Jump to content

Recommended Posts

Posted

Last I checked they still hadn't (yesterday). This issue only came about as the network in question and printer drivers were installed prior to July 2016. I was required to update the drivers yesterday and there was the problem.

 

End users see the 'Trust driver install' notification, but despite clicking Install, it continues to re-prompt them.

Posted

In Group Policy there is the setting Computer Policy setting Under Administrative Templates > Printers > Point and Print Restrictions.

 

Initially when I rolled out GPP Printers 2 years ago I had issues where printers were not getting deployed and used this setting.

Point and Print Restrictions: Enabled

Users can only point and printe to these servers: Enabled and listed Print Servers.

 

In Security Prompts:

When installing drivers for a new connection: Do not show warning or elevation prompt

When updating drivers for an existing connection: Do not show warning or elevation prompt

 

Does this windows kill this deployment??

Posted
In Group Policy there is the setting Computer Policy setting Under Administrative Templates > Printers > Point and Print Restrictions.

 

Initially when I rolled out GPP Printers 2 years ago I had issues where printers were not getting deployed and used this setting.

Point and Print Restrictions: Enabled

Users can only point and printe to these servers: Enabled and listed Print Servers.

 

In Security Prompts:

When installing drivers for a new connection: Do not show warning or elevation prompt

When updating drivers for an existing connection: Do not show warning or elevation prompt

 

Does this windows kill this deployment??

 

Essentially what's happening is if the driver isn't packaged (like the Canon drivers), it will ignore the 2 x Do not show warning or elevation prompt. Using the registry tweak above will make Windows Server 'think' the driver is packaged and install it without prompting the end user.

  • Thanks 1
Posted
Essentially what's happening is if the driver isn't packaged (like the Canon drivers), it will ignore the 2 x Do not show warning or elevation prompt. Using the registry tweak above will make Windows Server 'think' the driver is packaged and install it without prompting the end user.

@Michael Thanks for clearing that up. Will bear in mind (try to remember) if the Print Deployment stops working all of a sudden .

Posted
Hello all,

 

Note this involves modifying the Registry, so please take care!

 

As many of you are aware, installing KB3170455 and equivalent can cause havoc with Point and Print Restrictions, but I've stumbled across a few websites and came up with the following -

 

If you navigate to Admin Tools > Print Management. Highlight your print server, then 'Drivers'

 

Scroll across to the 'Packaged' column. If the driver reads 'true' it means it can be deployed with Point and Print Restrictions without prompting the user. If it reads 'false' it means the driver won't work well with Point and Print Restrictions, however the following tweak makes Windows Server treat the driver as packaged.

 

Close Print Management, then open regedit and navigate to (in turn):

 

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Print\Environments\Windows x64\Drivers\Version-3\Printer Name

 

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Print\Environments\Windows NT x86\Drivers\Version-3\Printer Name

 

Look for 'PrinterDriverAttributes' and set it to a value of 5.

 

Now restart the Spooler and return to Print Management. The 'Packaged' column should now read 'true' for all printers you modified.

 

I've so far tried this with a Canon Photocopier, as none of their drivers are packaged and neither are RISO's or Oki (next on the list). Ricoh's and Kyocera's are packaged and HP are 50/50 depending on the model.

 

I hope this helps someone else :)

 

Yep you are right, the Canon is showing false yet nearly all the others are packaged.

Posted
Last I checked they still hadn't (yesterday). This issue only came about as the network in question and printer drivers were installed prior to July 2016. I was required to update the drivers yesterday and there was the problem.

 

End users see the 'Trust driver install' notification, but despite clicking Install, it continues to re-prompt them.

 

It seems that Canon hasn't updated the driver download pages but see the last post by johnnypg here: https://social.technet.microsoft.com/Forums/windows/en-US/4c3e2b2d-3caa-4540-a93e-4abf88b5a95b/point-print-restrictions-gpo-not-working-as-expected-in-windows-10?forum=win10itprogeneral

  • Thanks 1
Posted
Another reason to stick with my Server 2008 R1 print server, though your fix looks very handy.

 

I'm still running 2008 R2 print server and i still got this problem with my printers.

Posted (edited)

Yup, R2 is affected, R1 is not.

 

Just done this on a secondary 2012 R2 print server, seemed fine. I haven't had any reported problems because I held KB3170455 back, but no doubt an update rollup will include it at some point.

Edited by 3s-gtech
Posted

 

Thanks for this, but I'd rather wait until Canon release it through the proper channels. I can confirm however it has worked 100% with the Canon drivers, so will try it out with RISO's next as their drivers are even worse.

Posted
None of my printers in the registry have a PrinterDriverAttributes key. Can this just be created with a value of 5?

 

Thanks.

 

You sure? All of mine have got it?

 

Screenshot 2016-10-06 09.13.51.png

Posted
Yeah. Here we are.

 

[ATTACH=CONFIG]38978[/ATTACH]

 

This fix won't affect very old, unsupported versions of Windows Server - nothing before 2008 R2 has this setting. However, you won't get the point-and-print restrictions error anyway.

Posted
It is a 2003 server yes. I have however been receiving the prompt to install the driver since installing the update despite having my point and print restrictions set to to disabled.
Posted

Thinking about it, the problem has been created with newer Microsoft OSes to tighten up security, so the limiting factor is still the client rather than the server OS in this case.

 

You must (logically) have a newer server somewhere in your domain 2008 R2 or later, with Windows 10 GPOs installed, which then allows you to control the behaviour of Point and Print Restrictions. In saying that, I would suggest ditching 2003 altogether and moving your servers to 2008 R2 or later. Then the reg fix would apply.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...