Jump to content

Recommended Posts

Posted
@Michael

On the page you have linked to you have both...

 

Computer Config > Policies > Admin Templates > Printers > Point and Print Restrictions

 

User Config > Policies > Admin Templates > Control Panel > Printers > Point and Print Restrictions

 

Are you deploying both on your domain or just the one that matches how your printers are deployed?

 

Yes I set the GPOs as required, so it's future proof whether printers are deployed on a computer or user basis - it'll just work. Configure once and just forget.

  • Thanks 1
Posted

Just to feed back - the only niggly issues I'm seeing are devices with pending updates from WUfB which I use, but upon restarting/installing, this works fine 99% of the time thereafter.

 

You get the odd stubborn device, but manually/remotely restarting the spooler on the device again resolves it; but this is very far and few in the grand scheme of things.

Posted (edited)

Just going by a post on another forum, but can anyone who is not having problems please tell me if you have this setting enabled for your domain?

 

NTLM.JPG

Edited by Koldov
Posted
Just going by a post on another forum, but can anyone who is not having problems please tell me if you have this setting enabled for your domain?

 

[ATTACH=CONFIG]63475[/ATTACH]

 

On the Default Domain Policy, mine's Not Defined.

  • Thanks 1
Posted (edited)
On the Default Domain Policy, mine's Not Defined.

 

Thanks, what about your Default Domain Controller (getting a bit more complicated - it might not be a 'Default' GPO - you might have it created in a separate policy - I have)?

 

You would know if it has been set though I guess if you are in control of such things, it comes from disabling NTLM in your domain:

 

https://docs.microsoft.com/en-us/windows/security/threat-protection/security-policy-settings/network-security-restrict-ntlm-ntlm-authentication-in-this-domain

Edited by Koldov
Posted
Thanks, what about your Default Domain Controller (getting a bit more complicated - it might not be a 'Default' GPO - you might have it created in a separate policy - I have)?

 

You would know if it has been set though I guess if you are in control of such things, it comes from disabling NTLM in your domain:

 

https://docs.microsoft.com/en-us/windows/security/threat-protection/security-policy-settings/network-security-restrict-ntlm-ntlm-authentication-in-this-domain

 

Again Not Defined on the Default Domain Controllers policy.

  • Thanks 1
Posted

Hi Guys,

 

I have installed a Xerox printer via IP on a client machine using the Add Printer wizard. Printer installs and works fine, but in Sage when we try to print it says Connecting to 192.xxx.xxx.xxx and asks me for permissions to install a driver? Why would it install a driver from the printer if the driver is installed locally from one I downloaded? Is this part of the same problem in this thread? I can't get rid of it no matter which driver i use, even the signed one.

 

This isnt a domain environment, it's a small bunch of 7 PCs.

 

Thanks

Rob

Posted

Possibly not related (who knows with MS these days) unless your printer is shared by one of those 7 computers to the others somehow... But as you say you're not on a domain, not GPO deployed and as it's installed by IP and prints fine so I wouldn't think so - sounds like it is related to the software package being used.

 

Not a SAGE user here (but SIMS-FMS and it is also a quirky beast with installed and default printers), but is it related to telling the program it has a new printer - is it trying to print to the old one?

 

Sage - Changing the Default Printer

Posted (edited)

I think there are a couple of posts on one of these threads that says V4 drivers work (and are really what MS are trying to push us all to use), due to the fact that nothing is done client-side apparently.

 

I've seen some posts saying there are various issues with V4 drivers and Papercut and the fact that the client doesn't get any advanced dialogue (it has also been mentioned that this can be worked around by installing the V4 drivers on the client).... YMMV

Edited by Koldov
Posted

Hi,

Finally got a chance to resolve most of the printer issues we had .

I've been reading through the thread and applied the Point and Print GPOs configured the GPP regedit and although students and teachers can now add printers without an issue, I couldn't get the item level targeting working -e.g. for a given OU e.g. classroom, deploying a specific printer to it. Did anyone else have this issue - I may have missed it in the pages on this thread?

We use a print server and I checked that the KB's mentioned in previous threads were not applied.

 

TIA

Chris

Posted

Sorry if this has been posted, there are a lot of posts on here!

 

I was wondering if the October patches had created any new issues please?

