and turns every failure into a finding with captured evidence. How Wartiva works →
All 18 checks on this page
- Ensure Incoming Printer RPC Connections Use Negotiate Authentication Or Higher
- Ensure Incoming Printer RPC Connections Use RPC Over TCP
- Ensure IPP Printers Disallow An Invalid Certificate Authority
- Ensure IPP Printers Disallow An Invalid Certificate Common Name
- Ensure IPP Printers Disallow An Invalid Certificate Date
- Ensure IPP Printers Disallow Non-Server Certificates
- Ensure IPPS Is Required For IPP Printers
- Ensure Outgoing Printer RPC Connections Use Default Authentication
- Ensure Outgoing Printer RPC Connections Use RPC Over TCP
- Ensure Point And Print Shows Warning And Elevation Prompt When Installing New Drivers
- Ensure Point And Print Shows Warning And Elevation Prompt When Updating Existing Drivers
- Ensure Print Driver Installation Is Limited To Administrators
- Ensure Print Spooler Does Not Accept Client Connections
- Ensure Printer Redirection Guard Is Enabled
- Ensure Printer RPC Over TCP Port Is Set To Zero
- Ensure Queue-Specific Files Are Limited To Color Profiles
- Ensure RPC Packet Level Privacy Is Enabled For Incoming Printer Connections
- Ensure Windows Protected Print Is Enabled
Ensure Incoming Printer RPC Connections Use Negotiate Authentication Or Higher
Finding: Incoming printer RPC connections do not require Negotiate authentication or higher.
Checks whether the authentication protocol for incoming print-spooler RPC connections is Negotiate or Kerberos.
This rule fails when forceKerberosForRpc is not NEGOTIATE or KERBEROS.
Rationale: Requiring Negotiate (or the stronger Kerberos) for incoming spooler RPC forces authenticated, more secure connections.
Impact: Print configurations still relying on the older named-pipes protocol may cease to function.
Remediation
Open Computer Configuration > Policies > Administrative Templates > Printers > Configure RPC listener settings: Configure protocol options for incoming RPC connections and set the authentication protocol to Enabled: Negotiate or Enabled: Kerberos.
From the command line:
reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows NT\Printers\RPC" /v ForceKerberosForRpc /t REG_DWORD /d 0 /f
- Risk
- External Attack Surface
- MITRE ATT&CK tactic
- Defense Evasion (TA0005)
Ensure Incoming Printer RPC Connections Use RPC Over TCP
Finding: Incoming printer RPC connections do not use RPC over TCP.
Checks whether incoming RPC connections to the print spooler are restricted to the TCP transport rather than named pipes.
This rule fails when rpcProtocols is not RPC_OVER_TCP.
Rationale: Restricting the spooler to TCP instead of named pipes is a more secure communication method for incoming RPC.
Impact: Print configurations still relying on the older named-pipes protocol may cease to function.
Remediation
Open Computer Configuration > Policies > Administrative Templates > Printers > Configure RPC listener settings: Protocols to allow for incoming RPC connections and set it to Enabled: RPC over TCP.
From the command line:
reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows NT\Printers\RPC" /v RpcProtocols /t REG_DWORD /d 5 /f
- Risk
- External Attack Surface
- MITRE ATT&CK tactic
- Defense Evasion (TA0005)
Ensure IPP Printers Disallow An Invalid Certificate Authority
Finding: IPP printers accept certificates from an unknown certificate authority.
Checks whether the IPP TLS/SSL security policy blocks printers presenting a certificate from an unknown certificate authority.
This rule fails when securityFlagsBlockUnknownCA is not true.
Rationale: Validating the certificate authority helps prevent spoofed or unauthorized printers, reducing the risk of credential theft and redirected print jobs.
Impact: The system enforces certificate validation and blocks printing when certificate errors are detected.
Remediation
Open Computer Configuration > Policies > Administrative Templates > Printers > Set TLS/SSL security policy for IPP printers: Disallow invalid certificate authority and set it to Enabled: Checked.
