The domain users without administrative permission cannot install printers shared on printer server

Dears
We have a printer server that OS is Windows server 2003 .And all clinets are installed windows 7.Now,the domain users cannot installed printers shared on the printer server.When i logon the clinent computer with a domain user and access printer server by
URL \\192.168.37.1 ,i can see all printers shared on the printer server.Then i double click on printer to install it on client computer.It will ask me to input user name and password of local administrator .  
How to install the printers with domain user directly. Thanks

refer step #8:
http://blogs.msdn.com/b/7/archive/2011/07/11/allowing-standard-users-to-install-network-printers-on-windows-7-without-prompting-for-administrative-credentials.aspx
Don
(Please take a moment to "Vote as Helpful" and/or "Mark as Answer", where applicable.
This helps the community, keeps the forums tidy, and recognises useful contributions. Thanks!)

Similar Messages

  • Installing the Java-Plugin without administrative rights

    I would like to find a way to allow a user without administrative rights to install the Java-Plugin for using Java-Applets. As far as I understood, the plugin can be installed in a silent way withou registry modifiactions. Is this working for users without admin rights?
    Furthermore I would like to have the web page containing the applet installing the plugin (if necessary) in a fully automatic way so the user does not need to deal with installing the plugin manually. This should work without admin rights as well.
    Any ideas?

    I would like to find a way to allow a user without
    administrative rights to install the Java-Plugin for
    using Java-Applets. As far as I understood, the
    plugin can be installed in a silent way withou
    registry modifiactions. Is this working for users
    without admin rights?Could anyone please explain, why it is so difficult for Sun to create an installation package for user without admin rights? The whole "GetJava"-program is just crap for ordinary users if they get the JRE downloaded seamlessly and then the installation fails due to missing admin rights. This way Java would never succeed on the desktop.
    Andr�

  • Allowing the domain users Group to SCCM 2012 Remote Control

    Hi There,
    been working on this issue for the last few days now and its frustrating the crap out of me. My company has requested for all Domain users to be allowed to Remote Control to everyone's computer. This is so that users will be able to show each other how to
    use in house application. In SCCM 2012 console, I've added the Domain users to the Premitted viewer tab. I've also added the domain user group to the administrative user section, added the Remote operator role and assigned the
    ALL security scope to it. On another machine, i run the CMRCviewer to this machine and it prompts for username advising me the one i provided isn't authorized. when i check on the targeted machine, i can see domain users populated in the ConfigMgr
    remote control user group
    It seems only domain admins have rights to Remote control in. i've only got one client setting defined (default policy).
    the interesting thing is the following layout
    WINDOWS XP ---> WINDOWS 7      prompts for username
    WINDOWS 7 -----> WINDOWS XP  works
    WINDOWS XP -----> WINDOWS XP  works
    WINDOWS 7 ------> WINDOWS 7     prompts for username

    Hi Dave,
    1) yes domain users is part of the configMgr remote control users". CMRCSERVICE.log shows the following
    === Starting security handshake ===
    CmRcService
    11/03/2013 10:44:29 AM
    4808 (0x12C8)
    HandshakeWorker failed.. 
    The logon attempt failed (Error: 8009030C; Source: Windows)
    CmRcService 11/03/2013 10:44:29 AM
    4808 (0x12C8)
    Security filter server: DoHandshake failed.. 
    The logon attempt failed (Error: 8009030C; Source: Windows)
    CmRcService 11/03/2013 10:44:29 AM
    4808 (0x12C8)
    m_pSecFilter DoHandshake() failed. CmRcService
    11/03/2013 10:44:29 AM 4808 (0x12C8)
    DoHandshake failed on server side. 
    The logon attempt failed (Error: 8009030C; Source: Windows)
    CmRcService 11/03/2013 10:44:29 AM
    4808 (0x12C8)
    Failed to do Handshake in Server. 
    The logon attempt failed (Error: 8009030C; Source: Windows)
    CmRcService 11/03/2013 10:44:29 AM
    4808 (0x12C8)
    Failed to create security context.. Security Handshake failed.
    The logon attempt failed (Error: 8009030C; Source: Windows)
    CmRcService 11/03/2013 10:44:29 AM
    4808 (0x12C8)
    Failed to validate Security requirement.. 
    The logon attempt failed (Error: 8009030C; Source: Windows)
    CmRcService 11/03/2013 10:44:29 AM
    4808 (0x12C8)
    Failed to complete the RDP connection.. 
    The logon attempt failed (Error: 8009030C; Source: Windows)
    CmRcService 11/03/2013 10:44:29 AM
    4808 (0x12C8)
    i've confirmed this user is part of domain users as well.