 

Thanks.

Posted
Has anyone managed to push drivers out so RestrictDriverInstallationToAdministrators can be left set to 1? I've successfully pushed the drivers out but we still get prompted for admin credentials
Posted
Has anyone managed to push drivers out so RestrictDriverInstallationToAdministrators can be left set to 1? I've successfully pushed the drivers out but we still get prompted for admin credentials

 

I found it depends on the printer driver and also if you map the printer in the user context. GPP User Context and PowerShell in the user context worked. However if you use the per machine Group Policy Printer connections the mapping fails.

 

The Toshiba universal print driver doesn’t seem to like any method other than setting the registry setting to 0 which makes you vulnerable to attacks.

Posted
I found it depends on the printer driver and also if you map the printer in the user context. GPP User Context and PowerShell in the user context worked. However if you use the per machine Group Policy Printer connections the mapping fails.

 

The Toshiba universal print driver doesn’t seem to like any method other than setting the registry setting to 0 which makes you vulnerable to attacks.

We use printer mapper as we had issues via GPO. We're prompted when manually adding the printer and via printer mapper nothing happens.

 

We have Sharp MFPs and HP Pagewide enterprises both of which do the same

Posted

The annoying thing with the October update issues is that for some reason (haven't worked out why yet) it doesn't seem to be affecting everyone like the August/September 'Print Nightmare' updates did. I've seen on another forum it might be related to domains that have restricted NTLM authentication, but can't seem to verify it anywhere.

 

I haven't even seen MS publicly acknowledge this is an issue.... therefore I wonder if it is actually going to be fixed.

 

For some unknown reason we suffered with it here and in my testing I couldn't find a way around it (apart from replacing DLLs as mentioned above), the October CU on the clients killed printing for us.

Posted

OK, so looks like a public acknowledgement of the issue here:

 

https://docs.microsoft.com/en-us/windows/release-health/status-windows-10-21h1#2737msgdesc

 

Unfortunately the 'workarounds' don't seem to make any sense to me...

 

"Workaround: You can take steps to workaround this issue on print servers that meet the following prerequisite:

 

Print clients must have installed a Windows update released on or after January 2021 before the print server has installed KB5006670."

 

None of my clients are 10 months behind on their updates...

 

"Ensure that network security and VPN solutions allow print clients to establish RPC over TCP connections to print server over the following port range:

Default start port: 49152

Default end port: 65535

Port Range: 16384 ports"

 

If my Firewall was actually on for the Print Server (I know...) this 'Inbound Rule' is set:

 

File and Printer Sharing (Spooler Service - RPC)

 

Inbound rule for File and Printer Sharing to allow the Print Spooler Service to communicate via TCP/RPC - TCP/RPC Dynamic Ports - All Ports.

 

"You also benefit from using client side rendering for print jobs. The 'Render print jobs on client computers' option is available from the printer's device Properties, and it is recommended that its checkbox is selected on the print server. Note this step will not help if clients have overwrites which prevent the server setting from taking effect."

 

All the printers have this box ticked...

Posted

I am literally at my whits' end with this problem. The time I have spent with a colleague trying to get printers working is unbelievable. The school can no longer afford to keep paying for us to spend time on something which is simply not working.

The education of children is now severely being affected by this and I am disgusted that so many organisations have been left in this situation.

 

Here is everything we have done so far along with the servers we have.

 

Server 1: 2016 1607 FRDC Server, DNS and DHCP Server, also was original Print Server

Server 2: 2016 1607 Server Domain connected but not a DC for Backup , Paxton Access and WSUS

Server 3: Third 2019 1809 server domain connected but not a DC for new backup and new WSUS. Now the new print server with updated printer drivers.

 

Windows 10 client computers running a mixture of Windows 10 versions both Edu and Pro.

2 x RISO the ComColor 7150 Copiers

 

One Printer GPO on FRCD server for the above two printers which goes out to all stations on the network. No location based printer options, just a really simple setup.

