Skip to content
arrow_back
search
ISM-1828 policy ASD Information Security Manual (ISM)

Disable Print Spooler on AD DS Domain Controllers

Ensure the Print Spooler is turned off on AD DS domain controllers for security.

record_voice_over

Plain language

Disabling the Print Spooler service on your Microsoft Active Directory Domain Services (AD DS) domain controllers is like locking a door that doesn’t need to be opened. It prevents unnecessary risk because hackers can exploit this service to access sensitive data or disrupt your network. By turning it off, you’re simply reducing an avenue for cyber attacks on your important systems.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

Feb 2023

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

The Print Spooler service is disabled on Microsoft AD DS domain controllers.
policy ASD Information Security Manual (ISM) ISM-1828
priority_high

Why it matters

If Print Spooler runs on AD DS domain controllers, spooler flaws (e.g. PrintNightmare) can enable domain-level privilege escalation or credential theft.

settings

Operational notes

Use GPO to disable Print Spooler on all domain controllers; regularly audit service state after patches and ensure no admin action re-enables it.

Mapping detail

Mapping

Direction

Controls