Printer management (Windows 2003 R2)


hi!

 

server os: windows 2003 r2

ad schema: w2003 r2

clients: windows xp swedish different sp versions.

 

i’ve installed printer management (windows 2003 r2) , got problems.

i’ve created 1 security group each printer deployment make computers member of.

i’ve created 1 gpo each printer following security settings:

<picture gpo , security filtering each security group>

 

i’ve deployed printers this:

<picture each printer deployed each gpo object. per-machine gpo>

 

one gpo running ”pushprinterconnections.exe” @ client.

i’m giving computer accounts membership security groups (see above) , printers deploying. it’s working well.

but

when remove computer account security group printers not removed!

when i’m logging ”pushprinterconnections.exe” get:

microsoft windows operating system deploy printer connections utility v1.0

copyright (c) microsoft corporation. rights reserved.

 

... logging enabled command line switch.

... logging started @ 15:26:41  2010-04-13.

... found , applied gpo: printer_gbg_city_canon.

... found , applied gpo: printer_gbg_a0_plotter_vån9      .

... found , applied gpo: printer_gbg_canon_vån9.

... found , applied gpo: printer_thn_canon.

... found , applied gpo: default domain policy.

... found , applied gpo: printer_gbg_canon_vån8.

... found deployed printer connection setting \\xxxsrv02\gbg city canon in active directory.

... found deployed printer connection setting \\xxxsrv02\gbg a0 plotter vån9 in active directory.

... found deployed printer connection setting \\xxxsrv02\gbg canon vån9 in active directory.

... found deployed printer connection setting \\xxxsrv02\thn canon in active directory.

... found deployed printer connection setting \\xxxsrv02\gbg canon vån8 in active directory.

... there no connections remove.

... deploying per machine connection \\xxxsrv02\gbg city canon.

... deploying per machine connection \\xxxsrv02\gbg a0 plotter vån9.

... deploying per machine connection \\xxxsrv02\gbg canon vån9.

... deploying per machine connection \\xxxsrv02\thn canon.

... deploying per machine connection \\xxxsrv02\gbg canon vån8.

deploy printer connections utility logs ”there no connections remove” , installing 5 pcs of printers don’t want deploy anymore.

 

i’m checking computer account membership:

h:\>gpresult /scope:computer

 

operativsystemet microsoft (r) windows (r) xp.

verktyg för resultat av grupprincip v2.0

copyright (c) microsoft corporation 1981-2001

 

skapades den 2010-04-13 15:35:02

 

 

resultat för xxx\xxxxxxx på centurion: loggningsläge

--------------------------------------------------------

 

operativsystemstyp:            microsoft windows xp professional

operativsystemskonfiguration:  medlemsarbetsstation

operativsystemsversion:        5.1.2600

domännamn:                     xxx

domäntyp:                      windows 2000

platsnamn:                     klippan

central profil:

lokal profil:                  c:\documents , settings\es000000

anslutning över långsam länk:  nej

 

 

datorinställningar

-------------------

    cn=centurion,ou=workstations_ou,ou=xxx_ou,ou=sweden_ou,dc=xxx,dc=local

 

    grupprincipen tillämpades senast:   2010-04-13 @ 15:26:33

    grupprincipen tillämpades från:     xxx.xxx.local

    tröskelvärde för långsam länk:      500 kbps

 

    tillämpade grupprincipobjekt

    -----------------------------

        tech.all.computer

        default domain policy

 

    följande grupprincipobjekt tillämpades inte eftersom de filtrerades bort

    -------------------------------------------------------------------------

        printer_none

            filtrering:  inte tillämpad (okänd orsak)

 

        tech.gbg.users

            filtrering:  inaktiverad (grupprincipobjekt)

 

        printer_thn_canon

            filtrering:  inte tillämpad (okänd orsak)

 

        printer_gbg_a0_plotter_vån9

            filtrering:  inte tillämpad (okänd orsak)

 

        printer_gbg_canon_vån8

            filtrering:  inte tillämpad (okänd orsak)

 

        printer_gbg_canon_vån9

            filtrering:  inte tillämpad (okänd orsak)

 

        tech.all.users

            filtrering:  inaktiverad (grupprincipobjekt)

 

        lokal grupprincip

            filtrering:  inte tillämpad (tom)

 

        printer_gbg_city_canon

            filtrering:  inte tillämpad (okänd orsak)

 

    datorn är medlem följande säkerhetsgrupper:

    ---------------------------------------------

        administratörer

        alla

        användare

        nätverk

        autentiserade användare

        centurion$

        domain computers

 

h:\>

the computer not member of group deploy printers to

 

what’s wrong?

