Jump to content

Recommended Posts

Posted
yes we have have 2012r2 print server and ltsc 1809 clients :(

so was your fix to just roll back oct and nov updates ?

Take it Michael's reg fix didn't work for you ? http://www.edugeek.net/forums/windows-10/223374-printing-issues-driver-update-needed-7.html#post1915622

 

Yes, unfortunately I took the decision to roll back in October (and block November).... I know, I know!

 

I seem to remember we used various reg fixes to get over the September issues (as you can see from the date of the post you referenced), but they didn't seem to work for us when October updates kicked in and November didn't fix anything for us.

 

I don't know what to say, it has gone so quiet on the 'Print Nightmare/Print Hell' front it feels like everybody else has got it sorted (somehow), but on my test VMs it (Oct/Nov updates) still kills printing even with various hacks so I can't roll them out.

 

I tried replacing DLLs without much luck (and I don't want to do that site-wide), the only thing that did work was this:

 

'[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Policies\Microsoft\FeatureManagement\Overrides]' DWORD 3598754956 VALUE 0

 

But I wasn't keen on rolling that out site-wide either...

Posted

So the registry file that people have put in place, is that a semi-permanent thing now? or are we waiting for Microsoft to release any further updates?

 

I know there were recent updates that addressed the errors however there's still the prompting of credentials if a non admin tries to install drivers.

Posted
So the registry file that people have put in place, is that a semi-permanent thing now? or are we waiting for Microsoft to release any further updates?

 

I know there were recent updates that addressed the errors however there's still the prompting of credentials if a non admin tries to install drivers.

 

As far as I can tell the recent updates that addressed the errors were only for 20H & 21H and above... nothing has been fixed for any lower versions as far as I know.

 

It's a strange one and I'm not sure if Microsoft are particularly happy about their security fixes (random hole plugging) being largely overridden with reg edits (as always), so I'm not sure if that will stick around for ever...

 

But the September 'Print Nightmare' seems to have been worked around so I'm still a little bit unsure of what the actual problem is now with the October and November updates (and nobody seems to know)... I for one am not against users being unable to install printers, in fact I moaned in a thread I created a couple of years back about how much trouble I was having trying to stop them (be careful what you wish for, eh?).

 

The way it works here is that users are given a set of printers for their job/role/where they work etc... All through their user log-on, all done by GPP, worked a treat....

 

Didn't need Point and Print, didn't need manual installs, didn't need Admin credentials... the server gives you the printer... why they needed to stop that working I will never know!

  • Thanks 1
Posted
is this still causing people problems ?

 

Not had time to go through all 20 pages but we are starting to see print issues after some windows updates.

Not sure if it is this driver issue though: some people can print ok, others get

"Access Denied unable to connect"

and in event log for PrintService

Win32 error code returned by the print processor: 283.

:(

 

I’m with you.

 

Stopped Sept/Oct/Nov updates and haven’t touched anything since!

Posted

found this:

 

If you are getting " Win32 error code returned by the print processor: 283 " Its because you have a windows version mismatch (print spooler server is updated compared to client machines)

 

(from comments here https://www.papercut.com/kb/Main/PrintQueueSetUpOnWindows#print-deploy

even though we don't use papercut)

 

led me to

https://support.microsoft.com/en-us/topic/managing-deployment-of-printer-rpc-binding-changes-for-cve-2021-1678-kb4599464-12a69652-30b9-3d61-d9f7-7201623a8b25#bkmk_enforcement

 

So might try setting RpcAuthnLevelPrivacyEnabled to 0 on print server but "Not recommended"

Posted

Well, '2021-12 Cumulative update' has arrived on our WSUS servers...

 

Grumbles on the internet say it hasn't fixed anything - anyone been brave enough to try it?

 

Rumour has it that 2004, 20H & 21H were fixed with out of band updates earlier (which I presume will be included in the 'Cumulative' anyway), so really interested in anyone running lower versions...

Posted
Well, '2021-12 Cumulative update' has arrived on our WSUS servers...

 

Grumbles on the internet say it hasn't fixed anything - anyone been brave enough to try it?

 

Rumour has it that 2004, 20H & 21H were fixed with out of band updates earlier (which I presume will be included in the 'Cumulative' anyway), so really interested in anyone running lower versions...

 

That's a good point actually, I should look at that. I wonder what people are grumbling about it not fixing?

Posted (edited)
I wonder what people are grumbling about it not fixing?

 

Can I take that to mean you are one of the chosen ones who hasn't had an issue with printing?

 

There isn't much on t'internet as of yet, but there wasn't last month, or the month before either (sometimes I think it is only me left with an issue).

 

But there is an ongoing discussion here:

 

https://www.bleepingcomputer.com/forums/t/759880/kb5006670-network-printer-problems-again-this-month/?p=5295880

 

To be honest I don't even know what 'the issue' is anymore... just a cycle of updates>no print>remove updates>print>wait a month>updates>no print>remove updates...

