Account Settings > Settings
The Settings tab under Account Settings centralize common configuration options for Secure Print and Secure Print Direct in HP Insights. From this section, administrators can manage organization-wide settings such as:
Settings Page Lock
Note: Administrators can secure the Settings page by locking it with an encryption key (available to System Administrators only). When locked, all settings become read-only for other users. Access to this tab and its features may also be limited based on user roles and account licensing.
Note: Locking is per page, but some features depend on more than one. For example, generating or regenerating a SCIM token (see User and Group Sync below) requires Account Settings > Settings and Secure > Settings to both be unlocked. If either page is locked, the web console displays an error naming the locked page, for example, "Unable to generate SCIM token: Secure settings are currently locked. Please unlock secure settings and try again."
How to lock the Account Settings > Settings tab:
- Navigate to the Account Settings > Settings tab of the web console. If the page is unlocked, you'll see "This page is unlocked. Click here to lock it."
- Clicking this link opens a dialog box prompting you to enter the Site Encryption Key. Once the correct key is entered, select Lock. The settings will be locked and become read-only. A lock icon will appear indicating the settings are now locked.
How to unlock a settings page:
- Navigate to the locked page (Account Settings > Settings or Secure > Settings). A lock icon indicates the page is locked and read-only.
- Click the lock icon. In the dialog that opens, enter the Site Encryption Key and select Unlock. The page becomes editable and the lock icon is removed.
Note: The Site Encryption Key was generated during initial setup, in the Setup Guide's "Save Site Encryption Key" step. See Save Site Encryption Key if you need to locate it.
User Authentication Providers
The User Authentication Providers section in the Settings screen is where administrators configure how users authenticate to HP Insights services like Secure Print and Secure Print Direct. This configuration determines the identity verification method for print users and system users.
For more information, refer to the Authentication Providers topic.
Friendly URL
Administrators can use the Friendly URL field to create a short, easy-to-read name for the User Portal link. This replaces the default system-generated identifier shown on the Home Page field in the Secure > Settings > User Portal Settings, making the URL simpler to share and remember.
Notes:
-
The Friendly URL is limited to 20 alphanumeric characters.
-
Only users with System Administrator and IT Administrator roles can configure the Friendly URL for the User Portal.
-
Friendly URLs cannot contain special characters; only alphanumeric characters are allowed.
Integration APIs
On the Account Settings > Settings screen, you can connect to an API endpoint to help you integrate Secure Print into your print environment. Three APIs are available: User Import, User Removal, and User Registration Removal.
For setup steps, request formats, and curl examples for each API, see Integration APIs.
User and Group Sync (using SCIM)
The User and Group Sync section, available in the Account Settings > Settings tab, imports users and groups from an identity provider using the System for Cross-domain Identity Management (SCIM) protocol. It applies to both Secure Print and Secure Print Direct.
Note: To generate or regenerate a SCIM token, both settings pages must be unlocked: Account Settings > Settings and Secure > Settings. If either page is locked, the web console displays an error naming the locked page, for example, "Unable to generate SCIM token: Secure settings are currently locked. Please unlock secure settings and try again."
For supported identity providers, generating and regenerating a token, and checking sync status, see Set up automatic user and group provisioning with SCIM.
Auto-Provision
The Auto‑Provision toggle controls whetherHP Insights automatically creates user accounts when users sign in through external identity providers. This setting is available under Account Settings > Settings and allows administrators to enable or disable just‑in‑time user provisioning for authentication via OpenID or SAML. Prior to HP Insights 4.4, this behavior was always enabled and could not be turned off. By controlling auto provisioning, organizations can better manage user access and licensing costs.
-
When Auto‑Provision is enabled, HP Insights automatically creates a user account the first time a user signs in through a supported identity provider (OpenID or SAML). Users can sign in from any supported access point, including mobile app, User Portal, Chrome extension, Secure printers, and Print Scout.
-
When Auto‑Provision is disabled, users are not allowed to self‑register during OpenID or SAML authentication.User accounts must instead be created by an administrator or provisioned through SCIM.
Notes:
-
Auto‑Provision is enabled by default for all customers. If the setting is not changed, HP Insights will continue to automatically create users on their first OpenID or SAML sign‑in.
-
This setting applies only to auto provisioning through OpenID and SAML. Internal and AD users are not affected; the toggle does not appear for these auth types and auto-provision continues to work as before.
Admin SSO
The Admin SSO under Account Settings > Settings is where you configure SCIM-based SSO for system users signing in to the HP Insights web console. When enabled, system users sign in through your identity provider instead of a local account, and which parts of the web console they can access is controlled by group membership in your IdP, mapped to roles via the Group Mapping tab.
For more information on how to configure Single Sign-On for the web console with SCIM and group mapping, refer to Configure SSO with SCIM for system users documentation.
Note: When the Enable SSO Sign-in for System Users is enabled, the older Single Sign-On Configuration tab under Account Settings is still present but only shows “This feature is not applicable”.
Email Notifications
Email notification settings are available in the web console under Account Settings > Settings > Email Notifications. From this tab, administrators can review all HP Insights features and workflows that generate email notifications.
Email notifications are grouped by audience and clearly distinguish between configurable notifications and Essential Email Notifications.
-
Configurable notifications appear under Print User Notifications and Administrator Notifications. These can be enabled or disabled using the available checkboxes and include items such as passcode emails, registration notifications, and administrator logs.
-
Essential Email Notifications (Always on) support core features such as Secure Print (Internal), External Proximity Card, Guest Print, and Scan to Office 365. These notifications are required and cannot be disabled.
This ensures critical workflows continue to function even when optional notifications are turned off.
Password Expiration for System Users
HP Insights supports password expiration for system (internal) users, allowing administrators to enforce stronger password hygiene and align with organizational security and compliance requirements.
By default, system user passwords do not expire. When password expiration is enabled, administrators can define how often passwords must be changed, prevent reuse of recent passwords, and force immediate password changes when needed. These controls apply only to system users who authenticate directly against HP Insights, not users authenticated through external identity providers.
Password expiration helps reduce long‑lived credentials and ensures administrative access remains protected over time.
Who Password Expiration Applies To
Password expiration applies to System (internal) users who sign in using HP Insights credentials.
Enable Password Expiration
Turn Enable password expiration ON to require system users to change their passwords on a regular schedule.
-
When OFF, passwords do not expire and users can continue using their existing passwords.
-
When ON, password expiration rules are enforced for all system users.
By default, password expiration is disabled until explicitly enabled by an administrator.
-
Password expiry (Valid range 1–365 days) - Defines how long a password can be used before it must be changed.
-
Reset all system users passwords - Immediately expires the passwords of all internal users in the tenant, forcing a password change at next login.