Forum Discussion
Job Owner "System"
- May 11, 2020Sorted, the machine needs to be joined to the local AD
ManagedPrintMax Could you please clearify if the end users device has to be joined to the local AD or just the machine that has the connecter installed?
- Philip_DemareeMay 13, 2020Former Employee
SimonHessBZP For the username to be associated with the print job on a Connector, you would need to have an AAD/AD Hybrid configuration, and the Connector server would need to be AD and AAD joined. Provided everything is set up correctly in regard to AAD/AD, the Connector will try to impersonate the user by converting the AAD UPN used to submit the job to UP to the associated on-prem AD account and submit the job to the spooler and the print queue using that user's name.
Phil
- DonzaMacMay 28, 2020Copper Contributor
Hi Phil,
Is there any desire to change this so an AAD joined machine can pass the UP through to the spooler? We use papercut and need the names passed through for follow me printing. It works currently as the connector is domain joined. We are trying to go full cloud and printing is one of the main things holding us back. Kind of defeats the purpose of cloud print when we need a connector to be domain joined.
- Philip_DemareeMay 28, 2020Former Employee
DonzaMac Based on my understanding, the issue is that Windows as an operating system still only understands Kerberos (AD) validation, so the Spooler needs to be provided the AD user account associated with the AAD account. Papercut should be able to use the AD account as this is how the legacy Windows Point and Print works. The tricky part is having your AAD/AD Hybrid environment configured correctly so that the association between the AAD account that UP uses and the AD account that Windows uses succeeds.
The Dev team is currently working on how to address this moving forward in regard to a server-less environment that would be AAD-only. Part of this is that the printers themselves need to be able to connect to AAD as AAD-joined devices. The Connector is part of the transition to allow legacy printers to communicate with Universal Print.
Phil
- TheAlanMorrisMay 14, 2020Copper Contributor
- ManagedPrintMaxMay 12, 2020Copper Contributor
SimonHessBZPI havent tested, but I would expect only the machine with the connector installed.