Skip to content
Prevent Users From Installing Printer Drivers using Intune

Prevent Users From Installing Printer Drivers using Intune

Written By Jitesh Kumar
Last Updated October 5, 2021
Posted In Intune
SHARE

This post gives you a quick walkthrough of how you can Prevent Users From Installing Printer Drivers using Intune. This security setting determines who is allowed to install a printer driver as part of connecting to a shared printer. For a computer to print to a shared printer, the driver for that shared printer must be installed on the local computer.

It may be appropriate in some organizations to allow users to install printer drivers on their own workstations. However, in a high security environment, you should allow only Administrators, not users, to do this, because printer driver installation may unintentionally cause the computer to become less stable. A malicious user could install inappropriate printer drivers in a deliberate attempt to damage the computer, or a user might accidentally install malicious software that masquerades as a printer driver.

Here you will see the steps to create a policy to prevent users from installing printer drivers. When you create the policy, it creates a device configuration profile. You can then assign or deploy this profile to devices in your organization. You can learn more –


Only Administrators will be able to install a printer driver as part of connecting to a shared printer. The ability to add a local printer will not be affected.

Patch My PC

Prevent Users From Installing Printer Drivers using Intune

Let’s follow the below steps to Prevent Users From Installing Printer Drivers using Intune –

Configuration Profiles - Create Profile
Configuration Profiles – Create Profile

In Create Profile, Select Platform, Windows 10, and later and Profile, Select Profile Type as Settings catalog. Click on Create button.

Intune Configuration Profiles – Select Platform, Profile type
Intune Configuration Profiles – Select Platform, Profile type

On the Basics tab, enter a descriptive name, such as Prevent Users From Installing Printer Drivers. Optionally, enter a Description for the policy, then select Next.

Create Profile – Enter Name, Description for profile setting
Create Profile – Enter Name, Description for profile setting

In Configuration settings, click Add settings.

In Configuration settings, click + Add settings.
In Configuration settings, click + Add settings

On the Settings Picker windows, Select Local Policies Security Options to see all the settings in this category. Select Devices Prevent Users From Installing Printer Drivers When Connecting To Shared Printers below. After adding your settings, click the cross mark at the right-hand corner to close the settings picker –

Note – In policy, use the search box to find specific settings. You can search by category or a keyword, such as Installing Printer Drivers. It will display all the related settings available.

Settings picker - Local Policies Security Options
Settings picker – Local Policies Security Options

The setting is shown and configured with a default value. Set Devices Prevent Users From Installing Printer Drivers When Connecting To Shared Printers to Enabled, Click Next.

Devices Prevent Users From Installing Printer Drivers When Connecting To Shared Printers – This security setting determines who is allowed to install a printer driver as part of connecting to a shared printer. If this setting is enabled, only Administrators can install a printer driver as part of connecting to a shared printer. If this setting is disabled, any user can install a printer driver as part of connecting to a shared printer. This setting does not affect the ability to add a local printer, Administrators.

Devices Prevent Users From Installing Printer Drivers When Connecting To Shared Printers - Enabled
Devices Prevent Users From Installing Printer Drivers When Connecting To Shared Printers – Enabled

Under Assignments, In Included groups, click Add groups and then choose Select groups to include one or more groups. Click Next to continue.

Assignments – Select groups to include
Assignments – Select groups to include

In Scope tags, you can assign a tag to filter the profile to specific IT groups. Add scope tags (if required) and click Next.
In Review + create, review your settings. When you select Create, your changes are saved, and the profile is assigned.

Review + Create Configuration settings
Review + Create Configuration settings

A notification will appear automatically in the top right-hand corner with a message. Here you can see, Policy “Prevent Users From Installing Printer Drivers” created successfully. The policy is also shown in the Configuration profiles list.

Policy "Prevent Users From Installing Printer Drivers" created successfully
Policy “Prevent Users From Installing Printer Drivers” created successfully

Your groups will receive your profile settings when the devices check-in with the Intune service. Once the policy applies to the devices, Only Administrators will be able to install a printer driver as part of connecting to a shared printer. The ability to add a local printer will not be affected.

Author

About Author -> Jitesh has over 5 years of working experience in the IT Industry. He writes and shares his experiences related to Microsoft device management technologies and IT Infrastructure management. His primary focus area is Windows 10 Deployment solution with Configuration Manager, Microsoft Deployment Toolkit (MDT), and Microsoft Intune.

Written by

Jitesh has over 5 years of working experience in the IT Industry. He writes and shares his experiences related to Microsoft device management technologies and IT Infrastructure management. His primary focus area is Windows 10 Deployment solution with Configuration Manager, Microsoft Deployment Toolkit (MDT), and Microsoft Intune.

Discussion · 2 comments

Join the discussion

Your email address will not be published. Required fields are marked *

Related guides

Intune

Simplify Windows Devices to Run Only the Required Applications using Intune

Key Takeaways Hey, let’s learn about Simplify Windows Devices to Run Only the Required Applications using Intune. This policy lets administrators replace the default windows shell with a custom or lightweight shell. it improves performance by using system resources and is useful for devices that run a dedicated application. If the policy is disabled or […]

AC Anoop C Nair 8 min read
Intune

Enhance macOS Compliance with Custom Security and Compliance Checks to Improve Device Security using Microsoft Intune

Key Takeaways In this post we are discussing about Enhance macOS Compliance with Custom Security and Compliance Checks to Improve Device Security using Microsoft Intune. Microsoft has announced the general availability of Custom Compliance Settings for macOS in Microsoft Intune. The feature helps organizations strengthen security controls while supporting many types of macOS management scenarios. […]

AC Anoop C Nair 4 min read
Intune

Manage Samsung Galaxy Firmware Versions to Improve Security and Compliance using Microsoft Intune

Key Takeaways In this post we are discussing Manage Samsung Galaxy Firmware Versions to Improve Security and Compliance using Microsoft Intune. Microsoft Intune has received a new update that expands firmware management capabilities for Samsung Galaxy devices through Firmware Versionsintegration. This enhancement gives IT administrators more control over firmware and operating system updates, helping them […]

AC Anoop C Nair 4 min read
Intune

MS Intune Adds Windows Registry Data Collection to Device Inventory for Single Values All Key Values and Subkeys

Key Takeaways Microsoft Intune 2607 introduces Windows Registry Data collection in Device Inventory, allowing IT admins to verify actual device configurations without relying on custom discovery or remediation scripts. Using the Properties Catalog, admins can collect registry information through Single Value, All Values Under a Key (Non-Recursive), or Same Value Across Subkeys. MS Intune Adds […]

AC Anoop C Nair 5 min read