Windows Protected Print: What AVD, Citrix & RDS Admins Need to Know

By Brock McKenna on October 8, 2026

<span id="hs_cos_wrapper_name" class="hs_cos_wrapper hs_cos_wrapper_meta_field hs_cos_wrapper_type_text" style="" data-hs-cos-general-type="meta_field" data-hs-cos-type="text" >Windows Protected Print: What AVD, Citrix & RDS Admins Need to Know</span>

Print drivers are a real attack surface. According to Microsoft, print-related bugs accounted for 9% of cases reported to the Microsoft Security Response Center over a three-year period, and Microsoft's analysis found that Windows Protected Print mode (WPP) could have mitigated more than half of the print-related vulnerabilities examined. Moving toward a more secure, driver-independent printing architecture makes sense.

But what does that mean for organizations running Azure Virtual Desktop (AVD), Citrix, or Remote Desktop Services (RDS)?

Virtual desktop environments have long depended on different approaches to connecting remote sessions with physical printers. Some require manufacturer-specific drivers on session hosts, while others rely on printer redirection, universal printing technologies, or cloud services. WPP doesn't affect all these approaches equally, which makes understanding the dependencies important before changing anything.

Why is Windows Protected Print a challenge for virtual desktops?

The fundamental challenge with VDI printing is that applications run inside remote sessions while printers are often located elsewhere. Traditional printing architectures address this in different ways:

Printer redirection makes locally connected printers available inside the session. Microsoft's Remote Desktop Easy Print, for example, avoids the need for manufacturer-specific drivers on the session host. However, redirected printer names may include session-specific suffixes, which can cause problems for applications expecting fixed printer names.

Universal printing technologies, such as Citrix Universal Print Driver and Windows Easy Print, reduce the need for individual manufacturer drivers on session hosts. Depending on the configuration, they can introduce other considerations, including bandwidth usage and compatibility with specialized printer functionality.

Direct network printing allows session hosts to send jobs to network printers. This can work well, but may require manufacturer drivers and reliable connectivity between session hosts and printers.

it-man-printing-vdi

For a closer look at these architectures, see How Printing Works in AVD, Citrix and RDS - And Why It Often Breaks.

The important distinction is that not every VDI printing method requires third-party drivers on the session host. Its compatibility with WPP depends on the components involved.

What does WPP change for a session host?

Windows Protected Print mode, introduced with Windows 11 24H2 and supported on Windows Server 2025, restricts printing to Microsoft's built-in IPP-based architecture. Third-party print drivers cannot be used while WPP is enabled.

For VDI administrators, this raises three considerations.

Existing drivers in golden images. If an AVD, Citrix, or RDS image includes manufacturer-specific print drivers, WPP prevents those drivers from being used. Enabling WPP also removes installed printers that depend on third-party drivers.

Printer redirection. Not all redirected printers require manufacturer drivers on the session host. Nevertheless, administrators should verify whether their specific redirection configuration and printing components work with WPP enabled.

Older and specialized printers. Devices that depend on legacy manufacturer drivers may no longer be available through conventional Windows printer installations. Label printers, older MFPs, and other specialized hardware deserve particular attention. Alternative printing architectures may allow some of these devices to remain usable.

WPP is not mandatory today, and Microsoft has not announced when it will become the default. However, its broader transition away from legacy print drivers is already underway:

  • January 15, 2026: Microsoft stopped routinely accepting new third-party printer drivers for publication through Windows Update on Windows 11 and Windows Server 2025 and later, with exceptions considered individually.
  • July 1, 2026: Windows began prioritizing the built-in IPP class driver when selecting printer drivers.
  • July 1, 2027: Microsoft will stop accepting non-security updates for third-party printer drivers through Windows Update.

Existing third-party printer drivers will remain available for installation through Windows Update, and manufacturers can continue providing drivers through separate installation packages. Microsoft's roadmap does not mean that legacy printer drivers will suddenly stop working in July 2027.

Nevertheless, organizations maintaining VDI golden images should consider how long they want to depend on manufacturer-specific drivers. Microsoft's official roadmap makes the direction clear.

Before Enabling WPP: A VDI Compatibility Checklist

Before enabling WPP across an AVD, Citrix, or RDS environment, IT teams should establish where their printing dependencies actually exist.

Start with the drivers. Are manufacturer-specific drivers installed in golden images, added dynamically to session hosts, or used only on endpoint devices? WPP affects the Windows system on which it is enabled, so the distinction matters.