 

I don't even think it is related to the September 'print nightmare' anymore really (only that what they're doing to 'fix' it kills printing even more), we all worked around that - but something they did after that I can't seem to work around no matter what I do.

 

There is some talk of 'feature overrides' and 'spool dlls' but I was just hoping they would fix it, without having to implement any workarounds...

 

EDIT: Also still some talk of printing being forced to use NTLM (which is blocked on our Domain)...

 

From one of the posts in the above mentioned thread:

 

"Still doesn't make sense, everything I see in the win10 trace points to the client forcing NTLM SSP which all requires SMB V2+"

 

Also:

 

"It appears that the Windows 10 December CU (KB5008212) removes the following registry key from the print server:

 

Windows Registry Editor Version 5.00

 

[HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Print]

 

"RpcAuthnLevelPrivacyEnabled"=dword:00000000"

Edited by Koldov
Posted
Can I take that to mean you are one of the chosen ones who hasn't had an issue with printing?

 

 

No, you misunderstand. There have been plenty of issues with printing, but there was a new one each month for about three months introduced with each subsequent patch. The December patch is supposed to fix what was broken in 2021-10, the 0x000006e4 and 0x00000709 errors. If people are expecting this new patch to fix other faults, they're going to be disappointed. That's what I'm wondering what they think it's going to fix.

Posted

Ah I see....

 

Yes, I think I am going to be one of those that will be disappointed! :( I was hoping they were just going to fix 'it' (whatever 'it' is)....

 

What I can't actually get my head around (and what annoys me the most out of all of it), is that I can't seem to find anywhere that MS publicly acknowledges that they have actually broken printing.... and how they have broken it.

 

I mean I guess it makes sense that they don't want everyone to know the actual detail of what they've coded to prevent the exploits, but ever since the 'Print Nightmare' whatever they've tried to fix just breaks something else.

 

If they say well we have made it admin only to deploy printers, then ok we know the simple reg hack for that... if they say we've raised the security priv level, then ok we know the simple reg hack for that, etc...

 

But for the last couple of updates (Nov and now it appears Dec), none of that even seems to work for us and I can't find out what they've done to even find a workaround that doesn't include rolling back dlls or 'feature overrides'...

  • 1 month later...
Posted

So going back to the beginning.... being asked for credentials..

 

Has anyone solved this by having the drivers on the image? I've made a new image with 21H2, I can see the drivers in the driverstore on the image, but If I log in as a user it's asking for credentials. or is that usual behaviour?

Posted
So going back to the beginning.... being asked for credentials..

 

Has anyone solved this by having the drivers on the image? I've made a new image with 21H2, I can see the drivers in the driverstore on the image, but If I log in as a user it's asking for credentials. or is that usual behaviour?

 

If correct drivers are in driverstore users can connect to remote printer using Point-and-Print (also with Point-and-print restrictions set to Enabled) and not being prompted with admin credential.

Posted (edited)

This appears to have drifted out of the collective's consciousness (for now at least)... M$ have kept us busy and distracted with other faulty updates!

 

However, I still maintain that M$ don't see any problem or fault with what they've done and it is just how it is now.

 

For your 21H2 The only thing they seem to admit to (in the last 6 months) is waffling on about port numbers (and render jobs on the client):

 

https://docs.microsoft.com/en-us/windows/release-health/resolved-issues-windows-10-21h2#:~:text=October%202021,might%20encounter%20errors

 

It seems for me at least, users cannot install printers or have printers installed for them by GPO/GPP as standard, end of, unless, (for now at least it seems to work) I have all the reg edits and Point and Print settings enabled.

 

My GPO for client machines have the following:

 

Package Point and print - Approved servers = Print Server

Point and Print Restrictions - Everything enabled including Print Server FQDN. Both installing and updating = Do not show warning or elevation

 

RestrictDriverInstallationToAdministrators - reg edit = 0

 

RpcAuthnLevelPrivacyEnabled - reg edit = 0 (this is on both clients and the Print Server - not 100% sure it is necessary on both but I ran out of time for testing and left it as this once everything worked).

 

I think this circumvents all the 'protections' from the previous updates and is pretty much everything that M$ advise not to do, but what are we supposed to do without a proper 'fix' (which I doubt will come as M$ somehow don't see it as broken)...?

 

IIRC - this seemed to work on a brand new fresh Windows install with no drivers in the image, although it was a couple of months ago (feels like a lifetime) now.

 

EDIT: These seem to work for me, but if they don't I also messed about with a couple of machines using another reg edit:

 

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Policies\Microsoft\FeatureManagement\Overrides (you need to research the correct number for your Windows 10 version) 3598754956 (( for WINDOWS 10 1809 LTSC)).

