Tell us about your PDF experience.
Modern Print Platform
documentation
A new, modern, and secure print experience from Windows.
OVERVIEW REFERENCE REFERENCE
Discover the End of Mopria
Modern Print servicing plan Certified
Platform for third-part… Products
Modern Print for IT pros Modern Print for developers and
printer manufacturers
e Overview of Windows protected print mode
i Windows protected print mode for enterprises i Internet Printing Protocol (IPP) specification
i More information on Windows protected print i Print Support App design guide
mode for enterprises and developers i Print support app association
i Universal Print documentation i MSIX Manifest Specification for Print Support
i Help with installing printers on ARM PCs Virtual Printer
i [Link] Namespace
Additional resources
Legacy print documentation
Information about third-party driver design and
legacy print technologies.
Discover the Modern print platform
Modern print is Windows' preferred means of communicating to printers, including the
Internet Printing Protocol (IPP), eSCL scanning, and Universal Print.
Modern print doesn't require the installation third-party drivers. This provides a simple,
streamlined, and secure printing experience compared to legacy printers, regardless of the PC's
architecture. Modern print is designed to work with Mopria certified printers , and many
existing printers are already compatible with modern print.
Mopria
The Mopria alliance is a collection of printer manufacturers and software vendors that come
together to define the standards for IPP printing and eSCL scanning. Mopria certified devices
guarantee conformance to these standards.
Universal Print
Universal Print is a cloud print solution that eliminates the need for printer servers. For more
information, see Universal Print.
Modern print vs legacy print
) Important
We announced an end of servicing plan for legacy v3 and v4 Windows print drivers. For
more information, see End of servicing plan for third-party printer drivers on Windows.
Traditionally, PCs communicated with printers by installing drivers. Drivers are software
modules created by printer manufacturers that give PCs instructions on how to send printers
information about print jobs in a way that it understands. With modern print, printers
communicate to PCs without the need to install drivers, creating an experience with improved
security, compatibility, and reliability.
Security: Different printer models and manufacturers mean that there are thousands of
drivers out there, and there's no way to verify the security of all of them. For more
information about driver security, see More information about Windows protected print
mode for enterprises.
Compatibility: Modern print works regardless of a PC's architecture. Not all drivers work
with ARM devices.
Reliability: After Windows Update, drivers might not work as expected. Modern print
platform provides a more consistent printing experience without the daunting task of
keeping drivers up to date.
Print support applications
The modern print platform works in combination with print support applications to enable
customization of the print experience for Windows 10 and 11. For more information, see Print
support app design guide.
Introducing Windows protected print mode
Improve the security of a PC and eliminate driver issues by enabling Windows protected print
mode. Windows protected print mode provides additional print security features. It also
simplifies the printing experience by allowing PCs exclusively print using the Windows modern
print stack, which is designed to work with Mopria certified printers . For more information,
see Windows protected print mode.
Related articles
ノ Expand table
Article Description
Overview of Windows protected Provides an overview of Windows protected print mode, its
print mode benefits, and how to use it.
End of servicing plan for third-party Provides information about the end of servicing plan for legacy v3
printer drivers on Windows and v4 Windows print drivers.
Print Support App design guide Provides guidance and examples for printer OEMs and IHVs that
are implementing a print support app (PSA) for their device.
Discover Universal Print Provides an overview of Universal Print and the benefits of a cloud
print solution.
Last updated on 06/25/2025
Overview of Windows protected print
mode
Windows protected print mode exclusively uses the Windows modern print stack which
provides additional print security benefits on PCs. Enabling Windows protected print mode is
highly recommended.
The benefits of Windows protected print mode include:
Increased PC security.
Simplified and consistent printing experience, regardless of PC architecture.
Removes the need to manage print drivers.
Windows protected print mode is designed to work with Mopria certified printers. Many
existing printers are already compatible. For more information, see Windows protected print
mode device compatibility.
Enterprise administrators can secure and simplify their printer management experience using
Windows protected print mode. For more technical information, see Windows protected print
mode for enterprises.
