CIS Microsoft Windows 11 Stand-alone Benchmark · Section 18.7

Windows 11 Printers: 18 Checks

Wartiva runs 18 checks for section 18.7, Printers, of the CIS Microsoft Windows 11 Stand-alone Benchmark. Each one lists what it finds, why it matters, and how to fix it.

Wartiva evaluates these checks on its cloud mirror every time an endpoint changes, with zero endpoint load, and turns every failure into a finding with captured evidence. How Wartiva works →

All 18 checks on this page

Ensure Incoming Printer RPC Connections Use Negotiate Authentication Or Higher

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.7

Finding: Incoming printer RPC connections do not require Negotiate authentication or higher.

Checks whether the authentication protocol for incoming print-spooler RPC connections is Negotiate or Kerberos.

This rule fails when forceKerberosForRpc is not NEGOTIATE or KERBEROS.

Rationale: Requiring Negotiate (or the stronger Kerberos) for incoming spooler RPC forces authenticated, more secure connections.

Impact: Print configurations still relying on the older named-pipes protocol may cease to function.

Remediation

Open Computer Configuration > Policies > Administrative Templates > Printers > Configure RPC listener settings: Configure protocol options for incoming RPC connections and set the authentication protocol to Enabled: Negotiate or Enabled: Kerberos.

From the command line:

reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows NT\Printers\RPC" /v ForceKerberosForRpc /t REG_DWORD /d 0 /f
Risk
External Attack Surface
MITRE ATT&CK tactic
Defense Evasion (TA0005)

Ensure Incoming Printer RPC Connections Use RPC Over TCP

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.7

Finding: Incoming printer RPC connections do not use RPC over TCP.

Checks whether incoming RPC connections to the print spooler are restricted to the TCP transport rather than named pipes.

This rule fails when rpcProtocols is not RPC_OVER_TCP.

Rationale: Restricting the spooler to TCP instead of named pipes is a more secure communication method for incoming RPC.

Impact: Print configurations still relying on the older named-pipes protocol may cease to function.

Remediation

Open Computer Configuration > Policies > Administrative Templates > Printers > Configure RPC listener settings: Protocols to allow for incoming RPC connections and set it to Enabled: RPC over TCP.

From the command line:

reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows NT\Printers\RPC" /v RpcProtocols /t REG_DWORD /d 5 /f
Risk
External Attack Surface
MITRE ATT&CK tactic
Defense Evasion (TA0005)

Ensure IPP Printers Disallow An Invalid Certificate Authority

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.7

Finding: IPP printers accept certificates from an unknown certificate authority.

Checks whether the IPP TLS/SSL security policy blocks printers presenting a certificate from an unknown certificate authority.

This rule fails when securityFlagsBlockUnknownCA is not true.

Rationale: Validating the certificate authority helps prevent spoofed or unauthorized printers, reducing the risk of credential theft and redirected print jobs.

Impact: The system enforces certificate validation and blocks printing when certificate errors are detected.

Remediation

Open Computer Configuration > Policies > Administrative Templates > Printers > Set TLS/SSL security policy for IPP printers: Disallow invalid certificate authority and set it to Enabled: Checked.

From the command line:

reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows NT\Printers\IPP" /v SecurityFlagsBlockUnknownCA /t REG_DWORD /d 1 /f
Risk
Unprotected Data
MITRE ATT&CK tactic
Command and Control / Exfiltration (TA0011, TA0010)

Ensure IPP Printers Disallow An Invalid Certificate Common Name

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.7

Finding: IPP printers accept certificates with an invalid common name.

Checks whether the IPP TLS/SSL security policy blocks printers presenting a certificate whose common name is invalid.

This rule fails when securityFlagsBlockCertCNInvalid is not true.

Rationale: Validating the certificate common name helps prevent spoofed or unauthorized printers, reducing the risk of credential theft and redirected print jobs.

Impact: The system enforces certificate validation and blocks printing when certificate errors are detected.

