---
title: CIS Windows 11 Printers: 18 Checks | Wartiva
description: Wartiva's 18 checks for section 18.7, Printers, of the CIS Microsoft Windows 11 Stand-alone Benchmark: what each one finds, why it matters, and how to fix it.
url: https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/printers.html
updated: 2026-10-07
---

CIS Microsoft Windows 11 Stand-alone Benchmark · Section 18.7

# Windows 11 Printers: 18 Checks

Wartiva runs 18 checks for section 18.7, Printers, of the CIS Microsoft Windows 11 Stand-alone Benchmark. Each one lists what it finds, why it matters, and how to fix it.

Wartiva evaluates these checks on its cloud mirror every time an endpoint changes, with zero endpoint load, and turns every failure into a finding with captured evidence. [How Wartiva works →](https://wartiva.com/platform.html)

## [Ensure Incoming Printer RPC Connections Use Negotiate Authentication Or Higher](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/printers.html#incoming-printer-rpc-connections-use-negotiate-authentication-or-higher)

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.7

**Finding:** Incoming printer RPC connections do not require Negotiate authentication or higher.

Checks whether the authentication protocol for incoming print-spooler RPC connections is Negotiate or Kerberos.

This rule fails when `forceKerberosForRpc` is not `NEGOTIATE` or `KERBEROS`.

**Rationale:** Requiring Negotiate (or the stronger Kerberos) for incoming spooler RPC forces authenticated, more secure connections.

**Impact:** Print configurations still relying on the older named-pipes protocol may cease to function.

### Remediation

Open **Computer Configuration > Policies > Administrative Templates > Printers > Configure RPC listener settings: Configure protocol options for incoming RPC connections** and set the authentication protocol to **Enabled: Negotiate** or **Enabled: Kerberos**.

From the command line:

```powershell
reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows NT\Printers\RPC" /v ForceKerberosForRpc /t REG_DWORD /d 0 /f
```

Risk

External Attack Surface

MITRE ATT&CK tactic

Defense Evasion ([TA0005](https://attack.mitre.org/tactics/TA0005/))

## [Ensure Incoming Printer RPC Connections Use RPC Over TCP](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/printers.html#incoming-printer-rpc-connections-use-rpc-over-tcp)

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.7

**Finding:** Incoming printer RPC connections do not use RPC over TCP.

Checks whether incoming RPC connections to the print spooler are restricted to the TCP transport rather than named pipes.

This rule fails when `rpcProtocols` is not `RPC_OVER_TCP`.

**Rationale:** Restricting the spooler to TCP instead of named pipes is a more secure communication method for incoming RPC.

**Impact:** Print configurations still relying on the older named-pipes protocol may cease to function.

### Remediation

Open **Computer Configuration > Policies > Administrative Templates > Printers > Configure RPC listener settings: Protocols to allow for incoming RPC connections** and set it to **Enabled: RPC over TCP**.

From the command line:

```powershell
reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows NT\Printers\RPC" /v RpcProtocols /t REG_DWORD /d 5 /f
```

Risk

External Attack Surface

MITRE ATT&CK tactic

Defense Evasion ([TA0005](https://attack.mitre.org/tactics/TA0005/))

## [Ensure IPP Printers Disallow An Invalid Certificate Authority](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/printers.html#ipp-printers-disallow-an-invalid-certificate-authority)

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.7

**Finding:** IPP printers accept certificates from an unknown certificate authority.

Checks whether the IPP TLS/SSL security policy blocks printers presenting a certificate from an unknown certificate authority.

This rule fails when `securityFlagsBlockUnknownCA` is not `true`.

**Rationale:** Validating the certificate authority helps prevent spoofed or unauthorized printers, reducing the risk of credential theft and redirected print jobs.

**Impact:** The system enforces certificate validation and blocks printing when certificate errors are detected.

### Remediation

Open **Computer Configuration > Policies > Administrative Templates > Printers > Set TLS/SSL security policy for IPP printers: Disallow invalid certificate authority** and set it to **Enabled: Checked**.

