AD-PRINT-01 - Printer total count should be retrievable
Overviewβ
Published printers in Active Directory provide visibility into your organization's printing infrastructure. While printers themselves may not seem like a security concern, they present several security considerations:
- Information disclosure: Printer names and locations may reveal organizational structure
- Access control: Published printers may be accessible to unintended users
- Driver vulnerabilities: Printer drivers can be a vector for attacks
- Document security: Print jobs may contain sensitive information
- Network exposure: Printers may be accessible from unauthorized network segments
Understanding your printer publishing configuration helps:
- Audit exposure: Identify what printer information is publicly available
- Access review: Ensure printers are only accessible to appropriate users
- Documentation: Maintain accurate inventory of printing resources
- Compliance: Some regulations require tracking of printing infrastructure
Security Recommendationβ
Secure your printing infrastructure:
- Minimize publishing: Only publish printers that need to be discoverable
- Location data: Review printer location information for sensitive details
- Access controls: Restrict printer access using security groups
- Secure printing: Implement pull printing or secure release solutions
- Regular audits: Periodically review published printers for unauthorized additions
How the Test Worksβ
This test queries Active Directory for printQueue objects to count published printers and provide details about printer publishing in the domain.
Related Testsβ
Test-MtAdOuEmptyCount- Identify empty OUs that may contain legacy printer objectsTest-MtAdGroupDistributionCount- Review groups that may control printer access
Test Metadataβ
| Field | Value |
|---|---|
| Test ID | AD-PRINT-01 |
| Severity | Info |
| Suite | Active Directory |
| Category | AD.Printer |
| PowerShell test | Test-MtAdPrinterTotalCount |
| Tags | AD, AD-PRINT-01, AD.Printer |
Sourceβ
- Pester test:
tests/ad/printer/Test-MtAdPrinterTotalCount.Tests.ps1 - PowerShell source:
powershell/public/ad/printer/Test-MtAdPrinterTotalCount.ps1

