We help IT Professionals succeed at work.

Administrator can see other users' printers in a 2003 terminal server session

Medium Priority
Last Modified: 2013-11-21

i have a windows 2003 terminal-server (with sp1)
i have 10 users ho have no administrator-rights and they all have there local printer when they connect to the terminal-server with rdp.
i have 1 user ho have administrator-rights, and that user can see all the printers of the other users.
The problem is that that user print sometimes on the wrong printer.

Is there a way to make that user not to see other users printers ?

Watch Question

nprignanoTechnical Architect

This only happens if your users have Power User rights or higher.  If you want to resolve this, reduce their permissions, or convert all of your local printers into network printers, use login scripts to map printers based on group membership or username, and finally turn off connect session printers.  I ran into this same problem setting up users on Citrix - if certain programs require users have certain rights, you can set the progrma to run as a higher level, or switch to network printers.  In the end, thats the easiest method.



is there really no way to set the account of that administrator to not see other users printers, that woud bee the best sollution for me.


If a user has administrator rights then they are an Administrator and therefore can manage the machine.  I know if one of my users couldn't figure out which printer to use I sure wouldn't make them an administrator on a server.  That user has enough rights to blow up that machine and they can't even print correctly.  You might want to rethink the setup.

Technical Architect
>>is there really no way to set the account of that administrator to not see other users printers, that woud bee the best sollution for me.

the only way is to turn off session printing domain wide.  but then you would need your printers as network printers to be able to print.  welcome to the lovely world of terminal services.  things aren't always as easy as an option that you can select or deselect.


Not the solution you were looking for? Getting a personalized solution is easy.

Ask the Experts


Yes, there is a way. There a policy you need to change either locally on the terminal server by going to Start>Run and opening gpedit.msc or from a group policy in AD. Here's the details...

Load and unload device drivers
Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment

Determines which users can dynamically load and unload device drivers. This privilege is necessary for installing drivers for Plug and Play devices.

Default: Administrators.
Access more of Experts Exchange with a free account
Thanks for using Experts Exchange.

Create a free account to continue.

Limited access with a free account allows you to:

  • View three pieces of content (articles, solutions, posts, and videos)
  • Ask the experts questions (counted toward content limit)
  • Customize your dashboard and profile

*This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.


Please enter a first name

Please enter a last name

8+ characters (letters, numbers, and a symbol)

By clicking, you agree to the Terms of Use and Privacy Policy.