Package Point and print - Approved servers
Verified with Windows 11 25H2 — updated on July 30, 2026
Supported on: Windows Server 2008 and Windows Vista
Path in the GPO console
User Configuration\Administrative Templates\Control Panel\Printers Description
Restricts package point and print to approved servers. This policy setting restricts package point and print connections to approved servers. This setting only applies to Package Point and Print connections, and is completely independent from the "Point and Print Restrictions" policy that governs the behavior of non-package point and print connections. Windows Vista and later clients will attempt to make a non-package point and print connection anytime a package point and print connection fails, including attempts that are blocked by this policy. Administrators may need to set both policies to block all print connections to a specific print server. If this setting is enabled, users will only be able to package point and print to print servers approved by the network administrator. When using package point and print, client computers will check the driver signature of all drivers that are downloaded from print servers. If this setting is disabled, or not configured, package point and print will not be restricted to specific print servers.
Registry
Software\Policies\Microsoft\Windows NT\Printers\PackagePointAndPrint Value name: PackagePointAndPrintServerList
Enabled: PackagePointAndPrintServerList = 1
Disabled: PackagePointAndPrintServerList = 0
MDM / Intune (CSP)
./User/Vendor/MSFT/Policy/Config/ADMX_Printing/PackagePointAndPrintServerList Microsoft Learn documentation Mapping data: Microsoft Learn (CC BY 4.0)
Export Builder
BETAConfigure the state, scope and options, then generate .reg, PowerShell, Intune and SCCM outputs — or add the setting to a multi-setting collection.
These exports write the registry — this is not a managed GPO. ⓘ
.reg file
Windows Registry Editor Version 5.00
; Exported from gporais.com
; Policy: Package Point and print - Approved servers
; State: Enabled
; Supported on: Windows Server 2008 and Windows Vista
[HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows NT\Printers\PackagePointAndPrint]
"PackagePointAndPrintServerList"=dword:00000001
[HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows NT\Printers\PackagePointAndPrint\ListofServers]
; List values: enter one value per line in the builder UI. More formats (PowerShell, Intune, SCCM)
PowerShell
# Exported from gporais.com
# Policy: Package Point and print - Approved servers
# State: Enabled
# Supported on: Windows Server 2008 and Windows Vista
# Warning: In SYSTEM context (the Intune default), HKCU targets the SYSTEM profile. Run this script using the logged-on credentials.
$path = 'HKCU:\Software\Policies\Microsoft\Windows NT\Printers\PackagePointAndPrint'
New-Item -Path $path -Force | Out-Null
Set-ItemProperty -Path $path -Name 'PackagePointAndPrintServerList' -Value 1 -Type DWord
$path = 'HKCU:\Software\Policies\Microsoft\Windows NT\Printers\PackagePointAndPrint\ListofServers'
New-Item -Path $path -Force | Out-Null
# List values: enter one value per line in the builder UI. Intune XML
OMA-URI: ./User/Vendor/MSFT/Policy/Config/ADMX_Printing/PackagePointAndPrintServerList
Data type: String
Value:
<enabled/>
<!-- PackagePointAndPrintServerList_Edit: enter one value per line before copying this XML payload. --> Intune Remediation
# === Detection script ===
# Exported from gporais.com
# Policy: Package Point and print - Approved servers
# State: Enabled
# Supported on: Windows Server 2008 and Windows Vista
# Warning: In SYSTEM context (the Intune default), HKCU targets the SYSTEM profile. Run this script using the logged-on credentials.
function Test-RegistryValue {
param(
[Parameter(Mandatory = $true)][string]$Path,
[Parameter(Mandatory = $true)][string]$Name,
[object]$Expected,
[ValidateSet('String', 'DWord', 'MultiString')][string]$Kind = 'String',
[switch]$Absent
)
try {
$item = Get-ItemProperty -LiteralPath $Path -Name $Name -ErrorAction Stop
} catch {
return $Absent.IsPresent
}
if ($Absent.IsPresent) { return $false }
$actual = $item.$Name
if ($Kind -eq 'DWord') { return ([int64]$actual) -eq ([int64]$Expected) }
if ($Kind -eq 'MultiString') {
$actualValues = @($actual)
$expectedValues = @($Expected)
if ($actualValues.Count -ne $expectedValues.Count) { return $false }
for ($i = 0; $i -lt $expectedValues.Count; $i++) {
if ([string]$actualValues[$i] -ne [string]$expectedValues[$i]) { return $false }
}
return $true
}
return [string]$actual -eq [string]$Expected
}
# HKCU:\Software\Policies\Microsoft\Windows NT\Printers\PackagePointAndPrint\ListofServers: List values: enter one value per line in the builder UI.