About Windows protected print mode
Why should I enable Windows protected print mode?
By default, many Mopria certified printers are installed using legacy drivers. Enabling
Windows protected print mode ensures that printers are installed using the modern print
platform, creating the best printing experience possible.
Enabling Windows protected print mode provides additional security benefits. By creating an
environment that exclusively uses modern print, the printing experience is simplified.
What happens when I enable Windows protected print mode?
Upon enabling Windows protected print mode, printers that use third–party drivers are
uninstalled.
The print driver is deleted from the print driver store, and it can't be used while Windows
protected print mode is active.
When Windows protected print mode is disabled and the printer is reinstalled, the
original driver is reinstalled.
If a Mopria Certified printer was originally installed using a third-party driver:
The printer is uninstalled, but can be reinstalled. When reinstalled, it uses the modern
print stack instead of its third-party driver.
If Windows protected print mode is disabled, installed printers continue to use the
modern print stack unless they're removed and reinstalled with Windows protected print
mode disabled.
If a printer was originally installed with the modern print stack, enabling Windows protected
print mode won't uninstall the printer.
Windows protected print mode device compatibility
Are my printers compatible with Windows protected print mode?
Mopria certified printers are compatible with Windows protected print mode. Most new
printers and over 120 million printers already sold are Mopria certified. To see if a printer is
compatible with Windows protected print mode, see Mopria certified products.
Are my scanners compatible with Windows protected print mode?
Not all scanners are compatible with Windows protected print mode. To see if a scanner is
compatible with Windows protected print mode, see Mopria certified products.
OneNote printer in Windows protected print mode
Turning on Windows protected print mode uninstalls all unsupported software printers on
Windows, including "OneNote(Desktop)". To continue printing to OneNote with Windows
protected print mode enabled, use the new "OneNote (Desktop) – Protected virtual printer". The
"OneNote (Desktop) – Protected virtual printer" is installed by default in all OneNote Windows
app versions 2410 and later running on Windows 11 version 26100 or higher. For more details
on both printers and how to use them, see the support article: Print documents and files to
OneNote - Microsoft Support.
XPS and Fax Reinstall Steps
XPS and fax are removed when Windows protected print mode is turned on. To reinstall fax
and XPS on your Windows system after disabling Windows protected print mode, follow these
instructions:
XPS
1. Open "Start"
2. Search "Windows Features"
3. Select "Microsoft XPS Document Writer"
4. Click "OK" to apply the changes.
Fax
1. Open "Settings" > "System: > "Optional Features"
2. Locate the feature named "Windows Fax and Scan."
3. Check the box next to "Windows Fax and Scan" to select it.
How to use Windows protected print mode
How to enable Windows protected print mode
1. Press Start.
2. Navigate to Settings > Bluetooth & Devices > Printers & scanners.
3. Scroll down to Printer Preferences and under Windows protected print mode select Set
up.
1. Select Yes, continue for all prompts.
Windows protected print is now enabled. Non-compatible printers are uninstalled.
How to disable Windows protected print mode
1. Select Start.
2. Navigate to Settings > Bluetooth & Devices > Printers & scanners.
3. Scroll down to Printer Preferences and under Windows protected print mode, select
Turn Off.
41 Select Yes.
Windows protected print mode is now disabled. You can now install printers that use third
party drivers.
7 Note
If Windows protected print mode is enabled as group policy, you won't be able to disable
it without contacting your administrator.
For more information on enabling Windows protected print mode as group policy, see
Enabling Windows protected print mode as group policy.
FAQ
See FAQs at Windows protected print mode FAQ.
Related articles
ノ Expand table
Article Description
Modern print platform Provides an overview of the modern print platform, and its
security, compatibility, and reliability benefits over legacy
printer drivers.
Windows protected print mode for Provides guidance for enterpises using Windows protected
enterprises print mode.