 

This worked for a couple of test machines and then for some reason found that recently I haven't needed to use it...

Edited by Koldov
  • Thanks 1
Posted
If correct drivers are in driverstore users can connect to remote printer using Point-and-Print (also with Point-and-print restrictions set to Enabled) and not being prompted with admin credential.

 

hmm that's what we have but its still asking for credentials. Gonna have to do some more testing I think.

Posted
This appears to have drifted out of the collective's consciousness (for now at least)... M$ have kept us busy and distracted with other faulty updates!

 

However, I still maintain that M$ don't see any problem or fault with what they've done and it is just how it is now.

 

For your 21H2 The only thing they seem to admit to (in the last 6 months) is waffling on about port numbers (and render jobs on the client):

 

https://docs.microsoft.com/en-us/windows/release-health/resolved-issues-windows-10-21h2#:~:text=October%202021,might%20encounter%20errors

 

It seems for me at least, users cannot install printers or have printers installed for them by GPO/GPP as standard, end of, unless, (for now at least it seems to work) I have all the reg edits and Point and Print settings enabled.

 

My GPO for client machines have the following:

 

Package Point and print - Approved servers = Print Server

Point and Print Restrictions - Everything enabled including Print Server FQDN. Both installing and updating = Do not show warning or elevation

 

RestrictDriverInstallationToAdministrators - reg edit = 0

 

RpcAuthnLevelPrivacyEnabled - reg edit = 0 (this is on both clients and the Print Server - not 100% sure it is necessary on both but I ran out of time for testing and left it as this once everything worked).

 

I think this circumvents all the 'protections' from the previous updates and is pretty much everything that M$ advise not to do, but what are we supposed to do without a proper 'fix' (which I doubt will come as M$ somehow don't see it as broken)...?

 

IIRC - this seemed to work on a brand new fresh Windows install with no drivers in the image, although it was a couple of months ago (feels like a lifetime) now.

 

EDIT: These seem to work for me, but if they don't I also messed about with a couple of machines using another reg edit:

 

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Policies\Microsoft\FeatureManagement\Overrides (you need to research the correct number for your Windows 10 version) 3598754956 (( for WINDOWS 10 1809 LTSC)).

 

This worked for a couple of test machines and then for some reason found that recently I haven't needed to use it...

 

So the decisions in the series of patches concerning Print Nightmare would have been from a security perspective.

 

It may be possibly to deploy drivers on machine leavel and use printui or powershell to map the printers. The main focus was remeidaiting the CVES.

 

I may do some further testing as this is bound to come up again.

Posted

Anyone having printer issues again?

 

We seem to be experiencing printers removing themselves and then getting Printer not found when trying to re add it?...

  • Thanks 1
  • 1 month later...
Posted

Hi all, I can't believe this issue is still ongoing, all of a sudden, I have client systems showing the message asking for Driver Update Needed etc.

 

We have server 2016 Standard.

In my notes, I have written that if I remove KB5005573, that will prevent this issue occurring.

I made sure I removed this update some time ago. I have checked installed updates on the server and this update is not on it.

 

These are the latest updates installed to the server:

ServerUpdates.JPG

 

 

And these are the latest updates installed on the affected Windows 10 system:

ClientUpdates.png

 

This is the second Windows 10 system which has started doing this again in a week so something is going on. The systems do not use WSUS as it is just a small admin network.

Any advice would be greatly appreciated :p

Posted
I'm also getting this again, did you manage to fix it?

 

Hi, I am afraid not. I found that one started to work after I installed another Windows Update.

Sadly, we now have five other office computers that are still doing it. I have wasted so much time on this, I have given up for now and asked staff to use alternative computers due to Microsoft's lack of assistance on this issue and their products subsequently not working as they should.

Very frustrating and another reason we are starting the move to Google Workspace for Education.

Posted
Hi, I am afraid not. I found that one started to work after I installed another Windows Update.

Sadly, we now have five other office computers that are still doing it. I have wasted so much time on this, I have given up for now and asked staff to use alternative computers due to Microsoft's lack of assistance on this issue and their products subsequently not working as they should.

Very frustrating and another reason we are starting the move to Google Workspace for Education.

 

Further to my last post, I am not sure which server version you have, we have 2016 1607. Our Windows 10 systems are all running Windows 10 21H2.

 

I am finding that if I go to Print Management on the server in question, I am not even able to print directly from the server to a printer. No errors show, the job just never arrives. Same if I use Notepad or similar on the server. This is also the case on client machines now which are not showing any kind of error, they just don't print.

 

If I look at the server installed updates, the only recent two updates are:

KB5011495 and KB5011570.

 

I have a growing number of pi$$ed off users who are unable to print and absolutely no resolution I can give them as we have multiple printers in various locations. Microsoft need to sort this out, it is a total mess.

