ITM is an open framework - Submit your contributions now.

Insider Threat Matrix™

  • ID: DT139
  • Created: 12th August 2025
  • Updated: 12th August 2025
  • Platform: Windows
  • Contributor: The ITM Team

Microsoft Defender, Printed File

This detection monitors when a subject prints a file from a device protected by Microsoft Defender for Endpoint. By generating an alert on file print events, investigators gain early visibility into potential data loss vectors and can correlate the activity with the originating device, the initiating account, and the context of the printed content.

 

This detection is dependent on the respective device running Microsoft Defender for Endpoint.

 

In the Microsoft Defender portal at https://security.microsoft.com, navigate to Email & collaboration > Policies & rules > Alert policy. To go directly to the Alert policy page, use https://security.microsoft.com/alertpoliciesv2.

 

Click + New Alert Policy in the top-left corner. Assign a clear name to the alert policy and select an appropriate Severity and Category. On the next page, under Activity is, search for and select “Printed file”. Configure the remaining settings as required.

 

When a device that has Microsoft Defender for Endpoint deployed prints a file, an alert will be generated.

Sections

ID Name Description
IF006Unauthorized Printing of Documents

A subject exfiltrates information by printing it to paper or other physical medium.

PR013Testing Ability to Print

A subject attempts to print a document from a system to identify if this capability is permitted, restricted, or not possible.

ME014Printing

A subject has the ability to print documents and other files.

IF006.002Printing of Documents with Work Printer

A subject prints a document using a printer owned by the organization, with the intent to physically exfiltrate the information.

IF006.001Printing of Documents with Personal Printer

A subject prints a document using a printer they own, physically exfiltrating the information.

ME014.001External Printing

A subject has the ability to print documents and other files with a printer outside of the organisation’s control.