Skip to content

Est. 2011ยทMicrosoft Partner 7033487ยทDelivery under 3 minยทSupport 7 days a week

Your vault is empty.

License Error 0x00000BC6

Error 0x00000BC6: Windows has blocked this printer driver as harmful

12 min read Updated October 5, 2026 Networking, Sharing & Printing

Recommended fix

Windows 11 Pro Retail license

Original price was: 25,00 €.Current price is: 14,99 €.

Fix It Now

Fix it now

Microsoft publishes 0x00000BC6 as ERROR_PRINTER_DRIVER_BLOCKED, the printer driver is known to harm the system. It is a decision about the driver, not about your rights: Windows has been told this package is harmful and will not install it. The fix is a different driver, and elevating the install will not change the answer.

Run these on the machine that is refusing the driver, in an elevated PowerShell session

Get-PrinterDriver | Select-Object Name,MajorVersion,Manufacturer
pnputil /enum-drivers
  1. Identify the exact driver the queue is offering, from the print server if it is a shared queue: Get-Printer -Name "QueueName" | Select-Object DriverName.
  2. Get a current package for that model from the manufacturer’s own download page, not from a file share copy that has been sitting there for years, and install it on the server.
  3. Point the queue at it: Set-Printer -Name "QueueName" -DriverName "New driver name", then remove the old driver so clients cannot pick it up again.
  4. Where the manufacturer has nothing current, move the queue to the in-box class driver, or connect the client to the device over IPP and leave the print server out of it.
  5. Read the client’s own account of the refusal in Event Viewer, under Applications and Services Logs, Microsoft, Windows, PrintService, Admin, written at the moment you tried.

0x00000BC5 is the same list one step down: ERROR_PRINTER_DRIVER_WARNED, the printer driver is known to be unreliable. If you see that one, the install may succeed and the driver is still the thing to replace.

If a standard user can now add the queue and print, you are done. If the refusal persists or you are seeing one of the companion codes instead, the next section separates the driver decision from the policy one.

Why it happens

Two different things stop a printer driver installing, and they produce different codes. This one is a judgement about the package. Windows keeps a view of which printer drivers are known to harm the system and which are known to be unreliable, and 0x00000BC6 is the first of those – published as ERROR_PRINTER_DRIVER_BLOCKED, the printer driver is known to harm the system. Its neighbour 0x00000BC5 is ERROR_PRINTER_DRIVER_WARNED, the same list one step down.

The other thing is Point and Print, and it is about rights rather than about the package. Point and Print lets a client connect to a shared queue and pull the driver from the print server automatically. It is also how a compromised or impersonated print server could put driver code on every workstation that connected to it, so it has been progressively restricted. Those restrictions are real and worth setting, but they are not what this code reports, and a reader who spends the afternoon in Group Policy will come back to a driver that is still blocked.

The way to tell them apart takes a minute. Try the same connection from an elevated session. A driver Windows has blocked is refused for an administrator too, because the decision is about the package. A Point and Print restriction is not: it succeeds when you have the rights and fails when you do not. If it fails both ways, stop looking at policy.

The companions describe neighbouring failures. 0x0000000D is ERROR_INVALID_DATA, which is what a damaged or incomplete package looks like to the installer. 0x000003E3 is ERROR_OPERATION_ABORTED, seen when the installing process or the spooler is torn down mid-install. 0x00000BC8 is ERROR_CORE_DRIVER_PACKAGE_NOT_FOUND: the package depends on a core package this machine does not have.

The driver package is one Windows will not install

You have this one if The install is refused from an elevated session as well as a standard one, on more than one machine.

  1. Replace the driver rather than the rights. Download a current package for the model from the manufacturer.
  2. Install it on the print server and repoint the queue with Set-Printer -DriverName, then remove the old driver from the server.
  3. Where nothing current exists for the model, move the queue to the in-box class driver.

Removing the old driver from the server matters. Leaving it there means the next client to connect can still be offered it.

A dependent core package is missing on the client

You have this one if 0x00000BC8 accompanies the failure, and the driver is one of the families that layers a model-specific package on a shared core package.

