Solved

Terminal Server - Prevent Users from seeing other printers

Posted on 2004-08-24
3
653 Views
Last Modified: 2008-03-06
This is a windows 2003 terminal server running quickbooks enterprise.

A couple of interesting points about quickbooks enterprise and its requirements on terminal server:  

According to their tech support users need to be in at least the Power Users group for the product to work correctly
Printer names can be no longer then 20 charecters for the printing to work from quickbooks

I have users accessing this from both inside and outside.  The inside users have appropriately named printers that quickbooks can print from without an issue.  For the outside users I've set up a script that renames their printer to one that meets the 20 charecter limit.  This has worked for the most part except for a small issue:

It seems that the users can browse everyone elses printers.  I've read an article that suggests power users can do this by default on a TS but I don't know where to modify this.  The question is two fold:

Does the power user group membership give the ability to see other users printers?
How can I modify this permission to assure users only see their own printers?

I'm somewhat TS and 2003 savvy but this one is eluding me hence the 500pts.  I welcome and appreciate all input and comments.
0
Comment
Question by:SamuraiCrow
3 Comments
 
LVL 9

Author Comment

by:SamuraiCrow
ID: 11900233
OK guys, after a day of staring down the barrel of this question I have come upon if not a true solution (being that the true problem is Quickbooks Enterprise REQUIRES users to be members of the Power Users group) at least it's a workaround.  Here's what I did:

Downloaded SubInACL from Microsoft:

http://www.microsoft.com/downloads/details.aspx?FamilyID=e8ba3e56-d8fe-4a91-93cf-ed6985e3927b&displaylang=en

Copied the EXE to the Terminal Server and set up the following batch file:

cd c:
cd\
cd c:\Kix\SubInACL
subinacl /printer * /revoke="power users"

Finally, I placed this batch file in the startup folder of the existing users and in the all users folder so that it automagically applies to new users logging on to the server for the first time.

In effect this script removes the Power Users from the ACL of any printer generated by clients logging in to the TermServ.  This in turn prevents the printers from being accessable to anyone but the user who generated them and administrators.  

With that I will close the question.  I hope this will save somebody out there some time someday.
0
 

Accepted Solution

by:
modulo earned 0 total points
ID: 12791690
PAQed with points refunded (500)

modulo
Community Support Moderator
0

Featured Post

Is Your Active Directory as Secure as You Think?

More than 75% of all records are compromised because of the loss or theft of a privileged credential. Experts have been exploring Active Directory infrastructure to identify key threats and establish best practices for keeping data safe. Attend this month’s webinar to learn more.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

I guess it is not common knowledge to most Wintel engineers/administrators: If you have an SNMP-based monitoring system in your environment (and it's common to have SNMP or Syslog) it's reasonably easy to enable monitoring of the Windows Event logs,…
This may not be a text book method to resolve VSS backup issues but it seemed to have worked on few of the Windows 2003 servers we had issues while performing a Volume Shadow Copy backup. If you have issues while performing a shadow copy backup usin…
Internet Business Fax to Email Made Easy - With eFax Corporate (http://www.enterprise.efax.com), you'll receive a dedicated online fax number, which is used the same way as a typical analog fax number. You'll receive secure faxes in your email, fr…
Both in life and business – not all partnerships are created equal. As the demand for cloud services increases, so do the number of self-proclaimed cloud partners. Asking the right questions up front in the partnership, will enable both parties …

920 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

14 Experts available now in Live!

Get 1:1 Help Now