How can I grant users the ability to pause/resume printing without a "print operators group" password.

Greetings,
We are running 10.8.5 on 30 machines in an active directory environment (graphics lab). The clients are experiencing a persistant error when pausing or resuming print jobs. Each time something is paused, it requires an administrator password to resume the job. Administrators are not always present so designers are locked out of all of the printers until we come in (or remote in) to authenticate.
I spoke with Apple today and they said they would not support active directory accounts and that the account must be edited by the department that created the account because the restrictions come from the Active Directory account preferences.
On the other hand, I ALSO read that I can edit this in the CUPS interface or modify it with the terminal command below, locally.
dseditgroup -o edit -u admin_name -p -a user_name -t user _lpadmin
"dseditgroup" adds the user_name to a group (in this case, _lpadmin).
And admin_name is the name of your administrator's account.
a) Must this be modified on the Active directory account or CAN I modify this on the local machine via CUPS or terminal?
b) If so, how would I grant users the ability to resume printing without an admin password?
c) If not, exactly what must be modified in the active Directory account to allow pause/resume without an admin password.
I have seen a terminal command that adds users to the print operatiors group (Ipadmin) and I have seen some info on editing the CUPS interface, If i must edit the CUPS interface to allow this, can anyone point to detailed instructions on how to make this change.
I also saw info on editing the CUPS interface but the suggestion lacked details as to how and how to return to default if it does not work.
I also saw a post with these suggestions below but without detail as to how one would carry this out.
/etc/cups/cupsd.conf
# All administration operations require an administrator to authenticate...
<Limit CUPS-Add-Modify-Printer CUPS-Delete-Printer CUPS-Add-Modify-Class CUPS-Delete-Class CUPS-Set-Default CUPS-Get-Devices>
AuthType Default
*#Require user @SYSTEM*
*Require valid-user*
Order deny,allow
</Limit>
# All printer operations require a printer operator to authenticate...
<Limit Pause-Printer Resume-Printer Enable-Printer Disable-Printer Pause-Printer-After-Current-Job Hold-New-Jobs Release-Held-New-Jobs Deactivate-Printer Activate-Printer Restart-Printer Shutdown-Printer Startup-Printer Promote-Job Schedule-Job-After CUPS-Accept-Jobs CUPS-Reject-Jobs>
AuthType Default
*#Require user @AUTHKEY(system.print.operator) @admin @lpadmin*
*Require valid-user*
Order deny,allow
</Limit>
/etc/authorization
+The system.print.operator key is new to Snow Leopard and seems to control resuming and pausing a printer queue among other things.+
<key>system.print.admin</key>
<dict>
<key>allow-root</key>
<true/>
<key>class</key>
<string>user</string>
<key>group</key>
<string>staff</string>
<key>shared</key>
<true/>
</dict>
<key>system.print.operator</key>
<dict>
<key>allow-root</key>
<true/>
<key>class</key>
<string>user</string>
<key>group</key>
<string>staff</string>
<key>shared</key>
<true/>
</dict>
I have read all posts on this subject and I still am not clear on how to proceed, please assist.
Thanks in advance,
V

Hello again.  For AD environments you can run the following command on each workstation:
sudo dseditgroup -o edit -n /Local/Default -u localadmin -p -a "Domain Users" -t group _lpadmin
This command assumes you are typing this interactively on the machine.  Obviously change localadmin to the Mac's local admin's name.  When running you will be prompted for password twice.  Once to elevate permissions (sudo) and once to validate you are localadmin.
If you are using Apple Remote Desktop (or JAMF or other management suite), you can push this command out while embedding the localadmin's password. 
sudo dseditgroup -o edit -n /Local/Default -u localadmin -P yourpass -a "Domain Users" -t group _lpadmin
Please note, if your password uses special characters (/-\) this may fail over ARD.
In Mavericks, AD groups are cached once they are referenced.  If you are dealing with a lot mobile users (laptops) you might want to replace Domain Users with everyone
R-
Apple Consultants Network
Apple Professional Services
Author "Mavericks Server – Foundation Services" :: Exclusively available in Apple's iBooks Store

Similar Messages

  • How can I turn off the ability to turn off the phone from the lock screen for more security?

    How can I turn off the ability, to turn off the phone, from the lock screen for more security?

    There is no such option.
    There will be some additional features included with iOS 7.
    http://www.tuaw.com/2013/06/10/ios-7-to-include-security-feature-dubbed-activati on-lock/

  • How can I grant users to access/modify system folders (C:/Windows/Fonts) by using GPO in Win7 ?

    In our company there are some folks that require often new fonts that they take from the internet. Unfortunately, some of them have offices on in a diferrent country, so going there to insert my admin paswoord is not a solution.
    If you copy the ttf file into the C:/Windows/Font folder is enough, you don't have to also add the registry.
    One way to bypass the window that asks for admin credentials is to insert my crdentials into the bat file (runas). But this is very unsecure, as I am an administrator.
    Is there a way to create a shared folder that can also store fonts that can be used by windows? Can I give them the right to modify files in this folder without making them administrators? Or do you see any solution to this issue? Any help would
    be greatly appreciated.
    Thank you in advance.