  1. Install the manufacturer’s core or base package on the client first, then reconnect to the shared queue.
  2. Where the manufacturer ships a single combined installer, run that locally rather than relying on Point and Print for the first install.
  3. Confirm it landed with pnputil /enum-drivers and look for the manufacturer’s INF in the list.

The package is damaged or is for the wrong architecture

You have this one if 0x0000000D appears with the failure, or the client is on a different processor architecture from the one the server publishes.

  1. On the server, read which architectures the queue publishes in Print Server Properties, Drivers tab, environment column.
  2. Add the missing architecture, or move that client to a driver that exists for its platform.
  3. If the package is damaged, remove it and reinstall from a freshly downloaded package rather than a copy on a file share.

The install is being torn down before it finishes

You have this one if 0x000003E3, often on a machine where the spooler is restarting or an endpoint product is intervening.

  1. Confirm the spooler stayed up through the attempt: Get-Service Spooler immediately afterwards.
  2. Check the PrintService Admin log for what was written at the same moment.
  3. Retry with the driver pre-staged locally, so the install is not happening across a connection that can be interrupted.

Point and Print restrictions are stopping a standard user

You have this one if The same queue installs from an elevated session on the same machine and fails for the user.

  1. Add the trusted print server to Package Point and print – Approved servers, under Computer Configuration, Policies, Administrative Templates, Control Panel, Printers.
  2. Enable Only use Package Point and print in the same folder, so clients accept package-aware drivers from approved servers only.
  3. Or push the connection from the server side with Group Policy Preferences or your management tool, so the install runs with the rights it needs.
  4. Run gpupdate /force and retest from a standard user account.

This is a different problem from 0x00000BC6 and belongs here only so you can rule it out. If the elevated attempt failed too, this section is not yours.

Full reference

The five numbers, and what Microsoft publishes

Code Published meaning
0x00000BC6 ERROR_PRINTER_DRIVER_BLOCKED: the printer driver is known to harm the system
0x0000000D ERROR_INVALID_DATA: the data is invalid
0x000003E3 ERROR_OPERATION_ABORTED: the I/O operation has been aborted because of either a thread exit or an application request
Event ID 808 Not published. Where it appears in the PrintService Admin log it names a file, and the file is the useful part
0x00000BC8 ERROR_CORE_DRIVER_PACKAGE_NOT_FOUND: unable to find a core driver package that is required by the printer driver package

Where an event in that log names a specific DLL rather than the driver as a whole, the blocked item is a component the driver loads rather than the driver package itself. Reinstall that component from a current package, install the driver without its optional modules, or move the queue to the in-box class driver, which has no such modules to load.

The printer policies worth setting anyway

These live under Computer Configuration, then Policies, Administrative Templates, Control Panel, Printers. They are not the fix for a blocked driver, and they are what keeps you from meeting the next one.

Policy What Microsoft says it does
Point and Print Restrictions Controls the client Point and Print behaviour, including the security prompts. Applies only to non-Print-Administrator clients and to computers that are members of a domain
Package Point and print – Approved servers Restricts package point and print connections to approved servers. Independent of Point and Print Restrictions, which governs non-package connections
Only use Package Point and print Restricts clients to package point and print only, so users can point and print only to printers using package-aware drivers, and the client checks the driver signature of everything downloaded from print servers

The direction Windows printing is moving in

Windows protected print mode is the end state Microsoft is building towards. Its own description is that it prevents the installation of third-party drivers and removes the need for driver management, enforcing Windows Ready Print, which works with Mopria certified printers. It is enabled at Computer Configuration, Administrative Templates, Printers, with the Configure Windows protected print setting, or through Intune with the ConfigureWindowsProtectedPrint policy.

That is worth knowing when you are deciding how much effort to spend rescuing a blocked driver. A machine heading for protected print mode is not going to load it anyway, and a device that works over IPP will work there without a driver decision at all. Where the device is Mopria certified, moving the queue is usually less work than finding a package Windows will accept.

