Re: how to forbid users to connect directly to printers



"Lanwench [MVP - Exchange]"
<lanwench@xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx> wrote in
news:ekAGNMYFIHA.1324@xxxxxxxxxxxxxxxxxxxx:

Yann <Yann@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote:
Lanwench, I totally agree with you... unfortunately it's too late,
they have already been granted local admin rights, that's why they
can use printers without using the server. But the suggestion was
good.

Thanks


OK, but that doesn't really explain why you you can't *revoke* the
rights. Talk tothe business owners about the dangers of granting users
permissions they don't actually require - they can get infested with
very damaging malware, viruses, can deliberately or inadvertently make
changes to the operating system & network, install illegal software
(for which the company is likely liable), etc.




"Lanwench [MVP - Exchange]" wrote:

Perhaps this is a silly suggestion, but if you don't give users
local admin or power user rights, they won't be *able* to do this
(can't add local printers or printer ports at all).





I may be jumping into this a bit late - can't see the beginning of this
thread - but many network connected printers have internal settings to
limit the IP numbers that they will accept connections from. You could
set this to only allow access from the server. Turn off unused protocols
like Appletalk/IPP/FTP printing... Another way is if the printer can do
DLC protocol, you can set it to only do this, and have the server connect
using DLC - there is often a setting to make it exclusive so that once a
connection is made, it is not released when the print job is done so that
another computer can connect (the server just has to get there first for
this to work).

Or, if you have control over the network and have the right type of
switches so that you can create a VLAN that only the printer and server
are in, other machines could not see the printer.
.



Relevant Pages

  • Re: SCW question.
    ... Created a new Server and installed IIS. ... and saw that the default rights for IUSR and IWAM users are there. ... Server to the domain without and GPO's applied...Local Security policy ... rights (which coincides with my Member server GPO settings). ...
    (microsoft.public.windows.server.security)
  • Re: SBS 2003 folder redirection, offline files, ..and more
    ... you log into a shared PC with admin rights and go to Windows Explorer Folder ... documents are redirected to the server. ... without redirection, they wouldn't have been. ...
    (microsoft.public.windows.server.sbs)
  • Re: file rights issue...
    ... Domain Admin has rights to everything so not being able to access the ... The Terminal Server is an entirely different ... of BV we are running uses an SQL DB engine called Pervasive SQL to ... the accounting data on the Windows 2000 server through the pervasive ...
    (microsoft.public.backoffice.smallbiz2000)
  • Re: Error
    ... This posting is provided "AS IS" with no warranties, and confers no rights. ... the network or Internet, and then try again. ... You are trying to use a file that is stored on a server, ... protocols in the Player are not enabled. ...
    (microsoft.public.windowsmedia.player)
  • Re: sbs2003 to (new)server2003 user issue
    ... Meinolf Weber ... This posting is provided "AS IS" with no warranties, and confers no rights. ... sbs server dead sunday night. ... Even if the account in the domain and the local account on the ...
    (microsoft.public.windows.server.active_directory)