Posted

Hi All,

 

Im having all these issues now too. I am finding some success with allocating printers via TCPIP in group policy. Seems to be working for most but i dont know what effect that might have on printing in general. Im having to rebuild all of my workstations to Windows 10 21H2 also to resolve the issue so i have a massive job on my hands.

 

Changing the reg key to 0 doesnt work for me, so ive kept it on 1 and applied all point and print settings recommended by microsoft so hopefully its locked down still. Papercut Deploy is working well for printers, but everyone gets every printer on that without paying £1800 which is a lot of money to get round the issue. Everyone is going nuts though not being able tpo print, microsoft have really shafted us.

 

If you connect printers directly via TCTIP do you need a print server moving forward? To apply it in group policy it still wanted a printer share, so i cant see a way around ditching it.

  • Thanks 1
Posted
Hi All,

 

Im having all these issues now too. I am finding some success with allocating printers via TCPIP in group policy. Seems to be working for most but i dont know what effect that might have on printing in general. Im having to rebuild all of my workstations to Windows 10 21H2 also to resolve the issue so i have a massive job on my hands.

 

Changing the reg key to 0 doesnt work for me, so ive kept it on 1 and applied all point and print settings recommended by microsoft so hopefully its locked down still. Papercut Deploy is working well for printers, but everyone gets every printer on that without paying £1800 which is a lot of money to get round the issue. Everyone is going nuts though not being able tpo print, microsoft have really shafted us.

 

If you connect printers directly via TCTIP do you need a print server moving forward? To apply it in group policy it still wanted a printer share, so i cant see a way around ditching it.

 

Glad I am not the only one, but I 100% agree with your sentiments:

microsoft have really shafted us

 

When you say you are allocating via TCPIP, do you mean you are manually adding the printer on each machine so it is effectively a local printer by logging in as an admin>control panel>add printer> add printer by IP>select drivers from have a disk>install printer?

I have done this for the head and bursar as they have their own printers, but it is not feasible to do this for office staff as they use a multitude of printers.

 

Also, are you finding that your users get any kind of error? Mine get nothing, the job goes through as expected, no errors regarding drivers or job not printing. It just never comes through to the printer. The same happens even if I am administrator doing it.

 

My printers are deployed in Group Policy with the path names so as an example:

Computer Config>Policies>Windows Settings>Printer Connections>Path> Printer 1: \\servername\printer1

There is a different GPO within each OU so that depending on where the computer is, it will be given a particular list of printers.

Same with reg key for me as you state, it has made no difference, though it did before when we used to get the driver error messages a few months back.

 

I am so upset that Microsoft have left us in this situation, it is has and is still putting an incredible amount of strain on my IT services and I haven't done anything to cause this.

Posted
Glad I am not the only one, but I 100% agree with your sentiments:

 

When you say you are allocating via TCPIP, do you mean you are manually adding the printer on each machine so it is effectively a local printer by logging in as an admin>control panel>add printer> add printer by IP>select drivers from have a disk>install printer?

I have done this for the head and bursar as they have their own printers, but it is not feasible to do this for office staff as they use a multitude of printers.

 

Also, are you finding that your users get any kind of error? Mine get nothing, the job goes through as expected, no errors regarding drivers or job not printing. It just never comes through to the printer. The same happens even if I am administrator doing it.

 

My printers are deployed in Group Policy with the path names so as an example:

Computer Config>Policies>Windows Settings>Printer Connections>Path> Printer 1: \\servername\printer1

There is a different GPO within each OU so that depending on where the computer is, it will be given a particular list of printers.

Same with reg key for me as you state, it has made no difference, though it did before when we used to get the driver error messages a few months back.

 

I am so upset that Microsoft have left us in this situation, it is has and is still putting an incredible amount of strain on my IT services and I haven't done anything to cause this.

 

I'm allocating them via group policy under computer configuration > preferences > control panel settings > printers > TCP/IP Printer. Select 'create' option and put in the ip address of printer, give it a name and select the printer from the list that matches. Thats worked after i have rebuilt the workstation onto 21H2.

 

Before upgrading to 21H2, ive had a mixture of error 0x00011b, just error connecting to printer or like you say no errors, just nothing prints out. After performing upgrade to 21H2 and adding the abive into my printer gpo it has shown on most if not all devices. FWIW i have left in the same policy the printer that has been deployed via the print server also, so its added both in the normal way and again as IP printer if that makes sense.

 

Im so annoyed by this. 400 devices to reformat and only me here to do it. Laptops are going to be a killer! Cant do inline upgrade on student devices because 1) Its just as slow 2) All the default apps reappear after the upgrade like xbox, as you cant use a custom wim to upgrade :( :mad:

  • Thanks 1

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...