Authentication and Accounting Feature
Summary
Use the authentication feature to restrict access to the machine itself, or restrict access for each service. This also allows users to process and manage data on service usage status per user.
Types of Users
Users are grouped into the following categories when using the authentication feature.
Administrator
This type of user is able to register and change system setting value according to the user environment.
Administrators use a specially defined user ID called an administrator ID.
Login User
This type of user is registered to the machine or an external server. Each user is authenticated by a user ID.
The user ID of an authenticated user can be associated with a sub user based on its intended use. The user ID of an authenticated user can be associated with up to 10 sub user IDs.
Note
Set the User ID within 32 characters.
A separate application is required to use sub users. For details, contact your local representative.
Guest User
This type of user has not been registered.
Guest users cannot access restricted services.
Administrator Permissions and Authorization Groups
Administrator permissions and authorization groups can be set for each user on the machine.
If using our products (sold separately) as the remote accounts, set them in the products (sold separately). If using LDAP or Microsoft Entra ID as the remote accounts, set them in Internet Services.
Administrator Permissions
You can configure administrator and account administrator permissions for each authenticated user.
Administrator
The same permissions as the administrator can be granted. However, the following actions will be unavailable.
Folder Operations
Controlling job flow sheets
Changing administrator passwords
Account Administrator
The following permissions can be granted.
Regarding, deleting, changing (password cannot be changed by themselves) or referencing (may be unavailable based on some setting configurations) user information
Registering, deleting, changing or referencing accounting data
Changing alternative name for user ID/mask user ID (***)
Changing alternative name for account ID/mask account ID (***)
Printing accounting reports
Authorization Groups
You can divide permissions allowing access to features for registering authenticated users. Users belonging to an authorization group can perform the same actions as the administrator.
Refer
Refer to Authorization Groups for more information.
Usage Limit
Usage Limit Across Entire System
You can restrict access to the machine and each service in Authentication Mode. User authentication is required to use this.
Refer
Refer to [Authentication] for more information.
Usage Limit by User
You can restrict the creation, editing and use of Usage Limit, Account Limit, Job Flow Sheets and Folder for a service for each user.
Refer
Refer to Services that Allow Usage Limit or Accounting Settings for Authentication/Accounting Mode and Authentication for Job Flow Sheets and Folders for more information.
Types of Authentication and Authentication Method
Types of Authentication
Log In to Local Accounts
Authentication is performed using user information registered to the machine.
Authentication/Accounting Mode is set to [Local]/[Network], Authentication becomes “Local Accounting”.
Note
Print information sent directly from the client computer is authenticated by comparing authentication information preset in client-side printer drivers with authentication information registered to the machine, before it can be received by the machine.
If [Network] is set, register the user details managed with remote services and performs authentication using the details.
Log In to Remote Accounts
Authentication is performed using user information managed in an external authentication server. For users using an external server (LDAP, Kerberos, our products (sold separately) or Microsoft Entra ID). User information is not registered to the machine.
Authentication/Accounting Mode is set to [Remote], Authentication becomes “Remote Account”.
Note
The remote authentication kit is required.
When using remote accounts (other than when using our products (sold separately)), you can select available services from the touch panel display on the machine based on access permission information retrieved from the external authentication server.
Authentication Method
User ID Authentication
User information such as User IDs and passwords is registered to the machine or an external authentication server in advance for users to enter in their user ID and password from the touch panel display on the machine directly for authentication.
Card Authentication
User information such as card numbers registered to cards, user IDs and passwords is registered to the machine or an external authentication server in advance for card authentication.
Combined Use of Card Authentication and User ID Authentication
Allows the combined use of card authentication and user ID authentication.
Note
To use card authentication and user ID authentication in local accounts, set [Login When Card Reader Is Connected] to [IC Card /
Control Panel Login]. Refer to [Authentication] for more information.
Accounting Feature
Types of Accounting Modes
Local Accounting
Accounting reports are performed using authenticated user information registered to the machine.
