Restrict printing to corporate locations

%3CLINGO-SUB%20id%3D%22lingo-sub-1224132%22%20slang%3D%22en-US%22%3ERestrict%20printing%20to%20corporate%20locations%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1224132%22%20slang%3D%22en-US%22%3E%3CP%3EI%20was%20approached%20with%20the%20question%20if%20we%20can%20restrict%20printing%20with%20Intune.%20We%20have%20Intune%20managed%20clients%20where%20users%20are%20Admin%2C%20as%20we%20only%20protect%20the%20identity%20(Azure%20AD%20Conditional%20Access%2C%20CASB)%20and%20documents%20(Azure%20Information%20Protection)%20and%20the%20client%20is%20never%20entering%20the%20corporate%20network.%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3ENow%20Security%20wants%20to%20limit%20printing%20to%20corporate%20printers.%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI%20can't%20think%20of%20any%20way%20to%20achieve%20that%2C%20but%20I%20hope%20the%20community%20has%20solutions.%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EMaybe%20Applocker%2C%20PowerShell%20or%20policies%20I%20don't%20know%3F%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-1224132%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EIntune%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1224413%22%20slang%3D%22en-US%22%3ERe%3A%20Restrict%20printing%20to%20corporate%20locations%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1224413%22%20slang%3D%22en-US%22%3EIt%20looks%20like%20you%20can%20achieve%20the%20objective%20using%20%E2%80%98MAM%20policies%E2%80%99%2C%20have%20you%20tried%20it%3F%3CBR%20%2F%3E%3CBR%20%2F%3E%3CA%20href%3D%22https%3A%2F%2Fmicrosoftintune.uservoice.com%2Fforums%2F291681-ideas%2Fsuggestions%2F11600817-prevent-printout-via-mam-policy%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3Ehttps%3A%2F%2Fmicrosoftintune.uservoice.com%2Fforums%2F291681-ideas%2Fsuggestions%2F11600817-prevent-printout-via-mam-policy%3C%2FA%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1224748%22%20slang%3D%22en-US%22%3ERe%3A%20Restrict%20printing%20to%20corporate%20locations%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1224748%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F210221%22%20target%3D%22_blank%22%3E%40Philip%20B%C3%BCchler%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EIt's%20only%20possible%20to%20blocking%20printing%20as%20a%20whole%20through%20MAM.%3C%2FP%3E%3CP%3EThere%20is%20no%20built-in%20solution%20in-place.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI%20also%20can't%20think%20of%20a%20custom%20solution%20for%20the%20same.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1309095%22%20slang%3D%22en-US%22%3ERe%3A%20Restrict%20printing%20to%20corporate%20locations%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1309095%22%20slang%3D%22en-US%22%3EThis%20unfortunately%20is%20for%20mobile%20OS.%20I%20was%20looking%20for%20a%20solution%20for%20Windows.%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1309583%22%20slang%3D%22en-US%22%3ERe%3A%20Restrict%20printing%20to%20corporate%20locations%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1309583%22%20slang%3D%22en-US%22%3EYou%20could%20do%20that%20with%20WIP%20-%20%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fwindows%2Fsecurity%2Finformation-protection%2Fwindows-information-protection%2Fprotect-enterprise-data-using-wip%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3Ehttps%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fwindows%2Fsecurity%2Finformation-protection%2Fwindows-information-protection%2Fprotect-enterprise-data-using-wip%3C%2FA%3E%3CBR%20%2F%3E%3CBR%20%2F%3EBut%20be%20aware%2C%20the%20implementation%20is%20cumbersome%20and%20not%20straight%20forwarrd%3CBR%20%2F%3E%3CBR%20%2F%3EI%20try%20to%20stay%20away%20from%20it%20as%20much%20as%20possible%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1311928%22%20slang%3D%22en-US%22%3ERe%3A%20Restrict%20printing%20to%20corporate%20locations%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1311928%22%20slang%3D%22en-US%22%3EFunny%20enough%2C%20this%20customer%20uses%20WIP%20and%20I%20can%20confirm%20its%20cumbersomeness.%20It%20would%20only%20work%20if%20we%20used%20RMS%20as%20well%20though.%20And%20then%2C%20I%20think%2C%20it%20would%20prevent%20printing%20on%20a%20document%20level.%3CBR%20%2F%3EWhat%20the%20CISO%20wants%20to%20achieve%20is%20to%20limit%20printing%20to%20company%20printers.%20So%20a%20user%20can't%20print%20on%20his%20printer%20at%20home%2C%20but%20can%20print%20in%20the%20office.%20I%20will%20recommend%20to%20use%20AIP%20and%20solve%20it%20on%20a%20document%20level.%3CBR%20%2F%3E%3CBR%20%2F%3EMeanwhile%20I%20might%20test%20this%20out%3A%20%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fmem%2Fintune%2Fconfiguration%2Fdevice-restrictions-windows-10%23printer%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3Ehttps%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fmem%2Fintune%2Fconfiguration%2Fdevice-restrictions-windows-10%23printer%3C%2FA%3E%3CBR%20%2F%3ESetting%20the%20network%20printer%20as%20default%20and%20not%20allowing%20adding%20new%20printers.%3C%2FLINGO-BODY%3E
Contributor

I was approached with the question if we can restrict printing with Intune. We have Intune managed clients where users are Admin, as we only protect the identity (Azure AD Conditional Access, CASB) and documents (Azure Information Protection) and the client is never entering the corporate network. 

 

Now Security wants to limit printing to corporate printers. 

 

I can't think of any way to achieve that, but I hope the community has solutions. 

 

Maybe Applocker, PowerShell or policies I don't know?

5 Replies
It looks like you can achieve the objective using ‘MAM policies’, have you tried it?

https://microsoftintune.uservoice.com/forums/291681-ideas/suggestions/11600817-prevent-printout-via-...

@Philip Büchler 

 

It's only possible to blocking printing as a whole through MAM.

There is no built-in solution in-place.

 

I also can't think of a custom solution for the same.

This unfortunately is for mobile OS. I was looking for a solution for Windows.
You could do that with WIP - https://docs.microsoft.com/en-us/windows/security/information-protection/windows-information-protect...

But be aware, the implementation is cumbersome and not straight forwarrd

I try to stay away from it as much as possible
Funny enough, this customer uses WIP and I can confirm its cumbersomeness. It would only work if we used RMS as well though. And then, I think, it would prevent printing on a document level.
What the CISO wants to achieve is to limit printing to company printers. So a user can't print on his printer at home, but can print in the office. I will recommend to use AIP and solve it on a document level.

Meanwhile I might test this out: https://docs.microsoft.com/en-us/mem/intune/configuration/device-restrictions-windows-10#printer
Setting the network printer as default and not allowing adding new printers.