Wednesday, July 5, 2017

Error: "Login to [computer] failed. Check the username and password and try again" when remotely installing

Situation

Error

Solution

Saturday, July 1, 2017

Deploy Printers With Group Policy - Windows 2012 R2

Steps (21 total)
1. Planning

Start by planning out your site. Take a piece of paper and list all your printers that will need to be deployed and who will need them.
Create group names for the printer groups by floor or side of building / purpose.
In this example I will only be deploying one printer but you can get the feel of what to do and just repeat the steps for other printers and groups.

2. Install Printer On LAN
Setup and Install your printer on the LAN if you have not already done so. Record the IP address you assigned (preferably static) and the model number so we can download the drivers.

3. Install Print and Document Service
Expand
Login to the server that will host the printers and install the Print and Document Service by using Add Roles and Features from Server Manager. Check the box next to Print and Document Service and hit next

4. Print Features
Expand
Be sure that Print Server is checked and if you are going to need Mac / Unix printing support then check the box for LPD. I have never really used the Scan Server bit but feel free to explore.

5. Open Print Management
Once the install is finished go to Server Manager and choose tools then Print Management

6. Print Management Overview
Print Management control panel overview:
Start by expanding Print Servers and you should see the local server listed that you just installed Print Services on. You can also add other print servers in your environment as long as they have Print and Document Services installed. Just right click and Add Server to control everything from one place.

Under the print server then computer name you will find the Drivers management function. This is where you will control drivers and update them as new ones are released.

Forms is where you control the default forms assigned to the printers in your environment. This is a powerful feature and helps with deployment of forms and maintains a consistent standard across everyone that uses this print server. Explore this one in depth I will make you look like a champ to the end users.

Ports is all the ports TCP/IP, LPT, COM and File that are available to the local machine. As you add printers to the server and share them out you will get a TCP/IP port listed with the IP address of the printer. This is the same as right clicking the printer and choosing Properties then the Port tab.

Printers is the same as Devices and Printers from Control Panel

7. Download 32bit and 64bit drivers
Open your browser and search/download both the 32bit and 64bit drivers for the specific printer you are setting up. Try not to get the bundle but rather choose the basic driver for just printing. Get the driver for the version of Windows loaded on the Print Server. In this instance I am using 2012 R2 which is a Windows 8 kernel, so I got both the Windows 8 64bit and 32bit drivers

8. Extract Drivers
Lots of times the drivers will come as .exe or some installer file that immediately wants to install the driver. I prefer to extract these files before hand and manually add the drivers. You can use the installer if it is a straight extraction but if it tries to install then I would cancel and use WinRAR to extract the .exe.

9. Load the drivers

Back in Print Management right click on Drivers and choose Add Drivers
Check both 32 and 64 bit boxes.

10. Driver Selection
On the Driver Selection screen hit Have Disk and browse to the extracted drivers. Start with the 64 bit drivers on a 64bit local OS. Otherwise start with the 32 bit(Rare).

Once you find the .inf file for the 64bit drivers then you will hit ok and it should prompt you for the 32 bit driver file on the next Install Print drivers (x86) screen.
Browse to the 32 bit driver extract and hit ok.
It is rare but you might also be prompted for the 32 bit ntprint.inf file. You have a few choices to get this file. One is to find a 32bit machine in your environment and copy the file from the system32 folder or you can download a copy from the internet.

ntprint.inf link
http://www.adventech.net/downloads/techfortechs/NTPrint_x86.zip

11. Add and Share The Printer

Now we have the drivers in place we can add the printer and share it out. This is the same as you have always done so don't get it complicated.
Right click on the Printers folder under Print Servers and choose Add Printer
Choose the option for Add a TCP/IP or web services printer by IP or hostname and hit next
Key in the printer IP address on the LAN and hit next to let it autodetect.
On the next screen it should have the printer name - Change this to something very simple but descriptive of either the printer function or printer type. Something Like HP-ColorLaser or LabelPrinter-Front. This is what the end user will know it best by so make it easy for them.
Check the box for Share this Printer and change the Share Name to the same as the Printer Name. Please set the location and the comment so people can get this info.

12. Finish Installing Printer
Check the box next to Print Test Page and hit Finish.
Check that the test page printed correctly, remedy any printer issues at this time

13. List Printer In Active Directory

In the printers section of Print Management you should now have a new printer listed with queue status = Ready.
We are now going to list the printer in AD and get it ready for GPO deployment.
Right click on the Printer and you will see a nice list of options. (see screen shot)
Choose the option to List In Directory - it is just a switch so it does not look like it does anything until you right click again and it should now read Remove from Directory

14. Deploy with GPO

Now the fun stuff begins we can deploy this to workstations via Group Policy so everyone gets the printers they need wherever they happen to be.
Right click on the printer and choose the option for Deploy with Group Policy

15. Deploy with GPO - Create Object
Click the browse option and you will be presented with all your Group Policy Objects and templates. Do yourself a big favor and create new GPO objects for each group or grouping of printers. This makes it way easier to find and update later than having to dig through all the GPO's looking for printers.
After clicking browse you will choose the option next to the drop down for create new Group Policy Object.
Name the object something specific like Printers-Site1 or Printers-Floor2
Hit Ok and you will be returned to the Deploy Group Policy Screen and you should see the GPO name is now updated to the new GPO object you just created.

