How It Works: The New PrinterLogic Mobile Application

Mobile Printing

When I was in high school, my math teacher assured me that I needed to learn the mathematical concepts she was teaching because, in the future, I wasn’t going to consistently have a calculator with me to run calculations for me. Little did she know…the advancement of technology would give me exactly that—and so much more.

As a society, we have moved so quickly through technological innovation, it’s hard to even recognize the old world of boxy desktop computers and thick, heavy graphing calculators. Today, even elementary school students are completing most of their work on a Chromebook or iPad. In addition, employees across the world are using Android tablets, mobile phones, and other devices to accomplish tasks that used to require a lot more hardware.

These advances are equally advantageous when it comes to printing. While many companies are still primarily printing from desktop computers, BYOD (bring your own device) printing is becoming more and more commonplace. Leading technology companies like Apple, Google, and Windows have simplified printing so that individuals can easily connect to home printers via Bluetooth or wifi, and PrinterLogic has now brought similar capability to our own platform so large enterprises can enable their users to securely print from mobile devices.

The PrinterLogic mobile application for iOS and Android offers two new functionalities to your PrinterLogic environment: mobile printing and secure release printing. In this blog, we will take a look at how printing from a mobile device works and what happens behind the scenes. In Part 2 of this series, we will look at using the mobile application alongside the PrinterLogic Secure Release Printing module for releasing print jobs at the printer.

About the PrinterLogic Mobile App

The PrinterLogic App uses the native built-in functionality of a BYOD device for printing. Specifically, it uses IPP 2.0 (Internet Printing Protocol version 2.0), a driverless printing protocol, to communicate with the printers for configuration information and to send the completed job to the printer. There are three primary aspects of mobile printing that are important to understand as a user of PrinterLogic’s platform.

1. Authentication

Once the mobile application is installed on a device, the end user will enter the URL of the PrinterLogic instance. The end user will then authenticate to the mobile application using the supported Identity Provider (IdP) – LDAP, Azure, Okta, Google, etc. PrinterLogic supports the leading cloud-based IdPs as well as on-premises solutions. For companies using PrinterLogic SaaS and LDAP, a firewall rule must be built to enable LDAP’s communication with the SaaS instance.

IdP Login Steps
PrinterLogic App IdP Login Steps

2. Administrative Deployment of Printers

For users with the app, PrinterLogic Administrators can deploy printers to mobile devices. From the PrinterLogic Admin Console, the admin can deploy printers based on third-party IdP users/groups, or by a mobile device IP address. 

For companies using an IdP, printers automatically deployed to a user via the Admin Console are deployed to the individual, not the device they’re using. In other words, any printer deployed to that user will also be deployed to any devices they log into using their IdP credentials. For companies deploying by IP address, deployments will follow the user’s location and provide access to appropriate printers wherever a user is.

3. Self-installation of printers

Users with the app are able to self-install printers to their mobile devices based on the same portal security assignments as a traditional operating system. This means that they will have access to the same printers on their mobile device as they do on their desktop. As detailed in the previous section, printers automatically deployed to a user by the IT admin will be immediately viewable in the PrinterLogic app. Any that are not listed can be self-installed by the user as long as they have been granted access. 

For the IT admin, this functionality means fewer Help Desk calls to install or access printers as well as quicker, easier access to printing across the organization.

PrinterLogic Self-Install for Printers
From the PrinterLogic app “Add Printer” screen, users can self-install printers.

What happens behind the scenes

PrinterLogic uses an advanced architecture to make mobile printing easy and serverless. The architecture takes a slightly different form depending on whether your organization uses the PrinterLogic SaaS platform or the PrinterLogic Virtual Appliance (the VA). Mobile printing is not supported on PrinterLogic Web Stack, the legacy version of the VA.

Mobile Printing Using PrinterLogic SaaS

The first step for setting up mobile printing with PrinterLogic SaaS is to install the PrinterLogic App on an iOS or Android device. The app functions as a Client, enabling communication between the device, the PrinterLogic SaaS instance, and the network of printers. 

Once the mobile app has been downloaded, users must log in and authenticate, a process that takes place between the PrinterLogic SaaS instance, the mobile device, and the organization’s IdP. Bidirectional communication between the PrinterLogic instance, the app, and the IdP validate the user and their credentials via single sign-on. 

The app then syncs with the PrinterLogic SaaS instance and deploys printers to that individual’s mobile device based on deployments specified by the IT Admin. The PrinterLogic app uses IPP 2.0 to communicate with the printer and display printer-specific options and settings within the mobile app. 

Mobile Direct IP Printing for PrinterLogic
Mobile devices authenticate with the IdP, send print jobs to the printer via direct IP, and communicate metadata to the PrinterLogic console (SaaS or the VA) for reporting and auditing.

 

From there, the user must connect to the company’s internal network in order to send a print job to a printer. Once the user initiates a print job, the app sends the job to the printer via IPP (Direct IP). Metadata about the job is simultaneously sent to the SaaS instance for auditing and reporting. The content of the print job stays local for security purposes.