From the command line:
reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows NT\Printers\IPP" /v SecurityFlagsBlockUnknownCA /t REG_DWORD /d 1 /f
Ensure IPP Printers Disallow An Invalid Certificate Common Name
Finding: IPP printers accept certificates with an invalid common name.
Checks whether the IPP TLS/SSL security policy blocks printers presenting a certificate whose common name is invalid.
This rule fails when securityFlagsBlockCertCNInvalid is not true.
Rationale: Validating the certificate common name helps prevent spoofed or unauthorized printers, reducing the risk of credential theft and redirected print jobs.
Impact: The system enforces certificate validation and blocks printing when certificate errors are detected.
Remediation
Open Computer Configuration > Policies > Administrative Templates > Printers > Set TLS/SSL security policy for IPP printers: Disallow invalid certificate common name and set it to Enabled: Checked.
From the command line:
reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows NT\Printers\IPP" /v SecurityFlagsBlockCertCNInvalid /t REG_DWORD /d 1 /f
Ensure IPP Printers Disallow An Invalid Certificate Date
Finding: IPP printers accept certificates with an invalid date.
Checks whether the IPP TLS/SSL security policy blocks printers presenting a certificate with an invalid (expired or not-yet-valid) date.
This rule fails when securityFlagsBlockCertDateInvalid is not true.
Rationale: Validating the certificate date helps prevent spoofed or unauthorized printers, reducing the risk of credential theft and redirected print jobs.
Impact: The system enforces certificate validation and blocks printing when certificate errors are detected.
Remediation
Open Computer Configuration > Policies > Administrative Templates > Printers > Set TLS/SSL security policy for IPP printers: Disallow invalid certificate date and set it to Enabled: Checked.
From the command line:
reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows NT\Printers\IPP" /v SecurityFlagsBlockCertDateInvalid /t REG_DWORD /d 1 /f
Ensure IPP Printers Disallow Non-Server Certificates
Finding: IPP printers accept non-server (wrong-usage) certificates.
Checks whether the IPP TLS/SSL security policy blocks printers presenting a non-server certificate (wrong certificate usage).
This rule fails when securityFlagsBlockCertWrongUsage is not true.
Rationale: Rejecting certificates issued for the wrong usage helps prevent spoofed or unauthorized printers, reducing the risk of credential theft and redirected print jobs.
Impact: The system enforces certificate validation and blocks printing when certificate errors are detected.
Remediation
Open Computer Configuration > Policies > Administrative Templates > Printers > Set TLS/SSL security policy for IPP printers: Disallow non-server certificates and set it to Enabled: Checked.
From the command line:
reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows NT\Printers\IPP" /v SecurityFlagsBlockCertWrongUsage /t REG_DWORD /d 1 /f
Ensure IPPS Is Required For IPP Printers
Finding: IPP printers are not required to use IPPS.
Checks whether communication with IPP Class Driver printers must use IPPS (IPP over TLS).
This rule fails when requireIPPs is not true.
Rationale: IPPS uses TLS to encrypt all client-to-printer communication, preventing interception or tampering of print data.
Impact: IPP printers using self-signed or locally issued certificates may not work, and installing non-compliant IPP printers will fail with an Application-log event.
Remediation
Open Computer Configuration > Policies > Administrative Templates > Printers > Require IPPS for IPP printers and set it to Enabled.
From the command line:
reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows NT\Printers\IPP" /v RequireIpps /t REG_DWORD /d 1 /f
Ensure Outgoing Printer RPC Connections Use Default Authentication
Finding: Outgoing printer RPC connections do not use default authentication.
Checks whether outgoing RPC connections to a remote print spooler use the Default authentication behavior.
This rule fails when rpcAuthentication is not DEFAULT.
Rationale: The Default behavior applies appropriate RPC authentication and, together with RPC over TCP, provides more secure spooler communication.
Impact: Print configurations still relying on the older named-pipes protocol may cease to function.
