Configure Active Directory Authentication
Active Directory authentication uses the user's Windows workstation identity. Print Scout reads the logged-in Windows credentials automatically. No separate user registration step is required. This is the only provider where users can print immediately without registering.
Note: As of July 2026, Internal and Active Directory are no longer offered as user authentication options for configuration. New customers see only OpenID Connect and SAML. Customers already configured with Internal or Active Directory continue to see their configured option alongside OpenID Connect and SAML (the option they are not configured for is removed), and their setup continues to work as-is. For details, see the July 2026 Monthly Updates. New customers who require Internal or Active Directory can contact customerpreview@pharos.com.
Switching to or from Active Directory clears all existing user registrations. All users must re-register. The Site Encryption Key is required to make this change.
How Active Directory Authentication works
When a user submits a print job, Print Scout captures their Windows workstation identity (UPN or NetBIOS format depending on configuration) and uses it as their print identity. The user's Active Directory credentials are never sent to HP Insights, only the identity string is used.
Because identity is derived from the workstation login, Active Directory is the fastest on-boarding path for large organizations. There is no registration email to send, no verification step, and no passcode to distribute.
Prerequisites
-
Device Scout installed and joined to the same AD domain as user workstations.
-
Print Scout deployed to user workstations.
Enable Active Directory authentication
1. Navigate to Account Settings > Settings > User Authentication Providers.
2. Select Active Directory.
3. Enter the Site Encryption Key when prompted.
4. Click Save.
No further configuration is required in the web console. Users can print immediately after Print Scout is installed on their workstation.
How users authenticate
At the printer (
Direct Print: Print Scout detects the user's Windows identity automatically. No user action is required.
This occurs when the workstation identity format differs between the authentication flow and the print spooler flow. The authentication flow may identify the user as user@domain.com (UPN format) while the spooler identifies them as DOMAIN\user (NetBIOS format). These are treated as different identities and the job cannot be matched to the user.
Check the Print Scout logs for the identity string captured during authentication and compare it with the string captured during print submission. Contact Support if the formats differ. This requires a configuration change for your organization, made by Pharos.
Related Topic: