Windows Protected Print: What AVD, Citrix & RDS Admins Need to Know
By Brock McKenna on October 8, 2026

Print drivers are a real attack surface. According to Microsoft, print-related bugs accounted for 9% of cases reported to the Microsoft Security Response Center over a three-year period, and Microsoft's analysis found that Windows Protected Print mode (WPP) could have mitigated more than half of the print-related vulnerabilities examined. Moving toward a more secure, driver-independent printing architecture makes sense.
But what does that mean for organizations running Azure Virtual Desktop (AVD), Citrix, or Remote Desktop Services (RDS)?
Virtual desktop environments have long depended on different approaches to connecting remote sessions with physical printers. Some require manufacturer-specific drivers on session hosts, while others rely on printer redirection, universal printing technologies, or cloud services. WPP doesn't affect all these approaches equally, which makes understanding the dependencies important before changing anything.
Why is Windows Protected Print a challenge for virtual desktops?
The fundamental challenge with VDI printing is that applications run inside remote sessions while printers are often located elsewhere. Traditional printing architectures address this in different ways:
Printer redirection makes locally connected printers available inside the session. Microsoft's Remote Desktop Easy Print, for example, avoids the need for manufacturer-specific drivers on the session host. However, redirected printer names may include session-specific suffixes, which can cause problems for applications expecting fixed printer names.
Universal printing technologies, such as Citrix Universal Print Driver and Windows Easy Print, reduce the need for individual manufacturer drivers on session hosts. Depending on the configuration, they can introduce other considerations, including bandwidth usage and compatibility with specialized printer functionality.
Direct network printing allows session hosts to send jobs to network printers. This can work well, but may require manufacturer drivers and reliable connectivity between session hosts and printers.

For a closer look at these architectures, see How Printing Works in AVD, Citrix and RDS - And Why It Often Breaks.
The important distinction is that not every VDI printing method requires third-party drivers on the session host. Its compatibility with WPP depends on the components involved.
What does WPP change for a session host?
Windows Protected Print mode, introduced with Windows 11 24H2 and supported on Windows Server 2025, restricts printing to Microsoft's built-in IPP-based architecture. Third-party print drivers cannot be used while WPP is enabled.
For VDI administrators, this raises three considerations.
Existing drivers in golden images. If an AVD, Citrix, or RDS image includes manufacturer-specific print drivers, WPP prevents those drivers from being used. Enabling WPP also removes installed printers that depend on third-party drivers.
Printer redirection. Not all redirected printers require manufacturer drivers on the session host. Nevertheless, administrators should verify whether their specific redirection configuration and printing components work with WPP enabled.
Older and specialized printers. Devices that depend on legacy manufacturer drivers may no longer be available through conventional Windows printer installations. Label printers, older MFPs, and other specialized hardware deserve particular attention. Alternative printing architectures may allow some of these devices to remain usable.
WPP is not mandatory today, and Microsoft has not announced when it will become the default. However, its broader transition away from legacy print drivers is already underway:
- January 15, 2026: Microsoft stopped routinely accepting new third-party printer drivers for publication through Windows Update on Windows 11 and Windows Server 2025 and later, with exceptions considered individually.
- July 1, 2026: Windows began prioritizing the built-in IPP class driver when selecting printer drivers.
- July 1, 2027: Microsoft will stop accepting non-security updates for third-party printer drivers through Windows Update.
Existing third-party printer drivers will remain available for installation through Windows Update, and manufacturers can continue providing drivers through separate installation packages. Microsoft's roadmap does not mean that legacy printer drivers will suddenly stop working in July 2027.
Nevertheless, organizations maintaining VDI golden images should consider how long they want to depend on manufacturer-specific drivers. Microsoft's official roadmap makes the direction clear.
Before Enabling WPP: A VDI Compatibility Checklist
Before enabling WPP across an AVD, Citrix, or RDS environment, IT teams should establish where their printing dependencies actually exist.
Start with the drivers. Are manufacturer-specific drivers installed in golden images, added dynamically to session hosts, or used only on endpoint devices? WPP affects the Windows system on which it is enabled, so the distinction matters.
Next, identify which printing methods and applications depend on those drivers. Pay particular attention to specialized printers, manufacturer-specific functionality, and applications configured to use fixed printer names.
Finally, test WPP on a representative session host before changing production images. Verify printer availability, application compatibility, and essential workflows. Microsoft confirms that enabling WPP removes printers using third-party drivers, and disabling it afterward does not automatically restore those printer configurations.
The objective isn't necessarily to replace your printing infrastructure immediately. It's to identify dependencies before they become compatibility problems.
Cloud Printing: Moving Printer Drivers Out of the VDI Session

