To deploy printers with Group Policy, you point each user or computer at a shared print queue, and Windows connects to it at sign-in. Since the PrintNightmare fixes in 2021, the hard part is no longer the connection but the driver: standard users can no longer install printer drivers through Point and Print. This guide covers Group Policy Preferences, Deployed Printers from Print Management, the Point and Print policies, driver pre-staging, targeting, Universal Print with Intune and troubleshooting.
Short answer: Install package-aware drivers on the print server and pre-install the same drivers on clients. Then create a GPO linked to the user OU, go to User Configuration » Preferences » Control Panel Settings » Printers, add a Shared Printer with action Update and path \\print01.contoso.com\HR-MFP, and target it to the SG-HR group with item-level targeting. Users get the printer at their next sign-in without an elevation prompt.
Table of Contents
Which method to use
| Method | Scope | Pros | Cons |
|---|---|---|---|
| GPP Shared Printer | Per user | Item-level targeting by group, site or IP range; default printer option | Driver must already be on the client or installable by the user |
| GPP TCP/IP Printer | Per computer or user | Direct IP printing without a print server | Needs a driver source; no central queue |
| Deployed Printers (Print Management) | Per user or per machine | Two clicks from the print server; removed when you remove it from the GPO | No item-level targeting; only security filtering |
| Universal Print with Intune | Per user, cloud | No print server or VPN; Entra-joined devices | Needs Universal Print licences and connector or native printers |
For most domains, the best way to deploy printers with Group Policy is Preferences Shared Printer items, because one GPO can serve every department and site. Use Deployed Printers for shared machines and Universal Print for cloud-only devices.
Prerequisites
- A print server running Windows Server 2016 to 2025 with the Print and Document Services role and shared queues.
- Type 4 or package-aware Type 3 drivers from the printer vendor. In Print Management, the Drivers view shows a Packaged column; prefer drivers where it says true.
- Clients on Windows 11 Pro, Enterprise or Education joined to the domain, with the latest cumulative updates on both clients and print server.
- Security groups per department or floor, and rights to create and link GPOs.
Plan queues, names and scope
A little planning makes it much easier to deploy printers with Group Policy and support them later:
- Queue names: use short names without spaces that describe place and type, such as LDN-F2-MFP or HR-MFP. The share name becomes part of the path in every GPO item.
- One driver per model family: a universal driver from the vendor (for example HP Universal Printing or a Type 4 driver) means one package to pre-stage instead of ten.
- Per user or per computer: choose per user when people move between desks and should see their department’s printers anywhere. Choose per computer for shared PCs, labs, meeting rooms and RDS hosts, where the printer belongs to the room, not the person.
- Location field: fill in the Location on each queue in Print Management. Users see it in the printer list, and it helps the service desk.
Write the plan as a simple table of queue, driver, group or site, and default yes or no. It becomes your list of preference items.
How drivers get installed after PrintNightmare
Since the August 2021 update (KB5005652), Windows sets RestrictDriverInstallationToAdministrators to 1 by default under HKLM\Software\Policies\Microsoft\Windows NT\Printers\PointAndPrint. With that value, only administrators can install any printer driver through Point and Print. A standard user can still connect to a shared printer if the matching driver is already on the PC. That gives you three safe options:
- Pre-install the drivers on every client (recommended).
- Use a computer-side deployment, where Windows installs the driver in the system context.
- Deploy the driver with Intune, Configuration Manager or your RMM.
Setting the value to 0 brings back user driver installs, but it reopens the attack surface the update closed. If you must do it, combine it with the Point and Print restrictions below.
Pre-stage drivers with a startup script
Copy the vendor driver folder to a share that Domain Computers can read, and run this as a computer startup script (Computer Configuration » Policies » Windows Settings » Scripts » Startup):
pnputil /add-driver "\\contoso.com\NETLOGON\Drivers\HP-UPD\*.inf" /install
powershell -NoProfile -Command "Add-PrinterDriver -Name 'HP Universal Printing PCL 6'"
pnputil adds the package to the driver store, and Add-PrinterDriver installs the print driver from it. The name must match the driver name on the print server exactly, including version, otherwise Windows tries to download the server’s copy.
Method 1: Group Policy Preferences Shared Printer
This is the most flexible way to deploy printers with Group Policy, because every printer is its own item with its own targeting.
