kxv2020 Posted August 18, 2021 Posted August 18, 2021 Hi, We’re in the process of connecting all staff/pupil devices to azure Ad (without Ad sync). The stumbling block is that papercut is still installed locally on a DC and that needs to authenticate against azure which we can do! How do we install the print queue ? (Which is asking for domain password username ? )
PaperCutterBrenda Posted August 18, 2021 Posted August 18, 2021 Hi there Kiran! PaperCutter here. That's a great question that will require brains much more techy than my own. Are you being supported by a reseller/ASC? If so, highly recommend you reach out to them for 1:1 assistance. If not, holler at our tech team – [email protected]. They'll help get you sorted! 1
MicrodigitUK Posted August 19, 2021 Posted August 19, 2021 (edited) How do we install the print queue ? (Which is asking for domain password username ? ) If you have one local domain Then the only way to stop this is to use AD Sync with device right back enabled to On prem domain. However if you have more than one site with multiple on prem domains you cannot get AD sync to write back to multiple, Only one on prime domain is allowed for device wright back. If you do have one domain this is by far the easiest method to print to on-site print servers. A standard Windows print server needs authentication on SMB print shares (Authenticated printer queues). Therefore needs those devices written back to the local domain the print server is joined to, to not prompt for authentication, as the device will be authenticated like any on prime device. (Using some certificates that are written back to onprem AD with the device identity) An alternative (If you have more than one on Site local AD) is to have non-authenticating Printer queues. And I have found the easiest way to achieve this is with an IPP print queue Hosted from a CUPS server. Then you allow the installed Papercut client on Windows (or macOS) to do all the authentication by passing on the username to the Papercut server from the Papercut client running on the device. This is precisely how it works if you have a secondary Papercut PrintServer for something like your Apple Mac computers or iOS devices. This doesn’t have to be macOS running CUPS (That could be expensive if you need a Apple Mac for each on prem side) it could be any Linux distribution like Ubuntu server, CentOS. Also apposed to popular belief, Windows will add printer use using IPP printer shares. It’s just normally in the Windows world we are commonly connect via SMB printer shares. No you won’t have all the bells and whistles of an SMP print share if you use IPP you will need some other method to distribute the print drivers AzureAD devices. But you could use something like Papercut print deploy to help you or to make this process of deploying drivers and IPP connections to clients. Then it’s just a case of pushing out the Papercut client via Intune. Edited August 19, 2021 by MicrodigitUK 1
fredesq Posted August 19, 2021 Posted August 19, 2021 (edited) If you have GSuite you can authenticate users with that. As you can't auth with the AAD Papercut sync, only the AD DS which costs per month - which is a real shame. You could even set up a GSuite for this as it's free for the basic stuff then enable SAML sign on and the automatic account provisioning so your users are replicated to GSuite and Auth with Azure (this does work with the following method btw) So for that avenue to work with GSuite user sync and auth, you can use Mobility Print and Print deploy to deploy a print queue to your devices from a standalone Papercut MF install without the need for SMB based auth. 1) Sync users from GSuite 2) Setup print queues + mobility queue 3) Deploy a mobility queue to a windows machine 4) Swap the driver out from the mobility one to the full fat one for your printer 5) Use the print deploy cloner software, which basically takes a print screen of your deployed printer with the proper driver 6) Deploy that queue to the other devices. Edited August 19, 2021 by fredesq 1
aicrd Posted August 19, 2021 Posted August 19, 2021 FYI - For the Azure AD DS stuff. You would be looking at £0.12 per hour for up to 25,000 objects, or £90 per month. If that's something you would consider. 3
kxv2020 Posted August 19, 2021 Author Posted August 19, 2021 An alternative (If you have more than one on Site local AD) is to have non-authenticating Printer queues. And I have found the easiest way to achieve this is with an IPP print queue Hosted from a CUPS server. Then you allow the installed Papercut client on Windows (or macOS) to do all the authentication by passing on the username to the Papercut server from the Papercut client running on the device. This is precisely how it works if you have a secondary Papercut PrintServer for something like your Apple Mac computers or iOS devices. This doesn’t have to be macOS running CUPS (That could be expensive if you need a Apple Mac for each on prem side) it could be any Linux distribution like Ubuntu server, CentOS. Also apposed to popular belief, Windows will add printer use using IPP printer shares. It’s just normally in the Windows world we are commonly connect via SMB printer shares. No you won’t have all the bells and whistles of an SMP print share if you use IPP you will need some other method to distribute the print drivers AzureAD devices. But you could use something like Papercut print deploy to help you or to make this process of deploying drivers and IPP connections to clients. Then it’s just a case of pushing out the Papercut client via Intune. Thanks for this! Do you know how to do this? - what are the steps - got a guide?