One way to reduce the impact of WPP is to move printer-specific rendering outside the virtual desktop.
With ezeep, print jobs are rendered in the cloud rather than through manufacturer-specific rendering drivers installed on session hosts. The processed jobs are delivered to printers through the ezeep Hub or an appropriate software Connector, depending on the deployment.
This reduces the need to maintain manufacturer-specific drivers in golden images and avoids relying on conventional RDP or ICA printer redirection for ezeep-managed printing.
ezeep also supports Windows Protected Print mode. According to the official ezeep documentation, the ezeep Print App for Windows (May 2026 or later) creates native IPP print queues using Microsoft's built-in IPP class driver. Printer-specific rendering takes place in the cloud, allowing ezeep-managed printers to be used without disabling WPP.
This approach can also help organizations continue using older, non-Mopria printers, provided those devices are supported and connected through a suitable ezeep configuration.
For VDI environments, the practical advantages include:
- No manufacturer-specific rendering drivers required on session hosts for supported ezeep-managed printers.
- Reduced driver maintenance and potential compatibility conflicts in golden images.
- Printing without relying on traditional client printer redirection.
- Centralized printer management and assignment.
Administrators should still verify application compatibility and multi-session behavior before enabling WPP across production hosts.
The Hidden VDI Printing Problem: Fixed Printer Names
Before changing printer configurations, there is one question worth asking: which applications in your environment depend on a specific printer name?
Line-of-business applications, especially ERPs, are often configured to print to named queues. In pooled multi-session environments, redirected printer names may include session-specific suffixes, potentially preventing applications from finding the expected printer.
The ezeep Print App for Services supports automated printing from Windows applications, including ERP systems. It can be used as part of a printing configuration that avoids conventional session-specific printer redirection. Applications requiring fixed queue names should be tested against the chosen configuration.
Before migrating, identify which applications depend on fixed printer names and how those dependencies will be maintained. If the answer is "several applications, and nobody is sure which," that is itself an important finding that should influence the migration sequence.
Preparing Your VDI Environment for Windows Protected Print
Windows Protected Print doesn't mean every existing VDI printing configuration needs to be replaced. But Microsoft's move away from legacy third-party print drivers makes it important to understand which components your environment depends on.
For organizations maintaining complex golden images and printer configurations, cloud rendering offers a way to reduce those dependencies while preparing for a more secure Windows printing architecture.
Frequently Asked Questions
Does Windows Protected Print work in Azure Virtual Desktop?
Windows Protected Print is available on supported Windows versions, including Windows 11 24H2 and Windows Server 2025. However, compatibility with a particular AVD printing configuration depends on the components involved. Administrators should test printer redirection, printer availability, and application workflows before enabling WPP on production session hosts.
Does WPP break printer redirection in Citrix and RDS?
Not necessarily. Some redirection methods, such as Microsoft's Remote Desktop Easy Print, do not require manufacturer-specific drivers on the session host. The impact of WPP depends on the redirection mechanism, Windows version, and printing components involved.
Can I continue using older or non-Mopria printers with WPP?
Potentially, yes. WPP restricts conventional Windows printing to its supported IPP-based architecture. However, cloud printing solutions such as ezeep may allow organizations to continue using older or non-Mopria printers by handling printer-specific rendering outside the WPP-enabled Windows system, provided the devices and configurations are supported.
Does ezeep work with Windows Protected Print enabled?
According to ezeep's documentation, the ezeep Print App for Windows (May 2026 or later) supports WPP by creating native IPP print queues using Microsoft's built-in IPP class driver. Printer-specific rendering takes place in the cloud, eliminating the need for manufacturer-specific rendering drivers on the Windows device. Compatibility with individual VDI configurations should still be verified.
- October 2026 (2)
- September 2026 (14)
- August 2026 (11)
- July 2026 (9)
- June 2026 (12)
- May 2026 (3)
- April 2026 (3)
- March 2026 (3)
- February 2026 (2)
- January 2026 (2)
- December 2025 (1)
- November 2025 (4)
- October 2025 (4)
- September 2025 (1)
- August 2025 (4)
- July 2025 (1)
- June 2025 (3)
- May 2025 (3)
- April 2025 (5)
- March 2025 (6)
- February 2025 (5)
- January 2025 (3)
- December 2024 (5)
- November 2024 (5)
- October 2024 (6)
- September 2024 (2)
- August 2024 (2)
- July 2024 (4)
- May 2024 (4)
- March 2024 (1)
- February 2024 (3)
- January 2024 (1)
- December 2023 (1)
- November 2023 (2)
- October 2023 (3)
- September 2023 (2)
- August 2023 (1)
- July 2023 (2)
- June 2023 (2)
- May 2023 (1)
- April 2023 (3)
- March 2023 (5)
- February 2023 (4)
- January 2023 (2)
- December 2022 (3)
- November 2022 (1)
- October 2022 (5)
- September 2022 (4)
- August 2022 (1)
- July 2022 (3)
- June 2022 (4)
- May 2022 (2)
- April 2022 (4)
- March 2022 (4)
- February 2022 (2)
- January 2022 (1)
- October 2021 (1)
- July 2021 (5)
- June 2021 (4)
- May 2021 (3)
- April 2021 (1)
- March 2021 (4)
- February 2021 (1)
- December 2020 (1)
- November 2020 (1)
- October 2020 (1)
- September 2020 (1)
- July 2020 (1)
- June 2020 (1)
- April 2020 (4)
- March 2020 (3)
- February 2020 (3)
- January 2020 (1)
- August 2019 (2)
- May 2019 (1)
- January 2018 (1)
You May Also Like
These Related Stories

The Latest ezeep Print App for Windows: Cloud Printing With Windows Protected Print (WPP) Mode Enabled

AVD Printer Redirection Not Working? Fixes and Solutions
