windows network printers ; a giant shitshow after printnightmare updates ( august 2021)

Peter Huiskens 47 Reputation points
2022-06-02T12:41:33.167+00:00

Hello All,

So first of all, before i start my story, i've been a sysadmin for about 15 years now, and i have tried everything i can think about , but the problems keep returning
So this post is a lengthy one since i am at a loss here.
Since the printnightmare updates from august 2021 we still run into massive problems with networked printers

the summary would be:
* the default printer keeps changing to a never used virtual printer ( like microsoft pdf or webex virtual printer)
* installed network printers suddenly stop working, i need to manually install the printer again
* the printer driver is suddenly missing and i need to manually install it again. but as user that gives an access denied message,

I get about 4-5 calls per day from users that suddenly can't print anymore due to one of the above 3 problems. ( this is with a userbase of about 400 users )
for the first; default printer keeps changing, i've tried different options like stop windows from managing the printer, but that doesn't seem to stick. , so the problem always returns.
for the second; the network printer stops working, the sollution is simple, just add it again and it works again.

for the third option i had to get a bit creative;
run: "rundll32 printui.dll,PrintUIEntry /il" as administrator, then add the network printer, and then do the same as the user
if i don't add it as admin, i get an access denied message, but that access denied message is gone after i first installed it as admin
all of the above options require a lot of time , and the repettitive task that it is, annoys the hell out of me
so far since the described update from august 2021 this has been a p.i..t.a. and i haven't found anything that permanently sticks.
if someone has suggestions i'd be happy to try them out.

just to be clear, I'm looking for a fix that will fix this at once for all our users / computers like gpo or deployment via sccm
powershell is fine too , but i wouldn't know where to start.

enviroment:
windows 10 (fat)clients, ranging from 1809 to 21h1 , we use roaming profiles since multiple users need to be able to logon to different pc's
We also have a VDI enviroment that can be used.
printserver: server 2016 and a 2019 server, both have the same issues
desktop management software: Microsoft Sccm

already tried:
* different printer drivers
* setting gpo for users to allow installation of printerdriver ( that has a strange sideeffect that you get an uac prompt, and need to enter credentials for almost every
app that allows priviledge escalation , for instance taskmanager or regedit), so that is not a valid option
* disable managing printers from windows, and use the old "set this printer as default"setting
* we tried using http printing ; but that system works terible and is very slow,
* googling for hours to find a solution, but all things suggested are not working

right now i am considdering removing and disallowing installation of KB5005010 ; but i wonder if that is even possible after 10 months after installation

so i was wondering, how do other organisation manage this, and why is this problem still in existance after 10 months?
i hope to hear from you,

With kind regards,
Peter

Windows Server Printing
Windows Server Printing
Windows Server: A family of Microsoft server operating systems that support enterprise-level management, data storage, applications, and communications.Printing: Printer centralized deployment and management, scan and fax resources management, and document services
698 questions
0 comments No comments
{count} votes

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.