How to forbid printing in Remote Work scenario?

%3CLINGO-SUB%20id%3D%22lingo-sub-2568646%22%20slang%3D%22en-US%22%3EHow%20to%20forbid%20printing%20in%20Remote%20Work%20scenario%3F%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2568646%22%20slang%3D%22en-US%22%3E%3CP%3EHi%2C%3C%2FP%3E%3CP%3EWith%20so%20many%20people%20working%20remote%20these%20days%20we%20have%20a%20question.%3C%2FP%3E%3CP%3EAssume%20our%20employee%20Bob%20goes%20home%2C%20and%20starts%20his%20personal%20home%20computer%2C%20opens%20a%20browser%20and%20connects%20to%20the%20Company%20Azure%20SharePoint%20Portal%2C%20Outlook%20Online%2C%20Teams%20online%2C%20etc%20and%20opens%20a%20Word%20document.%20Bob%20then%20prints%20this%20Word%20document%20on%20his%20home%20printer.%3C%2FP%3E%3CP%3EWe%20dont%20want%20that%20to%20happen.%20We%20dont%20want%20Bob%20printing%20company%20material%20when%20he%20is%20at%20home%20(on%20his%20home%20computer%20and%20via%20his%20home%20printer%20-%20neither%20being%20company%20controlled%20in%20any%20way).%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EHowever%2C%20when%20Bob%20returns%20to%20the%20office%20on%20Friday%2C%20he%20must%20be%20able%20to%20access%20and%20print%20that%20Word%20document%20-%20on%20the%20office%20provided%20computer%20and%20printer.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EOur%20question%20is%2C%20is%20this%20scenario%20even%20possible%3F%3C%2FP%3E%3CP%3EIMHO%2C%20the%20MS%20stack%20wont%20achieve%20the%20above...and%20we%20may%20need%20to%20explore%20things%20like%3A%3C%2FP%3E%3CP%3E-%20blocking%20the%20use%20of%20untrusted%20devices%20(home%20pc's)%3C%2FP%3E%3CP%3E-%20possibly%20the%20use%20of%20Citrix%20desktop%20%2F%20Windows%20Cloud%20PC%20(for%20home%20use)%3C%2FP%3E%3CP%3E-%20or%20enforcing%20the%20use%20of%20only%20company%20owned%20devices%20to%20access%20company%20resources%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EAre%20we%20on%20the%20right%20track%3F%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3ELook%20forward%20to%20hearing%20from%20you.%3C%2FP%3E%3CP%3ECheers%2C%3C%2FP%3E%3CP%3ESK%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-2573255%22%20slang%3D%22en-US%22%3ERe%3A%20How%20to%20forbid%20printing%20in%20Remote%20Work%20scenario%3F%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2573255%22%20slang%3D%22en-US%22%3EHi%20%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F465038%22%20target%3D%22_blank%22%3E%40ShimKwan%3C%2FA%3E%3CBR%20%2F%3E%3CBR%20%2F%3EJust%20for%20understanding%2C%20your%20company%20is%20a%20whole%20Azure%20env%20or%20only%20things%20like%20sharepoint%3F%3CBR%20%2F%3EIf%20so%20check%20out%20the%20following%20articles%3A%3CBR%20%2F%3E%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Factive-directory%2Fdevices%2Fconcept-azure-ad-register%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3Ehttps%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Factive-directory%2Fdevices%2Fconcept-azure-ad-register%3C%2FA%3E%3CBR%20%2F%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fazure-active-directory-identity%2Fprint-to-corporate-printers-from-azure-ad-joined-windows-10%2Fba-p%2F245341%22%20target%3D%22_blank%22%3Ehttps%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fazure-active-directory-identity%2Fprint-to-corporate-printers-from-azure-ad-joined-windows-10%2Fba-p%2F245341%3C%2FA%3E%3CBR%20%2F%3E%3CBR%20%2F%3EIf%20you%20are%20only%20using%20any%20MS%20online%20products%20I%20would%20recommend%20to%20use%20the%20variant%20to%20only%20allow%20a%20static%20set%20of%20IP%20addresses%20(just%20example)%3A%3CBR%20%2F%3E%3CA%20href%3D%22https%3A%2F%2Fcommunity.spiceworks.com%2Ftopic%2F2124004-restrict-management-access-by-ip-in-office-365%22%20target%3D%22_blank%22%20rel%3D%22nofollow%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fcommunity.spiceworks.com%2Ftopic%2F2124004-restrict-management-access-by-ip-in-office-365%3C%2FA%3E%3CBR%20%2F%3E%3CBR%20%2F%3EFeel%20free%20to%20give%20feedback%3CBR%20%2F%3E%3CBR%20%2F%3EBest%20regards%3CBR%20%2F%3ESchnittlauch%3CBR%20%2F%3E%3CBR%20%2F%3EMy%20answer%20helped%20you%3F%20Don't%20forget%20to%20leave%20a%20like.