Jump to content

Recommended Posts

Posted

Hi there,

Has anyone else started getting this message when their users are attempting to print?

Printer.JPG

 

We are running Server 2012, just 3 shared printers which print directly, no holding in queues etc.

They are shared by a GPO at the top of our AD, it goes to all machines and users and is configured in both Computer Config>Policies>Windows Settings>Printer Connections and User Config>Policies>Windows Settings>Printer Connections.

 

 

All client systems when logged in as teachers/pupils are showing the above message. If the user clicks on Install driver, it seems to install and shows progress, but then it pops up again and again every time you click Install Driver. Thus they are totally unable to print anything.

 

I have logged in as administrator and get no messages like this, the jobs just print. We have made no changes to Group Policy or the server in general so I cannot understand why all of a sudden this is happening.

 

Any ideas?

Posted
Have a look here It's related to Microsoft August 2021 patches for all mainstream OSes.

 

Thank you, very helpful.

My only issue is that from following the post you linked me to, it says:

Create a GPP regedit:

 

Code:

HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows NT\Printers\PointAndPrint

 

Value: RestrictDriverInstallationToAdministrators

 

Dword: 0

 

 

I am finding that when I go to make a new registry on the GPO with the printer settings, by going to Computer Config>Preferences>Windows Settings>Registry, I am only able to browse the key path to: SOFTWARE\Policies\Microsoft\Windows NT\Printers

There is no \PointAndPrint after the Printers folder. Any ideas on why that would be?

Posted
Thank you, very helpful.

My only issue is that from following the post you linked me to, it says:

Create a GPP regedit:

 

Code:

HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows NT\Printers\PointAndPrint

 

Value: RestrictDriverInstallationToAdministrators

 

Dword: 0

 

 

I am finding that when I go to make a new registry on the GPO with the printer settings, by going to Computer Config>Preferences>Windows Settings>Registry, I am only able to browse the key path to: SOFTWARE\Policies\Microsoft\Windows NT\Printers

There is no \PointAndPrint after the Printers folder. Any ideas on why that would be?

 

This is normal as you're creating this key. It's new to Windows from August 2021 onwards, but you can apply it on a workstation say it's running the July 2021 patch. It just won't apply/doesn't work, but will come into play when the August 2021 patch is installed.

  • Thanks 1
Posted

Make sure you are entirely happy with that regedit, as it isn't supported or recommended by MS.

 

Having said that you must risk assess your own network.

 

As far as the GPP is concerned, I think when you click browse you are browsing the machine you are on (I'll presume the server) and that probably won't have the reg keys you are looking for (in fact unless you have enabled Point and Print on your client machines it will possibly stop here on those - Computer\HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT - mine does (there is no 'Printers' or 'Point and Print').

 

You seem to need to enable Point and Print to use the regedit... then you will have to manually enter the path in the GPP to create it.

 

Untitled.jpg

 

I think there does seem to be other ways to accomplish this without Point and Print or the regedit, if you read the full thread (Type 4 drivers or some Powershell scripting magic).

  • Thanks 1
Posted

At the moment (as I've said prior), Microsoft are effectively disabling Point and Print, but then aren't really giving admins an alternative.

 

Apply this GPP regedit at your own risk, whilst maintaining exists Point and Print GPOs and it works.

 

I'm hoping that they'll be some revised guidance in the coming months. Type 4 drivers might be part of the solution, but then this confuses me more. Various websites say Type 4 are deployed directly from Windows Update, yet I can download Type 4 drivers from various printer manufacturers to deploy via Point and Print.

 

I know as much as the coding's different, but then the functions are more restricted.

 

One of Microsoft's latest guidance of 'provide a domain admin username/password' for end users to enter when prompted is just crazy.

  • Thanks 1
Posted (edited)

Yes, there are lots of things that are crazy about this whole situation! Microsoft having a knee jerk reaction doesn't help, but obviously they were caught with their pants down, revealing quite a large hole ready for someone to exploit (as if there aren't enough already) so they've just pretty much said printing as we know it isn't safe which is true... and until they can fix it (if they can) we're stuck with whatever we can bodge together...

 

Papercut haven't got much good to say about Type 4 drivers, I don't know if this is out of date info (and I don't use Papercut - it's just the first thing when I googled it).

 

https://www.papercut.com/kb/Main/WindowsType4PrintDrivers

 

The fact that there is reduced functionality and it doesn't appear to work for Macs?

 

I have got Type 4 drivers downloaded from the manufacturer, but haven't got the guts to deploy them yet (hopefully they will have more functionality than the MS ones)...

 

"With Type 4 drivers, only the server needs the driver, while clients use a generic driver that passes the job to the server, so there's no need to install drivers for all printers on the client any more."

 

https://www.reddit.com/r/sysadmin/comments/5199j2/are_type_4_print_drivers_worth_using/

Edited by Koldov
  • 2 weeks later...
Posted

Thanks everyone for your posts. This is just a total mess. I have applied the reg, Windows 10 computers still not liking it. It looks like some computers have not yet got the July 21 update due to WSUS issues. Had been hoping to move away from WSUS but school had not got the money to give me more time to look into this. I just do not have the time to keep wasting on this and the school cannot afford more of my time.

 

Does anyone know what the specific update is on the server which is enabling this new security feature? I am thinking of just removing it for now as the impact this is having is unprecedented.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...