From the command line:

```powershell
reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows NT\Printers\IPP" /v SecurityFlagsBlockUnknownCA /t REG_DWORD /d 1 /f
```

Risk

Unprotected Data

MITRE ATT&CK tactic

Command and Control / Exfiltration ([TA0011](https://attack.mitre.org/tactics/TA0011/), [TA0010](https://attack.mitre.org/tactics/TA0010/))

## [Ensure IPP Printers Disallow An Invalid Certificate Common Name](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/printers.html#ipp-printers-disallow-an-invalid-certificate-common-name)

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.7

**Finding:** IPP printers accept certificates with an invalid common name.

Checks whether the IPP TLS/SSL security policy blocks printers presenting a certificate whose common name is invalid.

This rule fails when `securityFlagsBlockCertCNInvalid` is not `true`.

**Rationale:** Validating the certificate common name helps prevent spoofed or unauthorized printers, reducing the risk of credential theft and redirected print jobs.

**Impact:** The system enforces certificate validation and blocks printing when certificate errors are detected.

### Remediation

Open **Computer Configuration > Policies > Administrative Templates > Printers > Set TLS/SSL security policy for IPP printers: Disallow invalid certificate common name** and set it to **Enabled: Checked**.

From the command line:

```powershell
reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows NT\Printers\IPP" /v SecurityFlagsBlockCertCNInvalid /t REG_DWORD /d 1 /f
```

Risk

Unprotected Data

MITRE ATT&CK tactic

Command and Control / Exfiltration ([TA0011](https://attack.mitre.org/tactics/TA0011/), [TA0010](https://attack.mitre.org/tactics/TA0010/))

## [Ensure IPP Printers Disallow An Invalid Certificate Date](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/printers.html#ipp-printers-disallow-an-invalid-certificate-date)

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.7

**Finding:** IPP printers accept certificates with an invalid date.

Checks whether the IPP TLS/SSL security policy blocks printers presenting a certificate with an invalid (expired or not-yet-valid) date.

This rule fails when `securityFlagsBlockCertDateInvalid` is not `true`.

**Rationale:** Validating the certificate date helps prevent spoofed or unauthorized printers, reducing the risk of credential theft and redirected print jobs.

**Impact:** The system enforces certificate validation and blocks printing when certificate errors are detected.

### Remediation

Open **Computer Configuration > Policies > Administrative Templates > Printers > Set TLS/SSL security policy for IPP printers: Disallow invalid certificate date** and set it to **Enabled: Checked**.

From the command line:

```powershell
reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows NT\Printers\IPP" /v SecurityFlagsBlockCertDateInvalid /t REG_DWORD /d 1 /f
```

Risk

Unprotected Data

MITRE ATT&CK tactic

Command and Control / Exfiltration ([TA0011](https://attack.mitre.org/tactics/TA0011/), [TA0010](https://attack.mitre.org/tactics/TA0010/))

## [Ensure IPP Printers Disallow Non-Server Certificates](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/printers.html#ipp-printers-disallow-non-server-certificates)

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.7

**Finding:** IPP printers accept non-server (wrong-usage) certificates.

Checks whether the IPP TLS/SSL security policy blocks printers presenting a non-server certificate (wrong certificate usage).

This rule fails when `securityFlagsBlockCertWrongUsage` is not `true`.

**Rationale:** Rejecting certificates issued for the wrong usage helps prevent spoofed or unauthorized printers, reducing the risk of credential theft and redirected print jobs.

**Impact:** The system enforces certificate validation and blocks printing when certificate errors are detected.

### Remediation

Open **Computer Configuration > Policies > Administrative Templates > Printers > Set TLS/SSL security policy for IPP printers: Disallow non-server certificates** and set it to **Enabled: Checked**.