- In GPMC, create a GPO linked to the user OU, for example USR – Printers.
- Go to
User Configuration » Preferences » Control Panel Settings » Printers, right-click and choose New » Shared Printer. - Set Action to Update. It creates the connection if missing and only changes the settings in the item.
- In Share path, type the fully qualified path, for example
\\print01.contoso.com\HR-MFP. Use the FQDN so it matches the approved server list later. - Tick Set this printer as the default printer only on the item for the user’s main printer.
- On the Common tab, tick Item-level targeting, click Targeting…, add a Security Group condition for SG-HR and click OK.
- Also tick “Remove this item when it is no longer applied”, so users who leave the group lose the printer.
Microsoft documents that the connection and default printer are always set in the current user’s context, while the driver install uses the security context on the Common tab. With the default Point and Print restriction, the user context cannot install a driver, which is why pre-staging matters.
Windows 11 can change the default printer to the last one used. If you set a default through the GPO, tell users to turn off Let Windows manage my default printer in Settings » Bluetooth & devices » Printers & scanners.
Method 2: GPP TCP/IP Printer
Use this for label printers, warehouse devices or sites without a print server.
- Go to
Computer Configuration » Preferences » Control Panel Settings » Printersand choose New » TCP/IP Printer. The computer side creates the printer for everyone who signs in. - Enter the IP Address (IPv4 only) or tick Use DNS name, then set a Local name such as Warehouse Labels. Windows uses the local name to decide whether the printer already exists.
- In Printer path, enter a shared printer that uses the same driver (for example
\\print01.contoso.com\Labels). The item uses it as the driver source. - Under Port Settings, keep Raw on port 9100 unless the vendor says otherwise.
- Add item-level targeting on Computer Name or IP Address Range.
Method 3: Deployed Printers from Print Management
- On the print server, open Print Management, expand the server and select Printers.
- Right-click a printer and choose Deploy with Group Policy.
- Click Browse and pick a GPO, then choose The users that this GPO applies to (per user) or The computers that this GPO applies to (per machine), click Add and OK.
The connection appears in the GPO under Policies » Windows Settings » Deployed Printers. Per-machine connections are added when a user signs in, so every user of that PC gets the printer; per-user connections are added during background refresh. When you remove a printer from the GPO, Windows removes it from clients at the next refresh or sign-in. Per-machine connections are a good fit for shared PCs, meeting rooms and RDS hosts.
Method 4: Point and Print policies
Whichever way you deploy printers with Group Policy, set the Point and Print policies in a computer GPO linked to the workstation OU. All three live in Computer Configuration » Policies » Administrative Templates » Printers:
| Setting | Recommended value | Effect |
|---|---|---|
| “Limits print driver installation to Administrators” | Enabled | Writes RestrictDriverInstallationToAdministrators = 1; only admins install drivers |
| “Point and Print Restrictions” | Enabled, Users can only point and print to these servers with your print server FQDNs; both security prompts set to Show warning and elevation prompt | Blocks connections to unknown servers |
| “Package Point and print – Approved servers” | Enabled, same FQDN list | Package-aware drivers install only from listed servers |
Microsoft notes that the Point and Print Restrictions settings can override the driver restriction value, so never set the security prompts to Do not show warning or elevation prompt; that combination is what attackers abused. Also leave RpcAuthnLevelPrivacyEnabled at 1 or unset on print servers.
On Windows 11 24H2 and later, “Configure Windows protected print” in the same node switches the PC to Windows protected print mode, where only the inbox IPP class driver is used and third-party drivers stop working. Test your printers with it before enabling it.
Universal Print with Intune
For Entra-joined devices without line of sight to a print server:
- Register printers in Universal Print (natively or through the Universal Print connector) and share them.
- In Intune, create a Settings catalog profile for Windows 10 and later, add the Printer Provisioning category and fill in Cloud Device ID, Printer Shared ID and Printer Shared Name from the Universal Print portal, with action Install.
- Assign the profile to users; it is a user-scoped setting.
Admins and users need Universal Print licences, which are included in many Microsoft 365 plans.
Targeting and exceptions
- By department: Security Group targeting per Shared Printer item, as above.
