RE: Anonymous Web based printing for standard users

From: DaveB (DaveB_at_discussions.microsoft.com)
Date: 03/02/05


Date: Wed, 2 Mar 2005 07:25:06 -0800

Cliff,

We have the same problem and have been srtuggling with it for some time now.
I doubt you will get any help from Microsoft. This seems to be part of the
"all or nothing" mentality that has been their foundation for years. An
effective security policy should be one that allows some flexability to give
users rights to perform routine operations without having to give them the
keys to the kingdom.

The only solution that we can find is to temporarily add the user to the
local admin group, login and install the printer(s) as the user, then remove
them from the admin group.

So much for efficient administration!

DaveB

"Cliff" wrote:

> I'm having some problems setting this up correctly. A company wants a
> solution where a client can plug into their network, browse to a webpage and
> connect to a printer. I have set a DNS alias for the Print server with IIS on
> called Printers and auto-forward to http://printers/printers. I have
> installed Web based printing, enabled Internet Printing in the Web Service
> Extensions and enabled Web-Based Printing in the Default Domain Group Policy.
> The IIS anonymous user has been given print rights to all the printers and
> the Directory Security for the site has been set to Anonymous access only.
>
> This works to a degree as i can see all the printers available and check the
> status of them but if a standard user (non-local admin) tries to connect it
> comes up with "you do not have enough privilege to complete the printer
> installation on the local machine" on WinXP clients or "Access Denied" on
> Win2K clients.
>
> I have done a bit of searching and from what i've read there are 2 ways
> which the printer is installed, either using IPP or RPC. When IPP is used it
> creates a local queue which requires local admin rights and with RPC it does
> the spooling remotely so therefore doesn't require admin rights. Here's a
> quote:
>
>
>
> --------------------------------------------------------------------------------
>
> When the Initialize and script ActiveX controls not marked as safe setting
> for the local intranet is set to Disable or to Prompt, Windows creates a
> remote procedure call (RPC) printer connection when you try to connect to an
> intranet-based printer through your Web browser. In this scenario, printer
> installations are successful for both users and administrators because RPC
> printer connections use the Windows remote spooler.
>
> --------------------------------------------------------------------------------
>
>
> I've tried messing with this setting, adding the server to the trusted zone
> and dropping security to low for Intranet but nothing seems to make any
> difference, anyone got any ideas?



Relevant Pages

  • Re: Client Installation Issues: SMS 2.0 SP5
    ... Log on locally as LOCAL admin and install. ... Log on Locally as domain user who has LOCAL admin rights. ... The SMS Service account IS a domain admin ...
    (microsoft.public.sms.setup)
  • Re: Deny Interactive Logon but Allow Runas
    ... that occasionally an install can become 'corrupt' and needs re-installing. ... client has version 6 of the software, with fix pack 2, so they need to get ... We've tried virtualisation, running VMware, and giving the users local admin ...
    (microsoft.public.windowsxp.security_admin)
  • Local Vs. Domain Accounts
    ... there u can choose if he´s a local user or admin! ... admins can install everything ... ... >the local admin which does not have access to my network ... >How can I allow the regular user account to install, ...
    (microsoft.public.windowsxp.security_admin)
  • Re: Flash Install needs Administrator Rights
    ... It will install so far (that nice little blue line ... > itself - the local admin account. ... > to the local workstation, logging in as local admin, and installing? ...
    (microsoft.public.win2000.active_directory)
  • Re: Deny Interactive Logon but Allow Runas
    ... users may also need to install a fix-pack, ... be an admin to install. ... if your secret app is really so bad ... As our users don't have local admin rights they usually have ...
    (microsoft.public.windowsxp.security_admin)