From the command line:

```powershell
reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows NT\Printers\IPP" /v SecurityFlagsBlockCertWrongUsage /t REG_DWORD /d 1 /f
```

Risk

Unprotected Data

MITRE ATT&CK tactic

Command and Control / Exfiltration ([TA0011](https://attack.mitre.org/tactics/TA0011/), [TA0010](https://attack.mitre.org/tactics/TA0010/))

## [Ensure IPPS Is Required For IPP Printers](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/printers.html#ipps-is-required-for-ipp-printers)

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.7

**Finding:** IPP printers are not required to use IPPS.

Checks whether communication with IPP Class Driver printers must use IPPS (IPP over TLS).

This rule fails when `requireIPPs` is not `true`.

**Rationale:** IPPS uses TLS to encrypt all client-to-printer communication, preventing interception or tampering of print data.

**Impact:** IPP printers using self-signed or locally issued certificates may not work, and installing non-compliant IPP printers will fail with an Application-log event.

### Remediation

Open **Computer Configuration > Policies > Administrative Templates > Printers > Require IPPS for IPP printers** and set it to **Enabled**.

From the command line:

```powershell
reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows NT\Printers\IPP" /v RequireIpps /t REG_DWORD /d 1 /f
```

Risk

Unprotected Data

MITRE ATT&CK tactic

Command and Control / Exfiltration ([TA0011](https://attack.mitre.org/tactics/TA0011/), [TA0010](https://attack.mitre.org/tactics/TA0010/))

## [Ensure Outgoing Printer RPC Connections Use Default Authentication](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/printers.html#outgoing-printer-rpc-connections-use-default-authentication)

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.7

**Finding:** Outgoing printer RPC connections do not use default authentication.

Checks whether outgoing RPC connections to a remote print spooler use the Default authentication behavior.

This rule fails when `rpcAuthentication` is not `DEFAULT`.

**Rationale:** The Default behavior applies appropriate RPC authentication and, together with RPC over TCP, provides more secure spooler communication.

**Impact:** Print configurations still relying on the older named-pipes protocol may cease to function.

### Remediation

Open **Computer Configuration > Policies > Administrative Templates > Printers > Configure RPC connection settings: Use authentication for outgoing RPC connections** and set it to **Enabled: Default**.

From the command line:

```powershell
reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows NT\Printers\RPC" /v RpcAuthentication /t REG_DWORD /d 0 /f
```

Risk

External Attack Surface

MITRE ATT&CK tactic

Defense Evasion ([TA0005](https://attack.mitre.org/tactics/TA0005/))

## [Ensure Outgoing Printer RPC Connections Use RPC Over TCP](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/printers.html#outgoing-printer-rpc-connections-use-rpc-over-tcp)

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.7

**Finding:** Outgoing printer RPC connections do not use RPC over TCP.

Checks whether outgoing RPC connections to a remote print spooler use TCP rather than named pipes.

This rule fails when `rpcUseNamedPipeProtocol` is not `RPC_OVER_TCP`.

**Rationale:** Forcing TCP instead of named pipes for spooler RPC is a more secure communication method.

**Impact:** Print configurations still relying on the older named-pipes protocol may cease to function.

### Remediation

Open **Computer Configuration > Policies > Administrative Templates > Printers > Configure RPC connection settings: Protocol to use for outgoing RPC connections** and set it to **Enabled: RPC over TCP**.

From the command line:

```powershell
reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows NT\Printers\RPC" /v RpcUseNamedPipeProtocol /t REG_DWORD /d 0 /f
```

Risk

External Attack Surface

MITRE ATT&CK tactic

Defense Evasion ([TA0005](https://attack.mitre.org/tactics/TA0005/))

## [Ensure Point And Print Shows Warning And Elevation Prompt When Installing New Drivers](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/printers.html#point-and-print-shows-warning-and-elevation-prompt-when-installing-new-drivers)

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.7

**Finding:** Point and Print installs new-connection drivers without a warning or elevation prompt.

Checks whether Point and Print shows a warning and a UAC elevation prompt before installing a driver for a new printer connection.

This rule fails when `noWarningNoElevationOnInstall` is not `WARN_AND_ELEVATE_ON_INSTALL`.