%20Also%20mark%20the%20answer%20as%20solved%20when%20your%20problem%20is%20solved.%20%3A)%3C%2Fimg%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-2573540%22%20slang%3D%22en-US%22%3ERe%3A%20How%20to%20forbid%20printing%20in%20Remote%20Work%20scenario%3F%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2573540%22%20slang%3D%22en-US%22%3EThank%20you%20for%20those%20links.%3CBR%20%2F%3EUnfortunately%20we%20are%20talking%20about%20home%20computers%20that%20are%20not%20part%20of%20anything%2C%20not%20domain%20joined%2C%20not%20AAD%20joined%2C%20no%20Intune%20deployed%2C%20its%20not%20even%20a%20BYOD%20scenario.%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-2584191%22%20slang%3D%22en-US%22%3ERe%3A%20How%20to%20forbid%20printing%20in%20Remote%20Work%20scenario%3F%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2584191%22%20slang%3D%22en-US%22%3Efml%20%3A(%3C%2Fimg%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-2584612%22%20slang%3D%22en-US%22%3ERe%3A%20How%20to%20forbid%20printing%20in%20Remote%20Work%20scenario%3F%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2584612%22%20slang%3D%22en-US%22%3EYou%20may%20restrict%20printing%20in%20case%20you%20are%20using%20Information%20Right%20Management.%3CBR%20%2F%3EThey%20could%20be%20a%20home%20PC%20but%20as%20long%20as%20they%20required%20authentications%20like%20using%20Microsoft%20365%20to%20access%20document%2C%20you%20may%20restrict%20them.%3CBR%20%2F%3EFor%20example%2C%20this%20is%20applicable%20for%20a%20home%20PC%20when%20they%20want%20to%20access%20document%20using%20SharePoint%20online.%3CBR%20%2F%3E%3CA%20href%3D%22https%3A%2F%2Fsupport.microsoft.com%2Fen-us%2Ftopic%2Frestrict-access-to-documents-with-information-rights-management-in-word-94aa8ab1-465e-42d7-a323-d61f911b2d0f%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3Ehttps%3A%2F%2Fsupport.microsoft.com%2Fen-us%2Ftopic%2Frestrict-access-to-documents-with-information-rights-management-in-word-94aa8ab1-465e-42d7-a323-d61f911b2d0f%3C%2FA%3E%3CBR%20%2F%3E%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fmicrosoft-365%2Fcompliance%2Fset-up-irm-in-sp-admin-center%3Fview%3Do365-worldwide%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3Ehttps%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fmicrosoft-365%2Fcompliance%2Fset-up-irm-in-sp-admin-center%3Fview%3Do365-worldwide%3C%2FA%3E%3CBR%20%2F%3E%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fmicrosoft-365%2Fenterprise%2Factivate-rms-in-microsoft-365%3Fview%3Do365-worldwide%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3Ehttps%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fmicrosoft-365%2Fenterprise%2Factivate-rms-in-microsoft-365%3Fview%3Do365-worldwide%3C%2FA%3E%3CBR%20%2F%3E%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2FExchange%2Fpolicy-and-compliance%2Finformation-rights-management%3Fview%3Dexchserver-2019%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3Ehttps%3A%2F%2Fdocs.microsoft.com%2Fen-us%2FExchange%2Fpolicy-and-compliance%2Finformation-rights-management%3Fview%3Dexchserver-2019%3C%2FA%3E%3C%2FLINGO-BODY%3E
Contributor

