<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://blogs.msdn.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>How to allow users to manage file and print shares without granting other advanced privileges</title><link>http://blogs.msdn.com/aaron_margosis/archive/2005/04/18/409105.aspx</link><description>By default, the ability to manage file and print shares is granted only to members of the Administrators, Power Users, and Server Operators groups. Because members of those groups have many other system-level privileges, it is not recommended to make</description><dc:language>en-US</dc:language><generator>CommunityServer 2.1 SP1 (Build: 61025.2)</generator><item><title>Table of contents, Aaron Margosis' non-admin blog</title><link>http://blogs.msdn.com/aaron_margosis/archive/2005/04/18/409105.aspx#409482</link><pubDate>Tue, 19 Apr 2005 03:22:46 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:409482</guid><dc:creator>Aaron Margosis' WebLog</dc:creator><description>Complete list of Aaron Margosis' non-admin / least privilege posts, for easy lookup.</description></item><item><title>More non-admin tips from Aaron</title><link>http://blogs.msdn.com/aaron_margosis/archive/2005/04/18/409105.aspx#412997</link><pubDate>Thu, 28 Apr 2005 17:05:26 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:412997</guid><dc:creator>.net &lt;i&gt;DE&lt;/i&gt;lirium</dc:creator><description>How to allow users to manage file and print shares without granting other advanced privileges&lt;br&gt;&lt;a rel="nofollow" target="_new" href="http://blogs.msdn.com/aaron_margosis/archive/2005/04/18/409105.aspx&amp;amp;amp;nbsp"&gt;http://blogs.msdn.com/aaron_margosis/archive/2005/04/18/409105.aspx&amp;amp;amp;nbsp&lt;/a&gt;...</description></item><item><title>Spread the LUA joy</title><link>http://blogs.msdn.com/aaron_margosis/archive/2005/04/18/409105.aspx#427791</link><pubDate>Fri, 10 Jun 2005 19:12:48 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:427791</guid><dc:creator>tonyso</dc:creator><description>Get your friends and family, all those folks that come to you for computer help once their machines have...</description></item><item><title>re: How to allow users to manage file and print shares without granting other advanced privileges</title><link>http://blogs.msdn.com/aaron_margosis/archive/2005/04/18/409105.aspx#441532</link><pubDate>Fri, 22 Jul 2005 00:28:48 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:441532</guid><dc:creator>Jon Morningstar</dc:creator><description>Do you have any advice about and/or a way to allow standard users to add fonts?</description></item><item><title>re: How to allow users to manage file and print shares without granting other advanced privileges</title><link>http://blogs.msdn.com/aaron_margosis/archive/2005/04/18/409105.aspx#461670</link><pubDate>Wed, 07 Sep 2005 02:33:34 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:461670</guid><dc:creator>kevin</dc:creator><description>Hi Aaron,&lt;br&gt;&lt;br&gt;Currently our users need admin rights when they install a Palm like device.  The need is to sync up with Outlook etc.&lt;br&gt;Do you have any suggestions for this?&lt;br&gt;thanks.&lt;br&gt;</description></item><item><title>Palm...</title><link>http://blogs.msdn.com/aaron_margosis/archive/2005/04/18/409105.aspx#475241</link><pubDate>Thu, 29 Sep 2005 11:33:59 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:475241</guid><dc:creator>Chamach</dc:creator><description>&lt;br&gt;Palm and admin :&lt;br&gt;&lt;a rel="nofollow" target="_new" href="http://kb.palm.com/SRVS/CGI-BIN/WEBCGI.EXE/,/?St=38,E=0000000000160050878,K=7811,Sxi=17,Case=obj"&gt;http://kb.palm.com/SRVS/CGI-BIN/WEBCGI.EXE/,/?St=38,E=0000000000160050878,K=7811,Sxi=17,Case=obj&lt;/a&gt;(1465)</description></item><item><title>re: How to allow users to manage file and print shares without granting other advanced privileges</title><link>http://blogs.msdn.com/aaron_margosis/archive/2005/04/18/409105.aspx#476887</link><pubDate>Tue, 04 Oct 2005 18:27:02 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:476887</guid><dc:creator>Glenn Woodruff</dc:creator><description>It's nice that this can be done from TweakUI, but this doesn't help a lot in a managed or (in my case) XPe enviroment.  Is there another way to do this?