**Rationale:** Requiring UAC elevation for new print-driver installation helps mitigate the PrintNightmare vulnerability (CVE-2021-34527) and other Print Spooler attacks, serving as a backstop if the default behavior is ever reversed.

**Impact:** None; this is the default behavior.

### Remediation

Open **Computer Configuration > Policies > Administrative Templates > Printers > Point and Print Restrictions: When installing drivers for a new connection** and set it to **Enabled: Show warning and elevation prompt**.

From the command line:

```powershell
reg add "HKLM\Software\Policies\Microsoft\Windows NT\Printers\PointAndPrint" /v NoWarningNoElevationOnInstall /t REG_DWORD /d 0 /f
```

Risk

Vulnerability

MITRE ATT&CK tactic

Privilege Escalation ([TA0004](https://attack.mitre.org/tactics/TA0004/))

## [Ensure Point And Print Shows Warning And Elevation Prompt When Updating Existing Drivers](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/printers.html#point-and-print-shows-warning-and-elevation-prompt-when-updating-existing-driver)

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.7

**Finding:** Point and Print updates existing-connection drivers without a warning or elevation prompt.

Checks whether Point and Print shows a warning and a UAC elevation prompt before updating a driver for an existing printer connection.

This rule fails when `updatePromptSettings` is not `WARN_AND_ELEVATE_ON_UPDATE`.

**Rationale:** Requiring UAC elevation for print-driver updates helps mitigate the PrintNightmare vulnerability (CVE-2021-34527) and other Print Spooler attacks, serving as a backstop if the default behavior is ever reversed.

**Impact:** None; this is the default behavior.

### Remediation

Open **Computer Configuration > Policies > Administrative Templates > Printers > Point and Print Restrictions: When updating drivers for an existing connection** and set it to **Enabled: Show warning and elevation prompt**.

From the command line:

```powershell
reg add "HKLM\Software\Policies\Microsoft\Windows NT\Printers\PointAndPrint" /v UpdatePromptSettings /t REG_DWORD /d 0 /f
```

Risk

Vulnerability

MITRE ATT&CK tactic

Privilege Escalation ([TA0004](https://attack.mitre.org/tactics/TA0004/))

## [Ensure Print Driver Installation Is Limited To Administrators](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/printers.html#print-driver-installation-is-limited-to-administrators)

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.7

**Finding:** Non-administrators can install print drivers.

Checks whether only Administrators can install print drivers on the host.

This rule fails when `restrictDriverInstallationToAdministrators` is not `true`.

**Rationale:** Restricting print-driver installation to Administrators mitigates the PrintNightmare vulnerability (CVE-2021-34527) and other Print Spooler attacks.

**Impact:** None; this is the default behavior.

### Remediation

Open **Computer Configuration > Policies > Administrative Templates > Printers > Limits print driver installation to Administrators** and set it to **Enabled**.

From the command line:

```powershell
reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows NT\Printers\PointAndPrint" /v RestrictDriverInstallationToAdministrators /t REG_DWORD /d 1 /f
```

Risk

Vulnerability

MITRE ATT&CK tactic

Privilege Escalation ([TA0004](https://attack.mitre.org/tactics/TA0004/))

## [Ensure Print Spooler Does Not Accept Client Connections](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/printers.html#print-spooler-does-not-accept-client-connections)

High severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.7

**Finding:** Print Spooler accepts remote client connections.

Checks whether the Print Spooler service is prevented from accepting remote client connections.

This rule fails when `registerSpoolerRemoteRpcEndPoint` is not `false`.

**Rationale:** Blocking remote client connections to the spooler mitigates the PrintNightmare vulnerability (CVE-2021-34527) and other remote Print Spooler attacks.

**Impact:** Users can still print locally, but the host will not accept client connections or share printers; already-shared printers remain shared.

### Remediation

Open **Computer Configuration > Policies > Administrative Templates > Printers > Allow Print Spooler to accept client connections** and set it to **Disabled**.

