Windows IT Pro is the authoritative and independent resource for windows nt, windows 2000, windows 2003, windows xp. Features a collection of resources and magazines for windows IT professionals.
  
  
  Advanced Search 


January 2004

AD Printer Publishing

Advertise printer resources for users to find
RSS
Subscribe to Windows IT Pro | See More Active Directory (AD) Articles Here | Reprints | Or get the Monthly Online Pass—only $5.95 a month!

The pruner runs on all AD DCs. Periodically, the pruner connects to the server print queue to ensure that printers published in AD are still available on the network. The pruner will try to contact a print queue a certain number of times within a given time frame. The default interval is three checks at 8-hour intervals in 24 hours (you can configure this interval in the MMC Group Policy snap-in under Computer Configuration, Administrative Templates, Printers). If the pruner is unable to contact the print queue within the given period, the pruner removes the print queue object from AD. Thus, using the default interval, the pruner can prune a printer from AD within a 24-hour period.

Each DC's pruner begins by compiling a list of all the printers published in AD. The pruner then uses DNS to determine which print servers are in its own AD site. The pruner then attempts to contact each print queue on the print servers in the same site, in turn, removing print queue objects from AD as required.

Problems can occur when the pruner can't find the print-server information in DNS and thus can't determine whether the print server is in the same AD site as the DC. In that event, the pruner simply assumes that the printer is in the same AD site as the DC on which the pruner is running. This assumption can cause problems in environments in which the DC and print server are in different locations with a slow network connection between them or if one of the machines is behind a firewall. If the DC can't contact a print queue within a specified period, the pruner will simply remove the print queue information from AD. The DC performing the deletion will of course use standard directory replication to replicate the change to all other DCs in the domain.

Another problem involves the DHCP client service. As you might be aware, the DHCP client service is necessary for dynamic DNS (DDNS) registrations. So, if the DHCP client service is stopped on the print server, the server can't dynamically reregister its host address (A) and pointer (PTR) resource records. After a period of time, the print server's DNS record might be removed from DNS through aging and scavenging. If the print server's record is removed, each pruner will assume that the DC on which it's running is in the same AD site as the print server. Again, if no network connection exists between any of these DCs and the print server, the pruner will remove the printers from AD. It's important to ensure that the DHCP client is running on all print servers in AD deployments that run DDNS, a task that you can enforce through Group Policy. Similarly, if you unplug a DC from the network for a period exceeding the configured retry interval but the DC continues to run, the pruner running on that DC will remove all published printers because it can't contact them. If the DC reconnects to the network, the DC will replicate the removal to other DCs.

Several event-log entries can be useful in troubleshooting printer pruning, including event ID 47 in the System event log on a DC. This event typically occurs when the pruner attempts, and fails, to contact the print queue on the print server. When event ID 47 is followed by event ID 50 in the System event log, the pruner retry threshold has been reached and AD has removed the print queue object.

Let's look at an example to show how these events can help you troubleshoot pruner problems. Imagine that you suddenly notice that some or all of your published printers no longer appear in AD. If you suspect a DNS problem, you need to identify which DC's pruner was responsible for deleting the printers. Rather than opening the Event Viewer for each DC in turn, you can use the EventCombMT utility from the Microsoft Windows Server 2003 Resource Kit to search the DCs for event IDs 47 and 50. EventCombMT has a graphical interface and lets you search for specific events in the event logs on a specified range of machines. The utility logs summary output information to a text file for easy viewing. After you identify the offending DC, you can determine what's causing the problem.

Under certain circumstances, you might see the opposite condition: the pruner's failure to remove printers from AD. To avoid this problem, don't remove the Print permissions assigned (by default) to the Everyone group in the security settings of the printers on the print server. If you really need to restrict access to the printer, you can remove the permissions assigned to the Everyone group and assign Print permissions only to the Domain Controllers group. Remember that the pruner running on DCs requires access to the print queues on the print servers. Without a minimum of Print permissions, the pruner can't perform its role.

Typically, the print server republishes printer information only when the spooler service restarts on the print server. Thus, without some other form of intervention, pruned printers won't reappear in AD. If a printer does drop off the list of published printers, you can clear, then select the List in the Directory check box on the Sharing tab in the printer's Properties dialog box. Alternatively, you can change a Group Policy setting to force the print servers to republish print queue information on a regular basis.

   Previous  1  2  [3]  4  Next 


Reader Comments

You must log on before posting a comment.

If you don't have a username & password, please register now.




Top Viewed ArticlesView all articles
Microsoft Kills OneCare, Will Launch Free Security Solution

Microsoft on Tuesday announced that it would retire its $50-a-year security subscription product, Windows Live OneCare, and replace it with a free solution codenamed "Morro." Unlike OneCare, however, Morro will focus only on core anti-malware features and ...

The website is down because someone removed the X-Box

What happens when a manager mistakes a server for a games console. ...

Xbox 360 Overhaul Arrives with New UI, Avatars

Xbox 360 owners who logon to the system's Xbox Live system this morning will receive the most significant functional change yet to the console's user interface, or dashboard. Dubbed the New Xbox Experience, this new front-end features a completely new ...


Active Directory (AD) Whitepapers Sustainable Compliance: How to reconnect compliance, security and business goals

Managing Unix/Linux with Microsoft System Center Operations Manager 2007 Cross Platform Extensions Beta

Addressing the Insider Threat with NetIQ Security and Administration Solutions

Related Events Check out our list of Free Email Newsletters!

Windows OSs eBooks Understanding and Leveraging Code Signing Technologies

Keeping Your Business Safe from Attack: Monitoring and Managing Your Network Security

Windows 2003: Active Directory Administration Essentials

Related Active Directory (AD) Resources Become a VIP member of the Windows IT Pro community!
Get it all with the VIP CD and VIP access. A $500+ value for only $279!

Subscribe to Windows IT Pro!
Solve your toughest technical problems with our experts and access 10,000 + articles online. 30% off

Monthly Online Pass - Only $5.95!
Get instant access to 10,000+ articles from Windows IT Pro Magazine!

TechNet Virtual Labs
Evaluate and test Microsoft's newest products.


Windows IT Pro Home Register FAQ for Windows WinInfo News
Europe Edition About Us Contact Us/Customer Service Media Kit Affiliates / Licensing  
SQL Server Magazine Office & SharePoint Pro Windows Dev Pro IT Job Hound ITTV
IT Library Technology Resource Directory Connected Home Windows Excavator Windows SuperSite 
 
 Windows IT Pro is a Division of Penton Media Inc.
 Copyright © 2008 Penton Media, Inc., All rights reserved. Terms and Use | Privacy Statement | Reprints and Licensing