</description></item><item><title>re: How to allow users to manage file and print shares without granting other advanced privileges</title><link>http://blogs.msdn.com/aaron_margosis/archive/2005/04/18/409105.aspx#485613</link><pubDate>Thu, 27 Oct 2005 17:33:16 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:485613</guid><dc:creator>Chris </dc:creator><description>Nice work!&lt;br&gt; I'm wonder if there is any way that I can alow my users to install local printer without belong to a Power User group? Thanks</description></item><item><title>Function permissions without granting other advanced privileges</title><link>http://blogs.msdn.com/aaron_margosis/archive/2005/04/18/409105.aspx#499010</link><pubDate>Thu, 01 Dec 2005 21:09:08 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:499010</guid><dc:creator>John</dc:creator><description>I'm a sys admin with a question about desktop permissions. We are in a Win2K (migrating to XP) mid-size environment. We have customers who occasionally request admin rights to run certain software titles, etc. Sometimes we can grant limited file or registry permissions to allow them to function without elevated rights, sometimes not. &lt;br&gt;&lt;br&gt;The current dilemma before me is a group of users who need to run regsvr32 to register new dll's on a fairly regular basis. Do you know of an explicit permission that would allow this, without elevating rights to power user or admin? Thanks </description></item><item><title>re: How to allow users to manage file and print shares without granting other advanced privileges</title><link>http://blogs.msdn.com/aaron_margosis/archive/2005/04/18/409105.aspx#503437</link><pubDate>Wed, 14 Dec 2005 06:50:20 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:503437</guid><dc:creator>Aaron Margosis</dc:creator><description>John, take a look at this utility.  It takes advantage of the fact that Windows 2000 introduced per-user registration data - HKCR is now a merged view of HKLM\Software\Classes and HKCU\Software\Classes (the latter is user-writable).&lt;br&gt;&lt;br&gt;RegSvrEx - An Enchanced COM Server Registration Utility&lt;br&gt;&lt;a rel="nofollow" target="_new" href="http://www.codeproject.com/w2k/regsvrex.asp"&gt;http://www.codeproject.com/w2k/regsvrex.asp&lt;/a&gt;&lt;br&gt;&lt;br&gt;</description></item><item><title>re: How to allow users to manage file and print shares without granting other advanced privileges</title><link>http://blogs.msdn.com/aaron_margosis/archive/2005/04/18/409105.aspx#506854</link><pubDate>Thu, 22 Dec 2005 23:03:49 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:506854</guid><dc:creator>Ryan</dc:creator><description>I'm stuck in a Windows 2000 environment and can't use that version of tweakui.  Is there another easy way of doing this?</description></item><item><title>re: How to allow users to manage file and print shares without granting other advanced privileges</title><link>http://blogs.msdn.com/aaron_margosis/archive/2005/04/18/409105.aspx#506945</link><pubDate>Fri, 23 Dec 2005 04:22:06 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:506945</guid><dc:creator>Aaron Margosis</dc:creator><description>Ryan, TEST THIS FIRST, but you may be able to build the ACLs you want on a Windows XP computer, then export those values from the registry and import them to the Windows 2000 computer.  The three values you care about are: SrvsvcConnection, SrvsvcShareFileInfo, and SrvsvcSharePrintInfo.</description></item><item><title>re: How to allow users to manage file and print shares without granting other advanced privileges</title><link>http://blogs.msdn.com/aaron_margosis/archive/2005/04/18/409105.aspx#507695</link><pubDate>Wed, 28 Dec 2005 13:25:52 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:507695</guid><dc:creator>Davoud</dc:creator><description>Hi,&lt;br&gt;&lt;br&gt;I would like to know why changes to the “Manage file and printer sharing” operation are not needed and not recommended? And is there anyway to invoke these security windows such as “Manage file/print server connections” security window and so forth, directly and without using Tweakui?&lt;br&gt;&lt;br&gt;Thanks &lt;br&gt;&lt;br&gt;</description></item><item><title>re: How to allow users to manage file and print shares without granting other advanced privileges</title><link>http://blogs.msdn.com/aaron_margosis/archive/2005/04/18/409105.aspx#522577</link><pubDate>Thu, 02 Feb 2006 01:47:27 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:522577</guid><dc:creator>Steve</dc:creator><description>How do you support the remote LUA user whose machine for example has been exploited via a unpatched vulnerability such as blaster/sasser? The normal course of action would be to download a scan/repair utility, and install then run the utility. In the remote LUA scenario the installation/execution is prohibited. That has left us looking at a local administrator account as our &amp;quot;sky is falling&amp;quot; backdoor to deal with firmwide consequences of such an attack. Is there an alternative to having this backdoor in place.