Mobile Printing Using PrinterLogic Virtual Appliance

Mobile printing on the VA functions exactly the same as it does on PrinterLogic SaaS. The only difference is that, in order to receive printer deployments, the device has to be connected to the same network as the VA as soon as the app is downloaded. Once connected to the company network, the user can receive deployments and self-install printers.

Core PrinterLogic Capabilities

As mobile printing becomes more and more commonplace, companies are going to need direct IP printing capability to ensure employees, partners, and customers have access to the documents they need. In addition to mobile printing, PrinterLogic also offers core functionality to support the modern enterprise:

  • Off-network printing
  • Serverless printing
  • Identity Provider (IdP) integration
  • Self-service printer installation
  • Driver and profile management
  • Reporting and auditing

To learn more about how PrinterLogic can empower your users – and ease the burden of managing printing for your IT administrators – contact PrinterLogic to schedule a demo.

PrinterLogic Secure-Release Printing Now Works with Fuji Xerox Multifunction Printers

This month, Vasion released its PrinterLogic Control Panel Application (CPA) for the ApeosPort series of Fuji Xerox multifunction printers. The PrinterLogic app installs on the printer and provides a flexible secure-printing experience for IT administrators and end users.

The new CPA supports more than 60 printer models, listed here. Any Fuji Xerox ApeosPort model that supports EWB 5.0 and above will work with the new PrinterLogic app. FUJIFILM tested and approved the CPA prior to release.

Advanced Security Bundle supports eight major printer brands

With this addition, PrinterLogic’s SaaS and Virtual Appliance platforms now support eight major network printer brands, representing more than 90 percent of the commercial multifunction printer market. Secure-release printing is available as part of the PrinterLogic Advanced Security Bundle, introduced last month.

Secure-release printing—also known as pull printing or “follow me” printing—ensures that the user who initiates the print job is physically standing at the printer before the output appears in the tray. This approach helps protect confidential information and reduces waste caused by redundant or abandoned print jobs.

New app uses PrinterLogic’s latest SSO and IdP support technology

The new CPA employs core PrinterLogic technology that supports Single Sign-on (SSO) protocols. Users authenticate one time to access any app or function on that printer. Once the user authenticates on the printer, PrinterLogic’s app employs a “listener” mode and allows them to release held documents without signing in again.  

The new app features an intuitive touchscreen interface that gives users four choices for proving their identity. These include badge swipe, smartphone release with QR code support, UserID/PIN, and conventional Username/Password login credentials. PrinterLogic supports Microsoft Active Directory and leading cloud-based Identity Providers (IdPs) such as Okta, Azure AD, Google Identity, Ping, and more.

How it works: Secure-Release Printing workflow for users

Once network printers are configured for either pull printing or secure printing, the user workflow proceeds as follows:

  • First, a user prints from their workstation as usual, and the print job is held securely on the workstation until the user goes to the printer to retrieve it. 
  • At the printer, the user swipes their badge or authenticates using any of the available methods. All held print jobs appear on the printer’s screen. Users simply pick the job or jobs they want to print. Or, users can delete jobs they no longer care about.
  • With the pull-printing option, a universal driver is used. That means users can decide which printer they want to use after initiating the print job.

Secure printing ensures that confidential documents get into the right hands and aren’t left sitting on a printer tray to tempt prying eyes. In addition, these methods do away with abandoned print jobs and wasted consumables. For more details, see our Secure Release Printing feature page.

In addition to secure printing, PrinterLogic offers many additional security features:

  • PrinterLogic eliminates print servers, each of which is a repository for thousands of confidential documents and is vulnerable to attack.
  • PrinterLogic has passed the AWS Well-Architected Review and inherits all of the benefits of AWS Cloud Security.
  • PrinterLogic uses centrally-managed direct IP printing to keep jobs local. Printing continues even if your internet connection goes down.
  • PrinterLogic automatically logs document name, print source, print destination, and authenticated username for audit tracking and data-loss prevention.
  • PrinterLogic’s architecture complies with strict U.S. government standards (FIPS 140-2, with 140-3 compliance pending).
  • PrinterLogic supports multifactor authentication, including CAC/PIV-enabled release printing on any network printer.

A true SaaS solution that eliminates all print-related infrastructure

Unlike some “cloud-optimized” print management software, PrinterLogic is a true, multi-tenant SaaS offering. It’s not a cloud-hosted shortcut that leaves you stuck with server licensing, configuration, and maintenance. Automatic updates ensure you have the most current and reliable solution possible—backed by a guaranteed service-level agreement.

How the Epic Connector Allows Healthcare Organizations To Manage All Printing From One Admin Console

Epic Systems Inc. is the leading supplier of Electronic Medical Records (EMR) software in the U.S. and is expanding its customer base worldwide. It’s a highly trusted solution for many healthcare organizations. 

Despite Epic’s many strengths, managing printing in this environment is often challenging for IT because Epic queues are handled separately from other forms of (non-clinical) printing. 

