I do not know what guys are doing different. I followed Microsoft practices for configuring security settings. Then, i connected to all available printers published on printerserver which will then download neccessary drivers, of course with local admin. Then use builtin export drivers powershell function to a folder. Removed all non-printerdrivers. Then use this exported folder to deploy once with SCCM for example to all devices. Now when that is all done, users can connect to any printershare without admin. So long as client has same driver as printerservers (assuming you do not update printerdriver on the serverside to another version of course) all will work flawelessly.
Now when a new printerdriver is published, repeat steps above and only published the delta to endpoints and you are good to go.