group policy

Allow Non-administrators to Install Printer Drivers via GPO


By default, non-admin domain users do not have permissions to install the printer drivers on the domain computers. In order to install a driver, user should have local admin privileges on a computer (for example, by adding to the local Administrators group). This is great from the point of security because the installation of incorrect or fake device driver could compromise PC or degrade the system performance. However, this approach is extremely inconvenient in terms of IT-department, because it requires Support-team intervention when a user tries to install a new printer driver.

You can allow non-administrator users to install printer drivers on their Windows 10 computers (without need to grant local Admin permissions) using Active Directory Group Policies.

Configure GPO to Allow Non-Administrators to Install Printer Drivers

At first, create a new (or edit an existing) GPO object (policy) and link it to the OU (AD container), which contains the computers on which is necessary to allow users to install printer drivers. You can implement the same settings on a standalone (non-domain) computer using the local Group Policy Editor (gpedit.msc).

Expand the following branch in the Group Policy editor: Computer Configuration > Policies > Windows Settings > Security Settings > Local Policies > Security Options. Find the policy Devices: Prevent users from installing printer drivers.

Set the policy value to Disable. This policy allows non-administrators to install printer drivers when connecting a shared network printer (the printer’s driver downloaded from the print-server host). Then you can set the policy value to Disable, any unprivileged user can install printer driver as a part of connection shared printer to a computer. However, this policy not allows downloading and installing untrusted (not-signet) printer driver.

allow non-administrators to install printer drivers windows 10

Adding Printer Device GUIDs Allowed to Install via GPO

The next step is to allow user to install the printer drivers via GPO. In this case, we are interested in the policy Allow non-administrators to install drivers for these device setup classes in the GPO section Computer Configuration > Policies > Administrative Templates > System > Driver Installation.

Enable the policy and specify the device classes that users should be allowed to install. Click the Show button and in the appeared window add two lines with device class GUID corresponding to printers:

  • Class = Printer {4658ee7e-f050-11d1-b6bd-00c04fa372a7}
  • Class = PNPPrinters {4d36e979-e325-11ce-bfc1-08002be10318}

You can find a full list of the device class GUIDs in Windows here.

Then you enable this policy, members of local Users group can install new device driver for any device that match the specified device classes.

Note. You can enable this policy through the registry using the command:

reg add "HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\DriverInstall\Restrictions" /v AllowUserDeviceClasses /t REG_DWORD/d 1 /f

The list of allowed to install device GUIDs you can find under the registry key: HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\DriverInstall\Restrictions\AllowUserDeviceClasses.

Now save the policy.

allow non-administrators to install drivers for these device setup classes

Configuring Point and Print Restrictions Policy

In Windows 10 there is another feature relating to the UAC (User Account Control) settings, which occurs when you are trying to install a shared network printer. If the UAC is enabled, a message appears in which you want to specify the credentials of Administrator. If UAC is disabled, then when you try to install the printer under the non-admin user—the system hangs for some time and finally displays an error message: “Windows cannot connect to the printer. Access is denied“.

allow users to install printer drivers

To solve this problem you need to disable the policy Point and Print Restrictions. This policy is located under the Computer and User Configuration section of the GPO editor. In order to enable compatibility with previous versions of the Windows operating system, it is recommended to disable both policies. They are located in the following sections:

  • Computer Configuration > Policies > Administrative Templates > Printers
  • User Configuration > Policies >Administrative Templates > Control Panel -> Printers

gpo allow printer driver install




Then you disable this policy for Windows 10 computers, the security warnings and elevated command prompts do not appear then user trying to install network printer or then printer driver is updating.

Note. You can disable Point and Print Restrictions via the registry. Use the following command:

reg add "HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows NT\Printers\PointAndPrint" /v Restricted /t REG_DWORD /d 0 /f

If you want to restrict the list of print servers from which users are allowed to install print drivers without admin permissions, you need to set the Point and Print Restriction policy to Enabled.

Then enable the option “Users can only point and print to these servers”. In the
Enter fully qualified server names separated by semicolons” specify a list of your trusted print servers (FQDN).

Under the “Security Prompts” section select the “Don’t show warning or elevation prompt” for the policy parameters “Then installing drivers for a new connection” and “Then updating drivers for an existing connection”.

gpo install printer without admin rights

Test the Policy to Allow Users to Install Printer Drivers

It remains to test the policy on client computers (requires restart). After rebooting and applying Group Policy settings, users will be allowed to install printer drivers without Admin permissions.

Tip. After installing the update KB3170455, released on July 12 2016, in order to successfully install the printer, the printer driver must meet the following requirements:

  • The driver must be signed by a trusted digital signature;
  • The driver must be packed (Package-aware print drivers). Installing of the unpacked (non-package-aware) drivers through Point and Print Restrictions is impossible

This means then when you try to install the non-package-aware v3, you will see the warning “Do you trust this printer?” with the Install driver UAC button, which requires printer drivers installation under admin account.

gpo allow users to install printers

You can check your driver type on print server under the node Print Management > Print Servers > Server Name > Drivers. For package-aware print drivers you can see the True value in the Packaged column.

group policy install printer driver without admin rights

Add Your Comment