In this blog, we’ll describe Epic’s two primary hosting models and explain how PrinterLogic’s new Epic Connector can unify the management of both administrative and clinical printing in a single Administrative Console. 

Epic Hosting Architectures

Epic has two primary hosting architecture options: an on-premises customer-hosted model and a cloud-based Epic-hosted model. Customers may choose either model based on their infrastructure and the amount of control they want to have over their environment.

On-premises

An on-premises customer-hosted model is a traditional method for Epic installations. It offers IT admins more control but requires more infrastructure and resources. Print management can be labor-intensive. Because printing is mission-critical, IT admins must create and manage multiple identical print servers for load balancing. They monitor their status and keep them synchronized.

Cloud-based

When Epic hosts the solution in the cloud, print servers are no longer controlled by the healthcare client, and administrators can no longer add to, remove from, or make changes to, their print queues. Nor can they install software to help them manage their environment. They must contact Epic to open a ticket for every change. The response can be fast, but in some cases, there are delays. Many admins we talk to want a more straightforward solution they can control.

Either model has upsides and downsides. In any case, managing printing can be complicated without a solution to reduce the complications of multiple asynchronous servers and limited administrative access.

That’s where PrinterLogic comes in. 

How PrinterLogic Solves Challenges with Epic

PrinterLogic gives IT full control and allows healthcare organizations to manage all of their printing from one Admin Console—both for the clinical Epic environment and business-management office printing.

There are two ways PrinterLogic manages printing for Epic customers. One involves keeping the traditional Epic print servers but providing a powerful Admin Console for managing drivers and print settings across the Epic infrastructure. The other method, announced this month, is by installing the PrinterLogic Epic Connector. The Epic Connector eliminates the need to deploy drivers and queues to print servers altogether. Below we’ll explain how the new Epic Connector works and unifies all forms of healthcare print management—including clinical and general office printing—from a single pane of glass.

The PrinterLogic Epic Connector

The PrinterLogic Epic Connector reroutes print jobs so that, rather than flowing through a web of disconnected servers and drivers, they flow through PrinterLogic directly to the destination printers. PrinterLogic then becomes “mission control,” enabling you to manage the various servers, drivers, and queues across both Epic and clinical printing without the need for third-party equipment or services. Here’s how it works.

      1. The Epic Connector utilizes Epic’s Output Management API to receive documents to be printed directly from Epic, sent via HTTPS.
      2. These documents are sent with an XML file specifying the destination printer, print settings, the user who sent the job, and other metadata. 
      3. The Epic Connector then uses driverless technology to process and print the job without needing to spool and render the job with a traditional driver. If a driver is needed for specialty printers like label printers, the Connector will automatically detect this and will fall back to a selected driver for these cases. 
      4. Once printed, the Connector will use the included metadata to properly report user-level printing records and will respond back to Epic that the job was successfully printed. This service includes automatic redundancy to protect against failures to ensure business-critical Epic printing is not interrupted. 

 

epic connector diagram

This architecture can be used with either on-premises or cloud-hosted instances of Epic on version 2018 or later.

Additionally, this method can provide pull or secure printing, allowing end-users to securely hold their print jobs, which prevents the job from being printed until the user releases the print job with a badge swipe, QR code scan from a mobile device, pin or password, and other release mechanisms. Secure printing can reduce print volume by up to 20-percent and prevent print jobs lying on print trays with potential PHI or PII from being exposed to unintended viewers. 

Setting up PrinterLogic with Epic

Setting up management of printer drivers and settings for all Epic print servers is very straightforward. It only requires one simple step: The administrator installs the PrinterLogic agent on each server and allows the agent to import all existing print queues and their settings. 

Once imported, the administrator can now work completely from PrinterLogic’s web-based Administrative Console to accomplish the following tasks:

    • Update drivers
    • Change settings
    • Add or remove queues
    • And more

These changes automatically apply to all appropriate print servers to keep them in sync with one another without the need for manual changes or scripting. This method is only supported with on-premises instances of Epic.

Zero Trust Security and How to Implement Off-Network Printing

Remote working was initially an unexpected turn of events in early 2020 in response to the global pandemic; however, it quickly became an effective option for the workplace—or lack thereof. IDC has predicted that mobile workers will come to dominate the US workforce over the next four years. By 2024, their number is expected to hit 93.5 million, up from today’s 78.5 million. Although workers have adapted to working from home, it often comes with its own set of challenges. 

 

Challenges Remote Employees Face

Sometimes mobile and remote workers need remote printing and on-demand network access. In IT circles, that access is known to carry certain risks. According to an article in IT Brief, more than 80% of IT leaders surveyed by Tessian expressed concern that their company could be more vulnerable to cyberattacks due to staff who are working from home.

Those and other findings—including a worrying rise in user-facilitated phishing attacks—were revealed in Tessian’s report titled Securing the Future of Hybrid Working.

For a growing number of organizations, the way to balance remote collaboration and security is through Zero Trust.

 

About Zero Trust

We now know employees have accessible printing capabilities outside of the workplace, but what is Zero Trust and how is it going to keep your network secure? Let’s break it down. 

Like its name suggests, Zero Trust is an approach that says end users and vital IT infrastructure shouldn’t mix.

In a Zero Trust environment, mission-critical infrastructure like servers and printers reside on their own tightly controlled network. This internal network is kept separate from the employee network. Denying access (rather than granting it) is the default. Server and printer access are only permitted as necessary based on user ID and other identifying criteria.

Since Zero Trust entails strict separation, it would seem to be at odds with remote collaboration and work-from-home policies. But that’s not true. Let’s explore how this environment works well with the example of remote printing. 

 

Remote Printing Can Coexist with Zero Trust

PrinterLogic’s Off-Network Printing bridges the gap between hardened security practices and a seamless printing experience for remote workers. Even when those users are on different networks, they can safely send their print jobs to authorized printers behind the company firewall. Their native print workflows remain the same.

To do that, PrinterLogic’s serverless printing infrastructure uses two components: an External Gateway and an Internal Routing Service. The first receives the off-network print jobs from the user’s remote workstation. The second detects and relays those incoming print jobs to internal printers. 

The solution is highly secure: Data is encrypted before it is routed through the internet and is not unencrypted until it’s behind the organization’s firewall and on the network where the printer is located.

That enables use cases such as:

  • Zero Trust networks. As Zero Trust becomes more widely adopted in the enterprise, organizations need to support remote printing without inconveniencing end users.
  • Onsite contractors. Fixed-term employees like contractors and freelancers are often limited to guest network access. But they still need local printer access.
  • Business-affiliate printing. This is common in healthcare scenarios. Here, an independent affiliate (like a hospital clinic), needs to print remotely to the partner organization’s secure primary network.

PrinterLogic’s Off-Network Printing is available with PrinterLogic SaaS as well as PrinterLogic’s Virtual Appliance.

 

Further Benefits of PrinterLogic’s Off-Network Printing

Creating a more seamless and secure environment for mobile and work-from-home employees to print remotely is just the start. PrinterLogic’s Off-Network Printing brings additional advantages, too. These include:

  • Reduced infrastructure. By eliminating the need for VPNs and external portals to provide printer access, Off-network Printing cuts down on costs and complexity.
  • High availability. PrinterLogic is part of the AWS Well-Architected Framework. That helps to augment reliability through optimized routing of print jobs and added redundancy.
  • Mobility and remote collaboration. No matter where team members are, they can all print to the same devices as long as they’re connected to the Internet.

As the ranks of remote workers grow in tandem with the demand for remote printing, PrinterLogic’s Off-Network Printing lets you maintain tight, Zero Trust security while ensuring convenient access to company MFPs. For more details on configurations and scenarios, be sure to read our white paper on Off-Network Printing.

What is Serverless Printing?

*UPDATE: Originally published March  24, 2020*

There’s a widespread assumption that enterprise print management goes hand-in-hand with print servers. In fact, nothing could be further from the truth.

At PrinterLogic, we’re all about challenging conventional wisdom. We’ve shown thousands of customers that serverless print management is not only possible, it’s actually superior to traditional enterprise print management solutions because it avoids many of the fundamental weaknesses that print servers introduce. That’s why “eliminate print servers” is our mantra.

Serverless Printing Benefits 

You’re probably asking yourself, “Why should I opt for a serverless print environment?” In this article, we’re here to answer that very question by breaking down the five leading benefits of serverless printing, including:

  1. Removing single points of failure
  2. Reducing WAN traffic
  3. Managing printing from a single pane of glass
  4. Making printing more secure
  5. Gaining next-level features

We promise you’ll thank us later. 

  1. Remove Single Points of Failure

First off, serverless printing solutions remove single points of failure. When a print server goes down, it affects more than print operations and can bring an entire office to a complete halt. With PrinterLogic, you’re able to avoid this because our solution is inherently redundant; end users can continue printing uninterrupted—even in the event of a WAN outage or a host server failure.

This constant availability is virtually unheard of in environments that continue to rely on print servers. 

  1. Reduce WAN Traffic

Traditionally, print servers place a heavy load on the WAN. A serverless print solution like PrinterLogic drastically reduces print-related WAN overhead, allowing your employees to print directly from end-point devices. That means individual print jobs–totaling dozens or even hundreds of megabytes–aren’t crossing the WAN throughout the day. By cutting down the network congestion from print-related traffic, it accelerates print processes as well as basic Web access. That makes for a nice productivity boost that employees will appreciate.

Now for the cherry on top, PrinterLogic also integrates with caching technologies to further reduce its WAN footprint. When you’re deploying or updating drivers enterprise-wide or just in select departments, you can cache them locally to sidestep cross-WAN driver downloading.

  1. Manage Print From a Single Pane of Glass

Day-to-day management of traditional print environments is complex and tedious. The PrinterLogic solution gives you centralized, at-a-glance control of your entire print environment all from a single pane of glass. Deploying printers? You can do it automatically, enterprise-wide—without the need for GPOs, scripting, or other time-consuming workarounds to accommodate print servers. Modifying printers? You can make individual or batch edits by simply ticking a box or using the handy find-and-replace feature.