  • HT6030 I have 2011 iMac it came with os x 10.6.6 i just upgraded the hard drive and now i cannot install OS X 10.6.6 every time i start installing after selecting the language it come up with error " OS X can't be installed on this mac " please help

    I have 2011 iMac it came with os x 10.6.6 i just upgraded the hard drive and now i cannot install OS X 10.6.6 every time i start installing after selecting the language it come up with error " OS X can't be installed on this mac " please help

    Be sure to start your iMac using its original grey System Install DVD: Insert that disc and start your Mac while holding the d key. At the Mac OS X Utilities screen select Disk Utility and format the hard disk. Select "Mac OS X Extended (Journaled)".
    Then, install OS X.

  • My Safari systematically use the wrong User Agent and I cannot fix it

    My Safari systematically use the wrong User Agent and I cannot fix it

    Back up all data before proceeding.
    Please triple-click anywhere in the line below on this page to select it:
    defaults delete -app Safari CustomUserAgent
    Copy the selected text to the Clipboard by pressing the key combination command-C. Quit Safari.
    Launch the built-in Terminal application in any of the following ways:
    ☞ Enter the first few letters of its name into a Spotlight search. Select it in the results (it should be at the top.)
    ☞ In the Finder, select Go ▹ Utilities from the menu bar, or press the key combination shift-command-U. The application is in the folder that opens.
    ☞ Open LaunchPad. Click Utilities, then Terminal in the icon grid.
    Paste into the Terminal window by pressing the key combination command-V.
    Wait for a new line ending in a dollar sign ($) to appear below what you entered. You can then quit Terminal. Test.

  • XML for Analysis parser: The 'Domain\User' value of the 'EffectiveUserName' XML for Analysis property is not valid.

    hi 
    i have sharepoint 2013 enterprise over sql server 2012 standard, and i want to create some reports trhought excel services and performance point using EffectiveUserName feature, but right actually my environment is not working, when a configure an excel
    to read a SSAS cube from my local machine the rol is ok, but when i published the excel and try to update from Internet Explorer this error is presenting
    XML for Analysis parser: The Domain\User' value of the 'EffectiveUserName' XML for Analysis property is not valid.
    Anybody can helpme is urgent find out for some solution
    thanks a lot

    Turns out that you need the SP Farm service account to be an admin on the SSAS server as well.  That fixed the problem for us.
    MS: Please update your documentation :)

  • Puzzled - parent domain user as administrator in child domain cannot add printer

