Device Control Printer Protection - Blocks Print to PDF

Copper Contributor

When using the OMA URI policy  ./Vendor/MSFT/Policy/Config/Printers/EnableDeviceControl to block printing via non-corporate printers. It is observed it blocks Print to PDF and Print to XPS function.

 

Using the Application Guard Security Policy under ASR does not provide the required exclusion.

 

Does anyone have any idea how to resolve.

 

Thanks

22 Replies
Same thing with me. I block USB printing and when I add All Users, it is not allowing me to print to PDF/XPS and it saves as 0KB file. But, when I remove the USB printing and do not assign anyone, then I can print to PDF / XPS and saves with the original file size.
Documentation here shows that you can now define a group for printing to PDF/XPS which would allow you to whitelist this, while blocking other printers.
At least if you manage this with the Device Control feature.
https://learn.microsoft.com/en-us/microsoft-365/security/defender-endpoint/printer-protection-overvi...

Documents list this under the same section as Printer Protection, but it seems to be a different feature, so may or may not work for you.
We urgently need a solution about the following problem:

The GPO “List of Approved USB-connected print devices” is active.
And when the GPO is enabled, the "eDoc" (Software Print to PDF) does not work anymore.

Importand:
No Intune or MS Defender is used.
Means the "printer protection v2" can`t used it.

What solution exists today or in the near future?