Steps done so far to try and resolve this:

1. Added the RestrictDriverInstallationToAdministrators REG DWORD entry to our Printer GPO.

2. Added to our Printer GPO, Point and Print Restrictions Enabled, entered in the FQDNs for our three servers. Enabled “Users can only point and print to machines in their forest” and set the two following security prompts to “Do not Show”: “When installing drivers for a new connection” + “When updating drivers for an existing connection”

3. Tried to remove the KB5005573 update from the FRDC. It would not uninstall.

4. Tried clearing the repository on the server, still it would not uninstall or clear.

5. Tried to not approve it on WSUS, couldn’t as WSUS server was totally full.

6. Tried using the PS Print Nightmare script someone helpfully posted on here to remove the update from the server. Wouldn’t uninstall again.

7. Re-shuffled WSUS GPO so that it didn’t apply to the FRDC.

8. Attempted again to manually remove the update, still not able to remove it.

9. Put WSUS GPO back to where it was before.

10. Gave up and focused on getting WSUS installed on our new 2019 server.

11. Installed WSUS on new 2019 server, however WSUS would not work showing errors when opening.

12. Followed all online guides to allocate more memory to WSUS etc so it would work, still it wouldn’t work.

13. Checked WSUS was uninstalled from secondary server, it was however in IIS it was still running. Stopped this service in IIS.

14. WSUS now worked on third 2019 server, however constantly kept crashing and showing same error message.

15. Again checked secondary server, WSUS not running, still crashing on 3rd.

16. After lots of crashing and trying, managed to find all of the following in WSUS and decline for install:

KB5005568 (Windows Server 2019)

KB5005573 (Windows Server 2016)

KB5005613 (Windows Server 2012 R2)

KB5005627 (Windows Server 2012 R2)

KB5005623 (Windows Server 2012)

KB5005607 (Windows Server 2012)

KB5005606 (Windows Server 2008)

KB5005618 (Windows Server 2008)

KB5005565 (Windows 10 2004, 20H2, and 21H1)

KB5005566 (Windows 10 1909)

KB5005615 (Windows 7 Windows Server 2008 R2)

KB5005568 (Windows Server 2019)

KB5005573 (Windows Server 2016)

KB5005613 (Windows Server 2012 R2)

KB5005627 (Windows Server 2012 R2)

17. Checked on FRDC server, updates mentioned above for 2016 now missing and not installed, good result.

18. Printers STILL not printing.

19. Re-verified that all settings were in place in printer GPO, things like “users can only point and print to machines in the forest”, making sure the specific printers listed that users can print to were correct and resolvable. Everything ok.

20. Still printers not printing.

21. Gave up YET AGAIN and set up the 2019 server as a print server.

22. Contacted RISO who supply the printers to ensure we have latest drivers.

23. RISO send me a link for their new ones. I download the 2019 server drivers and install as per their instructions for the ComColor 7150. All printers added, tested, and working perfectly.

24. I changed the Printer GPO on the FRDC to reflect the new printers on the 3rd server. I put in the new printer paths in Printer Connections, I ensure all paths are resolvable and everything is correct. I update the policy so everything is sent through to client computers.

25. I am told AGAIN, people are unable to print.

26. Again, I check the printer GPO, everything is correct and as it should be.

27. I run a GPResult on a client computer, I can see that the Printer Policy is being applied. Makes no sense at all, printers are not showing yet policy is being applied.

28. I test on multiple computers, still no printers but policy is being applied apparently.

29. I log in as a teacher, log out, delete profile, re log in, all printers now show.

30. I assume that this must be a profile issue then.

31. Log in as same teacher on another computer, printers do not show. So can’t be the profile.

32. I notice that some computers have Windows 10 Pro and others 10 Edu. I convert one from Edu to Pro, test, still not working.

33. I try with different teacher accounts and the same is happening so it is not related to a specific user.

34. I convert another from Pro to Edu, still not working.

35. I notice some have feature updates pending, I install these, still not working.

36. I test with another staff account, still not working.

37. A colleague installs the printer directly to a client workstation and tests by logging in as a member of staff. It works well as it is going direct to the printer and not through the server. This works for a few days, and then stops working.

 

 

We really thought this was profile related, but resetting profiles, although seeming to solve the problem, was not the fix we had hoped for.

Can anyone please help? The amount of time spent on this is ridiculous. I am only on site 2.5 hrs a fortnight, so the time this has taken in terms of weeks is immense as there are other jobs to be done at the same time.