16. Deploy with GPO - Per Machine

I always try to deploy printers on a per machine basis so that everyone that uses that machine gets the same printers. The only time I ever deploy per user is for accounting or shipping where they had to have access to the check printer or the label printer. I would create a new GPO object for just the per user deployments and let the others be on a per machine basis. This also helps with login loading times as it does not have to enumerate all the printers each time for the users.

Check the box next The Computers that this GPO applies to (per Machine) and Hit ADD.
You will then see the printer name and GPO / connection type listed. Hit OK at the bottom when you are happy with the results.

17. Create the Printer Security Group In AD

Open AD users and computers and locate your groups folder so we can create a new printer security group.
Create a new Universal security group called Printers-Floor1 or Printers-Site1 to match the name of the GPO you created in the previous step.
Add the computers that you want to have this printer installed into the group at this time. Feel free to nest another computer security group if you have one already created.

18. Scope GP Object

Open Group Policy and drill down to Group Policy Objects and click on the new Printer-Floor1 object you created. On the right pane you will see Security Filtering. Remove the Authenticated Users and Add the new Security Group Printers-Floor1 you created in the previous step.

19. Link GPO Object to your Computers OU

In Group Policy Managment drill down to your Computer OU and right click then choose Link an Existing GPO. Find the Printer Object and hit ok.
You should now see the object linked to the OU.

20. Restart the workstations

Printers only seem to load on startup so you will need to reboot the assigned workstations to get the GPO to apply correctly. I would also take this time to delete any old printers from the end users workstations. I had a ton of old printers pointing to another print server and ended up creating a login script that removed any old connections and then my current printers would apply correctly. You do not have to worry about this on a fresh printer install.

21. Windows XP and 2003
If you need to push printers out to XP machines then follow the deploy doc to add the Pushprinterconnections.exe logon script to the XP machines.
http://technet.microsoft.com/en-us/library/cc772505(v=ws.10).aspx

Friday, June 30, 2017

Cannot Remove or Delete Network Printer in Windows

Remove Network Printers from Windows via Registry Editor

Step 1: Click on Start, Run and then type in regedit and press Enter. This will open the registry editor.
Step 2: Navigate to the following key in the registry:
HKEY_CURRENT_USER – Printers – Connections
Here you should now see a list of all network printers with the server name first, then a comma, and then the name of the actual printer.
Go ahead and click on the printer in the left menu and press the Delete button or right-click and choose Delete. Unfortunately, that’s not all! You also have to delete the printer from one more location in the registry:
HKEY_LOCAL_MACHINE – SYSTEM – CurrentControlSet – Control – Print – Providers – LanMan Print Services – Servers – Printers
Now under the servers key, you should be able to expand it and see the name of the print server that actually hosts the printer you want to delete. Go ahead and expand the print server key and delete the printer from the list.
Now close the registry editor and reboot your computer. The undeletable network printer should now be gone! Note that the method above is just for network printers. If you have a local printer and want to remove it the same way via the registry, you need to go to the following registry keys below:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Print\Environments\ Windows NT x86\ Drivers\Version-3\
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Print\Printers\

Understanding Active Directory Domain Services (AD DS) Functional Levels

Applies To: Windows Server 2008, Windows Server 2008 R2, Windows Server 2012, Windows Server 2012 R2
Functional levels determine the available Active Directory Domain Services (AD DS) domain or forest capabilities. They also determine which Windows Server operating systems you can run on domain controllers in the domain or forest. However, functional levels do not affect which operating systems you can run on workstations and member servers that are joined to the domain or forest.
When you deploy AD DS, set the domain and forest functional levels to the highest value that your environment can support. This way, you can use as many AD DS features as possible. For example, if you are sure that you will never add domain controllers that run Windows Server 2003 to the domain or forest, select the Windows Server 2008 functional level during the deployment process. However, if you might retain or add domain controllers that run Windows Server 2003, select the Windows Server 2003 functional level.
When you deploy a new forest, you are prompted to set the forest functional level and then set the domain functional level. You cannot set the domain functional level to a value that is lower than the forest functional level. For example, if you set the forest functional level to Windows Server 2008, you can set the domain functional level only to Windows Server 2008. In this case, the Windows 2000 native and Windows Server 2003 domain functional level values are not available. In addition, all domains that you subsequently add to that forest have the Windows Server 2008 domain functional level by default.
You can set the domain functional level to a value that is higher than the forest functional level. For example, if the forest functional level is Windows Server 2003, you can set the domain functional level to Windows Server 2003or higher.
The following sections describe the features that are available at the different functional levels.

Features that are available at domain functional levels

The following table shows the features that are available at each domain functional level.

 

Domain functional levelAvailable featuresSupported domain controller operating systems
Windows 2000 native
All of the default AD DS features and the following directory features are available:
  • Universal groups for both distribution and security groups.
  • Group nesting
  • Group conversion, which allows conversion between security and distribution groups
  • Security identifier (SID) history
noteNote
In Windows Server 2008 R2, the Personal Virtual Desktop feature was introduced. It requires the Windows 2000 native domain functional level.
To deploy personal virtual desktops, your schema for the Active Directory forest must be at least Windows Server 2008. To use the added functionality provided by the Personal Virtual Desktop tab in the User Account Properties dialog box in Active Directory Users and Computers, you must run Active Directory Users and Computers from a computer running Windows Server 2008 R2 or a computer running Windows 7 that has Remote Server Administration Tools (RSAT) installed.
  • Windows Server 2008 R2
  • Windows Server 2008
  • Windows Server 2003
  • Windows 2000
Windows Server 2003
All the default AD DS features, all the features that are available at the Windows 2000 native domain functional level, and the following features are available:
  • The domain management tool, Netdom.exe, which makes it possible for you to rename domain controllers
  • Logon time stamp updates

    The lastLogonTimestamp attribute is updated with the last logon time of the user or computer. This attribute is replicated within the domain.
  • The ability to set the userPassword attribute as the effective password on inetOrgPerson and user objects
  • The ability to redirect Users and Computers containers

    By default, two well-known containers are provided for housing computer and user accounts, namely, cn=Computers, and cn=Users,. This feature allows the definition of a new, well-known location for these accounts.
  • The ability for Authorization Manager to store its authorization policies in AD DS
  • Constrained delegation

    Constrained delegation makes it possible for applications to take advantage of the secure delegation of user credentials by means of Kerberos-based authentication.

    You can restrict delegation to specific destination services only.
  • Selective authentication

    Selective authentication makes it is possible for you to specify the users and groups from a trusted forest who are allowed to authenticate to resource servers in a trusting forest.
  • Windows Server 2012 R2
  • Windows Server 2012
  • Windows Server 2008 R2
  • Windows Server 2008
  • Windows Server 2003
Windows Server 2008
All of the default AD DS features, all of the features from the Windows Server 2003 domain functional level, and the following features are available:
  • Distributed File System (DFS) replication support for the Windows Server 2003 System Volume (SYSVOL)

    DFS replication support provides more robust and detailed replication of SYSVOL contents.

    noteNote
    Beginning with Windows Server 2012 R2, File Replication Service (FRS) is deprecated. A new domain that is created on a domain controller that runs at least Windows Server 2012 R2 must be set to the Windows Server 2008 domain functional level or higher.
  • Domain-based DFS namespaces running in Windows Server 2008 Mode, which includes support for access-based enumeration and increased scalability. Domain-based namespaces in Windows Server 2008 mode also require the forest to use the Windows Server 2003 forest functional level. For more information, see Choose a Namespace Type (http://go.microsoft.com/fwlink/?LinkId=180400).
  • Advanced Encryption Standard (AES 128 and AES 256) support for the Kerberos protocol. In order for TGTs to be issued using AES, the domain functional level must be Windows Server 2008 or higher and the domain password needs to be changed.

    noteNote
    Authentication errors may occur on a domain controller after the domain functional level is raised to Windows Server 2008 or higher if the domain controller has already replicated the DFL change but has not yet refreshed the krbtgt password. In this case, a restart of the KDC service on the domain controller will trigger an in-memory refresh of the new krbtgt password and resolve related authentication errors.
    For more information, see Kerberos Enhancements.
  • Last Interactive Logon Information

    Last Interactive Logon Information displays the following information:

    • The total number of failed logon attempts at a domain-joined Windows Server 2008 server or a Windows Vista workstation
    • The total number of failed logon attempts after a successful logon to a Windows Server 2008 server or a Windows Vista workstation
    • The time of the last failed logon attempt at a Windows Server 2008 or a Windows Vista workstation
    • The time of the last successful logon attempt at a Windows Server 2008 server or a Windows Vista workstation
    For more information, see Active Directory Domain Services: Last Interactive Logon(http://go.microsoft.com/fwlink/?LinkId=180387).
  • Fine-grained password policies

    Fine-grained password policies make it possible for you to specify password and account lockout policies for users and global security groups in a domain. For more information, see Step-by-Step Guide for Fine-Grained Password and Account Lockout Policy Configuration (http://go.microsoft.com/fwlink/?LinkID=91477).
  • Personal Virtual Desktops

    To use the added functionality provided by the Personal Virtual Desktop tab in the User Account Properties dialog box in Active Directory Users and Computers, your AD DS schema must be extended for Windows Server 2008 R2 (schema object version = 47). For more information, see Deploying Personal Virtual Desktops by Using RemoteApp and Desktop Connection Step-by-Step Guide(http://go.microsoft.com/fwlink/?LinkId=183552).
  • Windows Server 2012 R2
  • Windows Server 2012
  • Windows Server 2008 R2
  • Windows Server 2008
Windows Server 2008 R2
All default Active Directory features, all features from the Windows Server 2008 domain functional level, plus the following features:
  • Authentication mechanism assurance, which packages information about the type of logon method (smart card or user name/password) that is used to authenticate domain users inside each user’s Kerberos token. When this feature is enabled in a network environment that has deployed a federated identity management infrastructure, such as Active Directory Federation Services (AD FS), the information in the token can then be extracted whenever a user attempts to access any claims-aware application that has been developed to determine authorization based on a user’s logon method.
  • Automatic SPN management for services running on a particular computer under the context of a Managed Service Account when the name or DNS host name of the machine account changes. For more information about Managed Service Accounts, see Service Accounts Step-by-Step Guide(http://go.microsoft.com/fwlink/?LinkId=180401).
  • Windows Server 2012 R2
  • Windows Server 2012
  • Windows Server 2008 R2
Windows Server 2012
The KDC support for claims, compound authentication, and Kerberos armoring KDC administrative template policy has two settings (Always provide claims and Fail unarmored authentication requests) that require Windows Server 2012 domain functional level. For more information, see What's New in Kerberos Authentication.
  • Windows Server 2012 R2
  • Windows Server 2012
Windows Server 2012 R2
  • DC-side protections for Protected Users. Protected Users authenticating to a Windows Server 2012 R2 domain can no longer:

    • Authenticate with NTLM authentication
    • Use DES or RC4 cipher suites in Kerberos pre-authentication
    • Be delegated with unconstrained or constrained delegation
    • Renew user tickets (TGTs) beyond the initial 4 hour lifetime
  • Authentication Policies

    New forest-based Active Directory policies which can be applied to accounts in Windows Server 2012 R2 domains to control which hosts an account can sign-on from and apply access control conditions for authentication to services running as an account.
  • Authentication Policy Silos

    New forest-based Active Directory object, which can create a relationship between user, managed service and computer, accounts to be used to classify accounts for authentication policies or for authentication isolation.
  • Windows Server 2012 R2

Features that are available at forest functional levels

The following table shows the features that are available at each forest functional level.

 

Forest functional levelAvailable featuresSupported domain controllers
Windows 2000
All of the default AD DS features are available.
  • Windows Server 2008 R2
  • Windows Server 2008
  • Windows Server 2003
  • Windows 2000
Windows Server 2003
All of the default AD DS features, and the following features, are available:
  • Forest trust
  • Domain rename
  • Linked-value replication

    Linked-value replication makes it possible for you to change group membership to store and replicate values for individual members instead of replicating the entire membership as a single unit. Storing and replicating the values of individual members uses less network bandwidth and fewer processor cycles during replication, and prevents you from losing updates when you add or remove multiple members concurrently at different domain controllers.
  • The ability to deploy a read-only domain controller (RODC)
  • Improved Knowledge Consistency Checker (KCC) algorithms and scalability

    The intersite topology generator (ISTG) uses improved algorithms that scale to support forests with a greater number of sites than AD DS can support at the Windows 2000 forest functional level. The improved ISTG election algorithm is a less-intrusive mechanism for choosing the ISTG at the Windows 2000 forest functional level.
  • The ability to create instances of the dynamic auxiliary class named dynamicObject in a domain directory partition
  • The ability to convert an inetOrgPerson object instance into a User object instance, and to complete the conversion in the opposite direction
  • The ability to create instances of new group types to support role-based authorization.

    These types are called application basic groups and LDAP query groups.
  • Deactivation and redefinition of attributes and classes in the schema. The following attributes can be reused: ldapDisplayName, schemaIdGuid, OID, and mapiID.
  • Domain-based DFS namespaces running in Windows Server 2008 Mode, which includes support for access-based enumeration and increased scalability. For more information, see Choose a Namespace Type (http://go.microsoft.com/fwlink/?LinkId=180400).
  • Windows Server 2012 R2
  • Windows Server 2012
  • Windows Server 2008 R2
  • Windows Server 2008
  • Windows Server 2003
Windows Server 2008
All of the features that are available at the Windows Server 2003 forest functional level, but no additional features are available. All domains that are subsequently added to the forest, however, operate at the Windows Server 2008 domain functional level by default.
  • Windows Server 2012 R2
  • Windows Server 2012
  • Windows Server 2008 R2
  • Windows Server 2008
Windows Server 2008 R2
All of the features that are available at the Windows Server 2003 forest functional level, plus the following features:
  • Active Directory Recycle Bin, which provides the ability to restore deleted objects in their entirety while AD DS is running.
All domains that are subsequently added to the forest will operate at the Windows Server 2008 R2 domain functional level by default.
If you plan to include only domain controllers that run Windows Server 2008 R2 in the entire forest, you might choose this forest functional level for administrative convenience. If you do, you will never have to raise the domain functional level for each domain that you create in the forest.
  • Windows Server 2012 R2
  • Windows Server 2012
  • Windows Server 2008 R2
Windows Server 2012
All of the features that are available at the Windows Server 2008 R2 forest functional level, but no additional features.
All domains that are subsequently added to the forest will operate at the Windows Server 2012 domain functional level by default.
  • Windows Server 2012 R2
  • Windows Server 2012
Windows Server 2012 R2
All of the features that are available at the Windows Server 2012 forest functional level, but no additional features.
All domains that are subsequently added to the forest will operate at the Windows Server 2012 R2 domain functional level by default.
  • Windows Server 2012 R2

Guidelines for raising domain and forest functional levels

The following guidelines apply to raising the domain or forest functional levels:
  • You must be a member of the Domain Admins group to raise the domain functional level.
  • You must be a member of the Enterprise Admins group to raise the forest functional level.
  • You can raise the domain functional level on the primary domain controller (PDC) emulator operations master only. The AD DS administrative tools that you use to raise the domain functional level (the Active Directory Domains and Trusts snap-in and the Active Directory Users and Computers snap-in) automatically target the PDC emulator when you raise the domain functional level.
  • You can raise the forest functional level on the schema operations master only. Active Directory Domains and Trusts automatically targets the schema operations master when you raise the forest functional level.
  • You can raise the functional level of a domain only if all domain controllers in the domain run the version or versions of Windows Server that the new functional level supports.
  • You can raise the functional level of a forest only if all domain controllers in the forest run the version or versions of Windows Server that the new functional level supports.
  • You cannot set the domain functional level to a value that is lower than the forest functional level, but you can set it to a value that is equal to or higher than the forest functional level.
  • With versions of Windows Server that are earlier than Windows Server 2008 R2, you cannot roll back or lower a functional level under any circumstances. If you have to revert to a lower functional level with a version of Windows Server that is earlier than Windows Server 2008 R2, you must rebuild the domain or forest or restore it from a backup copy.
  • After you set the domain functional level, you cannot roll back or lower the domain functional level except in the cases listed in the following table. The domain functional level can be lowered only by using Windows PowerShell. For more information, see Set-ADDomainMode.

