Client Security

By default all printing is automatically charged to the user's personal account. For a user to be able to select a shared account the user needs to be granted access to account selection popup.

Selecting a shared account from the popup

Figure 7.3. Selecting a shared account from the popup

Access to the account selection popup, as shown in the above figure, is controlled at the user level on the user's details page. The Show the account selection popup option needs to be selected for each user that requires access to shared accounts. System administrators might find the Bulk user actions section under the User List screen convenient for applying this change to many users.

The user's popup settings under User -> User Details

Figure 7.4. The user's popup settings under User -> User Details

Important

Users need to restart their workstation (or manually restart the PaperCut client software) for this change to take affect.

Users with the Show the account selection popup option enabled need to be running the client software at all times. Print jobs will not print until the user has selected the account.

In addition to granting users access to the popup they also need to be granted access to a shared account. Shared accounts access can be controlled using two methods:

If an account is allocated a PIN (an alpha-numeric access code) users with knowledge of the PIN can select the account. A PIN based system would be a sensible selection in an organization when PINs are already in use for other systems such as photocopiers or door access codes.

An alternate method is to delegate access to the shared account via network group membership. One advantage of group based control is that users do not have to remember PINs. Most medium to large organizations will already have their network structured into suitable groups representing their position, title, department or work area. These existing groups may be used to control access. Access to shared accounts can also be granted on an individual user basis, however best practice suggests group-based management for medium to large networks.

Tip

In a Windows Active Directory environment, Organization Units are treated as special groups. Hence they also can be used to control access to a shared account.

Controlling access to shared accounts via group membership rather than individual user accounts is recommended. By using group based control, new users created on the network inherit the correct account access by virtue of their network group membership. This alleviates the need for additional user setup inside PaperCut NG.

To grant access to a shared account or all members in a given network group:

  1. Log into the system as an administrator (i.e. admin account).

  2. Select the Accounts tab.

  3. Select the appropriate shared account from the list.

  4. Click on the Security tab.

  5. Select the appropriate group from the drop-down list.

  6. Click the Add button.

Setting up shared account security

Figure 7.5. Setting up shared account security