Deployment

Windows Protected Print Mode

Windows Protected Print Mode (WPP) uses the modern IPP-based Windows print stack and removes support for non-IPP print drivers and standard TCP/IP print ports when enabled. When WPP is enabled, Windows removes non-IPP print drivers and standard TCP/IP ports. If WPP is later disabled, the removed printers, drivers, and ports are not automatically recreated. IPPS ports and IPP-compatible drivers are preserved.

WPP is already configurable via Group Policy and Windows Settings in current Windows releases. Plan the transition before WPP is enabled on managed workstations, especially where current printing depends on vendor drivers, LPR, RAW, or standard TCP/IP ports.


What WPP Changes

When WPP is enabled on a workstation:

  • Non-IPP print drivers are removed. Vendor-specific drivers, such as PCL or PostScript drivers, cannot be used while WPP is active unless they are compatible with the IPP-based print model.

  • Standard TCP/IP ports (LPR, RAW) are removed. Printers configured with these ports stop working.

  • Only IPPS ports and the Windows built-in IPP class driver are preserved.

  • Adding new printers is restricted to IPP-based devices only.

Disabling WPP later does not automatically recreate printers, drivers, or ports that were removed when WPP was enabled.

Impact on MyQ X

IPPS queues are preserved under WPP. Queues configured with IPPS ports on the MyQ Print Server can continue to work, but output behavior and finishing options must be tested for each device model. Planning IPPS queue deployment before WPP is enabled is one of the key transition tasks.

Device Spooling is affected by WPP because it uses RAW ports, such as 10010-10013, for direct job delivery to devices. WPP removes RAW/TCP/IP ports, so Device Spooling workflows can stop working on WPP-enabled workstations. If Device Spooling is part of your resilience or branch office strategy, you need an alternative before WPP is enforced in those environments. Assess affected sites and user populations as part of your WPP planning.

Standard driver provisioning via MDC fails under WPP. If MyQ Desktop Client provisioning profiles still deploy standard print drivers when WPP is active, Windows blocks the printer configuration. Users can see a Configuring printers failed error on each provisioning attempt, and the affected printer is not installed. Switch affected profiles to Printer Provisioning Profiles that deploy IPPS or Universal IPP printers before WPP reaches those workstations.

Finishing options may be reduced under IPPS. Vendor print drivers can expose device-specific finishing capabilities, such as duplex modes, tray selection, stapling, punch, or booklet printing. IPPS relies on IPP attributes reported by the device, and some capabilities available through a vendor driver may not be available or may behave differently through IPPS. Test print output for each device model in your fleet before removing standard drivers.

Transition Planning

Treat WPP as a migration with a defined completion target, not a future compatibility issue. The steps below give you a structured approach.

Inventory your current print paths. Identify which workstations use standard TCP/IP or LPR ports, which use vendor drivers, and which already use IPPS. This tells you the scope of work before WPP reaches any part of your environment.

Deploy IPPS queues before removing standard queues. Users need a working IPPS-based print path in place before their existing paths are removed. Configure IPPS queues on the Print Server, verify certificate trust on target workstations, and confirm print output quality for each device model. Only then begin retiring standard queues.

Switch MDC provisioning profiles to IPPS. For environments using Desktop Client printer provisioning, update configuration profiles to use Printer Provisioning Profiles with the built-in IPPS driver. Disable or remove profiles that deploy standard drivers. Do this before WPP is enabled on any workstation covered by those profiles.

Address Device Spooling dependencies explicitly. Identify every site or use case that depends on Device Spooling. Determine whether Client Spooling is a viable substitute – it achieves similar network efficiency without RAW ports. Where Device Spooling is used for offline resilience in combination with Offline Login, assess whether that resilience model needs to be redesigned for affected sites.

Test finishing options per device model. For each device model in your fleet, print a test job via IPPS and verify that the finishing options your users need are available and function correctly. Document any gaps and decide whether they require firmware updates, device replacement, or workflow changes before standard drivers are removed.

Coordinate Central/Site environments carefully. In multi-site deployments, WPP may be enforced at different times across different workstation populations. A roaming user whose workstation has WPP enabled may visit a site whose MDC profiles still deploy standard drivers – this generates provisioning failures. Maintain a clear picture of which sites and profiles have been migrated and which have not, and restrict roaming users from receiving non-IPPS profiles during the transition period.

Communicate to users before the change. Removing a working print queue and replacing it with an IPPS queue is transparent if done correctly. Any gap in coverage can result in failed printing and additional support requests. Confirm replacement queues are working for representative users in each group before retiring standard queues fleet-wide.