Jump to content

Recommended Posts

Posted

Hi Everyone,

 

Sure I'm missing something simple but my brain is not functioning properly today, I have a school who is moving from Active Directory to Intune and we have agreed to re-purpose a backup server to become the new print server.

 

I've logged onto the server and added the print management role and imported printers from an export of print management on the old server, the printers are shared and permission is set to Everyone view/ print (using the default share option in print management not directing to a shared folder with printers published to that)

 

When I navigate to the ip/FQDN address from my Intune managed laptop to see the default share I'm seeing a UAC prompt to authenticate against AD on the server, am I missing something obvious? (File and printer sharing is enabled)

 

Other information - the DC has been retired and is now getting DHCP\DNS from the router, the new print server is still on the old AD domain, no VLAN's, no point and print restrictions, have not yet fully started going through gpo's/ registry as assuming I've missing something obvious... (I have another school setup but made the server myself and they still have a DC running)

 

Any insights or advice much appreciated,

 

Cheers,

Will

Posted

Is your print server joined to / aware of Azure AD? Can it check that you/your laptop is allowed to connect to it?

 

It sounds like you've chopped the DC out of the network and the print server is still trying to find the DC to check who's allowed to access printers.

 

Assuming the guest account is disabled (it should be), "Everyone" = "people the print server can see have valid accounts".

 

Depending on what sorts of printers you have to tolerate and the complexity of your environment, maybe consider something like PaperCut's Mobility Print instead.

  • Thanks 1
Posted
Or am I talking a load of waffle? our re-seller said that for Papercut MF client to support charging I need to clone the queues from a PC with printers connected via a network share (the plan is to use Print Deploy and the Papercut MF agent with Intune)
Posted
Is your print server joined to / aware of Azure AD? Can it check that you/your laptop is allowed to connect to it?

 

It sounds like you've chopped the DC out of the network and the print server is still trying to find the DC to check who's allowed to access printers.

 

Assuming the guest account is disabled (it should be), "Everyone" = "people the print server can see have valid accounts".

 

Depending on what sorts of printers you have to tolerate and the complexity of your environment, maybe consider something like PaperCut's Mobility Print instead.

 

Events kind of back this up as seeing quite a few DNS error relating to printers, I used mobility print before but found performance and drivers to not be great

Posted

Are you still battling this orcward problem, Frodo_Baggins? I'm a papercutter with no technical knowledge but I know colleagues who are super brainy. Their response follows, but I urge you to work with your reseller or holler out at [email protected].

 

BRAINY COLLEAGUE:

 

There's a few things going on here, and they may encounter more the further they go.

 

The first responder's first question is good - is that server actually joined to Intune/Azure? If not, that would explain one cause of a UAC prompt when trying to map a point-and-print connection from an Intune managed / Azure bound client. In the OP he says it’s joined to the old AD domain - Windows does not let you join to both an on-prem AD and Azure AD at the same time from memory - you have to remove it from the on-prem AD to even be able to join it to Azure AD.

 

They say there are no point-and-print restrictions, and I’m not sure but I’m guessing they’ve changed the registry on the server to not issue UAC prompts to non-admins when they try to add the printers - that’s part of changes MS made due to Print Nightmare (and the reg key change to rollback this security change is not recommended by MS, technically). Remember, in the post-Print Nightmare world, non-admins cannot add point-and-print connections (unless the exact driver and version happens to be pre-installed on their machine).

 

it’s worth checking what their plans are for syncing. If they have decommissioned the old AD I am assuming they are intending to move to syncing to Azure AD Standard/Graph - this will introduce a whole new set of challenges for them including MFA and UPN woes. PaperCut MF version 23 adds some more support for this stuff, and there are further User Client and Print Deploy Client changes planned for later to improve this / make things more seamless, but what they might have been angling at is using Print Deploy in PROMPT mode to push Mobility Print queues - this is the most surefire way to handle UPNs in PaperCut for now, as detailed on this page:

 

https://www.papercut.com/kb/Main/UsingUPNswithAzureADSync

 

Use Print Deploy in PROMPT mode (allowing users to authenticate with UPN/password), and if using server print queues, mix with one of the methods above, or switch to deploying Mobility Print queues

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...