From the command line:

```powershell
reg add "HKLM\Software\Policies\Microsoft\Windows NT\Printers" /v RegisterSpoolerRemoteRpcEndPoint /t REG_DWORD /d 2 /f
```

Framework mappings

- **CIS Controls v8**: 4.1 Establish and Maintain a Secure Configuration Process; 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
- **NIST SP 800-53 Rev. 5**: CM-1 Policy and Procedures; CM-2 Baseline Configuration; CM-6 Configuration Settings; CM-7 Least Functionality; CM-9 Configuration Management Plan; SA-3 System Development Life Cycle; SA-8 Security and Privacy Engineering Principles; SA-10 Developer Configuration Management
- **NIST SP 800-171 Rev. 2**: 3.1.18 Control connection of mobile devices; 3.4.1 Establish and maintain baseline configurations and inventories of organizational systems (including hardware, software, firmware, and documentation) throughout the respective system development life cycles; 3.4.2 Establish and enforce security configuration settings for information technology products employed in organizational systems; 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **CMMC 2.0 Level 2**: AC.L2-3.1.18 Control connection of mobile devices; CM.L2-3.4.1 Establish and maintain baseline configurations and inventories of organizational systems (including hardware, software, firmware, and documentation) throughout the respective system development life cycles; CM.L2-3.4.2 Establish and enforce security configuration settings for information technology products employed in organizational systems; CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **PCI DSS v4.0.1**: 1.1.1 Network security control policies and procedures kept documented, current, and applied; 1.2.1 Establish and uphold configuration baselines for NSC rulesets; 1.2.5 Approve and justify each allowed port, protocol, and service; 1.2.6 Add security features that offset risk from active insecure services; 1.2.7 Review NSC configurations for relevance and effectiveness every six months; 1.5.1 Harden dual-connected computing devices that reach both the internet and CDE; 2.1.1 Secure configuration policies and procedures kept documented, current, and applied; 2.2.1 Develop and maintain hardening standards covering all system components; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks

Risk

High Profile Threat

MITRE ATT&CK tactic

Initial Access ([TA0001](https://attack.mitre.org/tactics/TA0001/))

## [Ensure Printer Redirection Guard Is Enabled](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/printers.html#printer-redirection-guard-is-enabled)

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.7

**Finding:** Printer Redirection Guard is not enabled.

Checks whether Redirection Guard is enabled for the print spooler so file redirections cannot be followed within the spooler process.

This rule fails when `redirectionguardPolicy` is not `ENABLED`.

**Rationale:** Redirection Guard prevents non-administrators from redirecting files within the spooler process, closing a print-spooler privilege-escalation avenue.

**Impact:** None; this is the default behavior.

### Remediation

Open **Computer Configuration > Policies > Administrative Templates > Printers > Configure Redirection Guard** and set it to **Enabled: Redirection Guard Enabled**.

From the command line:

```powershell
reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows NT\Printers" /v RedirectionguardPolicy /t REG_DWORD /d 1 /f
```

Framework mappings

- **CIS Controls v8**: 10.5 Enable Anti-Exploitation Features
- **NIST SP 800-53 Rev. 5**: SI-16 Memory Protection

Risk

Vulnerability

MITRE ATT&CK tactic

Privilege Escalation ([TA0004](https://attack.mitre.org/tactics/TA0004/))

## [Ensure Printer RPC Over TCP Port Is Set To Zero](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/printers.html#printer-rpc-over-tcp-port-is-set-to-zero)

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.7

**Finding:** Printer RPC over TCP port is not set to zero.

Checks whether print-spooler RPC over TCP uses a dynamic port (value 0) rather than a fixed port.

This rule fails when `rpcTcpPort` is not `0`.

**Rationale:** Using a dynamic port makes it harder for an attacker to know which port the spooler is listening on and therefore which port to attack.