$checks = @(
(Test-RegistryValue -Path 'HKCU:\Software\Policies\Microsoft\Windows NT\Printers\PackagePointAndPrint' -Name 'PackagePointAndPrintServerList' -Expected 1 -Kind DWord)
)
if ($checks -notcontains $false) {
Write-Output 'Compliant'
exit 0
}
Write-Output 'Non-compliant'
exit 1
# === Remediation script ===
# Exported from gporais.com
# Policy: Package Point and print - Approved servers
# State: Enabled
# Supported on: Windows Server 2008 and Windows Vista
# Warning: In SYSTEM context (the Intune default), HKCU targets the SYSTEM profile. Run this script using the logged-on credentials.
$path = 'HKCU:\Software\Policies\Microsoft\Windows NT\Printers\PackagePointAndPrint'
New-Item -Path $path -Force | Out-Null
Set-ItemProperty -Path $path -Name 'PackagePointAndPrintServerList' -Value 1 -Type DWord
$path = 'HKCU:\Software\Policies\Microsoft\Windows NT\Printers\PackagePointAndPrint\ListofServers'
New-Item -Path $path -Force | Out-Null
# List values: enter one value per line in the builder UI. SCCM scripts
# Exported from gporais.com
# Policy: Package Point and print - Approved servers
# State: Enabled
# Supported on: Windows Server 2008 and Windows Vista
# SCCM Configuration Item guidance:
# Create a Configuration Item of type "Setting: Script".
# Discovery script: use the Detection script below.
# Remediation script: use the Remediation script below.
# Compliance rule: the Discovery script output equals 'Compliant'.
# === Detection script ===
# Exported from gporais.com
# Policy: Package Point and print - Approved servers
# State: Enabled
# Supported on: Windows Server 2008 and Windows Vista
# Warning: In SYSTEM context (the Intune default), HKCU targets the SYSTEM profile. Run this script using the logged-on credentials.
function Test-RegistryValue {
param(
[Parameter(Mandatory = $true)][string]$Path,
[Parameter(Mandatory = $true)][string]$Name,
[object]$Expected,
[ValidateSet('String', 'DWord', 'MultiString')][string]$Kind = 'String',
[switch]$Absent
)
try {
$item = Get-ItemProperty -LiteralPath $Path -Name $Name -ErrorAction Stop
} catch {
return $Absent.IsPresent
}
if ($Absent.IsPresent) { return $false }
$actual = $item.$Name
if ($Kind -eq 'DWord') { return ([int64]$actual) -eq ([int64]$Expected) }
if ($Kind -eq 'MultiString') {
$actualValues = @($actual)
$expectedValues = @($Expected)
if ($actualValues.Count -ne $expectedValues.Count) { return $false }
for ($i = 0; $i -lt $expectedValues.Count; $i++) {
if ([string]$actualValues[$i] -ne [string]$expectedValues[$i]) { return $false }
}
return $true
}
return [string]$actual -eq [string]$Expected
}
# HKCU:\Software\Policies\Microsoft\Windows NT\Printers\PackagePointAndPrint\ListofServers: List values: enter one value per line in the builder UI.
$checks = @(
(Test-RegistryValue -Path 'HKCU:\Software\Policies\Microsoft\Windows NT\Printers\PackagePointAndPrint' -Name 'PackagePointAndPrintServerList' -Expected 1 -Kind DWord)
)
if ($checks -notcontains $false) {
Write-Output 'Compliant'
exit 0
}
Write-Output 'Non-compliant'
exit 1
# === Remediation script ===
# Exported from gporais.com
# Policy: Package Point and print - Approved servers
# State: Enabled
# Supported on: Windows Server 2008 and Windows Vista
# Warning: In SYSTEM context (the Intune default), HKCU targets the SYSTEM profile. Run this script using the logged-on credentials.
$path = 'HKCU:\Software\Policies\Microsoft\Windows NT\Printers\PackagePointAndPrint'
New-Item -Path $path -Force | Out-Null
Set-ItemProperty -Path $path -Name 'PackagePointAndPrintServerList' -Value 1 -Type DWord
$path = 'HKCU:\Software\Policies\Microsoft\Windows NT\Printers\PackagePointAndPrint\ListofServers'
New-Item -Path $path -Force | Out-Null
# List values: enter one value per line in the builder UI. Building a multi-setting collection? Add this setting and generate combined .reg / PowerShell / GPO scripts.