More information on Windows protected Provides a technical deep dive of Windows protected print
print mode for enterprises and mode.
developers
Last updated on 07/17/2025
Windows protected print mode FAQ
Q: Can I turn off Windows protected print mode once I turn it on?
A: For more information on how to disable Windows protected print mode, see How to disable
Windows protected print mode.
Q: Will I lose custom driver features after turning on Windows protected print mode??
A: Your printer manufacturer will still be able to provide custom features via Print Support Apps
(PSAs).
Q: What happens to non-compatible printers when Windows protected print mode is
enabled?
A: Non-compatible printers are uninstalled and will be not able to be reinstalled while
Windows protected print mode is enabled. Compatible printers will be able to be reinstalled.
Q: Will my non-compatible printers be reinstalled when I disable Windows protected print
mode?
A: If you disable Windows protected print mode, you'll have to manually reinstall any
noncompatible printers.
Q: Will Windows protected print mode ever be enabled by default?
A: Windows protected print mode will be enabled by default at a future date.
Q: I enabled Windows protected print mode and now I can't see my scanner.
A: Not all scanners are compatible with Windows protected print mode. To see if a scanner is
compatible with Windows protected print mode, see Mopria certified products.
Q: My printer is Mopria certified, why did it get removed when I enabled Windows protected
print mode?
A: Some Mopria certified printers are default installed using third-party drivers. If so, that
printer is removed when Windows protected print mode is enabled but you'll be able to
reinstall the printer.
Q: What if I want to use a device that is unavailable in Windows protected print mode?
A: For more information on how to disable Windows protected print mode, see How to disable
Windows protected print mode.
Q: Will Mopria certified printers work on my ARM PC?
A: Yes, Mopria certified printers work regardless of your PC's architecture
For more information, see What happens when I enable Windows protected print mode?
ノ Expand table
Article Description
Discover the Modern Provides an overview of the modern print platform, and its security,
print platform compatibility, and reliability benefits over legacy printer drivers.
Windows protected Provides an overview of Windows protected print mode, its benefits, and how
print mode to use it.
Last updated on 07/17/2025
Windows protected print mode for
enterprises
Windows protected print mode creates peace of mind for enterprise administrators by adding
security benefits and completely removing the need for any driver management. When
Windows protected print mode is enabled, printers will "just work".
For more information about the basics of the modern print platform and Windows
protected print mode, see Discover the Modern Print Platform and Windows protected
print mode.
For more technical information on Windows protected print mode, see More information
on Windows protected print mode for enterprises and developers.
Security
Windows protected print mode prevents the installation of third-party drivers and enables
additional security features to help make environments more secure. Windows protected print
mode would mitigate over half of past reported security issues for Windows print.
Module blocking
Per-user XPS rendering
Lower privileges for common spooler tasks
Binary mitigations
Reliability and Compatibility
Windows protected print mode creates a reliable and consistent experience across a fleet of
PCs regardless of manufacturer or model.
Moving to a standard reduces risks of support calls and total cost of ownership and
troubleshooting issues is simpler.
Differentiation and unique features are still available via Print Support Apps (PSA).
Ensures all printers work with PCs of any architecture.
Removes the need to keep drivers up to date.
Experience the best of Windows
As Windows moves away from third-party drivers, new features are catered to the modern
print platform and work best when Windows protected print mode is enabled.
Enabling Windows protected print mode as group
policy
1. Press Start.
2. Open the Local Group Policy Editor.
3. Navigate to Computer Configuration > Administrative Templates > Printers.
4. Right click on Configure Windows protected print and click Edit.
5. Select the Enabled radio button.
6. Click Apply and click OK.
Windows protected print is now enabled.
Windows protected print mode enabled machines should display the following:
Windows protected print mode Intune
configuration
INF
OMA-URI: ./Device/Vendor/MSFT/Policy/Config/Printers/ConfigureWindowsProtectedPrint
Data Type: String
Value: <enabled/>
To find more information on customizing settings via Intune, see Add custom settings for
Windows 10/11 devices in Microsoft Intune.