Remediation
Open Computer Configuration > Policies > Administrative Templates > Printers > Configure RPC connection settings: Use authentication for outgoing RPC connections and set it to Enabled: Default.
From the command line:
reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows NT\Printers\RPC" /v RpcAuthentication /t REG_DWORD /d 0 /f
- Risk
- External Attack Surface
- MITRE ATT&CK tactic
- Defense Evasion (TA0005)
Ensure Outgoing Printer RPC Connections Use RPC Over TCP
Finding: Outgoing printer RPC connections do not use RPC over TCP.
Checks whether outgoing RPC connections to a remote print spooler use TCP rather than named pipes.
This rule fails when rpcUseNamedPipeProtocol is not RPC_OVER_TCP.
Rationale: Forcing TCP instead of named pipes for spooler RPC is a more secure communication method.
Impact: Print configurations still relying on the older named-pipes protocol may cease to function.
Remediation
Open Computer Configuration > Policies > Administrative Templates > Printers > Configure RPC connection settings: Protocol to use for outgoing RPC connections and set it to Enabled: RPC over TCP.
From the command line:
reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows NT\Printers\RPC" /v RpcUseNamedPipeProtocol /t REG_DWORD /d 0 /f
- Risk
- External Attack Surface
- MITRE ATT&CK tactic
- Defense Evasion (TA0005)
Ensure Point And Print Shows Warning And Elevation Prompt When Installing New Drivers
Finding: Point and Print installs new-connection drivers without a warning or elevation prompt.
Checks whether Point and Print shows a warning and a UAC elevation prompt before installing a driver for a new printer connection.
This rule fails when noWarningNoElevationOnInstall is not WARN_AND_ELEVATE_ON_INSTALL.
Rationale: Requiring UAC elevation for new print-driver installation helps mitigate the PrintNightmare vulnerability (CVE-2021-34527) and other Print Spooler attacks, serving as a backstop if the default behavior is ever reversed.
Impact: None; this is the default behavior.
Remediation
Open Computer Configuration > Policies > Administrative Templates > Printers > Point and Print Restrictions: When installing drivers for a new connection and set it to Enabled: Show warning and elevation prompt.
From the command line:
reg add "HKLM\Software\Policies\Microsoft\Windows NT\Printers\PointAndPrint" /v NoWarningNoElevationOnInstall /t REG_DWORD /d 0 /f
- Risk
- Vulnerability
- MITRE ATT&CK tactic
- Privilege Escalation (TA0004)
Ensure Point And Print Shows Warning And Elevation Prompt When Updating Existing Drivers
Finding: Point and Print updates existing-connection drivers without a warning or elevation prompt.
Checks whether Point and Print shows a warning and a UAC elevation prompt before updating a driver for an existing printer connection.
This rule fails when updatePromptSettings is not WARN_AND_ELEVATE_ON_UPDATE.
Rationale: Requiring UAC elevation for print-driver updates helps mitigate the PrintNightmare vulnerability (CVE-2021-34527) and other Print Spooler attacks, serving as a backstop if the default behavior is ever reversed.
Impact: None; this is the default behavior.
Remediation
Open Computer Configuration > Policies > Administrative Templates > Printers > Point and Print Restrictions: When updating drivers for an existing connection and set it to Enabled: Show warning and elevation prompt.
From the command line:
reg add "HKLM\Software\Policies\Microsoft\Windows NT\Printers\PointAndPrint" /v UpdatePromptSettings /t REG_DWORD /d 0 /f
- Risk
- Vulnerability
- MITRE ATT&CK tactic
- Privilege Escalation (TA0004)
Ensure Print Driver Installation Is Limited To Administrators
Finding: Non-administrators can install print drivers.
Checks whether only Administrators can install print drivers on the host.
This rule fails when restrictDriverInstallationToAdministrators is not true.
Rationale: Restricting print-driver installation to Administrators mitigates the PrintNightmare vulnerability (CVE-2021-34527) and other Print Spooler attacks.