    I've got a bare domain at the forest with 3 users and several "child" domains.  I'm trying to set it up so that the user (let's call it EA-Service) in the forest can do administrative work in each of the sub domains without having to log on to the various
    domains as each domain's domain administrator.  There are a handful of these domains at this time, but as we pick up more accounts (think hosting), we expect the number of domains to reach the hundreds.  I don't want hundreds of domain accounts
    to track.
    I thought adding EA-Service to a forest group called EA-Universal and adding EA-Universal to Builtin\Administrators on each of the domain controllers would give me administrator access on each of the domains.
    I spent a frustrating two days trying to add an internet printer's driver using EA-Service on one of the child domains and it kept failing (message wasn't clear).  Today I said, What the Heck, logon with my domain admin account on the child domain and
    try.  It worked.  I dropped the printer and then logged out and back in with my EA-Service account and I couldn't do it.  Clearly Builtin\Administrator isn't everything on a DC.
    What right, privilege, or piece of arcane magic did the domain administrator account have that the EA-Service account did not?  And how can I give that special whatever-it-might-be to my EA-Service account?
    How can I determine exactly what rights & privileges a particular userid on a machine has?  I could then compare the two sets of rights and see what was different.
    I really need to have a super-duper-administrator account to do various maintenance tasks and I don't want to have to use each domain's Admin account to do it. 
    Can y'all help me?
    -g

    I had an entire post built that took me all day with interruptions and poof, it's gone.  Rats.  Here is my second attempt:
    Assign permission on the resource using DL group.
    This last one is the one I'm having trouble with.
    I have to admint that I'm feeling very stupid about this whole thing.  Everyone seems to understand it completely.  I have read many posts and believe I understand them, but I'm not getting something as I've certainly not got it to work.
    I have seen some excellent writeup by Ace, Awinish, Meinolf that have really helped me understand the RBAC/AGUDLP/IGDLA.  This
    post by Ace Fekay is one such example among others.  I have read about the different group types and scopes.  I have read about rights, privileges and permissions.  I believe I understand them.  I've worked in security since IBM's
    RACF which is also RBAC.
    The problem is just what permissions need to be given to DA-DomainLocal (the group to which EA-Service, the forest user, ultimately belongs) so that its members have the same abilities as DA-Service (a domain administrator account on a child domain)?
    Clearly adding to Administrators on the child AD is insufficient as the EA-Service ID was directly added to it and it could not add a printer while DA-Service could.  EA-Service is also a member of the Enterprise Admins group on the parent/forest domain.
    What other permissions/rights/privileges does the DA-DomainLocal group (or directly, the EA-Service ID) still lack?  What are the differences between the access tokens/descriptors of EA-Service and DA-Service?  And how do I find out? 
    I believe I've seen some tool that showed them, but I can't seem to find it now that I'm looking.
    I listed the NTFS permissions (via AccessEnum from SysInternals) for the entire C drive and note that Administrators is on most of them and not once did I see something like Domain Admins appear and I saw nothing to do with printers at all.  The list
    was very long so I could have missed it if it was there.  I also used the same tool to look at the HKLM hive, but that was too large to browse through.
    I have set up the group structure exactly as Awinish suggested and remain stuck at the last piece.  If it was some specific resource I'd have no problem, I could add it, give it permissions/rights/privileges as needful.  The problem remains is
    that I don't know what those permissions/rights/privileges are nor how to discover a definitive list (I've seen some generic lists, but they don't list the exact names of the right/privileges).
    I'm sure I'm just being dumb.
    How do I go about discovering what permissions/rights/privileges that DA-Service has that EA-Service (via the DA-DomainLocal group) needs?
    I thank all of you for helping me.  I appreciate the time you are taking.
    -g

  • After joining computer to the windows doamin i cannot change password for Mac for the domain user

    After joining computer to the windows doamin i cannot change password for Mac for the domain user

    Hi,
    Did this problem occures after installed Windows 8.1 Update 1? Here is another thread that had similar problem. Also I don't think this problem relate with Domain. Please refer to the solution of the thread below for reference, If there is any
    progress, please let us know.
    http://social.technet.microsoft.com/Forums/en-US/08993680-b6f5-4e80-b031-d32fec97d682/not-able-to-right-click-on-tiles-after-81-update?forum=w8itproge
    Roger Lu
    TechNet Community Support