     

    Current domain functional levelCurrent forest functional levelRollback options
    Windows Server 2012 R2
    Windows Server 2012 R2
    None unless you first lower forest functional level
    Windows Server 2012 R2
    Windows Server 2012
    Windows Server 2012
    Windows Server 2012 R2
    Windows Server 2008 R2
    Windows Server 2012 or Windows Server 2008 R2
    Windows Server 2012 R2
    Windows Server 2008
    Windows Server 2012, Windows Server 2008 R2, or Windows Server 2008
    Windows Server 2012
    Windows Server 2012
    None unless you first lower forest functional level
    Windows Server 2012
    Windows Server 2008 R2
    Windows Server 2008 R2
    Windows Server 2012
    Windows Server 2008
    Windows Server 2008 R2 or Windows Server 2008
    Windows Server 2008 R2
    Windows Server 2008 R2
    None unless you first lower forest functional level
    Windows Server 2008 R2
    Windows Server 2008
    Windows Server 2008
    Windows Server 2008 or lower
    Windows Server 2008 or lower
    None
  • After you set the forest functional level, you cannot roll back or lower the forest functional level except in the cases listed in the following table. The forest functional level can be lowered only by using Windows PowerShell. For more information, see Set-ADForestMode. For more information about the Active Directory Recycle Bin, see What's New in AD DS: Active Directory Recycle Bin (http://go.microsoft.com/fwlink/?LinkId=141392).

     

    Current forest functional levelRecycle Bin enabled?Rollback options
    Windows Server 2012 R2
    Yes
    Windows Server 2012 or Windows Server 2008 R2
    Windows Server 2012 R2
    No
    Windows Server 2012, Windows Server 2008, or Windows Server 2008 R2
    Windows Server 2012
    Yes
    Windows Server 2008 R2
    Windows Server 2012
    No
    Windows Server 2008 R2 or Windows Server 2008
    Windows Server 2008 R2
    Yes
    None
    Windows Server 2008 R2
    No
    Windows Server 2008

Friday, June 23, 2017

List of print related hotfixes post Service Pack 2 for Windows Server 2003.

Applies to
Windows Server 2003 Service Pack 2
Windows Server 2003 SP2
W2K3 Service Pack 2
W2K3 SP2
Windows Server 2003 Service Pack 2 R2
Windows Server 2003 SP2 R2
W2K3 Service Pack 2 R2
W2K3 SP2 R2

List of print related hotfixes post Service Pack 2 for Windows Server 2003 as of Sep. 2012:

Originally published Sep. 2009.  Updated Mar. 2012.

Note: Regular support of Windows Server 2003 with Service Pack 2 ended in 2010. So there aren’t going to be any new hotfixes except for the Security hotfixes.

WARNING:  There should be a 3 hours scheduled change control.
The reason is for the hotfixes that contain unidrv.dll or ps5ui.dll, the print queues will have to go thru:
832219 Users cannot print after you install a service pack, update rollup, or printer hotfix on a server in Windows 2000 or in Windows Server 2003
http://support.microsoft.com?id=832219 
 

2712189 FIX: A custom .NET Framework 1.1 Service Pack 1 application that uses Windows Forms may not print or may not apply defined printer settings in Windows XP, Windows Server 2003 64-bit Edition or Itanium Edition, Windows Vista, or Windows Server 2008
http://support.microsoft.com/?id=2712189


Update(s):
System.Drawing.dll  1.1.4322.2497

2702328 FIX: A custom .NET Framework 4 application that uses Windows Forms may not print or may not apply defined printer settings in Windows XP, Windows Server 2003, Windows Vista, Windows Server 2008, Windows 7, or Windows Server 2008 R2
http://support.microsoft.com/?id=2702328


Update(s):
Setup.exe
SetupEngine.dll  10.0.30319.568
SetupUi.dll  10.0.30319.568
System.Drawing.dll  4.0.30319.568

2702327 FIX: A custom .NET Framework 2.0 Service Pack 2 application that uses Windows Forms may not print or may not apply defined printer settings in Windows XP or Windows Server 2003
http://support.microsoft.com/?id=2702327


Update(s):
System.Drawing.dll  2.0.50727.5729

2328677 Some text from an XPS file is printed incorrectly by a .NET Framework 4.0-based WPF applicati
http://support.microsoft.com/?id=2328677


Update(s):
Reachframework.dll  4.0.30319.352
SetupUi.dll  10.0.30319.352  295,248
Setupengine.dll  10.0.30319.352
Setup.exe  10.0.30319.352