Ready for the kicker? End users can perform routine printer installs themselves with a single click–no IT assistance required. Try that with traditional print server solutions!

  1. Make It Serverless and Secure

If you’re worried about the strength of security with a serverless print approach, fear not!
PrinterLogic’s intuitive central management makes it easy for you to configure printer assignments, so you can fine-tune authorizations for users and printers. Our solution actually makes printing more convenient and transparent for the end user, while also giving you more granular control over permissions—meaning an increase in security along with ease of use. It’s a win-win! 

  1. Enjoy Additional Features 

Now that remote work is swiftly becoming the norm, we’ve got you covered with additional serverless printing features to help you quickly adapt to modern workstations. Learn more about Off-Network Printing, Secure Release Printing, and advanced reporting capabilities on the blog

Serverless print management might not be the only way to approach enterprise printing, but here at PrinterLogic, we’re confident it’s the best.

Zero Trust: What Is It? How Does It Work? Why Should I Use It?

The recent uptick in remote work has highlighted both the promise and the pitfalls of our connected world. Many of the same technologies that give work-from-home employees and contractors access to enterprise networks also create gaps that hackers and other malicious actors can exploit.

To lock down network security without causing productivity to take a hit, Zero Trust has emerged as a best practice and policy of choice for many organizations.

 

What is Zero Trust?

The origins of Zero Trust are rooted in the shortcomings of traditional network security methods.

Since the early days of enterprise risk management, organizations have typically taken a classic defensive approach to network security. There’s an internal network (the LAN), an external network (the WAN) and a protective firewall separating the two. Anything inside the firewall is trusted. Anything outside is untrusted.

The complexity of modern IT networks and the fluidity of today’s workplaces have proven challenging to this vaguely medieval “inside/outside” mindset. For example, this simple binary design doesn’t suit remote workers who need offsite access to internal resources. And what about contractors who might be physically inside the building but don’t merit full access privileges?

Virtual private networks, or VPNs, offer one way to expand the internal network to include this new class of mobile users. From a security management standpoint, the major problem with VPNs is that they implicitly assume trust. If an attacker manages to gain VPN credentials or exploit the VPN connection, that attacker has more or less unrestricted access to the internal network.

IT professionals therefore started looking for a viable VPN replacement. Zero Trust arose as a more identity based, hardline approach to network security that accommodates the nuance of the modern workplace and its dynamic mobile workforce.

Zero Trust is inherently more skeptical than traditional perimeter network approaches. Rather than eagerly award users with sweeping access to large portions of the internal network, the first instinct in a zero-trust environment is to withhold blanket access and instead grant it only on an as-needed basis to business-critical network resources. This is often called the least privilege model.

 

How does Zero Trust work?

The first implementations of Zero Trust network access (ZTNA) took a micro-segmentation approach. This made sense as an updated form of risk management, but the underlying inside/outside rationale didn’t change significantly.

As a result, micro-segmentation mainly served to fragment the internal network into smaller perimeter-bound networks that were further subdivided into cloud and on-prem architectures. This worked well enough as a VPN alternative but had the drawback of decreasing network-wide visibility and increasing admin overhead.

Today, the emphasis in ZTNA has shifted more from the how to the who. It’s not about developing complex blueprints for network compartmentalization or the finicky process of creating walls within walls. Instead it’s about verifying trusted users through their identity. That identity—validated by single sign-on (SSO) solutions, cloud-based identity providers (IdPs), or multifactor authentication (MFA)—becomes the basis for determining which resources users are allowed to access.

This has multiple advantages:

  • Tighter, more consistent security management at the gateway
  • Restricted access, even among trusted users, to lateral resources or low-level core infrastructure
  • Better support for hybrid networks that make use of cloud and on-prem solutions
  • A more curated experience for end users stripped of unnecessary functionality
  • Seamless, secure access for remote workers and contractors alongside onsite employees

Within that broad identity-based approach, ZTNA policies can vary depending on the organization or the user pool. They can require end-to-end encryption of all network communications. They can enforce “hygiene” checks by inspecting devices and data streams for malware during authentication or on an ongoing basis. Or they can prioritize the uniformity of the trusted user experience regardless of network location.

 

Who should use Zero Trust?

Every organization, large or small, can benefit from ZTNA. From agencies that need to allow regular contractor printing to global enterprises with ever-growing fleets of mobile devices, Zero Trust offers a secure, flexible path to better network security and improved risk management.

What form ZTNA ultimately takes will be up to each organization. If they’re looking for VPN alternatives that can scale to support large numbers of remote workers, they might want to explore ZTNA solutions centered around cloud-based digital workspaces. If zero-trust printing is the priority, then solutions that allow for off-network printing will be a logical choice. And if an organization’s business model is heavily reliant on IoT devices, ZTNA will naturally look quite a bit different from the other two.

