Legacy Authentication
If your organization was configured with Internal or Active Directory user authentication before July 2026, nothing changes for you: your configuration, your users' registrations, and your printing workflows all continue to work as they always have. This page brings together everything specific to these two providers, so you can find it in one place.
Note: As of July 2026, Internal and Active Directory are no longer offered as user authentication options for configuration. New customers see only OpenID Connect and SAML. Customers already configured with Internal or Active Directory continue to see their configured option alongside OpenID Connect and SAML (the option they are not configured for is removed), and their setup continues to work as-is.
Your provider at a glance
| Internal | Active Directory | |
|---|---|---|
| Identity comes from | An email address and PIN managed directly by HP Insights | The user's logged-in Windows workstation session |
| Registration | User verifies their email and sets a 4-digit PIN through the Setup Guide | None. Users can print as soon as Print Scout is installed; accounts are created on the first print job |
| Sign-in at the printer | Email and PIN (Credential Login), registered card, or PIN | AD username and password, registered card, or PIN |
| Card registration | Email and PIN at the printer on first setup | Network username and AD password at the printer on first setup |
| User groups | Import a CSV of email addresses and groups in the Secure > Advanced tab; updates apply almost immediately | Print Scout uploads Global and Universal groups automatically on each user's first print job, then re-syncs with Active Directory daily |
| Configuration guide | Configure Internal Authentication | Configure Active Directory Authentication |
Registration details
Internal: users open the Setup Guide, enter their email address, verify it with the emailed link or code (valid for one hour), and set a 4-digit PIN. The email address becomes their print identity. The full flow, including restricting registration to specific email domains, is in Configure Internal Authentication.
Active Directory: there is nothing for users to do. Print Scout reads the Windows session and HP Insights creates the account on the first print job.
Guides for these providers
For administrators
- Configure Internal Authentication — including email domain whitelisting and troubleshooting
- Configure Active Directory Authentication — including the UPN/NetBIOS identity-format troubleshooting
- User card registration
For your users
- Register an email address (Internal)
- Reset a PIN (Internal)
- Email and PIN release (Internal)
- Username and password release (Active Directory)
- Proximity card release and activating proximity cards
- Activate mobile devices (requires Print Scout for these providers)
Limitations
- macOS Print Scout with Active Directory cannot load user domain groups into HP Insights. For group-based features (such as Delegate Print or printer restrictions), import users' email addresses instead.
- Active Directory group changes can take at least a day to reach HP Insights; Internal group imports apply almost immediately.
- Universal Print is not supported with Active Directory authentication.
- Chrome Direct Print does not support Internal or Active Directory authentication.
- Guest Print and External Card Integration require OpenID Connect or SAML.
Thinking about moving to OpenID Connect or SAML?
Newer capabilities (Universal Print, Guest Print, External Card Integration, Chrome Direct Print) require OpenID Connect or SAML, and both let users authenticate with the credentials they already use, with your identity provider's MFA and access policies applied automatically. See User Authentication Providers to compare, and plan for one important step:
Note: Switching the authentication provider clears all existing user registrations, including cards, PINs, and mobile devices, and requires the Site Encryption Key. Users must re-register under the new provider, so plan the change and notify users in advance.