2480118 You cannot print results to files by using web applications in Windows Server 2003, Windows Vista, Windows Server 2008, Windows 7, or Windows Server 2008 R2 after you install security update MS10-061
http://support.microsoft.com/?id=2480118


Update(s):
Spoolsv.exe 5.2.3790.4804

2279637 Some information is not printed when you print a large document on a computer that is running Windows Server 2003
http://support.microsoft.com/?id=2279637


Update(s):
Gdi32.dll 5.2.3790.4742
Supersede(s):
959482 Horizontal black stripes are displayed in the print output when you print an image to a PCL printer from a computer that is running Windows Vista, Windows Server 2008, Windows XP, or Windows Server 2003
http://support.microsoft.com/?id=
941973 A GDI object handle is leaked on a Windows Server 2003 Service Pack 2-based computer when you print a rotated picture by using Internet Explorer
936780 You may experience performance issues when you print documents from a 32-bit program in a 64-bit version of Windows Server 2003
930627 The private data of the DEVMODE data structure may be corrupted when you use raw mode to print a document in a 32-bit application on a computer that is running a 64-bit version of Windows

2279561 "0x00000050" Stop error occurs on a terminal server that is running Windows Server 2003 if a user mode printer driver is used in a terminal server session
http://support.microsoft.com/?id=2279561


Update(s):
Win32k.sys 5.2.3790.4743
Supersede(s):
2028925 "0x00000050" Stop error code in Windows Server 2003 Service Pack 2
http://support.microsoft.com/?id=2028925
960266 Error message when you call the CreateProcess function to start a process of a console application by using an account other than the current logon account in Windows Server 2003: "The application failed to initialize properly (0xc0000142)"
959828 Stop error on a Windows Server 2003 SP2-based terminal server or a Windows Server 2008 SP2-based terminal server when users print documents in terminal sessions: "0x0000008E" or "0x00000050"
959482 Horizontal black stripes are displayed in the print output when you print an image to a PCL printer from a computer that is running Windows Vista, Windows Server 2008, Windows XP, or Windows Server 2003
959338 You receive a PAGE_FAULT_IN_NONPAGED_AREA Stop error when you print a document from a Windows Server 2003 server that is running as a terminal server
939884

981650 You cannot print text in a terminal server session in Windows Server 2003, in Windows Server 2008, or in Windows Vista if the printer uses the "Generic / Text Only" driver
http://support.microsoft.com/?id=981650


Update(s):
Gdiplus.dll 5.2.6001.22729
Gdiplus.man
Supersede(s):
956807 The Unicode hyphen character (U+2010) is not drawn when you use an application that uses GDI+ API functions in Windows Server 2008, in Windows Vista, in Windows Server 2003, and in Windows XP
951759 When an application uses GDI+ to print to a color printer on a Windows Server 2003-based, Windows Vista-based, or Windows Server 2008-based computer, ICM color matching is not performed

981429 Some XPS file text is printed incorrectly by a .NET Framework 3.0-based WPF application
http://support.microsoft.com/?id=981429


Update(s):
Presentationcore.dll 3.0.6920.4031
Presentationframework.dll 3.0.6920.4031
Presentationhost.exe 4.0.40305.0
Presentationhostdll.dll 3.0.6920.4031
Presentationhostproxy.dll 4.0.31106.0
Reachframework.dll 3.0.6920.4031
System.printing.dll 3.0.6920.4031
Windowsbase.dll 3.0.6920.4031
Supersede(s):
980294 Characters in the Barcode font are printed in the Wingdings font in an XPS document that is created by using the .NET Framework 3.0

980276 The Print Spooler service crashes when you try to remove a printer on a computer that is running Windows Server 2003 SP2
http://support.microsoft.com/?id=980276


Update(s):
Localspl.dll 5.2.3790.4677
Supersede(s):
968585 A handle leak occurs in the print spooler service after you resubmit a print job to a shared printer on which the "Keep printed documents" option is enabled
962910 After security update MS08-062 is installed on a print client, the client cannot print documents to a Windows Server 2003-based IPP print server if the related printer driver is not installed
955455 The print process crashes under heavy stress on a computer that is running Windows Server 2003 or Windows XP Professional x64 Edition if the computer uses hyper-threading technology
952206 A printer-driver upgrade operation fails on printer clients that are running Windows Server 2003 or Windows XP when multiple printer queues are upgraded at the same time
934885 The Print Spooler service may stop sending print jobs to a printer that uses the standard port monitor on a Windows Server 2003-based computer
932699 A printer driver upgrade operation may fail in Windows Server 2003

979405 FIX: Error message when you run a script that uses the PrnAdmin utility to install the HP Universal Print Driver PCL6: "-2147024894: The system cannot find the file specified"
http://support.microsoft.com/?id=979405


Update(s):
Ntprint.dll 5.2.3790.4649
Wntprint.dll 5.2.3790.4649

977585 Text strings that are not in a clipping region are printed unexpectedly when you use Microsoft XPS Document Writer to print a file in Windows Server 2008, Windows Server 2003, or Windows Vista
http://support.microsoft.com/?id=977585


