English · Bahasa Indonesia
A diagnosis-first PowerShell TUI for troubleshooting Windows shared printers without applying broad security downgrades by default.
It inspects the actual failure layer first — Spooler, network profile, SMB/RPC reachability, Windows Protected Print, Point and Print policy, printer drivers, or legacy compatibility — then exposes the smallest relevant repair. It is useful when troubleshooting shared-printer failures commonly associated with errors such as 0x0000011b, 0x00000709, and 0x00000bc4, although an error code alone is never treated as proof of a specific fix.
Stable interface: the dependency-free Windows PowerShell TUI launched by
FixPrinter.bat. The experimental OpenTUI frontend is not part of stable releases.
Recommended: use the packaged ZIP from the latest GitHub Release.
- Open the latest release.
- Download
Windows-Printer-Sharing-Fix-vX.Y.Z.zipand extract it. - Double-click
FixPrinter.bat. - Accept the Administrator prompt.
- Choose Diagnose this PC first.
- Escalate to Safe, Advanced, or Legacy repair only when the diagnosis points there.
For automation from an already-elevated PowerShell session:
.\FixPrinter.ps1 -DiagnoseOnly -Json C:\Temp\printer-diagnosis.jsonThis runs the same read-only diagnosis and sanitized serializer without entering the TUI. If -Json is omitted, the deterministic output is %LOCALAPPDATA%\WindowsPrinterSharingFix\exports\diagnostic-headless.json.
Stable releases also publish SHA256SUMS.txt. Releases produced by the hardened workflow include GitHub build-provenance attestations; verification commands are documented in Release integrity.
Or clone the repository:
git clone https://github.com/man612/Windows-Printer-Sharing-Fix.git
cd Windows-Printer-Sharing-Fix
.\FixPrinter.batNo installer is required. Windows PowerShell 5.1 is the compatibility baseline.
| Principle | Stable v4 behavior |
|---|---|
| Diagnose before changing | Reads Windows/printer/network state before suggesting compatibility workarounds. |
| Smallest relevant repair | Safe actions are isolated instead of bundled into a broad “Full Fix”. |
| Security downgrades are explicit | RPC privacy, SMB1, guest auth, and LAN Manager fallbacks live outside Safe Repair. |
| Restore is scoped | Managed changes snapshot only the state relevant to that action. |
| Legacy stays legacy | Old compatibility options are available, but they are never treated as the default baseline. |
==============================================================================
WINDOWS PRINTER SHARING FIX v4.2.0
Diagnosis-first repair utility
> MAIN MENU
==============================================================================
OS: Windows 11 build 26100 Language: EN Spooler: Running
------------------------------------------------------------------------------
START HERE
[1] Diagnose this PC <RECOMMENDED>
REPAIR
[2] Safe Repair
[3] Compatibility Repair (Advanced)
[4] Legacy Compatibility (High Risk)
SUPPORT
[5] Restore latest managed changes
[6] Tools and Logs
[7] Guide
[8] Language
[9] Exit
------------------------------------------------------------------------------
The stable UI intentionally uses normal Windows PowerShell console primitives. It is lightweight, inspectable, and does not require a TUI framework, Node.js, Bun, or .NET package installation.
The local diagnosis is read-only and currently inspects:
- Windows product, exact servicing build (base build + UBR when available), and PowerShell version.
- Print Spooler state and installed printer inventory.
- Evidence-based printer-driver classification (v3/v4, Microsoft/third-party/unknown, and exact known Microsoft class-driver technology).
- Shared-printer host / network-printer client role.
- Active network profiles.
- Windows Protected Print (WPP) indicators plus conservative local readiness evidence from installed printer bindings, without claiming physical-device compatibility.
- RPC printer policy, including Named Pipes compatibility state, explicit print-RPC TCP port, Kerberos enforcement, and remote Spooler endpoint policy.
- Printer-policy source evidence from RSoP plus conservative MDM-aware signals, without assuming a registry value came from a domain GPO.
- Point and Print driver-installation protection.
- Modern SMB client/server signing and encryption posture, plus SMB1 client and insecure guest-auth state.
- LAN Manager compatibility and blank-password restrictions.
- Recent PrintService Admin warnings/errors.
- Conservative next-layer correlation that orders existing evidence without claiming a root cause.
For a specific \\HOST\Printer path, the optional target test checks name resolution, TCP 445/SMB, TCP 135/RPC Endpoint Mapper, an explicitly configured print-RPC TCP port when present, the host share namespace, and whether the printer is already connected locally. If SMB is reachable but the namespace fails, it can also collect only normalized recent SMB security-event categories as supporting evidence.