Managing Servers with Windows protected print
mode
When using a client with Windows protected print mode enabled, you cannot use Print
Management to manage servers with Windows protected print mode disabled. Windows
protected print mode enforces the use of the modern print stack, which is designed to work
with Mopria certified printers. Servers with Windows protected print mode turned off may
rely on legacy print drivers and protocols, which are not compatible with the modern print
stack. As a result, managing these servers from a client that has Windows protected print mode
enabled is not possible. By ensuring that both your client and servers have Windows protected
print mode turned on, you can take full advantage of the security and reliability benefits it
offers.
FAQ
See FAQs at Windows protected print mode FAQ.
Related articles
ノ Expand table
Article Description
Overview of Windows protected print Provides an overview of Windows protected print mode, its
mode benefits, and how to use it.
More information on Windows protected Provides a technical deep dive of Windows protected print
print mode for enterprises and mode.
developers
Discover the Modern print platform Provides an overview of the modern print platform, and its
security, compatibility, and reliability benefits over legacy
printer drivers.
Article Description
End of servicing plan for third-party Provides information about the end of servicing plan for
printer drivers on Windows legacy v3 and v4 Windows print drivers.
Print Support App design guide Provides guidance and examples for printer OEMs and IHVs
that are implementing a print support app (PSA) for their
device.
Print Support App v3 API design guide Provides guidance and examples for printer OEMs and IHVs
that are implementing a v3 Print Support App (PSA) for their
device.
Print Support App v4 API design guide Provides guidance and examples for printer OEMs and IHVs
that are implementing a v4 Print Support App (PSA) for their
device.
MSIX Manifest Specification for Print Provides MSIX manifest guidance and examples for printer
Support Virtual Printer OEMs and IHVs that are implementing a Print Support Virtual
Printer.
Print support app association Provides guidance and examples for associating a print
support app (PSA) with a printer.
Last updated on 07/17/2025
More information on Windows protected
print mode for enterprises and developers
To read about the basics of Windows protected print mode for enterprises, see Windows
protected print mode for enterprises.
The Windows print system has historically been a frequent target for attacks and Print bugs
accounted for 9% of all cases reported to the Microsoft Security Response Center (MSRC) over
the past three years. The Spooler service, which handles printer management, data conversion
and many other tasks, is the core of the Windows Print system. This process runs as SYSTEM,
which is one of the highest privilege levels in Windows, which is why it's such an attractive
target. The Spooler is also widely accessible to standard users and loads third-party code on
demand. These drivers were historically required to support a wide range of printers during a
time when the industry lacked uniform standards for document handling and printer
communication. This vast ecosystem of drivers from various manufacturers allows Windows to
support a wide range of older printers and their over 40 Page Description Languages (PDL) .
However, that complexity makes it difficult to have a common set of criteria. This complexity
presents many security challenges that limit Microsoft's ability to provide more secure options
for users. This article discusses challenges related to securing the print stack and shares some
information that can help users today. It also gives a preview of a collaboration between the
Microsoft Offensive Research & Security Engineering (MORSE) team and Windows Print team
on what we think will be the future of Windows Printing, an IPP-based revision to the print
stack that no longer loads third-party drivers and runs with reduced attack surface.
The driver problem
The security model for print drivers relies on a shared responsibility model where the Windows
printing stack and third-party drivers must each play a role in providing functionality and
enforcing security promises while avoiding introducing vulnerabilities. This is like other
subsystems in Windows, but printing is a challenging scenario because customers want the
process to be frictionless when loading remote code into a highly privileged system process.
Loading code from third parties presents several challenges from a security perspective. Not
only must you ensure you're loading the code you intended to load, that code may change the
behavior of your application in unexpected ways. For example, drivers support complex parsing
logic that can lead to bugs allowing full control of the Spooler or related print process. In the
event a vulnerability is discovered in a driver, Microsoft is dependent on the third-party to
update the driver. When publishers no longer exist or consider older products out of support,
there's no clear way to address the vulnerability.