    Another solution which will not compromise your security is to create a share folder and have the users to download fonts to the folder. After that a simple schedule task GPO on clients to copy the
    *.ttf files from the folder to the C:\Windows\Fonts folder. Since tha task can be run by administrative privileges I guess there will be no problem.
    Regards.
    Mahdi Tehrani Loves Powershell
    Please kindly click on Propose As Answer
    or to mark this post as
    and helpful to other people.

  • How can I restrict ONLY the ability to make purchases  on an Apple TV?

    I would like to set a password for purchases on my Apple TV in order to prevent my children from accidentally purchasing content. I am able to do this, however, turning on restrictions also forces a password to be entered to open the Netflix app. I do not want to restrict Netflix or any other app that doesn't offer purchases.
    I'm finding this to be a very frustrating problem and I also find the lack of some sort of purchase restriction as a default setting very suspect. The device should protect from unwanted purchases from the start, and it should not be so difficult to block unwanted itunes purchases without also blocking out other apps (If that's even possible). I've been using apple products almost exclusively for over 20 years primarily because they are (were) user-focused and user-friendly... I'm very disappointed in this oversight, and frankly it's hard to believe that it isn't intentional.
    Apologies if this isn't the place for complaints. If anyone can help me with this problem I would be very appreciative.

    I don't know what AppleTV can handle as far as bit rate is concerned, but increase the bit rate as high as it will let you. You are taking DV which is 25Mb/s and compressing it. If you're making an H.264, you should get great results needing no more than 6Mb/s. Bear in mind, the higher the bit rate, the larger the file size.

  • How can one scape from the edit window of an appointment without saving changes?

    I did move accidentally an appointment with invitees and it opened the edit windows, but I can´t escape from it without sending uselessly the changes to invitees !

    mardem,
    Try iCal>Edit>Undo.

  • How can I access user accounts on Macbook running 10.4 without resetting passwords

    Is it possible to access the desktop without resetting passwords?

    Not if if you don't have auto log-in turned on.
    Resetting or changing a password:
    For Snow Leopard or earlier:  http://support.apple.com/kb/HT1274
    If it's running Mac OS X 10.6.8 or earlier, insert a Mac OS X install DVD, restart with the Option key held down, click on it, and use the Reset Password utility.

  • How can I delete all the email from a user's account?

    I have a user account with a huge amount of mail (around 50K messages) that Apple Mail can't deal with... it constantly hangs and/or crashes whether I use POP or IMAP to try and delete all the mail from the client.
    How can I delete all the mail from the mailbox on the server? I don't want to delete the account entirely, I just want to empty everything out of it.
    Thanks!

    sudo -u _cyrus /usr/bin/cyrus/bin/ipurge -d 0 -f user/mailboxname
    HTH,
    Alex

  • How can i get all the users from weblogic server?

    how can i get all the users from weblogic server?
    i have configurated a LDAP server using iPlanet and
    in weblogic server console i see those users from LDAP
    server. but how can i get all the users in my program
    from weblogic server instead of LDAP server?
    BTW,how to configure a RDBMSAuthenticator and what should i do
    in Oracle? which tables should i create? and how are their architectures?
    Thanks
    Daniel

    BTW, i use weblogic platform 8.1
    "Daniel" <[email protected]> дÈëÓʼþ
    news:[email protected]..
    how can i get all the users from weblogic server?
    i have configurated a LDAP server using iPlanet and
    in weblogic server console i see those users from LDAP
    server. but how can i get all the users in my program
    from weblogic server instead of LDAP server?
    BTW,how to configure a RDBMSAuthenticator and what should i do
    in Oracle? which tables should i create? and how are their architectures?
    Thanks
    Daniel

  • How can I find out the screen size of the users moniter using the Acrobat SDK?

    How can I find out the screen size of the users moniter using the Acrobat SDK? I need to know how much sreen real estate that is available on the users moniter. Is there some call that I can make from the SDK to discover the maximun X and Y coordinates?
    Thanks,
    Gregory

    Currently, I am testing on multiple moniters and it is defaulting to the moniter designated as the #1 moniter. For our purposes, this is acceptable. Once the two documents have loaded, the user can move and re-size at will.
    Gregory

  • How can I find out the list of users who has the access to IT 0008

    All,
    How can I find out the list of users who has the W R permission for IT 008
    for others?
    SUIM doe not look like giving me the correct results.
    Please advise.
    Thanks,
    From
    PT.

    combine tables AGR_1251 and table AGR_Users on keyfield AGR_USERS
    in tabel AGR_1251 select on Field LOW values IT0008.OR W OR R,
    noiw you get also other values
    So better solution run the query twice over AGR1251 first on IT0008 and secondly on values W OR R and then the result over table AGR_USERS
    Youu also might put an additional selection on object P* (only selecting HR objects)
    output wll be UID in table AGR_USERS

  • Can I create a form that allows users the ability to add fields?