Impact: None; this is the default behavior.
Remediation
Open Computer Configuration > Policies > Administrative Templates > Printers > Limits print driver installation to Administrators and set it to Enabled.
From the command line:
reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows NT\Printers\PointAndPrint" /v RestrictDriverInstallationToAdministrators /t REG_DWORD /d 1 /f
- Risk
- Vulnerability
- MITRE ATT&CK tactic
- Privilege Escalation (TA0004)
Ensure Print Spooler Does Not Accept Client Connections
Finding: Print Spooler accepts remote client connections.
Checks whether the Print Spooler service is prevented from accepting remote client connections.
This rule fails when registerSpoolerRemoteRpcEndPoint is not false.
Rationale: Blocking remote client connections to the spooler mitigates the PrintNightmare vulnerability (CVE-2021-34527) and other remote Print Spooler attacks.
Impact: Users can still print locally, but the host will not accept client connections or share printers; already-shared printers remain shared.
Remediation
Open Computer Configuration > Policies > Administrative Templates > Printers > Allow Print Spooler to accept client connections and set it to Disabled.
From the command line:
reg add "HKLM\Software\Policies\Microsoft\Windows NT\Printers" /v RegisterSpoolerRemoteRpcEndPoint /t REG_DWORD /d 2 /f
- Framework mappings
- CIS Controls v8: 4.1 Establish and Maintain a Secure Configuration Process; 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
- NIST SP 800-53 Rev. 5: CM-1 Policy and Procedures; CM-2 Baseline Configuration; CM-6 Configuration Settings; CM-7 Least Functionality; CM-9 Configuration Management Plan; SA-3 System Development Life Cycle; SA-8 Security and Privacy Engineering Principles; SA-10 Developer Configuration Management
- NIST SP 800-171 Rev. 2: 3.1.18 Control connection of mobile devices; 3.4.1 Establish and maintain baseline configurations and inventories of organizational systems (including hardware, software, firmware, and documentation) throughout the respective system development life cycles; 3.4.2 Establish and enforce security configuration settings for information technology products employed in organizational systems; 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- CMMC 2.0 Level 2: AC.L2-3.1.18 Control connection of mobile devices; CM.L2-3.4.1 Establish and maintain baseline configurations and inventories of organizational systems (including hardware, software, firmware, and documentation) throughout the respective system development life cycles; CM.L2-3.4.2 Establish and enforce security configuration settings for information technology products employed in organizational systems; CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- PCI DSS v4.0.1: 1.1.1 Network security control policies and procedures kept documented, current, and applied; 1.2.1 Establish and uphold configuration baselines for NSC rulesets; 1.2.5 Approve and justify each allowed port, protocol, and service; 1.2.6 Add security features that offset risk from active insecure services; 1.2.7 Review NSC configurations for relevance and effectiveness every six months; 1.5.1 Harden dual-connected computing devices that reach both the internet and CDE; 2.1.1 Secure configuration policies and procedures kept documented, current, and applied; 2.2.1 Develop and maintain hardening standards covering all system components; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks
- Risk
- High Profile Threat
- MITRE ATT&CK tactic
- Initial Access (TA0001)
Ensure Printer Redirection Guard Is Enabled
Finding: Printer Redirection Guard is not enabled.
Checks whether Redirection Guard is enabled for the print spooler so file redirections cannot be followed within the spooler process.
This rule fails when redirectionguardPolicy is not ENABLED.
Rationale: Redirection Guard prevents non-administrators from redirecting files within the spooler process, closing a print-spooler privilege-escalation avenue.
Impact: None; this is the default behavior.
Remediation
Open Computer Configuration > Policies > Administrative Templates > Printers > Configure Redirection Guard and set it to Enabled: Redirection Guard Enabled.