Hi,

With so many people working remote these days we have a question.

Assume our employee Bob goes home, and starts his personal home computer, opens a browser and connects to the Company Azure SharePoint Portal, Outlook Online, Teams online, etc and opens a Word document. Bob then prints this Word document on his home printer.

We dont want that to happen. We dont want Bob printing company material when he is at home (on his home computer and via his home printer - neither being company controlled in any way).

 

However, when Bob returns to the office on Friday, he must be able to access and print that Word document - on the office provided computer and printer.

 

Our question is, is this scenario even possible?

IMHO, the MS stack wont achieve the above...and we may need to explore things like:

- blocking the use of untrusted devices (home pc's)

- possibly the use of Citrix desktop / Windows Cloud PC (for home use)

- or enforcing the use of only company owned devices to access company resources

 

Are we on the right track?

 

Look forward to hearing from you.

Cheers,

SK

7 Replies
Hi @ShimKwan

Just for understanding, your company is a whole Azure env or only things like sharepoint?
If so check out the following articles:
https://docs.microsoft.com/en-us/azure/active-directory/devices/concept-azure-ad-register
https://techcommunity.microsoft.com/t5/azure-active-directory-identity/print-to-corporate-printers-f...

If you are only using any MS online products I would recommend to use the variant to only allow a static set of IP addresses (just example):
https://community.spiceworks.com/topic/2124004-restrict-management-access-by-ip-in-office-365

Feel free to give feedback

Best regards
Schnittlauch

My answer helped you? Don't forget to leave a like. Also mark the answer as solved when your problem is solved. :)
Thank you for those links.
Unfortunately we are talking about home computers that are not part of anything, not domain joined, not AAD joined, no Intune deployed, its not even a BYOD scenario.
You may restrict printing in case you are using Information Right Management.
They could be a home PC but as long as they required authentications like using Microsoft 365 to access document, you may restrict them.
For example, this is applicable for a home PC when they want to access document using SharePoint online.
https://support.microsoft.com/en-us/topic/restrict-access-to-documents-with-information-rights-manag...
https://docs.microsoft.com/en-us/microsoft-365/compliance/set-up-irm-in-sp-admin-center?view=o365-wo...
https://docs.microsoft.com/en-us/microsoft-365/enterprise/activate-rms-in-microsoft-365?view=o365-wo...
https://docs.microsoft.com/en-us/Exchange/policy-and-compliance/information-rights-management?view=e...

Hi Reza,
Thank you for the links.
What I fail to understand is how Information Rights Management will solve this problem.

How will Rights Management be able to detect that when I am in the office, using company equipment I should be able to print a document....while when I am working from home, using my home computer (not company supplied), I shouldn't be able to print that very same document on my home printer (not company supplied).

Are you able to clarify, in detail, how Rights Management achieves this functionality?

Thank you.

Hi @ShimKwan,

 

IMO, you can do it with MCAS Conditional Access Apps Control apps and session control, take a look here.

 

Cheers,

 

 

 
 
 
 
 
Are you using local AD in your company?
In this case, you may setup a group and in that group you set the Right Management to permit printing and add users to this group.
So while they are at work, they would be able to print because they have access to this local AD group.
However, in Azure AD (outside company) the policy would prevent printing.
You may check conditional access too:
https://docs.microsoft.com/en-us/azure/role-based-access-control/conditional-access-azure-management