  • WLC integration with LDAP to authenticate domain users without Radius

    Dear All,
         I have a WLC 4404 with LWAPs, the customer has a microsoft LDAP and all users are joined to the domain and he wants the users to be authenticated against their domain accounts and this should be done automatically so that when users login to windows they are also authenticated and joined the WLAN.
    so how we can do that with the simplest way, without Radius server using only the LDAP and wwithout envolving any certificates.
    also i need to know when i add LDAP server to the WLC, how can i know that this LDAP is properly inegrated with the WLC ?
    thanks and BR

    Hi,
         I have followed the following document to make users authenticate against their AD domain accounts:
    http://www.cisco.com/en/US/products/ps6366/products_configuration_example09186a008093f1b9.shtml
    the device and the root of PKI certificates for the WLC were generated and installed successfully on the WLC, and now we are in the client (end user) part starting from the section "Generating a device certificate for the client" page 17, which as per the document to be done from the client PC using the client domain account, which consequently means this process is to be repeated for each end user separately, so my question is there any way to generate some sort of general certificate for all clients to be pushed through group policy to all client instead of making it PC by PC ?

  • Conflict with the domain/user management

    Unfortunately I configured the domain management twice with the Adobe server.
    As a result, the edcprincipalentity table has duplicate records (i.e my name appears twice in the table).
    I removed the duplicate domain and synchronized but I still able to see those records.
    Due to this issue, the AWS_ASSIGNED_ID field in the form shows Id of 'System Context Account' using which i'm unable to populate the logged in user's details.
    Any idea to remove the duplicate records?
    Thanks,
    Nith

    I traced my workflow and form I figured out there's something wrong with the process so that the logged in user details are not appearing.
    I tried opening the edcprincipaluserentity & edcprincipalentity tables to verify the assigned Id value of my principal.
    There I noticed the duplicate entry. I confirmed that each entry has duplicated in the table. Hence the process doesn't recognize the assigned id.
    Yesterday I tried re-installing the adobe suite and configured the domain again from scratch.
    Now it is working without any issues.
    Thanks & Regards,
    Nith

  • Give a windows domain user local administrative rights?

    I'm familiar with managing servers/computers in a windows environment, and I can't seem to find a tool to do something similar in OS X 10.5. I'm getting ready to ship a macbook pro to an employee who will be authenticating against our active directory windows domain for login. The machine is already setup to allow this (and I'm able to log in using my network credentials currently). However, I'd like to also give the user administrative rights so he can install software as he sees fit. In windows, I would just goto the groups section and add the user by typing in his account as : Domain\user and it would add him to that group. I haven't been able to find anything similar with the MacBook so far. Any help would be greatly appreciated.
    Message was edited by: vlitsupport
    Also.. if this needs to be in another section of the forum, please let me know.
    Thanks!
    Message was edited by: vlitsupport

    found a good tutorial:
    http://www.smallbizserver.net/Articles/tabid/266/articleType/ArticleView/Article ID/234/PageID/359/Default.aspx

  • Want to configure a GPO "Stop (domain) users [having admin rights] from installing software"

    Want to configure a GPO "Stop (domain) users [having admin rights for some particular users]  from installing/uninstalling software"
    Requirements :-
    1. Domain user should not be allowed to install/uninstall any software's. Rest all the actions can be performed by the user like an administrator can do.
    Please suggest if possible then how can I implement the same.