Regardless of use case, however, Zero Trust is fast becoming the de facto network security standard. The NSA has recently endorsed Zero Trust policies and published detailed guidance on adopting ZTNA models. According to a Deloitte poll in mid-2020, more than 70% of organizations said that ZTNA adoption had either remained on pace or accelerated during the COVID-19 pandemic. All this speaks to the value of Zero Trust and its recognition as critical security practice going forward.

Print Server versus Service Client: What’s the Difference?

At PrinterLogic, we have one overarching mission: to eliminate print servers. They’re a huge pain point for print environments of every shape and size, a resource vortex that devours time, money and effort with very little to show for it. IT departments and help desk staff would have a lot less headache if print servers were a thing of the past.

And that’s the thing—they are. Print servers are a legacy technology. They’ve been superseded by solutions like ours, which unites proven direct-IP printing with modern centralized management. End users enjoy seamless, secure, highly available print capabilities from almost any device. IT admins can easily oversee and control the print environment from a single pane of glass.

PrinterLogic is so good at what it does that many folks assume it’s some kind of magical, next-gen print server. But there are fundamental differences in the design and operation of a print server and the PrinterLogic Service Client. Those important differences are what we’re going to examine here.

 

What is a print server?

A print server is a device that allows you to share a printer with multiple computers on a network. Its primary function is to funnel the print jobs from those computers into a single, shared print queue. Then it feeds those jobs to the printer one by one.

Simple, right? Ah, not so fast. As always, there are other factors to consider. It’s these added complexities that make print servers cumbersome, labor-intensive and unreliable.

  • Deployment: Physical print servers have to be rolled out individually and on-prem.
  • Configuration: Each print server has to be painstakingly set up for its print microenvironment (e.g., users, printers).
  • Print drivers: As the crucial software interface between clients and printers, drivers can be a major source of instability.
  • Print services: These are the printing capabilities that are made available to the computers. They can vary significantly from device to device.
  • Operating system: Whatever operating system the print server uses has to be licensed, maintained and updated.
  • Hardware: Like software, print server hardware has purchase costs, maintenance costs and upgrade costs. 

 

How does that compare to the PrinterLogic Service Client? 

First off, the PrinterLogic Service Client is not a physical device. It’s also not responsible for connecting computers to a shared printer or a shared printer queue. In fact, isn’t even responsible for handling PrinterLogic’s core printing functionality.

As its name suggests, the Service Client instead provides powerful print-related capabilities, or services, to end users. These services go above and beyond what print servers can offer. They include:

Because it’s a software component, PrinterLogic’s Service Client can be managed from a single web-based portal, the Admin Console, and automatically deployed to end users’ devices. And, unlike a print server, the PrinterLogic service client:

  • Does not create a single shared queue for a particular printer. This minimizes common print queue errors and increases print security.
  • Does not require any kind of server hardware, OS or manual configuration. That speeds up deployment and makes management more efficient.
  • Does not need print drivers to be manually installed. Those are managed in a central repository via the Admin Console.
  • Does not connect printers to client computers over the network. That’s done separately by the PrinterLogic instance.

 

The basis for a serverless printing infrastructure

Understanding how the PrinterLogic Service Client differs from print servers is also key to understanding what makes our serverless printing infrastructure possible. Basically, not being a print server is how we’re able to eliminate them completely from your print environment.

The unique interplay between the PrinterLogic Service Client and the PrinterLogic instance creates our powerful combo of distributed printing and centralized management. It’s why IT admins can easily deploy printers and apply profiles across the enterprise without resorting to scripts or GPOs. It’s also why end users can still print as usual when the WAN connection goes down—even with our cloud-based solution, PrinterLogic SaaS.

And it’s why we continue to make good on our aim to eliminate print servers. We’re helping IT professionals move beyond legacy print solutions to achieve a secure, easy-to-manage, scalable and robust print environment, one customer at a time.

3 Common Security Mistakes When It Comes to Printing in Federal Organizations

In 2019, the online training platform Skillbox sent a rogue print job to unsecured network printers. To do that, they relied on a search tool called Shodan that discovers vulnerable Internet-connected devices. It was the very same tool that a prankster known as HackerGiraffe had used to hijack 50,000 network printers a few months earlier.

Both HackerGiraffe and Skillbox used Shodan for benign purposes. One was to promote a YouTube channel. The other was to print out flyers for a new design course. But, what’s worrying is that they were able to breach the defenses of security-conscious organizations.

Every few months, an equally high-profile—and much more serious—cyberattack makes headlines. This serves as an urgent reminder to federal governments and their agencies to reinforce their security infrastructures.

Often, government printing and print management are forgotten in that process. A Spiceworks study found that just 22% of organizations actively monitor their printer syslogs. Furthermore, only 13% integrate their printers into security information and event management (SIEM) tools. A 2019 Quocirca Global Print Security report found that nearly 60% of organizations had suffered a print-related data loss in the past year.

What explains that mismatch? Why are the vulnerabilities of printers and print management software frequently overlooked? And more importantly, what can federal IT officials do to fix things?

