This message was deleted.
# citrix-vad
s
This message was deleted.
n
Our current printing policy is pretty typical I think, we allow for all client printer redirection, set the client's default printer to the default one in the session, and only use native/universal print driver.
r
Print driver mapping a compatibility. Find the name of the pdf printer then set block
n
Yeah, that's the part that I thought might be easy to circumvent by someone motivated.....just use a different printer/driver name.
r
Yea that works but will log errors. Not sure I understand how it would be circumvented if it’s block to pass though from the client?
n
Maybe I misunderstood you then. It seems that blocking passthrough but mapping explicitly what you want to allow would make legit BYOD/print-at-home needs difficult to account for all the different types of printers we'd need to allow.
j
Yeah I'd just block via PDF driver name as Ray mentioned.
💯 1
👍 1
r
@Neal Dolson I’ll send you a doc I made in the AM. Basically I grab all the garbage printers that get redirected into a session. I grab the printer driver name. Throw it in studio policy and it will stop them from coming into the session. I don’t remember the exact names. But things like Onenote printer, MS PDF printer. Things like that.
@Neal Dolson, this will help you.
👍 1
🤯 1
n
Thanks @Ray Davis, that's a little different than the method I found in CTX articles which appeared to kind of be the reverse of what you're doing, in that they blocked everything by default with a catch all and then specifically allowed certain things. This method may be workable for us. Appreciate you sharing!
r
Which article show the block all? or catch all Curious on that one. Because there are times I want to do this. But no problem, sharing is caring 🙂
"Even after restricting client drive mapping in HDX sessions user can save files on their client through redirected client printer such as 'Microsoft Print to PDF' etc. There are hundreds of such printers which cannot be blacklisted through policy as we do not have the list."
The second sentence in that statement is what gave me pause about the effectiveness of blocking specific software printers
But, blocking things like the built in MS one that is native to Windows and keeping it from redirecting would at least eliminate confusion between the one on the Windows VM their Citrix session is hosted on, and the identically named (but also appended by "on %endpoint PC name%) that gets redirected into the session so they dont inadvertently print to the MS PDF printer on their home computer and save a file there by mistake.
The event that brought this up was that - user accessed Citrix from their home PC on the weekend, home PC had no actual printers defined, just the native Windows PDF printer, which got redirected into their session and set as default per the printing policy, then when they attempted to print to the PDF printer on the Citrix server itself, they inadvertently chose the "default" one on their home computer and got concerned when that file showed up on the desktop of the home computer.