Update(s):
Msxpsinc.amd64.gpd
Msxpsinc.amd64.ppd
Msxpsinc.gpd
Msxpsinc.ppd
Mxdwdrv.amd64.dll 0.3.6002.22298
Mxdwdrv.dll 0.3.6002.22298
Mxdwdui.dll 0.3.6002.22298
Mxdwdui.gpd
Mxdwdui.ini
Stddtype.gdl
Stdnames.gpd
Stdschem.gdl
Stdschmx.gdl
Unidrv.dll 0.3.6002.22298
Unidrv.hlp
Unidrvui.dll 0.3.6002.22298
Unires.dll 0.3.6002.22298
Xpssvcs.amd64.dll 6.0.6002.22298
Xpssvcs.dll 6.0.6002.22298
Supersede(s):
944203 You may be unable to print a job after you install the .NET Framework 3.0 or the XML Paper Specification Essentials Pack on a Windows XP SP2-based computer or on a Windows Server 2003-based computer

977225 Incorrect lines are printed when a Word document is printed on a computer that is running Windows XP, Windows Server 2003, Windows Vista, Windows Server 2008, Windows 7 or Windows Server 2008 R2
http://support.microsoft.com/?id=977225


Update(s):
Stddtype.gdl
Stdnames.gpd
Stdschem.gdl
Stdschmx.gdl
Unidrv.dll 0.3.7601.21760
Unidrv.hlp
Unidrvui.dll 0.3.7601.21760
Unires.dll 0.3.7601.17514
Supersede(s):
969744 Underlines are missing when you print a document

975126 Some custom-sized pages are printed incorrectly if they have different dimensions and are printed consecutively from a computer running Windows Server 2003, Windows Vista or Windows Server 2008
http://support.microsoft.com/?id=975126


Update(s):
Locale.gpd
P6disp.gpd
P6font.gpd
Pcl4res.dll 0.3.5479.0
Pcl5eres.dll 0.3.5479.0
Pcl5ures.dll 0.3.5479.0
Pclxl.dll 0.3.5479.0
Pclxl.gpd
Pjl.gpd
Ps5ui.dll 0.3.6002.22223
Pscript.hlp
Pscript.ntf
Pscript5.dll 0.3.6002.22223
Pscrptfe.ntf
Ps_schm.gdl
Ttfsub.gpd

974266 Group Policy Preferences Client-Side Extension Hotfix Rollup
http://support.microsoft.com/?id=974266 
 
971276 You receive incorrect print output if the IPrintPipelineProgressReport interface is used in your printing application on a Windows XP SP3 or Windows Server 2003 SP2-based computer
http://support.microsoft.com/?id=971276


Update(s):
Filterpipelineprintproc.amd64.dll 6.1.3790.4316 147,456 14-Aug-2009 12:49 x64 SP3
Filterpipelineprintproc.dll 6.1.2600.5863 89,088 14-Aug-2009 12:49 x86 SP3
Msxpsinc.amd64.gpd Not Applicable 73 19-Jun-2008 03:03 Not Applicable SP3
Msxpsinc.amd64.ppd Not Applicable 72 19-Jun-2008 03:03 Not Applicable SP3
Msxpsinc.gpd Not Applicable 73 19-Jun-2008 03:04 Not Applicable SP3
Msxpsinc.ppd Not Applicable 72 19-Jun-2008 03:04 Not Applicable SP3
Mxdwdrv.amd64.dll 0.3.6002.22136 760,320 14-Aug-2009 12:49 x64 SP3
Mxdwdrv.dll 0.3.6002.22136 779,776 14-Aug-2009 12:49 x86 SP3
Mxdwdui.dll 0.3.6002.22136 198,656 14-Aug-2009 12:49 x86 SP3
Mxdwdui.gpd Not Applicable 67,628 19-Jun-2008 03:04 Not Applicable SP3
Mxdwdui.ini Not Applicable 42 19-Jun-2008 03:04 Not Applicable SP3
Printfilterpipelinesvc.exe 6.1.2600.5863 594,432 14-Aug-2009 09:02 x86 SP3
Prntvpt.dll 6.1.2600.5863 117,760 14-Aug-2009 12:49 x86 SP3
Stddtype.gdl Not Applicable 23,812 30-Nov-2007 12:56 Not Applicable SP3
Stdnames.gpd Not Applicable 14,362 30-Nov-2007 13:03 Not Applicable SP3
Stdschem.gdl Not Applicable 59,116 30-Nov-2007 12:56 Not Applicable SP3
Stdschmx.gdl Not Applicable 2,278 30-Nov-2007 12:56 Not Applicable SP3
Unidrv.dll 0.3.6002.22136 372,736 14-Aug-2009 12:49 x86 SP3
Unidrv.hlp Not Applicable 21,225 30-Nov-2007 11:46 Not Applicable SP3
Unidrvui.dll 0.3.6002.22136 744,448 14-Aug-2009 12:49 x86 SP3
Unires.dll 0.3.6002.22136 761,344 15-May-2009 05:21 x86 SP3
Xpsshhdr.dll 6.0.6002.22136 575,488 14-Aug-2009 12:49 x86 SP3
Xpssvcs.amd64.dll 6.0.6002.22136 2,936,832 14-Aug-2009 12:49 x64 SP3
Xpssvcs.dll 6.0.6002.22136
Supersede(s):
954550 Some Microsoft XPS features are not available in Windows Server 2003 and in Windows XP

