Fix it now
Windows will not complete the connection to the shared queue. Microsoft publishes no meaning for 0x0000011B – it is not even a defined Windows error number – so work the companions instead: 0x00000709 is an invalid printer name and 0x00000BCB says the driver is not on this machine and would have to be downloaded.
Get-Printer -ComputerName printsrv | Select-Object Name,ShareName,Shared
net stop spooler
net start spooler
rundll32 printui.dll,PrintUIEntry /in /n "\\printsrv\ShareName"
- Connect with the ShareName exactly as it comes back, including case and spaces. A wrong or renamed share is what 0x00000709 is telling you and it is quicker to rule out than anything else here.
- Bring both machines to the same current update level and reboot both. Most of these are one end patched and the other not, and patching both settles it without any further change.
- Try the same connection from an elevated session. If it succeeds as an administrator and fails as a standard user, the block is driver installation rather than the connection, and the driver is the thing to fix.
- Pre-stage the driver on the client with your deployment tool or
pnputil /add-driver, so nothing has to be installed at connection time. - As an interim measure that avoids the shared queue entirely, add the printer on a standard TCP/IP port with the driver installed locally.
The registry workaround circulated for this code lowers the authentication level the print RPC call requires. Microsoft publishes neither the value nor the code’s meaning on Learn or its support site, so it is not a documented fix and it is not in this article.
If the standard user who reported it can now add the queue and print, you are done. If not, the next section covers what the connection actually involves and which half of it is failing.
Why it happens
Connecting to a shared printer is two operations that look like one. First the client makes a remote procedure call to the print server to enumerate the queue and open a handle to it. Then, in most cases, it obtains a driver for that queue and installs it locally. Both halves were tightened after the run of print spooler vulnerabilities, and a failure in either produces a dialog that says Windows cannot connect to the printer.
0x0000011B is worth being blunt about. Decimal 283 is not a defined Windows error number – it is absent from Microsoft’s own system error code list – and no Microsoft page publishes a meaning for it. What is published are its companions, and they are more useful than the headline. 0x00000709 is ERROR_INVALID_PRINTER_NAME, the printer name is invalid. 0x00000BCB is ERROR_PRINTER_DRIVER_DOWNLOAD_NEEDED, the driver was not found on the system and needs to be downloaded. 0x0000006E is ERROR_OPEN_FAILED, the system cannot open the device or file specified. 0x000003EB is ERROR_CAN_NOT_COMPLETE, cannot complete this function.
Read those four and the shape of the problem appears without needing a definition for the first. Either the name you gave does not exist on that server, or the driver half cannot complete, or the call itself was refused. Those are three different repairs, and the way to tell them apart is to change one variable at a time: the same queue from an administrator, the same queue from a second client, a direct port instead of the share.
The client and the print server are at different update levels
You have this one if Nobody can connect, administrators included, and it began after a maintenance window.
- Patch the print server and the clients to the same current level and reboot both.
- Where the print server has been excluded from updates by somebody, bring it back into the schedule.
- Retest before changing anything else. This resolves the majority of these on its own.
The share name is not what you are typing
You have this one if 0x00000709, or the queue is visible in the server’s own list and refuses the connection by that name.
- Read the ShareName from
Get-Printer -ComputerName printsrv | Select-Object Name,ShareName,Shared. - Connect by the share name, not the printer name. Renaming one does not rename the other.
- If Shared is False, share it before anything else:
Set-Printer -Name "QueueName" -Shared $true -ShareName "queuename".
The driver half cannot complete on the client
You have this one if 0x00000BCB, or an administrator can add the queue on the same machine and a standard user cannot.
- Pre-stage the driver package on the client with your deployment tool or
pnputil /add-driver, then reconnect. - Prefer a driver the client does not have to fetch from the server, such as the in-box class driver, where the device supports it.
- Deploy printer connections through policy with the driver already present, rather than relying on users to add them.
The server does not publish a driver for this client’s architecture
You have this one if Some clients connect and others cannot, and the ones failing are on a different processor architecture or a much newer build.
- On the server, check which architectures the queue publishes in Print Server Properties, Drivers tab, in the environment column.
- Add the missing architecture, or move that queue to a driver model that does not depend on a matching package.
- For a handful of machines, install the driver locally and connect to a direct port instead.
The print server is a desktop doing a server’s job
You have this one if Failures grow as more people connect, and the machine sharing the queues is a client edition.
- Count how many devices connect at once. Client editions cap concurrent inbound connections and printing consumes them.
- Move the queues to a machine intended for the role, with the print management tooling that goes with it.
- In the meantime, connect the busiest users to the device’s own address to take load off the shared queue.
Full reference
What each number here is published as
| Code | Published meaning |
|---|---|
0x0000011B |
Nothing. Decimal 283 is not in Microsoft’s system error code list and no Microsoft page defines it |
0x00000709 |
ERROR_INVALID_PRINTER_NAME: the printer name is invalid |
0x0000006E |
ERROR_OPEN_FAILED: the system cannot open the device or file specified |
0x000003EB |
ERROR_CAN_NOT_COMPLETE: cannot complete this function |
0x00000BCB |
ERROR_PRINTER_DRIVER_DOWNLOAD_NEEDED: the specified printer driver was not found on the system and needs to be downloaded |
That first row is the reason this article is structured the way it is. A page that tells you confidently what 0x0000011B means is telling you something Microsoft has not published, and the advice built on it – usually a registry value – is aimed at a cause nobody has documented. The companions are documented, so work those.