- By floor or site: Site or IP Address Range targeting, so laptops get the nearest printer wherever they sign in.
- RDS hosts: add Terminal Session targeting, or link a per-machine Deployed Printers GPO to the host OU.
- Exclude users: in the item’s targeting, add a Security Group condition with Is Not, or deny Apply group policy to a group on the GPO’s Delegation tab.
Verify it works
After you deploy printers with Group Policy to a pilot group, check each layer in order: the GPO, the connection, the driver and the logs. Test with a standard user account, not an administrator, because an administrator can install drivers that a normal user cannot, which hides the most common problem.
- Sign in as a test user and check the GPO:
gpresult /scope user /r
Get-Printer | Format-Table Name, Type, DriverName, PortName
Get-PrinterDriver | Format-Table Name, MajorVersion
Network connections showTypeConnection. - Check the Point and Print values:
reg query "HKLM\Software\Policies\Microsoft\Windows NT\Printers\PointAndPrint" - Look in the Application log for source Group Policy Printers; event 4098 means an item failed and includes the error code.
- On the print server and client, check
Microsoft-Windows-PrintService/Adminin Event Viewer for driver and connection errors.
Troubleshooting
When you deploy printers with Group Policy and a printer does not appear, first connect to the same share manually as the affected user. If that fails, the problem is the queue, the driver or permissions, not the GPO.
| Symptom | Likely cause | Fix |
|---|---|---|
| Users get an administrator prompt when connecting | Driver missing on the client and RestrictDriverInstallationToAdministrators is 1 | Pre-stage the exact driver version |
| Printer appears, then fails after a server driver update | Clients need the new driver version | Update the pre-staged driver before changing the server |
| Event 4098 for a Shared Printer item | Wrong share path, server unreachable or driver install blocked | Test the path with Test-NetConnection print01 -Port 445 and connect manually as the user |
| Printer missing on some PCs only | Targeting false, or GPO linked to the wrong OU | Check targeting in the item and gpresult |
| Default printer keeps changing | Let Windows manage my default printer | Turn it off, or set the default in only one item |
Error 0x0000011b | RPC privacy mismatch between an unpatched client and server | Install current updates on both; do not lower RPC privacy |
Roll back or undo
- GPP items: if “Remove this item when it is no longer applied” was ticked, unlink the GPO. Otherwise change the item’s action to Delete, let it apply, then remove it.
- Deployed Printers: remove the printer from the GPO in Print Management or GPMC; clients drop it at the next refresh or sign-in.
- Point and Print policies: keep them. If you enabled user driver installs as a test, set “Limits print driver installation to Administrators” back to Enabled.
- Universal Print: unassign the Intune profile or set the action to remove the printer.
Pilot on one department first; once drivers are pre-staged, you can deploy printers with Group Policy to the whole domain without users ever seeing an elevation prompt.
Deploy printers with Group Policy at a glance

Official documentation: KB5005652: Manage new Point and Print default driver installation behavior, Printers Policy CSP, Configure Universal Print in Intune.
Related guides: Map Network Drives with Group Policy: Drive Maps, Targeting and Fixes · PowerShell logon/startup scripts with Group Policy · GPO security filtering: target or exclude users and computers.
Frequently asked questions
Why do users get an administrator prompt when a GPO adds a printer?
Since KB5005652, Windows only lets administrators install printer drivers through Point and Print. Pre-install the exact driver on the clients, and the connection then works for standard users.
Should I use Group Policy Preferences or Deployed Printers?
Use Group Policy Preferences when you need item-level targeting by group, site or IP range and a default printer option. Use Deployed Printers from Print Management for simple per-machine connections on shared PCs or RDS hosts.
Is it safe to set RestrictDriverInstallationToAdministrators to 0?
It brings back the risk that the 2021 updates removed. If you must, also enable Point and Print Restrictions with your print server list and keep both security prompts on warning and elevation.
How do I remove a printer deployed by Group Policy?
For Deployed Printers, remove it from the GPO and clients drop it at the next refresh. For Preferences, use “Remove this item when it is no longer applied” or change the item’s action to Delete.
Can I deploy printers to Entra-joined devices without a print server?
Yes. Register the printers in Universal Print and deploy them with the Intune settings catalog Printer Provisioning category, assigned to users.