    Hi Amar Chand,
    You can do so by using certain Group Policy settings to control the behavior of the Windows Installer, prevent certain programs from running or restrict via the Registry Editor. The Windows Installer, msiexec.exe, previously known as Microsoft Installer,
    is an engine for the installation, maintenance, and removal of software on modern Microsoft Windows systems.
    You can try the following method to resolve this issue:
    Method 1: Disable or restrict the use of Windows Installer via Group Policy
    Open “GPMC”, create a GPO linked to the correct scope. You can refer to this article
    Create a new Group Policy object.
    Right-click it, click Edit, and then navigate to
    Computer Configuration/Policies/Windows Components/Windows Installer.
    In RHS pane double-click on Disable windows installer.
    Click Enable and configure the option as required. "Always "option indicates that Windows Installer is disabled.
    This setting affects Windows Installer only. It does not prevent users from using other methods to install and upgrade programs.
    Click Apply to save this configuration.
    Run gpupdate /force on the clients. 
    For your information, please refer to the following article to get more help:
    Managing options for computers through Group Policy
    http://www.microsoft.com/resources/documentation/windows/xp/all/proddocs/en-us/sag_wininstall_group_policy_computers.mspx?mfr=true
    Method 2: Restrict Programs from being installed via Registry Editor
    Open Registry Editor and navigate to the following key: HKEY_CURRENT_USER\Software\Microsoft\Windows\Current Version\Policies\Explorer\DisallowRun
    Create String value with any name, like 1 and set its value to the program’s EXE file.
    e.g., If you want to restrict msiexec, then create a String value
    1 and set its value to msiexec.exe. If you want to restrict more programs, then simply create more String values with names 2, 3 and so on and set their values to the program’s exe.
    Note: You may have to restart your computer.
    In addition, if you choose this method, you could deploy the registry configuration via GPO. Please refer to the following article:
    Configure a Registry Item
    http://technet.microsoft.com/en-us/library/cc753092.aspx
    Regards,
    Lany Zhnag

  • Error connectiong with teh SQL DB using the domain user

    Hello,
    I am installing BCM 7 SP02 on windows server 2008 / SQL server 2008 R2.
    i have insatlled the Virtual Units and added them to the HAC. When i try to launch them i have always error in the Core VU in the CEM component. in the log of the call dispatcher of the CORE VU i got the following:
    10:46:59.805 (05488/IpcWorker) WRN> Connection/01B84660 [172.29.6.41:21000<-172.29.6.39:53329]: Disconnecting due protocol error: Connection attempt with unidentified remote peer from
    10:47:00.403 (05636/BCMApplicationThread) ERR> Failed to initialize WCDService - near failure
    10:47:02.405 (02000/main          ) ALW> Watchdog: Application instance stopped
    10:49:07.094 (03452/main) ALW> Started [CallDispatcher] version [7.0.2.0] in virtual unit [Elis_Core] in computer [hostname] with process id [362c9234-437f-43fe-8daa-d11057fd38d6]
    and in the DataCollector ti have the folowing:
    16:25:09.396 (05544/TransactionHandler) ERR> Failed to connect to database destination [hostname- BCM_DEV_Monitoring_History] using [Driver=SQL Server;Server=hostname;Database=BCM_DEV_Monitoring_History;Trusted_Connection=no;UID=<protected>;PWD=<protected>;]
    16:25:09.396 (05544/TransactionHandler) ERR> SQLDriverConnect failed (/28000/[Microsoft][ODBC SQL Server Driver][SQL Server]Login failed for user 'DOMAIN\adminbcm_dev'.) : Connected = [false]
    16:25:09.396 (05544/TransactionHandler) ERR> Database = [], SQLState = [28000], errorCode = [18456] : [Microsoft][ODBC SQL Server Driver][SQL Server]Login failed for user 'DOMAIN\adminbcm_dev'.
    from the log of the SQl i saw the the domainuser adminbcm_dev is trying to connect to the DB as sql user authentication:
    01/09/2012 15:58:47,Logon,Unknown,Login failed for user 'DOMAIN\adminbcm_dev'. Reason: Attempting to use an NT account name with SQL Server Authentication. [CLIENT: IP]
    The DB was created using the same user and no error were generated, and the same user have the SA rights in the DB.
    In the VU of the Agents , Core and DB, the windows authentication option is checked and no password was provided.
    Does the "Trusted_Connection" should be YES, if yes how to change it?
    Thanks in advance for your help.