On the registry workaround
There is a registry value widely circulated for this code that reduces the authentication level the print RPC call requires. It is worth knowing it exists, because you will meet machines that have it, and worth knowing what it does: it takes the client and server back to accepting a call that the update made them refuse. Microsoft does not document it on Learn or its support site, which means nobody is committing to what it protects or when it will stop working.
- If you find it set on machines you inherited, record where, and plan to remove it once both ends are patched.
- Do not roll it out as a fix. It weakens every print connection that machine makes, not the one you are trying to repair.
- Prefer the routes that leave the security posture alone: patch both ends, pre-stage drivers, deploy connections by policy, or connect to the device directly.
- If you must use it to keep an office printing for a day, put a date on removing it and tell somebody other than yourself.
Which half of the connection is failing
| What you see | Where the fault is |
|---|---|
| An administrator can add the queue, a standard user cannot | The driver half, not the connection |
| Nobody can add the queue, administrators included | Update level mismatch, or the share does not exist as named |
| The printer name is rejected outright | A wrong or renamed share, or a stale stored connection |
| It works from one client and not another | Those clients are at different update levels or hold different drivers |
| A direct TCP/IP port to the device prints perfectly | The device is fine; everything here is between the two computers |
Deploying the connection instead of asking users to make it
The durable answer in a managed estate is that users do not add printers at all. The connection is deployed with the driver already staged, so nothing is fetched at connection time and the whole class of failure disappears. Microsoft documents printer settings under Group Policy, including the Point and Print settings, at Computer Configuration, then Policies, Administrative Templates, Control Panel, Printers – which is where Package Point and print – Approved servers lives, and it is the setting worth having whether or not you are chasing this error today.
Before you conclude the server is at fault
- Confirm the exact ShareName from the server rather than from anybody’s memory.
- Confirm both machines are at the same current patch level, and reboot them if you are not sure the last update finished.
- Test the same queue from a second client on the same subnet. Two clients failing differently is a client-side story.
- Remove the stored connection from the user’s profile and let it be recreated, so you are not testing a cached failure.
- Test a direct TCP/IP port to the device. If that prints, everything you are chasing is between the two computers and the printer is not involved.
Clearing the spooler’s queue folder with the service running can corrupt the queue for every user on a shared print server. Stop the service, clear it, start the service, and warn anyone with a job waiting that they will need to send it again.
When a licence is the actual fix
Patching both ends costs nothing and is the answer for most readers, so start there. The version of this that configuration cannot reach is a print server that will never receive another update, either because it is a desktop pressed into the role or because its build has left support. That machine cannot be brought level with the clients, it is not receiving fixes for anything else either, and every workaround for it involves weakening the clients instead. Windows Server 2022 Standard is the supported home for the role, with Print Management, driver isolation and policy-based deployment included, licensed on the usual server plus client access licence model. Arco can check whether your existing CAL position already covers another server instance. If both ends can simply be patched, patch them and buy nothing.
Every code this article covers
| Code | What it points at | Source |
|---|---|---|
0x0000011B |
Reported by the client when it will not complete the connection to a shared queue. Decimal 283 is not a defined Windows error number and Microsoft publishes no meaning for it, so diagnose from the companions below | not published by the vendor |
0x00000709 |
ERROR_INVALID_PRINTER_NAME: the printer name is invalid | Microsoft Learn |
0x0000006E |
ERROR_OPEN_FAILED: the system cannot open the device or file specified | Microsoft Learn |
0x000003EB |
ERROR_CAN_NOT_COMPLETE: cannot complete this function | Microsoft Learn |
0x00000BCB |
ERROR_PRINTER_DRIVER_DOWNLOAD_NEEDED: the specified printer driver was not found on the system and needs to be downloaded | Microsoft Learn |
Confirm the fix worked
- Have the standard user who reported the fault add the printer on their own machine and print a test page.
- Run
Get-Printeron that client and confirm the queue is listed with the driver you expected. - Confirm the connection survives a reboot rather than needing to be added again.
- Check the print server’s event log for further refusals after the change.
- Confirm any registry workaround you found or set has been removed once both ends are patched.
Questions people ask about this
What does 0x0000011B actually mean?
Microsoft has not said. Decimal 283 is not in the published system error code list and no Microsoft page defines it, so any article that gives you a confident definition is inventing one. The companion codes are documented and they are what the diagnosis is built on here.
Is the registry workaround safe to leave in place?
No, and it is not documented by Microsoft either. It lowers the authentication level required for the print RPC call on every connection that machine makes. If you use it to keep an office working while you patch, record where you set it and remove it afterwards.
Why did printing break when nothing changed on the printer?
Because the change was in Windows rather than in the printer. What was tightened is the connection between the client and the print server, which is why printers connected directly by address are usually unaffected and some queues survive while others do not.
Do we have to buy a server to run printers?
No. A supported Windows machine can share a queue, and direct connections to the device’s own address need no server at all. A server licence earns its place when you want central driver management, deployment by policy and driver isolation, or when the machine doing the job now cannot be patched.
Is connecting directly to the printer a real fix or a workaround?
For a small office it is a legitimate design. You lose central management, queue monitoring and the ability to change a driver in one place, so it suits a handful of machines and a printer that stays where it is.