Remediation

Open Computer Configuration > Policies > Administrative Templates > Printers > Set TLS/SSL security policy for IPP printers: Disallow invalid certificate common name and set it to Enabled: Checked.

From the command line:

reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows NT\Printers\IPP" /v SecurityFlagsBlockCertCNInvalid /t REG_DWORD /d 1 /f
Risk
Unprotected Data
MITRE ATT&CK tactic
Command and Control / Exfiltration (TA0011, TA0010)

Ensure IPP Printers Disallow An Invalid Certificate Date

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.7

Finding: IPP printers accept certificates with an invalid date.

Checks whether the IPP TLS/SSL security policy blocks printers presenting a certificate with an invalid (expired or not-yet-valid) date.

This rule fails when securityFlagsBlockCertDateInvalid is not true.

Rationale: Validating the certificate date helps prevent spoofed or unauthorized printers, reducing the risk of credential theft and redirected print jobs.

Impact: The system enforces certificate validation and blocks printing when certificate errors are detected.

Remediation

Open Computer Configuration > Policies > Administrative Templates > Printers > Set TLS/SSL security policy for IPP printers: Disallow invalid certificate date and set it to Enabled: Checked.

From the command line:

reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows NT\Printers\IPP" /v SecurityFlagsBlockCertDateInvalid /t REG_DWORD /d 1 /f
Risk
Unprotected Data
MITRE ATT&CK tactic
Command and Control / Exfiltration (TA0011, TA0010)

Ensure IPP Printers Disallow Non-Server Certificates

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.7

Finding: IPP printers accept non-server (wrong-usage) certificates.

Checks whether the IPP TLS/SSL security policy blocks printers presenting a non-server certificate (wrong certificate usage).

This rule fails when securityFlagsBlockCertWrongUsage is not true.

Rationale: Rejecting certificates issued for the wrong usage helps prevent spoofed or unauthorized printers, reducing the risk of credential theft and redirected print jobs.

Impact: The system enforces certificate validation and blocks printing when certificate errors are detected.

Remediation

Open Computer Configuration > Policies > Administrative Templates > Printers > Set TLS/SSL security policy for IPP printers: Disallow non-server certificates and set it to Enabled: Checked.

From the command line:

reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows NT\Printers\IPP" /v SecurityFlagsBlockCertWrongUsage /t REG_DWORD /d 1 /f
Risk
Unprotected Data
MITRE ATT&CK tactic
Command and Control / Exfiltration (TA0011, TA0010)

Ensure IPPS Is Required For IPP Printers

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.7

Finding: IPP printers are not required to use IPPS.

Checks whether communication with IPP Class Driver printers must use IPPS (IPP over TLS).

This rule fails when requireIPPs is not true.

Rationale: IPPS uses TLS to encrypt all client-to-printer communication, preventing interception or tampering of print data.

Impact: IPP printers using self-signed or locally issued certificates may not work, and installing non-compliant IPP printers will fail with an Application-log event.

Remediation

Open Computer Configuration > Policies > Administrative Templates > Printers > Require IPPS for IPP printers and set it to Enabled.

From the command line:

reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows NT\Printers\IPP" /v RequireIpps /t REG_DWORD /d 1 /f
Risk
Unprotected Data
MITRE ATT&CK tactic
Command and Control / Exfiltration (TA0011, TA0010)

Ensure Outgoing Printer RPC Connections Use Default Authentication

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.7

Finding: Outgoing printer RPC connections do not use default authentication.

Checks whether outgoing RPC connections to a remote print spooler use the Default authentication behavior.

This rule fails when rpcAuthentication is not DEFAULT.

Rationale: The Default behavior applies appropriate RPC authentication and, together with RPC over TCP, provides more secure spooler communication.

Impact: Print configurations still relying on the older named-pipes protocol may cease to function.

Remediation

Open Computer Configuration > Policies > Administrative Templates > Printers > Configure RPC connection settings: Use authentication for outgoing RPC connections and set it to Enabled: Default.