 

best regards

jonas

sorry swedish non existant.  had in english understand see.  see when removing machine account security group this:

gpresult /scope:computer

    applied group policy objects
    -----------------------------
        default domain policy
        modeling policy
        mach1                                           ---------> there printer here                                  
        mach2                                           ---------> , here
        local group policy

    following gpos not applied because filtered out
    -------------------------------------------------------------------
        users group
            filtering:  denied (security)

        building1_printers
            filtering:  not applied (empty)

        userconnections
            filtering:  denied (security)

        user2policy
            filtering:  denied (security)

        user3policy
            filtering:  denied (security)

    computer part of following security groups
    -------------------------------------------------------
        builtin\administrators
        everyone
        nt authority\network
        nt authority\authenticated users
        machine group2          -------------> security group picks connection in mach2 gpo
        machine group            -------------> security group picks connection in mach1 gpo
        domain computers
        certsvc_dcom_access

after removing the machine the security group machine group , machine reboot, printer connection obtained mach1 gpo is removed.  thing find interesting fact mach1 policy not listed in " following gpos not applied because filtered out" list.  hope sheds light you.

computer settings
------------------

    applied group policy objects
    -----------------------------
        default domain policy
        modeling policy
        mach2
        local group policy

    following gpos not applied because filtered out
    -------------------------------------------------------------------
        users group
            filtering:  denied (security)

        building1_printers
            filtering:  not applied (empty)

        userconnections
            filtering:  denied (security)

        user2policy
            filtering:  denied (security)

        user3policy
            filtering:  denied (security)

    computer part of following security groups
    -------------------------------------------------------
        builtin\administrators
        everyone
        machine group2
        domain computers
        certsvc_dcom_access

================================================================================

ppcmachine.log information

microsoft windows operating system deploy printer connections utility v1.0
copyright (c) microsoft corporation. rights reserved.
 
... logging enabled command line switch.
... logging started @ 3:18:05 pm  4/23/2010.
... found , applied gpo: default domain policy.
... found , applied gpo: modeling policy.
... found , applied gpo: mach2.
... found , applied gpo: mach1.
... found deployed printer connection setting \\spl-printdc5\building 2 machine printer in active directory.
... found deployed printer connection setting \\spl-printdc5\building 3 machine printer in active directory.
... there no connections remove.
... deploying per machine connection \\spl-printdc5\building 2 machine printer.
... deploying per machine connection \\spl-printdc5\building 3 machine printer.

after removal , reboot.

microsoft windows operating system deploy printer connections utility v1.0
copyright (c) microsoft corporation. rights reserved.
 
... logging enabled command line switch.
... logging started @ 3:37:23 pm  4/23/2010.
... found , applied gpo: default domain policy.
... found , applied gpo: modeling policy.
... found , applied gpo: mach2.
... found deployed printer connection setting \\spl-printdc5\building 2 machine printer in active directory.
... connection \\spl-printdc5\building 3 machine printer removed.
... deploying per machine connection \\spl-printdc5\building 2 machine printer.
... removing per machine connection \\spl-printdc5\building 3 machine printer.


alan morris windows printing team; search microsoft knowledge base here: http://support.microsoft.com/search/default.aspx?adv=1


Windows Server  >  Print/Fax



Comments

Popular posts from this blog

some help on Event 540

WMI Repository 4GB limit - Win 2003 Ent Question

Event ID 1302 (error 1307) DFS replication service encountered an error while writing to the debug log file