971314 All PCL inbox printer drivers become unsigned after you install the Microsoft .NET Framework 3.5 SP1 or the XPS Essentials Pack in Windows XP or in Windows Server 2003
http://support.microsoft.com/?id=971314


Update(s):
Ntprint.cat
Supersede(s):

961118

967663 Only one 32-bit service can print on a computer that is running a 64-bit version of Windows Server 2003 when multiple services are configured to run under one non-SYSTEM account
http://support.microsoft.com?id=967663


Update(s):
Splwow64.exe  5.2.3790.4457

967499 You encounter printing issues after a new OEM print driver, a printer hotfix, or a service pack is installed on a Windows Server 2003-based clustered printer server
http://support.microsoft.com?id=967499
 
960677 When you print a document to a redirected printer in a Windows Server 2003-based terminal server session, the document is printed to a redirected printer of a different client
http://support.microsoft.com/?id=960677


Update(s):
Rdpdr.sys 5.2.3790.4424
Note:  Only for Terminal Servers.
Supersede(s):
938645 You cannot communicate with the local device by using a redirected COM port in a Windows Server 2003-based terminal-server session

958910 When you send a print job to an Internet Printer Protocol (IPP) print server from a Windows-based computer, the print job fails and never restarts
http://support.microsoft.com/?id=958910


Update(s):
Inetpp.dll 5.2.3790.4417
Winetpp.dll 5.2.3790.4417

957389 When you run an SUA application that prints log messages from the system logger daemon, ISO 8859 characters are printed incorrectly on Windows Server 2003 R2-based, Windows Vista-based, and Windows Server 2008-based computers
http://support.microsoft.com/?id=957389


Update(s):
Syslogd 9.0.3790.4368

957187 Stop error if you use some OpenType fonts on a computer that is running Windows Server 2003, Windows Vista, or Windows Server 2008: "Stop 0x00000050"
http://support.microsoft.com/?id=957187


Note:  This replaces KB 948046 V1 which is known to cause the .bud file to keep on getting regenerated and slows printing (customers have reported slow down in printing up to 3X).
 
Update(s):
Locale.gpd
P6disp.gpd
P6font.gpd
Pcl4res.dll 0.3.5479.0
Pcl5eres.dll 0.3.5479.0
Pcl5ures.dll 0.3.5479.0
Pclxl.dll 0.3.5479.0
Pclxl.gpd
Pjl.gpd
Stddtype.gdl
Stdnames.gpd
Stdschem.gdl
Stdschmx.gdl
Ttfsub.gpd
Unidrv.dll 0.3.6001.22252
Unidrv.hlp
Unidrvui.dll 0.3.6001.22252
Unires.dll 0.3.6001.22252

Supersede(s):
948696 Text that is formatted in printer device fonts may not print correctly in x64 versions of Windows Server 2008, of Windows Vista, and of Windows Server 2003
948046 A Word document is not printed as expected after you install the Windows European Union Expansion Font pack in Windows Server 2003 or in Windows XP

956048 An application that calls the Image Color Management (ICM) functions in the Icm32.dll module may crash on a Windows Server 2003-based computer
http://support.microsoft.com/?id=956048


Update(s):
Icm32.dll 5.2.3790.4343
Wicm32.dll 5.2.3790.4343

955549 When you open an .rtf file that contains a MergeField field in a paragraph, indents that are added to the paragraph are not displayed in Windows Server 2003 and in Windows XP Professional x64 edition
http://support.microsoft.com/?id=955549


Update(s):
Msftedit.dll 5.41.21.2509
Riched20.dll 5.31.23.1229

954744 FIX: Some pages are printed in the incorrect orientation when you use Terminal Services Easy Print to print a document that contains both portrait-oriented pages and landscape-oriented pages
http://support.microsoft.com/?id=954744


Update(s):
.net framework 3.0 SP1:
Servicemodelreg.exe 3.0.4506.725 61,440 25-Sep-2008 17:17 x86 SP1
Tswpfwrp.exe 3.0.6920.1201
 
.net framework 3.0 SP2:
Tswpfwrp.exe 3.0.6920.1201
 
Note:  Only for Terminal Servers

953546 The Print Spooler process (Spoolsv.exe) crashes while it is copying print driver files on a computer that is running Windows Server 2003 or Windows XP
http://support.microsoft.com/?id=953546


Update(s):
Updates Win32spl.dll 5.2.3790.4301
Supersede(s):
931318

952909 When you try to print a document to a PostScript printer in an application, the application exits unexpectedly, or you find that an invalid PDF file is created from the incorrect data in the PostScript file
http://support.microsoft.com/?id=952909


Update(s):
Atmfd.dll 5.1.2.227

946198  The print queue status is displayed as "Offline" on a Windows Server 2003-based print server if SNMP is enabled and if the printer devices do not respond to SNMP commands
http://support.microsoft.com/?id=946198


Update(s):
Tcpmib.dll 5.2.3790.4211

937932 Error message when you run a 16-bit program in Windows Server 2003: "NTVDM has encountered a hard error"
http://support.microsoft.com/?id=937932


Update(s):
Wwow32.dll 5.2.3790.4087

937193  The complete name of a network printer cannot be displayed on a computer that is running Windows Server 2003 or Windows XP
http://support.microsoft.com/?id=937193


Update(s):
Printui.dll 5.2.3790.4077
Wprintui.dll 5.2.3790.4077