Zero Day Nightmare Print Issue, how do I add Papercut Printer

NightWing2099 11 Reputation points
2022-03-05T12:09:23.737+00:00

Microsoft still hasnt truly fix the print nightmare issue. I want to install Followme printer onto Windows 2016 Domain via GPO. Which keeps failuring that I dont have the rights to do so. How I get a printer setup. I have followed the Point and Process which doesnt work. Can anyone help with a solution to this microsoft nightmare

Windows for business | Windows Server | User experience | Print jobs
Windows for business | Windows Client for IT Pros | User experience | Other
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. Alan Morris 1,336 Reputation points
    2022-03-07T20:30:42.437+00:00

    Hi @NightWing2099 ,

    I work at PaperCut now on the support team but I still hang out on Microsoft forums too.

    To be clear and honest, Microsoft has fixed the remote spooler security exploit. That is done and dusted. Malware can't be dropped on the machine in an authenticated way.

    The changes now for Windows Point and Print, that's making a connections to a shared printer, have new defaults from Microsoft. First, the users on the Windows client must have administrative access on the machine in order to install the software from the server. If that software on the print server is infected, being admin is really not going to help actually, that kind of makes it worse.

    Since you have GPO deployment, you can add a registry setting to the client machine which reverts the new default to the past behavior where a standard user can install this software. The software from the server is the print driver.

    Another new default is that non Windows printer connections are now longer allowed by default. There is a registry setting for this behavior too. If you are not all Windows, then you can't connect to the shares.

    A very good policy for some locations that are allowing non admin access to installing the software from the server is to allow only connections to the shared printers on the company assets.
    Computer / Admin Templates / Printers /Package point and print - Approved servers.

    Finally, please listen to my podcast on the topic. https://www.papercut.com/blog/print-geeks-012-deepcuts-printnightmare/

    Your PaperCut reseller has been dealing with this too so they may have additional guidance based on the printer models and drivers they suggest.

    Thanks

    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.