The three most common print security mistakes

To answer those questions, it’s important to first identify where government printing often goes wrong.

1. Lack of awareness

Printers have been around for ages. That leads even tech-savvy people to see them as part of the furniture. But, of course, they’re not “dumb” at all. Like IoT devices, they’re connected to the network 24-7. This exposes all of their vulnerabilities to the network.

2. Using outdated legacy technology

When a printer is working like it should, it becomes an afterthought. From a print management standpoint, admins often hold off on updating printer drivers for fear of breaking functionality. This leaves the print environment riddled with exploitable, out-of-date software.

3. User error

It’s one thing to have tons of secure print safeguards in place. It’s another thing to make sure your end users actually utilize them. That’s one reason why phishing attacks are still t he most effective way of breaching IT security.

Security-conscious organizations take these mistakes seriously. They treat them more like outright threats to a secure print environment. PrinterLogic’s next-generation print management software is a valuable tool for addressing those threats.

Streamline printing while hardening security

The US Department of Defense and the US Department of Homeland Security trust PrinterLogic’s serverless printing infrastructure. More than 40 other federal entities use PrinterLogic to keep their print environments safe.

That’s not just because PrinterLogic offers dedicated secure print functionality. PrinterLogic’s streamlined print management allows IT to monitor the print environment more easily, as well as keep it up to date.

Secure print management by design

PrinterLogic’s Direct IP printing platform is inherently secure, keeping print jobs local. There are other federal security features that are worth noting as well.

FIPS 140-2 compliance

As the first print management software company to be independently tested and meet the FIPS 140-2 standard, PrinterLogic is a perfect solution for data-sensitive sectors.

Advanced reporting & monitoring

PrinterLogic’s Admin Console lets federal IT officials supervise and control the entire print environment from a single pane of glass. That includes updating drivers using a common repository. And it all happens safely behind the organization’s firewall.

Secure release printing

CAC/PIV is a tried-and-tested secure printing method in government printing. PrinterLogic’s CAC/PIV solution works with your existing printers. Not only is it easy to implement and, it also empowers your end users to conveniently release their print jobs from any printer.

On top of that, PrinterLogic’s unique direct IP printing platform makes it possible to eliminate print servers. Doing so reduces the attack surface by design and thwarts malicious actors.

PrinterLogic is ideal for government printing

As long as IT networks exist, there will be people who try to exploit their weaknesses to steal data.

By avoiding the common mistakes in print security, PrinterLogic helps eliminate those vulnerabilities. With inherently secure software, you’ll prevent your organization from becoming a statistic. Our print management software is a proven solution for government printing that simultaneously streamlines, simplifies and hardens your print environment to protect it against attacks.

Are Your Current Print Management Practices Future Proof?

When planning their enterprise print management strategies, most organizations try to take a long-term view.
They look to purchase cost-sensitive workhorse printers for their fleet and printer management solutions that will support and integrate with their wider IT infrastructure for years to come.

What’s wrong with traditional print management?

The problem is that traditional enterprise print management solutions are just that—traditional. The basic workstation/print server/printer paradigm has been around for decades, and no matter how many iterations of Windows Server are released with performance tweaks and improvements to longstanding issues, the same shortcomings tend to persist. What this means is that your print infrastructure will always be playing catch-up as your IT infrastructure evolves around it. It could even be holding your organization’s IT infrastructure back. Not to mention your productivity.

To truly future proof your organization’s current printer management practices, it’s essential to look to solutions that have four key characteristics:

  • Scalable—to grow with your organization, regardless of how that growth occurs
  • Versatile—to adapt to changes—both seen and unforeseen—in infrastructure, workflow and industry trends
  • Robust—to provide uncompromising stability in day-to-day use as well as over time
  • Efficient – to ensure that ease of use and cost-effectiveness don’t experience diminishing returns

The only enterprise print management solution that seamlessly unites these is PrinterLogic. Our approach to enterprise printing is unique because it combines the stability of direct IP printing with the unprecedented ease of centralized printer management, the smart convenience of end-user empowerment, and the power of a flexible printing platform with a remarkably small footprint. Taken together, those qualities amount to a future-proof print management strategy.

A closer look at future-proof print management

From a high-level perspective, that probably sounds ideal. But how exactly does it play out on the ground?

Let’s consider a common enterprise printing scenario. Standard practice is for most organizations to deploy new print servers to meet growth. The trouble with this is that growth can be unpredictable. Is it taking place in the same building or does it mean adding a new facility to a distributed environment? Will it involve a migration to a virtual desktop interface (VDI) solution? Are two very different print infrastructures and printer management approaches going to be merging as a result?

Unlike print servers, which are usually a response to growth and not a foundation for growth, PrinterLogic’s innate versatility and infinite scalability prepare you for any eventuality. So, for example, existing print infrastructures can easily be imported or merged into a single centralized server running PrinterLogic’s enterprise print management solution. Regardless of whether the organization is already distributed or about to become more distributed, PrinterLogic is able to expand to multiple sites with no need for additional remote infrastructure investment.