Ruling the driver in or out in five minutes

  1. Try the connection from an elevated session on the failing machine. Blocked is blocked for administrators too.
  2. Try the same queue from a second machine. A driver decision follows the package; a policy decision follows the machine.
  3. Read the driver name and version from the server with Get-Printer and Get-PrinterDriver, and check it against the manufacturer’s current download.
  4. Install the in-box class driver on a test queue and connect to that. If it works, you have your answer and a migration to plan.
  5. Only then look at policy, and only for the users who cannot install a driver that everybody else can.

Editing the printer policy keys by hand changes a security boundary on every machine that receives the change. Use Group Policy or Intune rather than hand-edited values, so what was applied is visible and reversible, and export anything you are about to change.

When a licence is the actual fix

Replacing a blocked driver costs nothing. Get a current package from the manufacturer, or move the queue to the in-box class driver, and the code goes away. The licensing question is a different one and it is about scale: the printer policies above, and Windows protected print mode, are delivered as Group Policy or Intune policy, so they apply to machines that can receive one or the other. Where your machines cannot, the only lever left is configuring each one by hand with nothing to enforce or audit it, and that is the case a Windows 11 Pro upgrade licence answers. Arco supplies Windows 11 Pro upgrade licences and will check which edition your machines are currently running before you order. For one standalone machine you are content to configure by hand, fix the driver and buy nothing.

Every code this article covers

Code What it points at Source
0x00000BC6 ERROR_PRINTER_DRIVER_BLOCKED: the printer driver is known to harm the system Microsoft Learn
0x0000000D ERROR_INVALID_DATA: the data is invalid, which is what a damaged or incomplete package looks like to the installer Microsoft Learn
0x000003E3 ERROR_OPERATION_ABORTED: the I/O operation has been aborted because of either a thread exit or an application request Microsoft Learn
Event ID 808 Seen in the PrintService Admin log alongside driver failures, naming a file the spooler could not load. Microsoft publishes no description of this event, so read the file name rather than the number not published by the vendor
0x00000BC8 ERROR_CORE_DRIVER_PACKAGE_NOT_FOUND: unable to find a core driver package that is required by the printer driver package Microsoft Learn

Confirm the fix worked

  1. Log on as a standard user, connect to the shared queue, and confirm it installs without prompting for administrative credentials.
  2. Run Get-Printer on the client and confirm the queue is listed with the driver you intended, not the old one.
  3. Run Get-PrinterDriver on the print server and confirm the blocked package has been removed.
  4. Print a test page and confirm it completes on the device.
  5. Check the PrintService Admin log for new entries written during the install.

Questions people ask about this

Will running the install as an administrator get past this?

No. 0x00000BC6 is published as the driver being known to harm the system, which is a decision about the package rather than about your rights. If elevating works, you were looking at a Point and Print restriction and not at this code.

How is 0x00000BC5 different?

It is the same judgement one step down: ERROR_PRINTER_DRIVER_WARNED, the printer driver is known to be unreliable. You may get an install out of it. You should still replace the driver, because Windows has told you what it thinks of the package.

Does this cost anything to fix?

Not on the driver side. A current package from the manufacturer, or the in-box class driver, costs nothing. It becomes a licensing question only when you need to apply printer policy across machines that cannot receive Group Policy or Intune policy.

Is a package-aware driver always available?

Not for every model. Where the manufacturer never produced one, the in-box class driver usually prints correctly over IPP, though it exposes fewer finishing options. That trade beats keeping a driver Windows has blocked.

Should I just enable Windows protected print mode?

If your devices are Mopria certified, it removes this whole class of problem, because there is no third-party driver to be blocked. Test the workflows that matter first – finishing options and any application that prints unusual output – because it is a change in what the machine will accept, not just a setting.

Related error codes

Was this article helpful?

Your feedback helps us improve our documentation.

Related articles

Free Fix Remote Desktop cannot verify the identity: certificate error 0x80090325 License Error Scan to folder fails with 0xC00000CC: the copier cannot reach your share Free Fix VPN error 741 and 742: data encryption mismatch between client and server Free Fix Remote Desktop error 0x108: your session ended because of a network error
โ† Back to Knowledge Base