I cannot believe how difficult this has been to resolve and STILL staff are not able to print, and we have a mountain of other issues which have been left due to this. :mad:

Posted (edited)

I can't really help here much as I have different Server and Client OS versions and printing and WSUS working here but... obviously with all the workarounds and not having clients updated I'm living on the edge...

 

Print Server 2012R2 VM on October CU - KB5006714 (I felt reasonably confident as various searches indicate it is a client issue this time).

 

Clients LTSB & LTSC on September CU - (October CU KB 5006669 & KB5006672 respectively was set to remove as it just stopped printing dead, but I haven't declined it just yet - I was hoping for a miracle - but with less than a week to go until the November CU I might).

 

Printers installed per USER GPO in GPP (no new ones have needed to be installed so can't comment on if they would or not but I've had no trouble on my test VMs - all laptops are still the same with same users etc).

 

Point and Print restrictions are set on the client per COMPUTER GPO with no elevation prompts and approved servers (by FQDN) and the regedit to allow non-admin install.

 

I do not have "[HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Print] RpcAuthnLevelPrivacyEnabled=dword:0" set on the server or clients as I it didn't seem to make a difference, but it might help for your set-up.

 

https://support.microsoft.com/en-us/topic/managing-deployment-of-printer-rpc-binding-changes-for-cve-2021-1678-kb4599464-12a69652-30b9-3d61-d9f7-7201623a8b25

 

On the print server the drivers have 'render on the client' and 'print directly' set.

 

One thing that bothers me is your WSUS server being full... You shouldn't have needed to find all those updates and remove them if you don't have clients that required them. Do you regularly run the clean-up wizard (and I do mean regularly - I do mine weekly and also skim through just before to decline anything that shouldn't be there - for other Windows 10 versions etc.) and I have only the very minimum of 'Products and Classification' enabled? Also, I have been through the settings to disallow automatic approval for CUs now finally because of this (in the Default Automatic Approval rule).

 

Also I personally would not have my servers in WSUS anyway (just personal preference) or at the very least have all updates set to not automatically approve.

 

EDIT:

 

One thing I have noticed (mentioned on another forum) is the fact that I have these set for our domain:

 

Network security: Restrict NTLM: Audit NTLM authentication in this domain - Enable all

Network security: Restrict NTLM: NTLM authentication in this domain - Deny all

 

When the October update hit the clients and during my testing, when trying to install printers the Security Event Log goes crazy - there must be a link...

 

EDIT 2: For some reason it appears that some people have had success with replacing spooler .dll files (YMMV) and what impact this will have further down the line (as with all these workarounds is anyone's guess)...

 

https://www.bleepingcomputer.com/forums/t/759880/kb5006670-network-printer-problems-again-this-month/?p=5273459

Edited by Koldov
  • Thanks 1
Posted

One problem I had (and fixed), was not being able to deploy printers using GPO to a lot of staff.

 

I found the issue was related to a really old GPO that was set to delete a printer connection. This delete GPO has been fine for many years and not caused any issues until very recently, so imagine it was caused by a recent update.

 

Removed the old policy and instantly all the printers deployed to the staff laptops.

  • Thanks 1
Posted
I can't really help here much as I have different Server and Client OS versions and printing and WSUS working here but... obviously with all the workarounds and not having clients updated I'm living on the edge...

 

Print Server 2012R2 VM on October CU - KB5006714 (I felt reasonably confident as various searches indicate it is a client issue this time).

 

Clients LTSB & LTSC on September CU - (October CU KB 5006669 & KB5006672 respectively was set to remove as it just stopped printing dead, but I haven't declined it just yet - I was hoping for a miracle - but with less than a week to go until the November CU I might).

 

Printers installed per USER GPO in GPP (no new ones have needed to be installed so can't comment on if they would or not but I've had no trouble on my test VMs - all laptops are still the same with same users etc).

 

Point and Print restrictions are set on the client per COMPUTER GPO with no elevation prompts and approved servers (by FQDN) and the regedit to allow non-admin install.

 

I do not have "[HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Print] RpcAuthnLevelPrivacyEnabled=dword:0" set on the server or clients as I it didn't seem to make a difference, but it might help for your set-up.

 

https://support.microsoft.com/en-us/topic/managing-deployment-of-printer-rpc-binding-changes-for-cve-2021-1678-kb4599464-12a69652-30b9-3d61-d9f7-7201623a8b25

 

On the print server the drivers have 'render on the client' and 'print directly' set.