Next, identify which printing methods and applications depend on those drivers. Pay particular attention to specialized printers, manufacturer-specific functionality, and applications configured to use fixed printer names.

Finally, test WPP on a representative session host before changing production images. Verify printer availability, application compatibility, and essential workflows. Microsoft confirms that enabling WPP removes printers using third-party drivers, and disabling it afterward does not automatically restore those printer configurations.

The objective isn't necessarily to replace your printing infrastructure immediately. It's to identify dependencies before they become compatibility problems.

Cloud Printing: Moving Printer Drivers Out of the VDI Session

printing-with-cloud-vdi

One way to reduce the impact of WPP is to move printer-specific rendering outside the virtual desktop.

With ezeep, print jobs are rendered in the cloud rather than through manufacturer-specific rendering drivers installed on session hosts. The processed jobs are delivered to printers through the ezeep Hub or an appropriate software Connector, depending on the deployment.

This reduces the need to maintain manufacturer-specific drivers in golden images and avoids relying on conventional RDP or ICA printer redirection for ezeep-managed printing.

ezeep also supports Windows Protected Print mode. According to the official ezeep documentation, the ezeep Print App for Windows (May 2026 or later) creates native IPP print queues using Microsoft's built-in IPP class driver. Printer-specific rendering takes place in the cloud, allowing ezeep-managed printers to be used without disabling WPP.

This approach can also help organizations continue using older, non-Mopria printers, provided those devices are supported and connected through a suitable ezeep configuration.

For VDI environments, the practical advantages include:

  • No manufacturer-specific rendering drivers required on session hosts for supported ezeep-managed printers.
  • Reduced driver maintenance and potential compatibility conflicts in golden images.
  • Printing without relying on traditional client printer redirection.
  • Centralized printer management and assignment.

Administrators should still verify application compatibility and multi-session behavior before enabling WPP across production hosts.

The Hidden VDI Printing Problem: Fixed Printer Names

Before changing printer configurations, there is one question worth asking: which applications in your environment depend on a specific printer name?

Line-of-business applications, especially ERPs, are often configured to print to named queues. In pooled multi-session environments, redirected printer names may include session-specific suffixes, potentially preventing applications from finding the expected printer.

The ezeep Print App for Services supports automated printing from Windows applications, including ERP systems. It can be used as part of a printing configuration that avoids conventional session-specific printer redirection. Applications requiring fixed queue names should be tested against the chosen configuration.

Before migrating, identify which applications depend on fixed printer names and how those dependencies will be maintained. If the answer is "several applications, and nobody is sure which," that is itself an important finding that should influence the migration sequence.

Preparing Your VDI Environment for Windows Protected Print

Windows Protected Print doesn't mean every existing VDI printing configuration needs to be replaced. But Microsoft's move away from legacy third-party print drivers makes it important to understand which components your environment depends on.

For organizations maintaining complex golden images and printer configurations, cloud rendering offers a way to reduce those dependencies while preparing for a more secure Windows printing architecture.

chrome-extension-print
Want to see how ezeep simplifies printing?
Try ezeep today.
Start Free Trial

 

Frequently Asked Questions

Does Windows Protected Print work in Azure Virtual Desktop?

Windows Protected Print is available on supported Windows versions, including Windows 11 24H2 and Windows Server 2025. However, compatibility with a particular AVD printing configuration depends on the components involved. Administrators should test printer redirection, printer availability, and application workflows before enabling WPP on production session hosts.

Does WPP break printer redirection in Citrix and RDS?

Not necessarily. Some redirection methods, such as Microsoft's Remote Desktop Easy Print, do not require manufacturer-specific drivers on the session host. The impact of WPP depends on the redirection mechanism, Windows version, and printing components involved.

Can I continue using older or non-Mopria printers with WPP?

Potentially, yes. WPP restricts conventional Windows printing to its supported IPP-based architecture. However, cloud printing solutions such as ezeep may allow organizations to continue using older or non-Mopria printers by handling printer-specific rendering outside the WPP-enabled Windows system, provided the devices and configurations are supported.

Does ezeep work with Windows Protected Print enabled?

According to ezeep's documentation, the ezeep Print App for Windows (May 2026 or later) supports WPP by creating native IPP print queues using Microsoft's built-in IPP class driver. Printer-specific rendering takes place in the cloud, eliminating the need for manufacturer-specific rendering drivers on the Windows device. Compatibility with individual VDI configurations should still be verified.

Back to top