Jump to content
EduGeek EdSec 2026 is Go! 27th Oct in Derby! Join us for a day of EdTech security focused talks, networking, and an evening social ×

Michael

Edu Supporters
  • Posts

    12,849
  • Joined

Everything posted by Michael

  1. Have a look here It's related to Microsoft August 2021 patches for all mainstream OSes.
  2. Last I looked no, you need Outlook 2016/2019.
  3. Xerox, Kyocera, Ricoh, RISO & Toshiba.
  4. Yes! Computer Config > Policies > Admin Templates > Printers > Point and Print Restrictions Specify server.fqdn and the drop down menus as follows: Create a GPP regedit: HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows NT\Printers\PointAndPrint Value: RestrictDriverInstallationToAdministrators Dword: 0 Registry on a workstation should look like this - User Config > Policies > Admin Templates > Control Panel > Printers > Point and Print Restrictions Specify server.fqdn and the drop down menus as follows: All working with Type 3 drivers. As I say, Microsoft's solution of disable Point and Print just isn't viable. Specifying your print server's FQDN via GPO is the best you can do to secure connections, but I expect in coming months they'll revise the guidance/recommendations.
  5. Presumably you can still see these users in G Suite Admin? Is the old domain still there, acting as an alias or not?
  6. Yes - Point and Print Computer/User GPOs have to remain enabled, with GPP regedit.
  7. Just to confirm I'm testing on the following, but should apply to any Windows 10 flavour - Build Windows 1607 LTSB & Windows Server 2016 + August 2021 Patch, or build 14393.4583 Using Ricoh PCL6 Universal Driver, Type 3 - Signing in as user with Domain Admin rights = no issues or prompts related to printers - Signing in as user with Standard rights = no issues or prompts related to printers I should add I have Point and Print GPOs configured in both Computer and User contexts And the GPP regedit added in a Computer context.
  8. About 8 so far - Christmas is normally worse than the Summer in my experience.
  9. This is why I haven't taken this approach. As you say, when Group Policy refreshes, then logically it'll see the user isn't a Domain Admin or Local Admin (whichever applies) and then removes access to the print share. GPP or script changes are generally pretty quick on modern versions of Windows. As I say, I think Microsoft's approach is - disable Point and Print, then you're secure, offering no real alternative on how to deploy printers. This isn't a solution in my view. It's like saying disable the print spooler on every workstation, then you're secure. The whole printer model/spooler service needs re-writing.
  10. There must be a conflict of GPP policy or script, as this regedit can't be added as a GPO. Microsoft may add it as a GPO at a later date maybe?
  11. The short version: Leave your Point and Print GPO 'as is' like this example, including your servername.fqdn: Create the following GPP regedit: HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows NT\Printers\PointAndPrint Value: RestrictDriverInstallationToAdministrators Dword: 0 Registry should look like this on a workstation:
  12. @gshaw - have you resolved this issue now?
  13. I've seen this behaviour before - it's simply a case of connecting an Ethernet cable or a USB Ethernet adapter, then an Ethernet cable. The newly imaged computer will then check into Microsoft and then continue as normal.
  14. Reassuring it's not just me! As per my registry screenshot here if you leave the registry keys as 1 and 2, rather than both 0, it should work as before. It's this bit in particular which is confusing. My understanding setting these as 0 effectively disables Point and Print. Microsoft's 'solution' appears to be disabling Point and Print resolves the security issues, but that really isn't the solution. Also (on the same reply), specifying allowed servers on the Point and Print GPO, should greatly reduce the surface area of attack. The theory being to successfully run the exploit, you'd either have to spoof the FQDN of your print server, or somehow take over your print server altogether. It just all seems highly unlikely coming from the outside world, but most likely someone on your LAN in terms of probability.
  15. What version of Papercut are you running? The latest is version 21. I'd be interested to know whether this has any bearing.
  16. Actually this does make sense - The default is either 0 for both entries, or they don't exist at all. As I wrote above, the answer would still be false for the majority of admins.
  17. Apologies for the slow reply - I had to digest this as I found it somewhat confusing - July 2021 Advisory So in my case (and I expect 99% of admins), the above are false. Those registry keys are controlled by Comp Configuration > Administrative Templates > Printers > Point and Print Restrictions, so need to be left 'as is' if you want to continue using Point and Print. What doesn't make any sense, are that both drop down menus are set to Do not show warning or elevation prompt but read as 1 and 2 and not 0 in the registry - August 2021 Advisory This guidance makes more sense: I appreciate this needs to be a managed security risk, but it's unclear whether this needs to remain as 0 each time printers are applied in an end user (non admin) context, or whether this can be set to 1 after a set period of time. By all means if I've understood anything incorrectly, please let me know!
  18. Not had any other reported issues, but I have noticed Google are now up to version 50.0.11.0. By disconnecting from Google Drive, clearing Google Chrome's cache/cookies etc.. and a restart has cleared any similar issues.
  19. My honest opinion is I think Microsoft are being somewhat disingenuous whether this issue is truly fixed. Longer term I suspect Type 4 drivers will be the norm, but back on planet earth, the vast majority of corporate/school environments probably will be using Point and Print + Type 3 drivers. In summary, these are the steps I took to evaluate each environment - On your Print Server, load up Print Management, then on the right navigate to More Actions > View > Add/Remove Columns, then add 'Type'. This'll give an overview of drivers in your environment. Highly recommended - add your Print Servers to an allow list servername.fqdn for both User and Computer GPOs, by amending the Point and Print GPO. Add the following GPP regedit - HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows NT\Printers\PointAndPrint Dword: RestrictDriverInstallationToAdministrators Value: 0 That's all you can do for now!
  20. I'm onto Google Support now, what exactly did they have to do to resolve this?
  21. Interestingly I've had one user report the exact symptoms this morning. @TwistedHelixis - is it possible you can PM your Google case number please, so they have something to relate to?
  22. I normally enable the Windows FW on the Standard GPO, but disable it on the Domain GPO.
  23. I should add, Google do like screen captures, so they can see exactly what's happening first hand, rather than a paragraph of text!
  24. At least you've narrowed it down to 4 devices. What version of Windows are you running? I'd be tempted to re-image where possible.
  25. Presumably doesn't mean O365 Admin > Users > Contacts
×
×
  • Create New...