    I would like to create an asset order form I can host on my company's intranet. I would like to give the users the ability to add additional fields per item they request rather than provide them with a limited amount of fields. For example, the template available from Formscentral has 5 dropdown selection boxes with predetermined supplies to choose from. My office receives requests for multiple, varying assets that I would not be able to list in generic dropdown selection boxes. I want to give users the freedom to enter item titles and provide URLs to online stores they would like me to purchase them from. I want my form to begin with two fields for this information and provide users with an add button that creates two additional fields for each additional item requested.

    Hi,
    In Acrobat Form, you create a hidden Text Field which will only get visible on a Button click for inserting additional text.
    Regards,
    Anoop

  • How can we find all the available  user-exits in sap without using SMOD?.

    How can we find all the available  user-exits in sap without using SMOD?.

    Hi,
    Please check this links for user exits list.
    http://www.planetsap.com/Userexit_List.htm
    http://www.easymarketplace.de/userexit.php
    http://www.sap-img.com/ab038.htm
    Regards,
    Ferry Lianto

  • How can i stop user to get the same screen while entering same T code

    hi experts,
    how can i stop user to get the same screen while entering same T code (_Means i want user enter same t code but got different different screen how it is possible.)_
    i want to know how can we set a authorization is such a manner ...
    Through different different login id user got different different screen while entering same T-code.
    for example if there is two functional login id mum & noida...
    then user login through that and
    enter any same functional tcode (for getting purchase order)
    but get different different window...so how come it is possible.....
    plz explain in brief
    thanks in advance...plz do reply as soon as possible

    For a custom transaction this is easy, you need to ask your developers to be able to direct users to different screens based on the results of an authorisation check.  You could have an auth field e.g. ZSCREEN which is checked in the program & decides what screen the user has access to.
    For standard transactions, unless already coded, I would forget it & do what is recommended by Subramaniam and create transaction variants as required.  Assign each variant to a custom t-code and users access it that way.
    What I am interested is is why do you want to do this?

  • How can give permissions to the users in wiki?

    Hi, in wiki how can give permissions to the users, i need to give one of the users full control for wiki only ( not the server ), so how can make this user wiki admin?.

    No answer!!??
    I Need to put one of staff as Wiki Admin then he can manage it ( Delete, Edit ...etc ), Wiki Creators users can't full admin the Wiki.
    Please help.

  • How can we prevent viewing the source code  of JSP by the user

    Dear sirs,
    how can we prevent viewing the source code by the user ( from the browser for the Viwe Sorce option) for a JSP file that use struts frame work.
    infact i don't wan the user to view the javascript that in incorporated in the JSP for various purpose...
    thanks and regards...
    Sudheesh K S
    INDIA

    Dear sirs,
    how can we prevent viewing the source code by the
    user ( from the browser for the Viwe Sorce option)
    for a JSP file that use struts frame work.
    infact i don't wan the user to view the javascript
    that in incorporated in the JSP for various
    purpose...
    thanks and regards...
    Sudheesh K S
    INDIAJSP and Servlets are programs/scripts that run on the server. The user/clients only sees the HTML output generated by the server. If you want to hide JavaScript from casual users then you can put the JavaScript code in a seperate file. This file can however be read from the Cache.

Maybe you are looking for

  • Problem with the MVMapView.print(printMapDiv,) function.

    Hello, I have a problem with the MVMapView.print(printMapDiv,) function. My FOIs are displayed correct on the screen but on the printed letter the stroke(border) color and the labels of a circle are not displayed. the fois have a custom style: var xm

  • Write.vi error

    In the attached VI, I am getting the following error Error -200547 occurred at DAQmx Write (Analog Wfm 1Chan NSamp).vi Possible reason(s): Measurements: DAQmx Write failed, because a previous DAQmx Write automatically configured the output buffer siz

  • Fcp keeps crashing on capture

    Please help! I don't know why this is happening. I am pasting the crash report - as this is the 2nd time since trying to capture. Process:         Final Cut Pro [757] Path:            /Applications/Final Cut Pro.app/Contents/MacOS/Final Cut Pro Ident

  • Any issues with having Personalization in Dev and not Production

    Hi, I'm wondering if there are any issues with having Personalization configured in our Dev and not Production?  If you run a create a query or Web Template in Dev with personalization and transport it to production which doesn't have personalization

  • Wifi is connected but nothing loads

    Off and on when using a Wifi in a hotel or at Starbucks etc., I have a strong network signal but nothing will load...my Touch checks for e mail but nothing happens, the weather application tries to update but nothing happens, internet errors with thi