Google Groups no longer supports new Usenet posts or subscriptions. Historical content remains viewable.
Dismiss

Adding Local Printers and Group Policy Restrictions?

14 views
Skip to first unread message

Brian Smith

unread,
Oct 23, 2001, 12:08:24 PM10/23/01
to
Allowing users to add and remove printers via GP does not
allow users to add a local printer in our domain...the
local option in Add Printers is greyed out. I cannot find
where to allow this or where we are preventing it. My
guess is it has something to do with the user not being a
local admin to the box, but I'm not sure. Any help/ideas
would be appreciated.

Andreas Kjellman [MSFT]

unread,
Oct 23, 2001, 6:25:31 PM10/23/01
to
You must be a Power user or Administrator to be able to add local printers.
There is no GPO to change this behaviour.
--
Of course, this posting wouldn't be complete without a nice, juicy
disclaimer from our lawyers: This posting is provided "AS IS" with no
warranties, and confers no rights. You assume all risk for your use. © 2001
Microsoft Corporation. All rights reserved.


"Brian Smith" <i...@flrsbx.com> wrote in message
news:201a01c15bdc$f15448d0$9be62ecf@tkmsftngxa03...

Brian Smith

unread,
Oct 24, 2001, 9:15:33 AM10/24/01
to
Wow...that really sucks. I don't want users to be able to
install apps and if I make them a Power User, they can.

>.
>

Andreas Kjellman [MSFT]

unread,
Oct 24, 2001, 9:33:19 AM10/24/01
to
The requirement of beeing Power User to be able to add local printers is
hardcoded in the o/s, so that can't be changed. If you need that, you must
give your users Power Users rights.

A user can install some applications even if they are only Users. However,
it is possible to restrict Power Users so they got the same rights on
filesystems and registry as a normal user, and they will find it a lot more
difficult to install applications.

For this second option, locate basicwk.inf in
%systemroot%\security\templates. Create a copy and change the template to
give Power User the same access rights as Users got. This security template
can then be loaded in a GPO in AD to be applied to local machines. You'll
then have the case that the users are Power Users on the machine, but on
their machine they only got normal Users rights to registry and filesystem.

Giving them Power Users right also gives them some other built-in rights,
like sharing folders. Built-in rights is documented in technet.

--
Of course, this posting wouldn't be complete without a nice, juicy
disclaimer from our lawyers: This posting is provided "AS IS" with no
warranties, and confers no rights. You assume all risk for your use. © 2001
Microsoft Corporation. All rights reserved.


"Brian Smith" <i...@flrsbx.com> wrote in message

news:350701c15c8d$f6194580$b1e62ecf@tkmsftngxa04...

0 new messages