 

One thing that bothers me is your WSUS server being full... You shouldn't have needed to find all those updates and remove them if you don't have clients that required them. Do you regularly run the clean-up wizard (and I do mean regularly - I do mine weekly and also skim through just before to decline anything that shouldn't be there - for other Windows 10 versions etc.) and I have only the very minimum of 'Products and Classification' enabled? Also, I have been through the settings to disallow automatic approval for CUs now finally because of this (in the Default Automatic Approval rule).

 

Also I personally would not have my servers in WSUS anyway (just personal preference) or at the very least have all updates set to not automatically approve.

 

EDIT:

 

One thing I have noticed (mentioned on another forum) is the fact that I have these set for our domain:

 

Network security: Restrict NTLM: Audit NTLM authentication in this domain - Enable all

Network security: Restrict NTLM: NTLM authentication in this domain - Deny all

 

When the October update hit the clients and during my testing, when trying to install printers the Security Event Log goes crazy - there must be a link...

 

EDIT 2: For some reason it appears that some people have had success with replacing spooler .dll files (YMMV) and what impact this will have further down the line (as with all these workarounds is anyone's guess)...

 

https://www.bleepingcomputer.com/forums/t/759880/kb5006670-network-printer-problems-again-this-month/?p=5273459

 

One problem I had (and fixed), was not being able to deploy printers using GPO to a lot of staff.

 

I found the issue was related to a really old GPO that was set to delete a printer connection. This delete GPO has been fine for many years and not caused any issues until very recently, so imagine it was caused by a recent update.

 

Removed the old policy and instantly all the printers deployed to the staff laptops.

 

Thanks everyone.

There are a couple of things you may be able to help me with......

 

 

Just to clarify, the new WSUS server has bags of space so having all of the updates is not an issue. The older server, did not have all of the updates, just the core ones, so I had already tried to free up as much room as I could.

 

1.You mention about the print server drivers having 'render on clent' and 'print directly' set. How is this done? Do I need to ask RISO to do this?

 

2.You mention that you do not have RpcAuthnLevelPrivacyEnabled=dword:0 set on server or clients. I have not heard of this before? Should I try it?

The only reg I have added to our printer policy is this:

 

RegistryPolicy.JPG

 

 

Lastly, can I just check that for Point and Print Restrictions within the GPO, have you set them under Computer Configuration or User Coniguration? And also have 'Users can only point and print to machines in their forest' disabled?

 

I notice I have set mine under Computer Config, but under User Config, I have the 'Printer Connections' and respective paths, these are also listed under Computer Config, so duplicated. Does this seem ok?

 

@TwistedHelixis, thanks, I will go back through my policies, but I have always kept anything printer related in one policy called PrintersAllLocations as we have quite a basic printer setup here.

 

Have a good weekend guys, don't have printer nightmares. ;)

Posted

Further to my last post and after spending three hours diagnosing this out of my own weekend, for free (thank you Microsoft)....

 

I am finding that one one example computer...

Windows 10 Pro 1909 Domain Connected.

It has the policy for the printers.

As the usual teacher for this computer, your domain account gets the printers as expected, however some users report that they can't print. The print queue seems blocked with jobs which have not gone through. If you delete these as the user in question, it works no problem.

As a teacher user who doesn't usually use the computer. You get no printers.

 

As a brand new test user, I have just made up, you get no printers.

This is making absolutely no sense.

I CANNOT DESCRIBE HOW UTTERLY FRUSTRATING THIS IS. WHY IS THERE NO WAY TO FIX THIS REDICILOUS PROBLEM? I HAVE SPENT HOURS ON THIS AND GETTING ABSOLOUTELY NOWHERE. :mad: :mad: :mad: :mad: :mad: :mad: :mad: :mad: :mad: :mad: :mad: :mad: :mad: :mad:

  • Thanks 1
Posted

I am getting something similar. Seems that newly images machines are not installing a needed update for the fix to take effect.

If you install the printer from the share directly, you'll get an error - hopefully 0x000011b.

 

Check for the following update KB5006670.

We have released this via SCCM, but its not being picked up.

Checking MS onine, find the above update and installs it.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...