Windows Server 2019 AD DC / Windows 10 Client - Unable to deploy printer on client computer

Kristaps Esterliņš 41 Reputation points
2022-01-11T14:12:09.88+00:00

Good Day!

I am trying to figure out the reason why I cannot successfully deploy our network printers via Windows Server 2019 Print Management. The infrastructure is as follows:

Server - One DC (ad1.domain.lv)

Client - Hyper-V Virtual Machine, Windows 10 Professional x64 21H1 (TEST-PC1) connected to the domain. Computer is in Domain Computers group

User - Test User with Users rights

Printer - Konica Minolta Bizhub 284e . Driver - PCL6 v5.4.0.0

Printer driver has been added in the Print Management and is visible under Drivers

163899-image.png

The printer was add and configured and is ready for deployment

163869-image.png

After that I created a new security group, under Active Directory Users and Computers => OU => Printers and named it Konica Minolta Bizhub 284e (Printer Driver 5.4.0.0). The group contains ONLY the TEST-PC1 workstation

To deploy the printer, I created a new group policy object, named it the same name as the security group, removed the Authorized Users group and added the Security Group (Konica Minolta Bizhub 284e (Printer Driver 5.4.0.0)). In the Delegations tab the Authorized Users groups was added again, only with Read permissions.

The group policy object was linked to the OU => Workstations entry

The printer was deployed with "Per Machine" Connection Type. and after the reboot the printer was visible on the client workstation. After I deleted the workstation from the security group and deleted the printer driver via the local Print Server I was unable to deploy the printer again. Now it shows the following message:

Group Policy was unable to add per computer connection \xxx-DC\Konica Minolta Bizhub C284e (Printer Driver 5.4.0.0). Error code 0xBCB. This can occur if the name of the printer connection is incorrect, or if the print spooler cannot contact the print server

Unfortunately I cannot find the culprit of this issue and the next challenge is - how to properly deploy printer drivers and delete them from client computer if the workstation is removed from the specific printer's security group.

Thanks!

163936-1.png

Windows Server Printing
Windows Server Printing
Windows Server: A family of Microsoft server operating systems that support enterprise-level management, data storage, applications, and communications.Printing: Printer centralized deployment and management, scan and fax resources management, and document services
641 questions
0 comments No comments
{count} votes

Accepted answer
  1. Limitless Technology 39,376 Reputation points
    2022-01-11T20:16:58.96+00:00

    Hello @Kristaps Esterliņš

    This is probably due to recent updates to protect from the PrintNightmare exploit.
    Only users with Admin rights would be able to see the printer because the would have access to the drivers. One workaround is to install manually the printer drivers locally, and this will allow any users on the computer to map the device. Otherwise Microsoft released an article regarding the printer and printer driver management post patching:

    https://support.microsoft.com/en-us/topic/kb5005652-manage-new-point-and-print-default-driver-installation-behavior-cve-2021-34481-873642bf-2634-49c5-a23b-6d8e9a302872

    Hope it helps,

    ------------

    --If the reply is helpful, please Upvote and Accept as answer--

    0 comments No comments

0 additional answers

Sort by: Most helpful