&lt;br/&gt;&lt;br/&gt;Thx in advance,&lt;br/&gt;Steve</description></item><item><title>re: How to allow users to manage file and print shares without granting other advanced privileges</title><link>http://blogs.msdn.com/aaron_margosis/archive/2005/04/18/409105.aspx#522868</link><pubDate>Thu, 02 Feb 2006 09:26:23 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:522868</guid><dc:creator>Aaron Margosis</dc:creator><description>Steve:  do you have any remote access (e.g., Remote Desktop, Remote Assistance) to the affected computer?  Can you use RunAs to run the Malicious Software Removal Tool?  BTW, once the MSRT has been run once as admin (and the EULA accepted), if you've enabled Automatic Updates MSRT will run automatically every month.&lt;br/&gt;&lt;a rel="nofollow" target="_new" href="http://support.microsoft.com/Default.aspx?kbid=890830"&gt;http://support.microsoft.com/Default.aspx?kbid=890830&lt;/a&gt;</description></item><item><title>re: How to allow users to manage file and print shares without granting other advanced privileges</title><link>http://blogs.msdn.com/aaron_margosis/archive/2005/04/18/409105.aspx#760414</link><pubDate>Mon, 18 Sep 2006 11:01:55 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:760414</guid><dc:creator>Taylor</dc:creator><description>Hi,Mr Margosis &lt;br&gt;I've changed the setting by using tweakUI,but it didn't work even if I reboot my computer.what's happened? </description></item><item><title>re: How to allow users to manage file and print shares without granting other advanced privileges</title><link>http://blogs.msdn.com/aaron_margosis/archive/2005/04/18/409105.aspx#768098</link><pubDate>Sat, 23 Sep 2006 20:06:45 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:768098</guid><dc:creator>Kaari</dc:creator><description>&lt;P&gt;Hi, &lt;BR&gt;I've got the same problem as Taylor. I set "Manage file shares" to FULL CONTROL for the local group INTERACTIVE, but no account in the local group USER can read, change or create file shares. &lt;BR&gt;OS: Windows XP SP2 incl. all patches&lt;/P&gt;
&lt;div class=ajmReply&gt;
&lt;P&gt;Review the instructions on this post carefully -- there are &lt;EM&gt;three&lt;/EM&gt; different items you need to change the access control for.&lt;/P&gt;
&lt;P&gt;-- Aaron&lt;/P&gt;&lt;/div&gt;</description></item><item><title>re: How to allow users to manage file and print shares without granting other advanced privileges</title><link>http://blogs.msdn.com/aaron_margosis/archive/2005/04/18/409105.aspx#776257</link><pubDate>Fri, 29 Sep 2006 02:03:23 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:776257</guid><dc:creator>Tom</dc:creator><description>&lt;P&gt;Hi, &lt;BR&gt;Is there any other ways to allow normal users to manage shares in addition to TweakUI? &lt;/P&gt;
&lt;div class=ajmReply&gt;
&lt;P&gt;TweakUI offers the only UI that I know of to edit the permissions.&amp;nbsp; Without that you're manipulating binary values in the registry.&amp;nbsp; Now, once you have established permissions on one system with TweakUI, you can export the relevant registry values (SrvsvcConnection, SrvsvcShareFileInfo, and SrvsvcSharePrintInfo) from that system and import them onto other systems.&amp;nbsp; If you do this, make sure that the accounts being granted access are either domain accounts or built-in accounts like "INTERACTIVE" and not local accounts that won't exist on the other systems.&lt;/P&gt;
&lt;P&gt;HTH&lt;/P&gt;
&lt;P&gt;-- Aaron&lt;/P&gt;&lt;/div&gt;</description></item><item><title>re: How to allow users to manage file and print shares without granting other advanced privileges</title><link>http://blogs.msdn.com/aaron_margosis/archive/2005/04/18/409105.aspx#784279</link><pubDate>Tue, 03 Oct 2006 09:20:18 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:784279</guid><dc:creator>Reniel</dc:creator><description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;Is there a way to incorporate "RUNAS.EXE" in logon scripts to run a program as an administrator without user intervention such as the password?&lt;/P&gt;