Tools and Logs also provides an explicit guided Windows test-page verification flow. It never runs from Diagnose automatically, warns before creating a real print job, and requires the user to confirm whether physical output actually appeared.
| Tier | Intended use | Examples |
|---|---|---|
| Safe Repair | First-line repair without lowering printer/network security protections. | Restart Spooler, clear a stuck queue, enable built-in sharing firewall rules for Private/Domain, start discovery services, change one selected network to Private. |
| Compatibility | Targeted workaround after diagnosis provides evidence. | Role-aware RPC Named Pipes fallback, temporary Point and Print relaxation, WPP guidance, targeted printer-connection reset. |
| Legacy | Last resort for proven old-device requirements. | SMB1 client, insecure SMB guest, LAN Manager compatibility level 1. |
High-risk actions require explicit typed confirmation. The utility intentionally refuses to automate remote blank-password logon.
Safe Repair is statically guarded from adding these behaviors:
RpcAuthnLevelPrivacyEnabled=0.- permanent
RestrictDriverInstallationToAdministrators=0. - SMB1 or insecure guest authentication.
- LAN Manager authentication downgrade.
LimitBlankPasswordUse=0.- broad Client Side Rendering Print Provider deletion.
Point and Print relaxation, when explicitly selected, is temporary around one connection attempt and restores its previous value in finally.
GitHub Actions runs on Windows with Windows PowerShell 5.1 and checks:
- syntax and static security invariants;
- PSScriptAnalyzer 1.25.0 Error/Warning diagnostics under the documented repo profile;
- repository governance/hygiene, full-SHA GitHub Action pinning, Dependabot configuration, and relative documentation links;
- diagnosis-only execution with a before/after managed-state fingerprint;
- structured JSON export reuse/privacy/read-only regression coverage;
- headless diagnosis CLI behavior and the formal Draft 2020-12 diagnosis schema;
- English/Indonesian localization output;
- migration of legacy language/restore state to the external runtime workspace;
- the end-user release ZIP and SHA256 checksum;
- bit-for-bit reproducible packaging across differing source file timestamps;
- release-workflow ordering and pinned GitHub Actions references.
CI is a guardrail, not a substitute for real printer hardware and host/client testing. Planned coverage lives in docs/TEST-MATRIX.md; accepted evidence is tracked separately in docs/REAL-WORLD-RESULTS.md.
Windows Printer Sharing Fix does not include telemetry or automatic report upload.
Starting with v4.0.2, runtime state is stored outside the repository under:
%LOCALAPPDATA%\WindowsPrinterSharingFix\
|-- backups\
|-- logs\
|-- exports\
|-- language.cfg
This keeps a Git clone clean when you change language or run diagnostics. Existing v4 backup state and language preference from the old repository-local layout are migrated on first run when possible. Set WPSF_DATA_ROOT before launch only if you intentionally need a custom runtime-data location.
| Platform | Status |
|---|---|
| Windows 11 | Primary target. |
| Windows 10 + PowerShell 5.1 | Supported on a best-effort basis; keep the OS fully patched / use eligible ESU where applicable. |
| Windows Server 2022 / 2025 | Diagnosis and repair paths are supported where the same Windows printing/network cmdlets exist; real printer environments can still differ by policy. |
| Windows 7 / 8 / 8.1 | Legacy best effort only; some modern cmdlets and protections do not exist. |
The project deliberately distinguishes Windows Server from Windows 11 even when they share a build family.
- Quick start
- Architecture
- Contribution and engineering checks
- Structured diagnostic JSON
- Formal diagnosis JSON Schema
- PrintService event classification
- Printer policy source evidence
- Printer driver classification
- Windows Protected Print readiness evidence
- Next-layer correlation
- Modern SMB/RPC diagnostics
- Release integrity and provenance
- Guided test-page verification
- Sanitized diagnosis examples
- Real-world test matrix
- Accepted real-world results
- Security policy
- Contributing
- Roadmap
- Changelog
Bug reports, compatibility findings, documentation improvements, and focused code changes are welcome.
Before opening a bug, run Diagnose this PC. Tools and Logs can export the latest diagnosis as sanitized structured JSON; review any file before posting it publicly. New contributors can look for issues labeled good first issue or help wanted.
Pull requests should explain the real-world failure scenario, what Windows state changes, the security/compatibility trade-off, how the change is tested, and how it can be restored. See CONTRIBUTING.md.
A modern OpenTUI frontend is being explored separately in draft PR #2. It is intentionally not the recommended interface and is not included in stable release packages.
- Report a bug or compatibility problem
- Ask a question or share a working setup
- For a security vulnerability, follow SECURITY.md instead of opening a public exploit report.
Does Diagnose change Windows settings?
No. The diagnosis path is tested against a managed-state fingerprint and must remain read-only.
Why not provide one big “fix everything” button?
Printer sharing failures can come from unrelated layers. Stacking security and registry changes can hide the real cause and make rollback harder.
Where are backups and logs?
Use Tools and Logs in the TUI, or open %LOCALAPPDATA%\WindowsPrinterSharingFix.
Is this an official Microsoft tool?
No. It is an independent open-source troubleshooting utility.
If the project saves you time, a GitHub star helps other Windows users and sysadmins discover it.
MIT. See LICENSE.
