[Samba] Share Printer via GPO per User

basti mailinglist at unix-solution.de
Mon Dec 17 16:09:42 UTC 2018


Share the printer via "Print Management -> Deploy with GPO" it works,
but then the Printer is default on all users which is not an option.

So I try to share it per User, but this does not work, the printer is
not added after login.

My GPO look like:


Data collected on: 12/17/2018 4:38:22 PM



Domain samdom.example.com

Owner SAMDOM\Domain Admins

Created 12/17/2018 3:56:44 PM

Modified 12/17/2018 4:28:26 PM

User Revisions 35 (AD), 35 (SYSVOL)

Computer Revisions 0 (AD), 0 (SYSVOL)

Unique ID {CCA8170A-EED3-4DD2-8BFE-5EEEFEAF813E}

GPO Status Enabled


Location Enforced Link Status Path

SAMDOM No Enabled samdom.example.com

This list only includes links in the domain of the GPO.

Security Filtering

The settings in this GPO can only apply to the following groups, users,
and computers:Name

NT-AUTORITÄT\Authentifizierte Benutzer


These groups and users have the specified permission for this GPOName
Allowed Permissions Inherited

SAMDOM\Domain Admins Edit settings, delete, modify security No

SAMDOM\Domain Users Read No

SAMDOM\Enterprise Admins Edit settings, delete, modify security No

NT-AUTORITÄT\Authentifizierte Benutzer Read (from Security Filtering) No


NT-AUTORITÄT\SYSTEM Edit settings, delete, modify security No

Computer Configuration (Enabled)

No settings defined.

User Configuration (Enabled)


Control Panel Settings


Shared Printer (Name: \\dc2.samdom.example.com\SAMDOM-PTR-004)

SAMDOM-PTR-004 (Order: 1)


Action Update

PropertiesShare Path \\dc2.samdom.example.com\SAMDOM-PTR-004

Set this printer as default printer True

Only if a local printer is not present True

Local Port


OptionsStop processing items on this extension if an error occurs on
this item No

Run in logged-on user's security context (user policy option) Yes

Remove this item when it is no longer applied No

Apply once and do not reapply No

Item-level targeting: Security GroupAttribute Value

bool AND

not 0

name SAMDOM\Domain Users

sid S-1-5-21-3008661040-3046359653-1299078886-513

userContext 1

primaryGroup 0

localGroup 0

Best Regards,

P.S. use "Domain Users" just for testing

More information about the samba mailing list