From the command line:

reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows NT\Printers\RPC" /v RpcAuthentication /t REG_DWORD /d 0 /f
Risk
External Attack Surface
MITRE ATT&CK tactic
Defense Evasion (TA0005)

Ensure Outgoing Printer RPC Connections Use RPC Over TCP

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.7

Finding: Outgoing printer RPC connections do not use RPC over TCP.

Checks whether outgoing RPC connections to a remote print spooler use TCP rather than named pipes.

This rule fails when rpcUseNamedPipeProtocol is not RPC_OVER_TCP.

Rationale: Forcing TCP instead of named pipes for spooler RPC is a more secure communication method.

Impact: Print configurations still relying on the older named-pipes protocol may cease to function.

Remediation

Open Computer Configuration > Policies > Administrative Templates > Printers > Configure RPC connection settings: Protocol to use for outgoing RPC connections and set it to Enabled: RPC over TCP.

From the command line:

reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows NT\Printers\RPC" /v RpcUseNamedPipeProtocol /t REG_DWORD /d 0 /f
Risk
External Attack Surface
MITRE ATT&CK tactic
Defense Evasion (TA0005)

Ensure Point And Print Shows Warning And Elevation Prompt When Installing New Drivers

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.7

Finding: Point and Print installs new-connection drivers without a warning or elevation prompt.

Checks whether Point and Print shows a warning and a UAC elevation prompt before installing a driver for a new printer connection.

This rule fails when noWarningNoElevationOnInstall is not WARN_AND_ELEVATE_ON_INSTALL.

Rationale: Requiring UAC elevation for new print-driver installation helps mitigate the PrintNightmare vulnerability (CVE-2021-34527) and other Print Spooler attacks, serving as a backstop if the default behavior is ever reversed.

Impact: None; this is the default behavior.

Remediation

Open Computer Configuration > Policies > Administrative Templates > Printers > Point and Print Restrictions: When installing drivers for a new connection and set it to Enabled: Show warning and elevation prompt.

From the command line:

reg add "HKLM\Software\Policies\Microsoft\Windows NT\Printers\PointAndPrint" /v NoWarningNoElevationOnInstall /t REG_DWORD /d 0 /f
Risk
Vulnerability
MITRE ATT&CK tactic
Privilege Escalation (TA0004)

Ensure Point And Print Shows Warning And Elevation Prompt When Updating Existing Drivers

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.7

Finding: Point and Print updates existing-connection drivers without a warning or elevation prompt.

Checks whether Point and Print shows a warning and a UAC elevation prompt before updating a driver for an existing printer connection.

This rule fails when updatePromptSettings is not WARN_AND_ELEVATE_ON_UPDATE.

Rationale: Requiring UAC elevation for print-driver updates helps mitigate the PrintNightmare vulnerability (CVE-2021-34527) and other Print Spooler attacks, serving as a backstop if the default behavior is ever reversed.

Impact: None; this is the default behavior.

Remediation

Open Computer Configuration > Policies > Administrative Templates > Printers > Point and Print Restrictions: When updating drivers for an existing connection and set it to Enabled: Show warning and elevation prompt.

From the command line:

reg add "HKLM\Software\Policies\Microsoft\Windows NT\Printers\PointAndPrint" /v UpdatePromptSettings /t REG_DWORD /d 0 /f
Risk
Vulnerability
MITRE ATT&CK tactic
Privilege Escalation (TA0004)

Ensure Printer Redirection Guard Is Enabled

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.7

Finding: Printer Redirection Guard is not enabled.

Checks whether Redirection Guard is enabled for the print spooler so file redirections cannot be followed within the spooler process.

This rule fails when redirectionguardPolicy is not ENABLED.

Rationale: Redirection Guard prevents non-administrators from redirecting files within the spooler process, closing a print-spooler privilege-escalation avenue.

Impact: None; this is the default behavior.

Remediation

Open Computer Configuration > Policies > Administrative Templates > Printers > Configure Redirection Guard and set it to Enabled: Redirection Guard Enabled.

