Solved

Allow Windows 7 Users to Update Network Printer Drivers connected to a Server 2003 Domain

Posted on 2010-11-30
10
1,171 Views
Last Modified: 2012-05-10
I am in the middle of deploying Windows 7 computers on a Server 2003 domain and have noticed that the Windows 7 has several more security settings than what is shown in the Windows 2003 Server Active Directory GPO.  For example I am trying to allow the Windows 7 users to update printer drivers without administrative rights, and I think I do this through the Point and Print Security in the GPO, and this option is not on the 2003 Server GPO.

Two part question:  1) How can I allow windows 7 users to update their own printer drivers?  It it is through the "Point and Print" GPO, how can I load this on my Windows 2003 server to configure it?
0
Comment
Question by:shrimpfork
  • 6
  • 3
10 Comments
 
LVL 9

Expert Comment

by:BDoellefeld
ID: 34241836
Yes, your on the right track. The point and print security is what you want.

The difference is, you'll want to edit the GPO using a Windows 7 client and the option will be there. The ADM file will be saved along with the policy.

0
 
LVL 6

Expert Comment

by:FDomingos88
ID: 34241844
I think that they need to be power users, as described in this website http://support.microsoft.com/default.aspx?scid=kb;en-us;297780 .
0
 

Author Comment

by:shrimpfork
ID: 34241876
BDoellefeld,
Please elaborate, how do I edit a 2003 GPO using a Windows 7 client?  I want to avoid going around to 40 windows 7 machines and have the policy set on the 2003 server.

0
What is SQL Server and how does it work?

The purpose of this paper is to provide you background on SQL Server. It’s your self-study guide for learning fundamentals. It includes both the history of SQL and its technical basics. Concepts and definitions will form the solid foundation of your future DBA expertise.

 

Author Comment

by:shrimpfork
ID: 34241904
FDomingos88,
My XP users do not have this problem, it is only with the new Windows 7 machines.  Adding then as a power user causes other problems.  I need a GPO setting.
0
 
LVL 9

Accepted Solution

by:
BDoellefeld earned 500 total points
ID: 34262794
Hello.

Your question "Please elaborate, how do I edit a 2003 GPO using a Windows 7 client?  I want to avoid going around to 40 windows 7 machines and have the policy set on the 2003 server."

On a Windows 7 client, install the Windows Remote Server Administration Tools and enable Group Policy Management
Full procedure outlined here: http://www.addictivetips.com/windows-tips/how-to-install-the-group-policy-management-in-windows-7/ 

Once installed, again from the Windows 7 client, create/edit the GPO for the print security. The additional ADMX file that applies will be saved with the policy on the 2003 domain controller, so no need to upload new ADM files.

In my case I created a new GPO specifically for this option and linked it at the domain level. Since the policy only affects options which are available on Windows 7, XP and 2000 clients are unaffected.
0
 

Author Comment

by:shrimpfork
ID: 34285212
BDoellefeld,
This looks good.  Give me a day to get this applied...stand by.
0
 

Author Comment

by:shrimpfork
ID: 34343209
BDoellefeld,
I got the GPO applied through a Win 7 client, but the workstations don't seam to be taking the policy.  They still require an admin to change drivers.  Any suggestion?
0
 
LVL 9

Expert Comment

by:BDoellefeld
ID: 34345515
Hi. Here is a screen of the settings I use, maybe check your settings against these. I have no issues.


Win7-PrintGPO.png
0
 

Author Comment

by:shrimpfork
ID: 34347778
I think I got it....but not sure why.  I originally placed the GPO in the OU that hold the computers.  When I moved it over to the OU that hold the users, it seems to work.  I thought it would work in either OU, even since it was a user GPO setting.
0
 

Author Comment

by:shrimpfork
ID: 34347857
I think I got it....but not sure why.  I originally placed the GPO in the OU that hold the computers.  When I moved it over to the OU that hold the users, it seems to work.  I thought it would work in either OU, even since it was a user GPO setting.
0

Featured Post

Simplifying Server Workload Migrations

This use case outlines the migration challenges that organizations face and how the Acronis AnyData Engine supports physical-to-physical (P2P), physical-to-virtual (P2V), virtual to physical (V2P), and cross-virtual (V2V) migration scenarios to address these challenges.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

On some Windows 7 (SP1) computers, Windows Update becomes super slow even the computer is reasonably fast.  There's one solution that seemed to have worked well for me (after trying a few other suggested solutions).
Last week, our Skyport webinar on “How to secure your Active Directory” (https://www.experts-exchange.com/videos/5810/Webinar-Is-Your-Active-Directory-as-Secure-as-You-Think.html?cid=Gene_Skyport) provided 218 attendees with a step-by-step guide for…
This tutorial will walk an individual through the process of transferring the five major, necessary Active Directory Roles, commonly referred to as the FSMO roles from a Windows Server 2008 domain controller to a Windows Server 2012 domain controlle…
This Micro Tutorial hows how you can integrate  Mac OSX to a Windows Active Directory Domain. Apple has made it easy to allow users to bind their macs to a windows domain with relative ease. The following video show how to bind OSX Mavericks to …

840 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question