Solved

Add local printer with group policy and user alternate credentials - (ET)

Posted on 2016-11-08
5
27 Views
Last Modified: 2016-11-16
I am trying to use group policy to map local printers on another domain over a VPN (see screenshot). Computers and domain controller are on Domain-A and printers are on Domain-B. I have to add them as local printers because of a certain unique printing scenario they have.
Group policy for local printers
 The GPO keeps failing because of failed failed credentials, which i understand.  
Event ID 4098
Can anyone think of a possible solution outside of manually adding them to each computer and entering the proper credentials? I have thought of a few possibilities:
- Have group policy object use alternate credentials. I dont know if this is even possible
- Change the security permissions on these printers to allow guest users. Again not sure if this is possible.
- Use a batch script rather than GPO and have it use alternate credentials. I tried working on this but couldnt figure out the right commands.
- Add domain-B credentials into credentials manager and then maybe group policy will work. Tried this option but might have put something in wrong because it didnt work.
0
Comment
Question by:tabush
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 3
  • 2
5 Comments
 
LVL 37

Expert Comment

by:Mahesh
ID: 41879955
On server where printers are shared, have you given everyone print permissions
Also try adding another domain users (domainA\group) print permissions
also domainA domain admins group should have manage printer permissions on printers
You should have trust between both domains in order to work above

The printers should get mapped as long as users have permissions to print and they are able to reach printers over SMB protocol (TCP 445)
0
 
LVL 2

Author Comment

by:tabush
ID: 41880535
Yes i have given EVERYONE print permissions but i think that only refers to everyone in domain-B active directory.
I dont think it will let me add domain users from domain-A unless i setup a trust. I dont think i can do that in this scenario for security reasons.
0
 
LVL 37

Expert Comment

by:Mahesh
ID: 41880964
Yes, that will not work unless you have trust between domains
Everyone is not domain specific, however users to cross AD boundary, trust would be required
0
 
LVL 2

Accepted Solution

by:
tabush earned 0 total points
ID: 41884192
I figured it out. I had to add the credentials to credentials manager on the computer then in the group policy object enable the setting "Run in logged-on user's security context"
0
 
LVL 2

Author Closing Comment

by:tabush
ID: 41889427
I figured out the solution on my own.
0

Featured Post

Is Your AD Toolbox Looking More Like a Toybox?

Managing Active Directory can get complicated.  Often, the native tools for managing AD are just not up to the task.  The largest Active Directory installations in the world have relied on one tool to manage their day-to-day administration tasks: Hyena. Start your trial today.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

My GPO's made for 2008 R2 servers were not allowing me to RDP into a new 2012 server by default.  That’s why I tried to allow RDP via Powershell, because I could log into a remote shell without further configuration. Below I will describe how I wen…
When you try to share a printer , you may receive one of the following error messages. Error message when you use the Add Printer Wizard to share a printer: Windows could not share your printer. Operation could not be completed (Error 0x000006…
In this Micro Tutorial viewers will learn how they can get their files copied out from their unbootable system without need to use recovery services. As an example non-bootable Windows 2012R2 installation is used which has boot problems.
This tutorial will walk an individual through the steps necessary to join and promote the first Windows Server 2012 domain controller into an Active Directory environment running on Windows Server 2008. Determine the location of the FSMO roles by lo…

733 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question