Legacy Authentication

If your organization was configured with Internal or Active Directory user authentication before July 2026, nothing changes for you: your configuration, your users' registrations, and your printing workflows all continue to work as they always have. This page brings together everything specific to these two providers, so you can find it in one place.

Note: As of July 2026, Internal and Active Directory are no longer offered as user authentication options for configuration. New customers see only OpenID Connect and SAML. Customers already configured with Internal or Active Directory continue to see their configured option alongside OpenID Connect and SAML (the option they are not configured for is removed), and their setup continues to work as-is.

Your provider at a glance

  Internal Active Directory
Identity comes from An email address and PIN managed directly by HP Insights The user's logged-in Windows workstation session
Registration User verifies their email and sets a 4-digit PIN through the Setup Guide None. Users can print as soon as Print Scout is installed; accounts are created on the first print job
Sign-in at the printer Email and PIN (Credential Login), registered card, or PIN AD username and password, registered card, or PIN
Card registration Email and PIN at the printer on first setup Network username and AD password at the printer on first setup
User groups Import a CSV of email addresses and groups in the Secure > Advanced tab; updates apply almost immediately Print Scout uploads Global and Universal groups automatically on each user's first print job, then re-syncs with Active Directory daily
Configuration guide Configure Internal Authentication Configure Active Directory Authentication

Registration details

Internal: users open the Setup Guide, enter their email address, verify it with the emailed link or code (valid for one hour), and set a 4-digit PIN. The email address becomes their print identity. The full flow, including restricting registration to specific email domains, is in Configure Internal Authentication.

Active Directory: there is nothing for users to do. Print Scout reads the Windows session and HP Insights creates the account on the first print job.

Guides for these providers

For administrators

For your users

Limitations

  • macOS Print Scout with Active Directory cannot load user domain groups into HP Insights. For group-based features (such as Delegate Print or printer restrictions), import users' email addresses instead.
  • Active Directory group changes can take at least a day to reach HP Insights; Internal group imports apply almost immediately.
  • Universal Print is not supported with Active Directory authentication.
  • Chrome Direct Print does not support Internal or Active Directory authentication.
  • Guest Print and External Card Integration require OpenID Connect or SAML.

Thinking about moving to OpenID Connect or SAML?

Newer capabilities (Universal Print, Guest Print, External Card Integration, Chrome Direct Print) require OpenID Connect or SAML, and both let users authenticate with the credentials they already use, with your identity provider's MFA and access policies applied automatically. See User Authentication Providers to compare, and plan for one important step:

Note: Switching the authentication provider clears all existing user registrations, including cards, PINs, and mobile devices, and requires the Site Encryption Key. Users must re-register under the new provider, so plan the change and notify users in advance.