kxv2020 Posted August 19, 2021 Author Posted August 19, 2021 And therefore what does Azure LDAP sync do?? https://www.papercut.com/support/resources/manuals/ng-mf/common/topics/sys-user-group-sync-azure.html It's all very confusing!
stebo730 Posted August 23, 2021 Posted August 23, 2021 Hi Kiran We have been troubleshooting this very issue for 2 weeks and have just got a solution. Deploy Mobility Print Deploy Print Deploy using inTune - Guide here Use Print Deploy to deploy Mobility Print printer queues. Users will need to sign into Print Deploy but should get prompted for this. Mobility Print itself requires admin credentials to run and install and there is no silent install but works well this way. Print Deploy needed credentials to add the print queues from the print server, so again didnt go smoothly and needed manual intervention. The combination of them both with Print Deploy being used to deploy the Mobility Print printers seems to work well (so far)! Best of luck. Hope this helps. 1
HereIGoAgain2601 Posted August 23, 2021 Posted August 23, 2021 We have done exactly this earlier in the break and seems to work well. We are using Azure Domain Services for authentication with Secure LDAP 1
kxv2020 Posted August 23, 2021 Author Posted August 23, 2021 We have done exactly this earlier in the break and seems to work well. We are using Azure Domain Services for authentication with Secure LDAP How much does this cost you?
HereIGoAgain2601 Posted August 24, 2021 Posted August 24, 2021 We are estimating it as £90 a month but it could end up being more. We are also using the Secure LDAP for authentication to our web filter / firewall. We have added it to our Microsoft CSP agreement so we can pay it to the reseller on invoice rather than credit card etc 1
fredesq Posted August 24, 2021 Posted August 24, 2021 We are estimating it as £90 a month but it could end up being more. We are also using the Secure LDAP for authentication to our web filter / firewall. We have added it to our Microsoft CSP agreement so we can pay it to the reseller on invoice rather than credit card etc Just out of interest, what filter are you using that can use ad ds?
HereIGoAgain2601 Posted August 24, 2021 Posted August 24, 2021 We use Sophos XG - it’s not Single Sign on as yet with Azure so we have deployed the authentication client via MSI that prompts for Azure credentials 1
kxv2020 Posted September 2, 2021 Author Posted September 2, 2021 Hi Kiran We have been troubleshooting this very issue for 2 weeks and have just got a solution. Deploy Mobility Print Deploy Print Deploy using inTune - Guide here Use Print Deploy to deploy Mobility Print printer queues. Users will need to sign into Print Deploy but should get prompted for this. Mobility Print itself requires admin credentials to run and install and there is no silent install but works well this way. Print Deploy needed credentials to add the print queues from the print server, so again didnt go smoothly and needed manual intervention. The combination of them both with Print Deploy being used to deploy the Mobility Print printers seems to work well (so far)! Best of luck. Hope this helps. The issue I have had is that print mobility only works on per machine basis rather than per user I believe... so if you have desktop workstations which multiple staff use, it didn't work - how did you overcome that? or did you not?
stebo730 Posted September 10, 2021 Posted September 10, 2021 I deployed the Papercut Devices via GPO in our normal Domain Joined environment.
kxv2020 Posted December 12, 2021 Author Posted December 12, 2021 Anyone tried the new update to Papercut?
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now