&lt;P&gt;I am using rundll32 in logon scripts to install printers on the remote machine. In order for the ordinary user to install printers, I used gpedit.msc to allow "Power Users" to "load and unload device drivers". However, I am having problems setting the printer settings (i.e. page setup, paper size, etc.).&lt;/P&gt;
&lt;P&gt;I have saved the settings of the printer in a network drive using the command:&lt;/P&gt;
&lt;P&gt;rundll32 printui.dll,PrintUIEntry /Ss /n &amp;lt;name of printer&amp;gt; /a &amp;lt;file where to save the settings&amp;gt;&lt;/P&gt;
&lt;P&gt;and then, tried to restore the settings using the following:&lt;/P&gt;
&lt;P&gt;rundll32 printui.dll,PrintUIEntry /Sr /n &amp;lt;name of printer&amp;gt; /a &amp;lt;file where to save the settings&amp;gt;&lt;/P&gt;
&lt;P&gt;However, it is telling me that the "Operation is not permitted" if I logon as a Power User. But if I use an account with Administrator rights, there is no problem.&lt;/P&gt;
&lt;P&gt;I hope to solve this using the "RUNAS.EXE" utility.&lt;/P&gt;
&lt;P&gt;Thanks!&lt;/P&gt;
&lt;DIV class=ajmReply&gt;
&lt;P&gt;RUNAS.EXE always requires the password to be entered at the console.&lt;/P&gt;
&lt;P&gt;-- Aaron&lt;/P&gt;&lt;/DIV&gt;</description></item><item><title>Create shared folder using command line on xp (rundll32)</title><link>http://blogs.msdn.com/aaron_margosis/archive/2005/04/18/409105.aspx#1510114</link><pubDate>Tue, 23 Jan 2007 01:58:37 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:1510114</guid><dc:creator>Jay</dc:creator><description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;Does anyone know a way to invoke a command to create and shared a folder in window XP? &amp;nbsp;I am not sure if the rundll32 will do all the trick.&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;Jay&lt;/P&gt;
&lt;P&gt;jaydiep@gmail.com&lt;/P&gt;
&lt;DIV class=ajmReply&gt;
&lt;P&gt;Jay: &lt;/P&gt;
&lt;P&gt;Did you try NET SHARE from a command prompt?&lt;/P&gt;
&lt;P&gt;HTH&lt;/P&gt;
&lt;P&gt;-- Aaron&lt;/P&gt;&lt;/DIV&gt;</description></item><item><title>re: How to allow users to manage file and print shares without granting other advanced privileges</title><link>http://blogs.msdn.com/aaron_margosis/archive/2005/04/18/409105.aspx#2262477</link><pubDate>Tue, 24 Apr 2007 20:46:13 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:2262477</guid><dc:creator>Pat Stafford</dc:creator><description>&lt;P&gt;When I try to install TweakUIPowerToySetup.exe, I get an error: "Entry Point Not Found - The procedure entry point GetDllDirectoryW could not be located in the dynamic link library KERNEL32.DLL"&lt;/P&gt;
&lt;P&gt;Is this supposed to be installable on Win2K? &amp;nbsp;I tried the earlier version of TweakUI, but it doesn't offer any of the screens for privileges described above.&lt;/P&gt;
&lt;DIV class=ajmReply&gt;
&lt;P&gt;Pat:&amp;nbsp; Each version of TweakUI is tightly coupled to the version of Windows for which it was made.&amp;nbsp; The XP version will not be usable on Windows 2000; and unfortunately, the Windows 2000 version did not include the extra ACL editing capability that the XP version allowed.&amp;nbsp; There may be ways to get through this if you don't mind some risky registry editing...&lt;/P&gt;
&lt;P&gt;-- Aaron&lt;/P&gt;&lt;/DIV&gt;</description></item><item><title>re: How to allow users to manage file and print shares without granting other advanced privileges</title><link>http://blogs.msdn.com/aaron_margosis/archive/2005/04/18/409105.aspx#4201305</link><pubDate>Fri, 03 Aug 2007 09:17:23 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:4201305</guid><dc:creator>Shrutika</dc:creator><description>&lt;p&gt;Hi,&lt;/p&gt;
&lt;p&gt;My machine is windows XP home edition, SP6.&lt;/p&gt;
&lt;p&gt;I cannot get option &amp;quot;Manage file/print server connections” operation in the “Access Control” dropdown in the right pane.&lt;/p&gt;
&lt;p&gt;I get 2 options namely &amp;quot;connect to registry remotely&amp;quot; and &amp;quot;access performance counter&amp;quot; on the tweakUI screen.&lt;/p&gt;
&lt;p&gt;Could you help?&lt;/p&gt;
&lt;p&gt;Thanks,&lt;/p&gt;
&lt;p&gt;Shrutika&lt;/p&gt;