The reliance on third-party drivers in a shared responsibility model limits Microsoft's agility and
options to secure customers. We're often on the cutting edge of new security protections but
can't uniformly deploy them when loading third-party code.
Compatibility
One challenge with print drivers is their age. Many print drivers are decades old and are
incompatible with modern security mitigations such as Control Flow Guard (CFG), Control Flow
Enforcement Technology (CET), Arbitrary Code Guard (ACG) and the many other protections
Microsoft has implemented over the years. These protections are often "all or nothing"
meaning that all participating binaries must take steps to be compatible for the protection to
be effective. Since not every print manufacturer has taken the necessary steps to update these
drivers, the Print service doesn't currently benefit from these modern exploit mitigations. If a
vulnerability is discovered, attackers are more likely to have success exploiting it.
Excessive permissions
The Windows Print stack keeps many aspects of its original design that is over two decades
old. The Print Spooler runs as SYSTEM with special privileges that make it more powerful than
standard Administrator accounts on Windows. Drivers loaded into the Spooler (including third-
party drivers) run at this privilege level for basic document printing and handling of user
requests. For every user's request the Spooler receives it must determine the right level of
access for that task that can prove to be difficult.
One reason the Spooler maintains these permissions is due to backwards compatibility
concerns. Thousands of drivers, made over the course of 30 years, are in use in Windows and
identifying all possible risks to users is difficult.
The ideal solution would be to remove drivers entirely and move the Spooler to a least
privilege security model. Some operations may require SYSTEM level privileges but most
certainly don't. The challenge that we often face at Microsoft is that any solution must consider
the compatibility requirements of our customers. Balancing this need with the desire to
improve security is a difficult task. Fortunately, we think we have a solution.
IPP basics
IPP is an HTTP based protocol and supports many of the authentication methods one would
expect from HTTP. Each IPP request is an HTTP POST message and printers are identified using
URIs such as ipps://[Link]/ipp/print. IPP supports all the common operations
one would expect from a printer such as:
Create-Job: Create a new print job
Send-Document: Add a document to a print job
Print-Job: Create a new print job with a single document
Get-Printer-Attributes: Get Printer status and capabilities
Get-Jobs: Get a list of queued jobs
Get-Job-Attributes: Get job status and options
Cancel-Job: Cancel a queued job
Driverless printing supports a limited number of PDLs based on public standards such as PWG
Raster and PDF. This limits the unique number of formats the operating system must handle for
conversion and greatly simplifies code. Client-side rendering is used to generate the final
document sent to the printer.
Print Support App (PSA)
PSAs allow printer OEMs and IHVs to extend our existing IPP support for their specific needs.
Not all printers support the same features and configuration options. PSAs allow for tailored
user experiences without compromising the experience users expect.
Point and Print
Point and Print is a feature that allows users to connect to a remote printer without providing
drivers, and has all necessary drivers installed on the client. Point and Print remains with IPP,
but it works differently. We no longer must install drivers, but some basic configuration is
required to set up the printer. This process works as follows with IPP:
1. Windows client and server make a connection over RPC
2. Both server and client use their inbox Microsoft IPP driver
3. Server uses IPP to communicate with printer
4. PSA is installed, if available
Security
IPP-based printing in Windows today removes the need for third-party drivers. IPP supports
transport encryption, and with a limited number of PDL's supported, parsing complexity is
substantially decreased. This is a meaningful improvement over the model requiring the use of
drivers.
IPP Printing in Windows today is already a great step forward from a security perspective, and
we encourage users to switch whenever possible. We also encourage administrators to
prioritize this action across your fleet.
Spooler security in Windows protected print mode
Windows protected print mode builds on the existing IPP print stack where only Mopria
certified printers are supported, and disables the ability to load third-party drivers. By doing
this, we can make meaningful improvements to print security in Windows that otherwise
couldn't happen. Our goal is to ultimately provide the most secure default configuration and
provide the flexibility to revert back to legacy (driver-based) printing at any time, if users find
their printer isn't compatible. To use Windows protected print mode, ensure printers have IPP
enabled.