    The databse BCM_DEV_Monitoring_History  was created in the SQL server.
    I got just one error several hours hours ago in the CEM service:
    10:14:39.626 (01256/Message Receiver) ERR> Connection/03D1567C [0.0.0.0:0->172.29.6.41:21009]: Failed to receive from [172.29.6.41:21009] : Socket = [-1], BytesRead = [0] : TcpConnection::ReceiveSync, WSARecv failed - 10038 (0x2736) An operation was attempted on something that is not a socket.
    All the other errors are related to the Datacollectore.
    14:23:23.608 (01800/TransactionHandler) ERR> Failed to connect to database destination [MD1ODYWSV1 - BCM_DEV_Monitoring_History] using [Driver=SQL Server;Server=MD1ODYWSV1;Database=BCM_DEV_Monitoring_History;Trusted_Connection=no;UID=<protected>;PWD=<protected>;]
    14:23:23.608 (01800/TransactionHandler) ERR> SQLDriverConnect failed (/28000/[Microsoft][ODBC SQL Server Driver][SQL Server]Login failed for user 'DOMELIS\adminbcm_dev'.) : Connected = [false]
    14:23:23.608 (01800/TransactionHandler) ERR> Database = [], SQLState = [28000], errorCode = [18456] : [Microsoft][ODBC SQL Server Driver][SQL Server]Login failed for user 'DOMELIS\adminbcm_dev'.
    Use Windows Authentication for Database Connections ELIS_DEV_DB:YES
    Configuration Database Server Address or Name           ELIS_DEV_DB:MD1ODYWSV1
    Configuration Database Name                                          ELIS_DEV_DB:BCM_DEV
    Configuration Database User Name                                 {[BCM_DEV_00].[HAC_SERVICE_USER]}
    Configuration Database Password                                   nothing was added stayed Blank
    Internal Server Certificate in Use                                       checked
    Internal Server Certificate Common Name                          BCM.elis.priv
    Internal Server Certificate Issuer                                       elis-MD1ODYWSV1-CA
    Internal Server Certificate Store                                         HKLM/My

  • When i try to open a pdf, i am told that i must sing the end users agreement. I cannot find out how.

    It tells me when i update the adobe reader that by checking install i am accepting the terms and agreement. However when i try to use the program i am told that i must go to the web site and accept the user agreement . I cannot find out where to do this on the site. Any help?

    In your iPhone? I ask because there is a special subforum for the iOS version of Reader.
    http://forums.adobe.com/community/adobe_reader_forums/ios?view=discussions

  • Deploying a report to the end user without using Crystal Reports Server

    Hello,
      I'm using Crystal Reports Professional XI.
      I finished creating a report that contains several subreports.  Now it's time for me to deploy the report to the end user so that they can start running it.  The company that I'm doing this consulting work for does not have Crystal Reports Server setup so what is the best approach to deploying this report to the end user?  For now it would just be one user using the report but down the road there could be other people within his department that are running it as well.
        if you have any questions or need additional information to answer my posting just let me know.  Have a good day.
    Regards,
    Ting

    Hi Ting,
    I see now.... In older versions of CR like 8.5 there was a Deployment Wizard one could use to compile the report and runtime into an executable to run on an end users PC so that user could preview and refresh the reports.
    That ability stopped as of CR 8.5 or earlier, I don't recall exactly now.
    Yes, if they want to be able to run your report they will need to install a copy of Crystal Reports, then just send them your RPT file, they can then set Database location to their DB Source and then preview and refresh the report as required.
    Or as mentioned use a third party app to do the same or write your own. It's quite simple to do and likely one of our samples applications is all you need with a few basic changes, report source and DB log on info would need to be updated.
    As for licensing, the end user must purchase a copy of Crystal Reports to be able to use your application. Third Party app's would include the licensing mostly but check with them if you go that way.
    The convenient part is if the users want to write their own reports they can.
    And for your sake if you want to protect your reports the next version of CR has a read only RPT file format that all the user can do is preview and refresh the report. They can not edit it in anyway.
    Thanks again
    Don

Maybe you are looking for