</description></item><item><title>XP SP2 How to Install Local Printers without granting Power User or Administrator?</title><link>http://blogs.msdn.com/aaron_margosis/archive/2005/04/18/409105.aspx#8353855</link><pubDate>Thu, 03 Apr 2008 16:55:53 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:8353855</guid><dc:creator>Jon88</dc:creator><description>&lt;p&gt;Does anyone know of away to How to Install Local Printers as a restricted user without granting Power User or Administrator in XP SP2? Thanks in advance.&lt;/p&gt;
</description></item><item><title>What changes does the manage file shares do?</title><link>http://blogs.msdn.com/aaron_margosis/archive/2005/04/18/409105.aspx#8953153</link><pubDate>Tue, 16 Sep 2008 01:07:14 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:8953153</guid><dc:creator>Aen</dc:creator><description>&lt;p&gt;I do not want to install tweak UI on every server, instead i rather just make the changes that tweak ui would do, and manually set them on my servers. &amp;nbsp;I have a script where i have users create shares with for new hires. &amp;nbsp;they need rights to create shares on the servers across the US, but i dont want them to have rights to do anything else but create a share on those few servers. &amp;nbsp;&lt;/p&gt;
</description></item><item><title>re: How to allow users to manage file and print shares without granting other advanced privileges</title><link>http://blogs.msdn.com/aaron_margosis/archive/2005/04/18/409105.aspx#9138817</link><pubDate>Mon, 24 Nov 2008 23:38:46 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:9138817</guid><dc:creator>Haas</dc:creator><description>&lt;P&gt;Hi Aaron,&lt;/P&gt;
&lt;P&gt;I was very happy when I found your solution for this problem.&lt;/P&gt;
&lt;P&gt;But it must be that I'm doing something wrong I implemented the three changes that you explain using tweakui, but I can still ot add any printers.&lt;/P&gt;
&lt;P&gt;When I use the Add Printer Wizard (or Print Managemtn) the 'Local Printer attached to this computer' is grayed out. &lt;/P&gt;
&lt;P&gt;When I add my user to the power users it works.&lt;/P&gt;
&lt;P&gt;Can you help me out please?&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;John&lt;/P&gt;
&lt;DIV class=ajmReply&gt;
&lt;P&gt;&lt;EM&gt;[Aaron Margosis]&amp;nbsp; This blog post is about file and printer &lt;STRONG&gt;sharing&lt;/STRONG&gt;, not about installing printers.&amp;nbsp; Installing local printers remains an admin task for the time being.&lt;/EM&gt;&lt;/P&gt;&lt;/DIV&gt;</description></item><item><title>re: How to allow users to manage file and print shares without granting other advanced privileges</title><link>http://blogs.msdn.com/aaron_margosis/archive/2005/04/18/409105.aspx#9141603</link><pubDate>Tue, 25 Nov 2008 14:36:44 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:9141603</guid><dc:creator>Haas</dc:creator><description>&lt;p&gt;Aaron, Thanks for the reply. &lt;/p&gt;
&lt;p&gt;For the time being is an interesting quote to take away. The task of adding drivers, ports and printers and sharing them is trivial and gets executed by helpdesk people or even key-users in a site.&lt;/p&gt;
&lt;p&gt;Now we need to give them at least power user membership to enable them to do this task. This creates a risk.&lt;/p&gt;
&lt;p&gt;Is it possible to figure out what individual rights I need to give a user to be able to give him the same possibilties?&lt;/p&gt;
&lt;p&gt;This would mean usinf tools like process monitor en process explorer and the like.&lt;/p&gt;
&lt;p&gt;Any quick pointers? Thanks, John&lt;/p&gt;
</description></item><item><title>re: How to allow users to manage file and print shares without granting other advanced privileges</title><link>http://blogs.msdn.com/aaron_margosis/archive/2005/04/18/409105.aspx#9801428</link><pubDate>Wed, 24 Jun 2009 15:51:49 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:9801428</guid><dc:creator>Thomas</dc:creator><description>&lt;p&gt;Hi Aaron&lt;/p&gt;
&lt;p&gt;I've configured the three registry values SrvsvcConnection, SrvsvcShareFileInfo and SrvsvcSharePrintInfo, using the tweakUI tool. The idea is to add a local built-in group (print operators?) or a domain group. Adding those using the UI is easy enough, and the settings are verified as saved.&lt;/p&gt;
&lt;p&gt;However, creating new printer objects, the configured group does not even appear on the new object. The system have of course been booted.&lt;/p&gt;
&lt;p&gt;Currently we use a script to change permissions on new printer objects, but changing the default permissions would be a much better solution.&lt;/p&gt;
&lt;p&gt;Thank you.&lt;/p&gt;
</description></item></channel></rss>