When users enable Windows protected print mode, normal spooler operations are deferred to
a new Spooler process that implements the Windows protected print mode improvements.
Let's look at some of those changes.
Limited and secure print configuration
In Windows protected print mode, many legacy configurations are no longer valid. A common
attack on Windows would abuse the fact that a printer port monitor can be a Dynamic Link
Library (DLL), and attackers would abuse this to load malicious code. Attackers would also use
symbolic links to trick the Spooler into loading malicious code, and that is no longer possible.
There are many legacy APIs's which are updated to restrict the configuration to values that
make sense only when using IPP. This limits the opportunity for attackers to use the Spooler to
modify files on the system.
Module blocking
APIs that allow module loading will be modified to prevent loading of new modules. For
example, AddPrintProviderW, and other calls, would result in loading modules that may be
malicious. We'll also enforce a restriction that ensures that only Microsoft Signed binaries
required for IPP are loaded.
Per-user XPS rendering
XPS rendering runs as the user instead of SYSTEM in Windows protected print mode. Most
print jobs in Windows today involve some XPS conversion and the process that handles this
task (PrintFilterPipelineSVC) is the source of many memory corruption vulnerabilities. As with
the other issues, by running this process as the user, the impact of these bugs is minimized.
Lower privileges for common Spooler tasks
Removing drivers also allows us to take common tasks performed by the Spooler process and
move those to a process running as the user. If these processes have memory corruption
vulnerabilities, that impact is limited to actions only the user can perform.
The new Spooler Worker process has a new restricted token that removes many privileges such
as SeTcbPrivilege, SeAssignPrimaryTokenPrivilege, and no longer runs at SYSTEM IL.
Binary mitigations
By removing third-party binaries, we're now able to enable many of the binary mitigations
Microsoft has invested in over the years. Processes in Windows protected print mode run with
many new binary mitigations. Here are some of the highlights:
Control Flow Enforcement Technology (CFG, CET) – Hardware based mitigation that helps to
mitigate Return Oriented Programming (ROP) based attacks.
Child Process Creation Disabled – Child process creation is blocked. This prevents attackers
from spawning a new process if they manage to get code execution in the Spooler.
Redirection Guard – prevents many common path redirection attacks that often target the Print
Spooler.
Arbitrary Code Guard – prevents dynamic code generation within a process.
These protections make it more difficult to abuse a vulnerability if one is found.
Point and Print with Windows protected print
mode
As mentioned above, Point and Print will normally allow driver loading as well as IPP printer
configuration. Some users may have an environment with only IPP printers, but malicious
attackers can pretend to be a printer and trick users into installing drivers. Windows protected
print mode prevents Point and Print from ever installing third-party drivers, mitigating this risk.
Related articles
ノ Expand table
Article Description
Overview of Windows protected Provides an overview of Windows protected print mode, its
print mode benefits, and how to use it.
Windows protected print mode for Provides guidance for enterprises using Windows protected print
enterprises mode.
Discover the Modern print platform Provides an overview of the modern print platform, and its security,
compatibility, and reliability benefits over legacy printer drivers.
End of servicing plan for third-party Provides information about the end of servicing plan for legacy v3
printer drivers on Windows and v4 Windows print drivers.
Print Support App design guide Provides guidance and examples for printer OEMs and IHVs that
are implementing a print support app (PSA) for their device.
Print Support App v3 API design Provides guidance and examples for printer OEMs and IHVs that
guide are implementing a v3 Print Support App (PSA) for their device.
Print Support App v4 API design Provides guidance and examples for printer OEMs and IHVs that
guide are implementing a v4 Print Support App (PSA) for their device.
MSIX Manifest Specification for Provides MSIX manifest guidance and examples for printer OEMs
Print Support Virtual Printer and IHVs that are implementing a Print Support Virtual Printer.
Print support app association Provides guidance and examples for associating a print support
app (PSA) with a printer.
Last updated on 07/17/2025