Skip to main content

Windows Protected Print, IPP, and Driverless Printing

Vasion Team
August 26, 2026
5 mins
Microsoft is rebuilding how Windows prints for security reasons, and the changes are landing whether IT teams are ready or not. Three terms keep showing up in the same breath: Windows Protected Print, IPP, and driverless printing. Proper planning requires understanding each one.

How the Three Terms Relate

Internet Printing Protocol (IPP) is the open standard that lets a computer send a print job straight to a printer without a manufacturer-specific driver translating in between. Driverless printing is what that standard makes possible: a printer that Windows can discover, configure, and print to using its own built-in class driver. Windows Protected Print Mode (WPP) is Microsoft's security policy that requires a device to use only that driverless, IPP-based path.
IPP is the protocol, driverless printing is the outcome, and WPP is the enforcement mechanism. Think of it as a ladder: IPP makes driverless printing technically possible, driverless printing removes the third-party driver from the equation, and WPP locks a Windows device into using that removal permanently.
Incidents like PrintNightmare showed how a flaw in the print spooler's driver-installation process could let an attacker push a malicious driver and gain system-level access fleet-wide. Third-party drivers also complicate Windows on ARM, where manufacturer drivers often don't exist. Standardizing on IPP solves both problems at once.

What Is Windows Protected Print?

Windows Protected Print blocks third-party printer drivers outright, runs spooler tasks with reduced privileges, isolates rendering per user, and applies additional binary-level mitigations. The goal is to remove the driver as an attack surface entirely, not just patch it more often.
Legacy Windows printing installs a driver package from the manufacturer for every printer model, each with its own code, its own update cycle, and its own vulnerability history. WPP replaces all of that with Windows' built-in IPP class driver, plus optional Print Support Apps for manufacturer-specific features like finishing options.
Existing printer installs that rely on a manufacturer driver are removed outright when WPP is enabled, even for otherwise Mopria-certified devices—and if a printer doesn't actually meet WPP's IPP requirements, it can't be reinstalled at all while the policy is active. Compatible printers keep working with no driver management required. IT administrators turn on Windows Protected Print through Group Policy or Intune, and Microsoft has said it intends to make the policy the default at a future date.

How IPP Enables Driverless Printing

Windows ships with a native IPP class driver, so any printer that speaks IPP can be added without downloading anything from the manufacturer. This is the same architecture that already powers AirPrint and Mopria printing on other platforms.
A Windows PC discovers IPP printers on the network, queries the device for its supported capabilities, and submits jobs in a standardized format the printer already understands. No installer, no reboot, no driver package to keep current.
Because the printer describes its own capabilities to Windows in real time, there's no manufacturer code running on the endpoint at all. Fewer moving parts means fewer things to patch, fewer compatibility conflicts between Windows updates and old driver versions, and one code path IT has to trust instead of dozens.

Printer Drivers vs. Driverless Printing

For three decades, every new printer meant installing, testing, and maintaining printer drivers, often per operating system version and architecture. Multiply that across a fleet with a dozen printer models and IT ends up managing hundreds of driver combinations.
With driverless printing, printers become closer to plug-and-play. There's less for IT to package, test, and roll back, and printers built on different chipsets, including ARM, work the same way.
The trade-off is that manufacturer-specific features, such as advanced finishing, custom color profiles, or accounting codes, aren't guaranteed under a pure IPP path unless the manufacturer has published a Print Support App. Some Mopria-certified devices also perform differently over IPP than they do with a full vendor driver, so testing matters more than the certification badge alone.

Windows Ready Print vs. Windows Protected Print

As of July 2026, new printer installations on Windows default to the IPP inbox driver through what Microsoft calls Windows Ready Print. Legacy drivers are still available as a fallback for devices that don't support IPP.
Windows Protected Print Mode is the strict version of the same idea. There's no fallback: only IPP-compatible, generally Mopria-certified, printers can be installed at all, and third-party drivers are blocked entirely rather than simply deprioritized.
Windows Ready Print is the everyday default most organizations are already living with. WPP is an explicit security policy IT chooses to enable now, for devices that need the stronger guarantee, ahead of Microsoft eventually making it the default.

Printer Compatibility and Enterprise Impact

Mopria certification is a strong signal of IPP compatibility, but it isn't a guarantee of WPP readiness or equal security. A device can be certified and still lose functionality, or perform more slowly, once its third-party driver is no longer an option.
Aging printer fleets, models without a published Print Support App, and workflows built around driver-level features like custom finishing or secure release are the most common places Windows Protected Print breaks something IT didn't expect.
Inventory which printers in the fleet are IPP-capable, pilot Windows Protected Print against a representative sample before any wider rollout, and confirm how essential print features hold up without a traditional driver. This is where PrinterLogic's architecture already fits: it installs printers using Windows' native IPP class driver instead of a manufacturer package, delivering the security benefits of a driverless model today, across Windows, macOS, and Linux, without waiting on Microsoft's default timeline.

FAQ: Windows Protected Print and IPP

Does WPP require IPP printers?

Yes. When Windows Protected Print Mode is enabled, only printers that support IPP, typically Mopria-certified devices, can be installed and used. Printers that depend on a third-party driver are removed.

Can legacy drivers still be used?

Not with WPP enabled. Legacy v3 and v4 drivers are blocked entirely. Outside of WPP, under the standard Windows Ready Print default, legacy drivers remain available as a fallback for printers that don't support IPP.

What is the difference between WPP and driverless printing?

Driverless printing is the general capability of printing without a manufacturer driver, made possible by IPP. WPP is a specific Windows security policy that forces every printer on a device to use that driverless path, with no exceptions.
Windows printing is moving toward a driverless, IPP-first future whether or not Windows Protected Print Mode is switched on in a given environment yet. The organizations in the best position understand the difference between the protocol, the outcome, and the policy, and have tested their printer fleets against all three.
Windows Protected Print, IPP, and Driverless Printing | Vasion