From the command line:

reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows NT\Printers" /v RedirectionguardPolicy /t REG_DWORD /d 1 /f
Framework mappings
  • CIS Controls v8: 10.5 Enable Anti-Exploitation Features
  • NIST SP 800-53 Rev. 5: SI-16 Memory Protection
Risk
Vulnerability
MITRE ATT&CK tactic
Privilege Escalation (TA0004)

Ensure Printer RPC Over TCP Port Is Set To Zero

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.7

Finding: Printer RPC over TCP port is not set to zero.

Checks whether print-spooler RPC over TCP uses a dynamic port (value 0) rather than a fixed port.

This rule fails when rpcTcpPort is not 0.

Rationale: Using a dynamic port makes it harder for an attacker to know which port the spooler is listening on and therefore which port to attack.

Impact: Environments configured for a specific TCP print port may need a firewall change to keep printing.

Remediation

Open Computer Configuration > Policies > Administrative Templates > Printers > Configure RPC over TCP port and set it to Enabled: 0.

From the command line:

reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows NT\Printers\RPC" /v RpcTcpPort /t REG_DWORD /d 0 /f
Risk
External Attack Surface
MITRE ATT&CK tactic
Discovery (TA0007)

Ensure Queue-Specific Files Are Limited To Color Profiles

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.7

Finding: Queue-specific file processing is not limited to color profiles.

Checks whether queue-specific files downloaded during printer installation are limited to the standard color-profile scheme.

This rule fails when copyFilesPolicy is not ICM_ONLY.

Rationale: Restricting which queue-specific files the spooler processes mitigates a Print Spooler remote code execution vulnerability (CVE-2021-36958).

Impact: None; this is the default behavior.

Remediation

Open Computer Configuration > Policies > Administrative Templates > Printers > Manage processing of Queue-specific files and set it to Enabled: Limit Queue-specific files to Color profiles.

From the command line:

reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows NT\Printers" /v CopyFilesPolicy /t REG_DWORD /d 1 /f
Framework mappings
  • CIS Controls v8: 10.5 Enable Anti-Exploitation Features
  • NIST SP 800-53 Rev. 5: SI-16 Memory Protection
Risk
Vulnerability
MITRE ATT&CK tactic
Execution (TA0002)

Ensure RPC Packet Level Privacy Is Enabled For Incoming Printer Connections

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.7

Finding: RPC packet level privacy is not enforced for incoming printer connections.

Checks whether packet-level privacy is enforced for incoming print-spooler RPC connections.

This rule fails when rpcAuthnLevelPrivacyEnabled is not true.

Rationale: Enforcing packet-level privacy raises the server-side authentication level and mitigates the Print Spooler spoofing vulnerability CVE-2021-1678.

Impact: None; this is the default behavior.

Remediation

Open Computer Configuration > Policies > Administrative Templates > MS Security Guide > Configure RPC packet level privacy setting for incoming connections and set it to Enabled.

From the command line:

reg add "HKLM\SYSTEM\CurrentControlSet\Control\Print" /v RpcAuthnLevelPrivacyEnabled /t REG_DWORD /d 1 /f
Risk
Vulnerability
MITRE ATT&CK tactic
Defense Evasion (TA0005)

Ensure Windows Protected Print Is Enabled

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.7

Finding: Windows protected print is not enabled.

Checks whether Windows protected print mode (modern print platform, Mopria-certified drivers only) is enabled.

This rule fails when windowsProtectedPrintGroupPolicyState is not true.

Rationale: Windows protected print hardens the entire print stack and, per Microsoft, mitigates over half of past reported Windows print security issues.

Impact: Printers that do not support Mopria cannot be used, and only Mopria-certified drivers are deployed via Windows Update.

Remediation

Open Computer Configuration > Policies > Administrative Templates > Printers > Configure Windows protected print and set it to Enabled.

From the command line:

reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows NT\Printers\WPP" /v WindowsProtectedPrintGroupPolicyState /t REG_DWORD /d 1 /f
Risk
Vulnerability
MITRE ATT&CK tactic
Execution (TA0002)