From the command line:
reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows NT\Printers" /v RedirectionguardPolicy /t REG_DWORD /d 1 /f
- Framework mappings
- CIS Controls v8: 10.5 Enable Anti-Exploitation Features
- NIST SP 800-53 Rev. 5: SI-16 Memory Protection
- Risk
- Vulnerability
- MITRE ATT&CK tactic
- Privilege Escalation (TA0004)
Ensure Printer RPC Over TCP Port Is Set To Zero
Finding: Printer RPC over TCP port is not set to zero.
Checks whether print-spooler RPC over TCP uses a dynamic port (value 0) rather than a fixed port.
This rule fails when rpcTcpPort is not 0.
Rationale: Using a dynamic port makes it harder for an attacker to know which port the spooler is listening on and therefore which port to attack.
Impact: Environments configured for a specific TCP print port may need a firewall change to keep printing.
Remediation
Open Computer Configuration > Policies > Administrative Templates > Printers > Configure RPC over TCP port and set it to Enabled: 0.
From the command line:
reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows NT\Printers\RPC" /v RpcTcpPort /t REG_DWORD /d 0 /f
- Risk
- External Attack Surface
- MITRE ATT&CK tactic
- Discovery (TA0007)
Ensure Queue-Specific Files Are Limited To Color Profiles
Finding: Queue-specific file processing is not limited to color profiles.
Checks whether queue-specific files downloaded during printer installation are limited to the standard color-profile scheme.
This rule fails when copyFilesPolicy is not ICM_ONLY.
Rationale: Restricting which queue-specific files the spooler processes mitigates a Print Spooler remote code execution vulnerability (CVE-2021-36958).
Impact: None; this is the default behavior.
Remediation
Open Computer Configuration > Policies > Administrative Templates > Printers > Manage processing of Queue-specific files and set it to Enabled: Limit Queue-specific files to Color profiles.
From the command line:
reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows NT\Printers" /v CopyFilesPolicy /t REG_DWORD /d 1 /f
- Framework mappings
- CIS Controls v8: 10.5 Enable Anti-Exploitation Features
- NIST SP 800-53 Rev. 5: SI-16 Memory Protection
- Risk
- Vulnerability
- MITRE ATT&CK tactic
- Execution (TA0002)
Ensure RPC Packet Level Privacy Is Enabled For Incoming Printer Connections
Finding: RPC packet level privacy is not enforced for incoming printer connections.
Checks whether packet-level privacy is enforced for incoming print-spooler RPC connections.
This rule fails when rpcAuthnLevelPrivacyEnabled is not true.
Rationale: Enforcing packet-level privacy raises the server-side authentication level and mitigates the Print Spooler spoofing vulnerability CVE-2021-1678.
Impact: None; this is the default behavior.
Remediation
Open Computer Configuration > Policies > Administrative Templates > MS Security Guide > Configure RPC packet level privacy setting for incoming connections and set it to Enabled.
From the command line:
reg add "HKLM\SYSTEM\CurrentControlSet\Control\Print" /v RpcAuthnLevelPrivacyEnabled /t REG_DWORD /d 1 /f
- Risk
- Vulnerability
- MITRE ATT&CK tactic
- Defense Evasion (TA0005)
Ensure Windows Protected Print Is Enabled
Finding: Windows protected print is not enabled.
Checks whether Windows protected print mode (modern print platform, Mopria-certified drivers only) is enabled.
This rule fails when windowsProtectedPrintGroupPolicyState is not true.
Rationale: Windows protected print hardens the entire print stack and, per Microsoft, mitigates over half of past reported Windows print security issues.
Impact: Printers that do not support Mopria cannot be used, and only Mopria-certified drivers are deployed via Windows Update.
Remediation
Open Computer Configuration > Policies > Administrative Templates > Printers > Configure Windows protected print and set it to Enabled.
From the command line:
reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows NT\Printers\WPP" /v WindowsProtectedPrintGroupPolicyState /t REG_DWORD /d 1 /f
- Risk
- Vulnerability
- MITRE ATT&CK tactic
- Execution (TA0002)