PrinterLogic also integrates smoothly with any kind of environment – including complex VDI setups like Citrix and VMware. And its effortless printer management scales to organizations of any size: 100 printers and drivers are just as easy to manage as 10,000.

Although the future is unknowable, implementing PrinterLogic’s enterprise print management solution means you don’t need a crystal ball. With it, your printer management practices can evolve dynamically and reliably along with your organization.

Simplify Chromebook Printing with PrinterLogic’s new Chrome OS Extension

Google’s Cloud Print solution will be phasing out at the end of the year. Meanwhile, Chromebooks are quickly gaining ground in the enterprise. This leaves a big opportunity for a scalable printing solution that is up to the task. 

Imagine a serverless printing infrastructure that supports Chromebooks right alongside all other endpoints. That’s what PrinterLogic delivers: a secure, easy-to-manage platform for enterprise Chrome OS printing. In this blog, I’ll break it down for you and explain how it works.

The new PrinterLogic Chrome OS Client Extension is available now and empowers network administrators to centrally manage Direct IP printing for Chrome OS users. This is accomplished the same way they do for Windows, Mac, and Linux workstations. Reliance on cloud-based printing services is over. Print jobs go straight to the printer, keeping them local and secure.  

The Extension is now part of PrinterLogic’s SaaS platform and will appear in the new PrinterLogic Virtual Appliance next month. Because PrinterLogic’s licensing is printer-based and not user-based, there’s no additional cost for deploying the solution to your Chromebook users.

 

Why develop a Chrome OS Extension?

  • Google announced its Cloud Print service is being phased out on December 31, 2020. Customers are looking for a new solution.
  • Customers told us they don’t want print jobs to go to and from the cloud because of security concerns. PrinterLogic’s new Extension keeps print jobs local.
  • Anytime you send a job to the cloud, there’s a hit to bandwidth and performance. PrinterLogic’s direct IP approach mitigates these concerns.
  • Cloud print services rely on an internet connection, which can be unreliable. With PrinterLogic, printing works even if the network is down.
  • Google supports CUPS printing. However, it’s more challenging to deploy on a large scale and doesn’t allow IT to manage all OS endpoints in one place.

Internet Printing Protocol (IPP) and driverless printing

The new Chrome OS Extension eliminates the need for print servers. Also, it doesn’t rely on Google Cloud Print. Instead, PrinterLogic employs the Internet Printing Protocol (IPP) to quickly pull available settings from printers. This feature takes settings and automatically configures them for Chromebook users. 

The new solution uses driverless printing technology to ensure broad printer compatibility. Meanwhile, accessing a printer’s features on-the-fly for the best possible output. When users select a printer, the Extension updates menu options based on that printer’s features. The user picks the options they want, clicks Print, the job renders, and goes directly to the printer. 

There’s no need for an internet connection or a cloud-based service to make printing work.

 

Easy to deploy and use

Chrome OS deploy process

  1. IT deploys the PrinterLogic Chrome OS Extension from a G-Suite account to managed devices. When a user logs in to their device, the Extension installs.
  2. Then, the Extension communicates with the PrinterLogic instance. The appropriate set of printers are set up and configured. 
  3. Printers deploy to Chrome OS devices based on AD users/groups, Google ID users/groups, endpoint IP address, Chromebook serial number, or Chromebook asset ID. 
  4. When it’s time to print, the user selects the desired printer from the native Chrome OS printing screen. Then, and the print job is sent via direct IP to the printer. Metadata about the print job goes to PrinterLogic for reporting and auditing.

More details about how the Extension works are available in our Admin Guide.

 

PrinterLogic’s rich feature set

PrinterLogic’s features work the same for Chrome OS endpoints as any other OS. For example, devices running Windows, macOS, and Linux. Here are just a few examples:

  • Reporting and SNMP alerts. Organizations can see who is printing how much to aid with cost reduction. Proactive alerts give IT a heads-up on printer outages. This helps IT address issues before they affect user productivity.
  • VDI printing. PrinterLogic works with Citrix, VMWare, and Windows Virtual Desktop. This allows IT teams to leverage existing front-end printing infrastructure, compress print jobs using standard VDI protocols. IT can also auto-deploy printers for session printing.
  • Secure-release printing. The user prints, but the job waits on the endpoint until the user goes to the printer to authenticate. This helps reduce abandoned print jobs, keeping confidential information away from prying eyes.

Migrate from Google Cloud Print

PrinterLogic’s Chrome OS Client Extension offers a simple, secure, scalable printing solution for Chrome OS devices. As such, it provides a straightforward migration path for organizations migrating from Google’s Cloud Print. 

The new PrinterLogic Extension makes it easier for organizations to embrace Chromebooks as a secure, cost-effective workstation by providing centralized printing management in mixed OS environments, keeping print jobs local, and supporting all of PrinterLogic’s advanced printing features. 

The Chrome OS Client Extension is free of charge with a PrinterLogic SaaS subscription. Why not check it out? Request a free trial setup of PrinterLogic SaaS today.