Re: Inherited Permissions for Printers

From: Herb Martin (news_at_LearnQuick.com)
Date: 01/11/05


Date: Tue, 11 Jan 2005 09:19:46 -0600


"Chriss3 [MVP]" <noSpamHere@chrisse.se> wrote in message
news:eMZ8B1#9EHA.2996@TK2MSFTNGP10.phx.gbl...
> Hello Paul,
> Good question. Yes it's possible to inheritance the Security (ACL) from
the
> computer object in the Active Directory, since all printers published in
> active directory is child objects to it's host/computer/server.

I don't think so. The Printer's so published are not
"children" of the computer object for several reasons
but the most important is that Computer objects are
NOT containers.

Also note, the Computer object in AD will not get
you permissions to the actual PRINTER (queue)
anyway.

Also, since these are local printers they may not
even be published in AD.

> You can give the "IT Helpdesk Staff" Full Control of child objects of type
> PrinterObjects or just Add / Remove Printer Objects. You should see an
entry
> for the Printer Operators group with rights Add / Remove Printer Objects
in
> the ACL list on the computer/host/server object in AD.

Unless I am totally wrong about this, there is no
place to "inherit permissions" on the PRINTER
(queue) share objects themselves since they have
no parent.

I.E., you still won't be able to print.

A Restricted Group MIGHT help but the group
used will need to be one that is already assigned
by default, or there must be another way to give
this group the requisite permissions.

A startup script might wrap this stuff up by
enumerating Print shares etc.....

-- 
Herb Martin
>
> -- 
> Regards
> Christoffer Andersson
> Microsoft MVP - Directory Services
>
> No email replies please - reply in the newsgroup
> ------------------------------------------------
> http://www.chrisse.se - Active Directory Tips
>
> "Paul Hadfield" <paul@anon.com> skrev i meddelandet
> news:%239EC3G99EHA.1084@tk2msftngp13.phx.gbl...
> > All,
> >
> > I realise this is a printing question, but I think it's probably more
> > GPO/AD related too.
> >
> > Is there any way that permissions for locally installed printers on a
> > Windows 2000 Advanced  server can be set to inherit in the same way that
> > files and folders can? E.g. when someone creates a new local printer, I
> > want to be able to specify what the default security permissions will be
> > set to.
> >
> > We have a Windows 2000 domain with print queues set up locally on
Windows
> > 2000 Advanced Server member servers. I'm trying to set up our member
> > servers so that when a member of the domain security group "IT Helpdesk
> > Staff" creates a new local printer, the correct permissions are
> > automatically assigned to it and all the IT staff needs to do is add the
> > relevant User groups with print access.
> >
> > The domain secirity group "IT Helpdesk Staff" has only domain user
rights
> > but is also a member of the local Power Users group on the Windows 2000
> > member servers, and so has full permissions to create new printers
> > locally.
> >
> > Thanks again,
> > Paul.
> >
> >
> >
>
>


Relevant Pages

  • Re: Inherited Permissions for Printers
    ... > Everyone groups so that a newly created print queue will only have the ... > Administrators and PowerUsers group in the security permissions. ... Herb Martin ... >>> computer object in the Active Directory, ...
    (microsoft.public.win2000.active_directory)
  • Re: Join domain requirement
    ... 1)create computer object in the active directory using domain admin ... Yes, if you grant the 4 permissions, a normal user (with no other admin ... GUI then grants the same 4 permissions listed in my previous link to the ...
    (microsoft.public.windows.server.active_directory)
  • Re: Join domain with access deny using domain user
    ... I have try precreate the computer object on the OU that I suppose the ... create computer objects on that or you can pre-create the computer account ... the command work perfectly fine with the domain admin or if i just add ... user doesn't have permissions to create the computer account in that OU, ...
    (microsoft.public.windows.server.active_directory)
  • Re: Joining Computers to Domain
    ... had to do with lacking the rights to reset a password on an existing ... because the computer object was not in the OU where I had the rights ... From the Permissions box, click to select the Allow check box next to ... >>>Instead of delegating at the OU, ...
    (microsoft.public.windows.group_policy)
  • Re: Inherited Permissions for Printers
    ... when a member of IT Helpdesk Staff creates a new printer ... Everyone groups so that a newly created print queue will only have the ... Administrators and PowerUsers group in the security permissions. ... the Computer object in AD will not get ...
    (microsoft.public.win2000.active_directory)

Loading