Link to home
Start Free TrialLog in
Avatar of parts_peripherals
parts_peripherals

asked on

Administrator can see other users' printers in a 2003 terminal server session

Hi,

i have a windows 2003 terminal-server (with sp1)
i have 10 users ho have no administrator-rights and they all have there local printer when they connect to the terminal-server with rdp.
i have 1 user ho have administrator-rights, and that user can see all the printers of the other users.
The problem is that that user print sometimes on the wrong printer.

Is there a way to make that user not to see other users printers ?

Rudy
p&p
Avatar of nprignano
nprignano
Flag of United States of America image

This only happens if your users have Power User rights or higher.  If you want to resolve this, reduce their permissions, or convert all of your local printers into network printers, use login scripts to map printers based on group membership or username, and finally turn off connect session printers.  I ran into this same problem setting up users on Citrix - if certain programs require users have certain rights, you can set the progrma to run as a higher level, or switch to network printers.  In the end, thats the easiest method.


nprignano
Avatar of parts_peripherals
parts_peripherals

ASKER

is there really no way to set the account of that administrator to not see other users printers, that woud bee the best sollution for me.

Rudy
p&p
If a user has administrator rights then they are an Administrator and therefore can manage the machine.  I know if one of my users couldn't figure out which printer to use I sure wouldn't make them an administrator on a server.  That user has enough rights to blow up that machine and they can't even print correctly.  You might want to rethink the setup.

Darren
ASKER CERTIFIED SOLUTION
Avatar of nprignano
nprignano
Flag of United States of America image

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
Ruby,

Yes, there is a way. There a policy you need to change either locally on the terminal server by going to Start>Run and opening gpedit.msc or from a group policy in AD. Here's the details...

Load and unload device drivers
Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment

Description
Determines which users can dynamically load and unload device drivers. This privilege is necessary for installing drivers for Plug and Play devices.

Default: Administrators.