**Impact:** Environments configured for a specific TCP print port may need a firewall change to keep printing.

### Remediation

Open **Computer Configuration > Policies > Administrative Templates > Printers > Configure RPC over TCP port** and set it to **Enabled: 0**.

From the command line:

```powershell
reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows NT\Printers\RPC" /v RpcTcpPort /t REG_DWORD /d 0 /f
```

Risk

External Attack Surface

MITRE ATT&CK tactic

Discovery ([TA0007](https://attack.mitre.org/tactics/TA0007/))

## [Ensure Queue-Specific Files Are Limited To Color Profiles](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/printers.html#queue-specific-files-are-limited-to-color-profiles)

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.7

**Finding:** Queue-specific file processing is not limited to color profiles.

Checks whether queue-specific files downloaded during printer installation are limited to the standard color-profile scheme.

This rule fails when `copyFilesPolicy` is not `ICM_ONLY`.

**Rationale:** Restricting which queue-specific files the spooler processes mitigates a Print Spooler remote code execution vulnerability (CVE-2021-36958).

**Impact:** None; this is the default behavior.

### Remediation

Open **Computer Configuration > Policies > Administrative Templates > Printers > Manage processing of Queue-specific files** and set it to **Enabled: Limit Queue-specific files to Color profiles**.

From the command line:

```powershell
reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows NT\Printers" /v CopyFilesPolicy /t REG_DWORD /d 1 /f
```

Framework mappings

- **CIS Controls v8**: 10.5 Enable Anti-Exploitation Features
- **NIST SP 800-53 Rev. 5**: SI-16 Memory Protection

Risk

Vulnerability

MITRE ATT&CK tactic

Execution ([TA0002](https://attack.mitre.org/tactics/TA0002/))

## [Ensure RPC Packet Level Privacy Is Enabled For Incoming Printer Connections](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/printers.html#rpc-packet-level-privacy-is-enabled-for-incoming-printer-connections)

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.7

**Finding:** RPC packet level privacy is not enforced for incoming printer connections.

Checks whether packet-level privacy is enforced for incoming print-spooler RPC connections.

This rule fails when `rpcAuthnLevelPrivacyEnabled` is not `true`.

**Rationale:** Enforcing packet-level privacy raises the server-side authentication level and mitigates the Print Spooler spoofing vulnerability CVE-2021-1678.

**Impact:** None; this is the default behavior.

### Remediation

Open **Computer Configuration > Policies > Administrative Templates > MS Security Guide > Configure RPC packet level privacy setting for incoming connections** and set it to **Enabled**.

From the command line:

```powershell
reg add "HKLM\SYSTEM\CurrentControlSet\Control\Print" /v RpcAuthnLevelPrivacyEnabled /t REG_DWORD /d 1 /f
```

Risk

Vulnerability

MITRE ATT&CK tactic

Defense Evasion ([TA0005](https://attack.mitre.org/tactics/TA0005/))

## [Ensure Windows Protected Print Is Enabled](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/printers.html#windows-protected-print-is-enabled)

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.7

**Finding:** Windows protected print is not enabled.

Checks whether Windows protected print mode (modern print platform, Mopria-certified drivers only) is enabled.

This rule fails when `windowsProtectedPrintGroupPolicyState` is not `true`.

**Rationale:** Windows protected print hardens the entire print stack and, per Microsoft, mitigates over half of past reported Windows print security issues.

**Impact:** Printers that do not support Mopria cannot be used, and only Mopria-certified drivers are deployed via Windows Update.

### Remediation

Open **Computer Configuration > Policies > Administrative Templates > Printers > Configure Windows protected print** and set it to **Enabled**.

From the command line:

```powershell
reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows NT\Printers\WPP" /v WindowsProtectedPrintGroupPolicyState /t REG_DWORD /d 1 /f
```

Risk

Vulnerability

MITRE ATT&CK tactic

Execution ([TA0002](https://attack.mitre.org/tactics/TA0002/))

---

Wartiva is in early access. Request access: https://wartiva.com/early-access.html  
All pages: https://wartiva.com/llms.txt
