Knowledgebase
Knowledgebase : PaperCut > Domains / Directories
PaperCut does not impose a 20 character long username limit, however
when using Windows Active Directory we utilise the
“sAMAccountName”. This is what is seen as the owner of the print
job in the print queues. Please see the attached screenshot:
This Act...
This article contains a collection of tips for tweaking LDAP
synchronization settings. You are using LDAP to sync if the setting at
Options → User/Group Sync → Sync Options → Sync Source is set to
LDAP. The tips in this article are aimed at administrators...
OVERVIEW
This is a case study of an operating environment that revolves around
a proprietary software system which is the primary handler of
authentication and maintains and stores user records. Such systems can
include proprietary industry-specific ERP ...
OVERVIEW
This is a case study of an operating environment that revolves around
a proprietary software system which is the primary handler of
authentication and maintains and stores user records. Such systems can
include proprietary industry-specific E...
USING LDAPS TO SECURE A SYNC SOURCE CONNECTION (LDAP OVER SSL)
LDAP is a great method of connecting PaperCut to your directory
services, however, LDAP is not encrypted by default. Standard LDAP
leaves some important information exposed to prying eyes. Fo...
If requested by support please follow the instructions below to gather
debug output from the Active Directory user provider (the component of
PaperCut that retrieves information from Active Directory).
TO GET DEBUG OUTPUT:
1. Open a command prompt on th...
Group based restriction on printing
Group based restrictions is a new feature that was added at version 8 of PaperCut that provides a feature for administrators to restrict printer access to a group or groups of users. Group based restrictions can be...
This article applies to the Linux and Mac versions of PaperCut. UNIX
command-line experience is required.
PaperCut support may ask for an LDAP schema data to diagnose complex
LDAP issues. The following commands can be used to produce a file with
LDAP inf...
NOTE: As of version 14.0, disabled users will not be imported in
PaperCut by default. If you want to import disabled users navigate to
OPTIONS → USER/GROUP SYNC and check Import disabled users. When you
are ready to make the change permanent, select Sy...
_“Help! Our environment has more than one Active Directory domain.
What are our options to get PaperCut to synchronize users from all the
domains?”_
In PaperCut it’s possible to synchronize users from more than one
source such as Active Directory and LDA...
Multiple network domains are common on larger networks, or special
environments such as schools where there is a need to partition the
network for security reasons. A common example is:
* A secure domain for staff users.
* A domain for student accoun...
THE PROBLEM: After checking the settings at _Options User/Group
Sync_, users are being imported successfully but no groups appear for
import via _Groups Add/Remove Groups_.
MISMATCHING LDAP SCHEMAS
PaperCut looks up groups by finding objects that con...
Mac Open Directory/LDAP Configuration
I'd like some assistance configuring PaperCut to work with my Open Directory/LDAP network
PaperCut version's 8.4 or higher will now attempt to auto detect Open Directory and LDAP configurations on Mac OS X Serve...
Managing laptops/notebooks in a network/domain environment
Most networks need to support laptop/notebook users that use their computers both onsite (the network) and remotely (at home). These laptops are often personally owned by students and staff a...
Merging two separate domains into one
We have separate domains at present but we will be merging them within the next 12 months. Does PaperCut support merging databases?
Merging two separate databases is a very complex task and not something we curr...
All PaperCut products released after 2004 include full native support
for Active Directory including support for Nested groups, and
Organizational Units. PaperCut still continues to support older NT
style domains too.
COMMON AD QUESTIONS
HOW DOES PAPERC...
It is common for organizations to want to limit printing or color
printing by Active Directory [1] group.
There are several ways of doing this in PaperCut that differ in the
level of complexity/
NO EXCEPTIONS
Applying user filters based on group...
PaperCut's strength has long been in our ability to support user and
group synchronization with many directory services. This capability
has now been tested against directory services hosted in the cloud,
such as Azure AD. For PaperCut customers, this mea...
In order to have PaperCut NG/MF sync a secondary email address from
Active Directory for your users, the trick is to set it up to point to
a custom field in AD.
1. Login to the PaperCut admin web interface.
2. Navigate to Options → Actions → Config edi...
I WOULD LIKE TO IMPORT/SYNC USERS FROM MULTIPLE GROUPS OR ORGANIZATION
UNITS. IS THIS POSSIBLE?
PaperCut's default user import configuration is to import all users
from the selected domain. This is appropriate for most, however some
organizations may wi...
Here at PaperCut, we are seeing more and more customers moving away
from traditional on-premise Directory Services. Many customers are now
introducing cloud-based Identity Management Systems. In these
conversations, we are often being asked: “Does PaperCu...
Okta is the leading independent provider of identity for the
enterprise. The Okta Identity Cloud [https://www.okta.com/] enables
organizations to both secure and manage their extended enterprise, and
transform their customers’ experiences.
If you have se...
_“Help! My users can’t log into the PaperCut User Web Interface,
Client, or Mobility Print using their Active Directory Domain
credentials, but internal user accounts can sign-in just fine.
What’s going on?”_
Note: for a more general FAQ on PaperCut and ...
PaperCut can use LDAP to synchronize user and group details from a
directory server such as Apple Open Directory, Novell eDirectory,
OpenLDAP and even Windows Active Directory (in addition to the native
integration when running on Windows). PaperCut perfo...
_“HELP! I’m a PaperCut system administrator and I’m having
issues with our user/group sync from Active Directory! How can I fix
it?”_
Importing users & groups from Active Directory is the most popular and
widely-used method of managing users in PaperCut ...
PaperCut identifies users primarily by their username. The domain or
GUID will not be used to uniquely identify a user, so e.g. domain1tim
will be viewed as the same as domain2tim by PaperCut.
If you're merging or migrating domains, it's worth making su...
What are the implications of users belonging to multiple groups?
Groups in PaperCut are used for a number of different purposes. Here is a brief description on how they behave when a user belongs to more than one group:
Quota allocation: A user th...
PaperCut makes use of directory servers such as Active Directory,
eDirectory, Open Directory and other LDAP and similar systems to
retrieve information about users and groups. This enables single entry
of your user and group information and efficient re-u...