Authentication/Accounting Mode is set to [Local], Authentication becomes “Local Accounting”.
Note
The following users can print accounting reports.
Administrator
Users granted administrator permissions
Users granted account administrator permissions
Network Accounting
Performs accounting using user details managed with remote services.
Job data saved to the machine by the external service is collected and processed by user.
Authentication/Accounting Mode is set to [Network], Authentication becomes “Network Accounting”.
Note
User information managed in an external service is sent from the external service to the machine and registered to the machine. When the user information managed in an external service is updated, the updated user information must be sent from the external service to the machine.
Accounting Using an Authentication Server
With this, accounting is performed using an authentication server.
Job data saved to the machine by the external service is collected and processed by user.
If you set Authentication/Accounting Mode to [Remote] and [Authentication System] is [Authentication Agent], this becomes “Accounting Using an Authentication Server”.
Note
If [Authentication System] is other than [Authentication Agent], accounting is not performed with the authentication server.
Services that Allow for Local Accounting
This section describes information for which accounting is possible by service jobs.
Service (Job) |
Applicable User |
Management Items |
|
---|---|---|---|
Normal Print |
Machine printer drivers |
Login User |
Number of sides/sheets printed |
Non-machine printer drivers※1 |
Guest User |
||
Secure Print |
Print from USB |
Login User |
|
Sample Set |
|||
Print Files from Folder |
|||
Delayed Print |
|||
Charge Print |
|||
Private Charge Print |
|||
Print Email※1 |
Guest User |
- Printing is possible if [Permissions] > [Permissions] > [Access Control] > [Non-Account Print] is set to [Unlocked] in Internet Services.
Scanner
Service |
Applicable User |
Management Items |
---|---|---|
Login User |
Scanning, sending Emails |
|
Scan to Folder |
Scanning |
|
Scan |
Scanning, forwarding files |
|
Scan to USB |
Scanning |
Fax
Service (Job) |
Applicable User |
Management Items |
|
---|---|---|---|
Fax Recipient |
Auto Send |
Login User |
Number of times/sheets to send as fax, frequency of communications |
Manual Send (outgoing calls, incoming calls) |
|||
Receive faxes, printing |
Auto Receive and Print |
-※1 |
Number of times/sheets received, number of sides/sheets printed |
Manual Receive Print (outgoing calls, incoming calls) |
|||
Store Fax - Local |
Auto Store and Receive |
-※1 |
Number of times/sheets received |
Store and Receive Print |
Login User※2 |
Number of sides/sheets printed |
|
Fax Polling |
Auto Send (to Folder) |
Guest User |
Number of times/sheets to send as fax |
Auto Receive and Print |
Login User |
Number of times/sheets polled, number of sides/sheets printed |
|
Confirm and Print Stored Files (Folder, Public Folder) |
Login User※2 |
Number of sides/sheets printed |
|
Send as Direct Fax |
Login User |
Number of times/sheets to send as fax, frequency of communications |
|
Send as Internet Fax |
Login User |
Number of times/sheets to send as Internet fax |
|
Receive, Print Internet Fax |
Auto Receive Print |
-※3 |
Number of times/sheets received, number of sides/sheets printed |
Auto Receive in Folder |
Number of times/sheets received |
||
Store and Receive Print |
Login User※2 |
Number of sides/sheets printed |
|
Receive Internet Fax, Transfer Fax |
Auto Send (Transfer) |
-※4 |
Number of times/sheets to send as fax, frequency of communications |
- Processed as faxes received.
- If [Print Files from Folder] is set to [Unlocked], guest user data will be accounted for. Refer to [Authentication] for [Print Files from Folder].
- Processed as Internet faxes received.
- Processed as Internet faxes received and transferred.
Cautions When Using Accounting Reports (Fax Jobs)
Faxes sent to the same address from different users will not be counted as batch send jobs.
Communication frequency is calculated using an independent timer installed within the machine. Be aware that this may result in slight differences between communication fees calculated from the communication frequency and the amount charged by the telecommunication company, etc.
When receiving segmented pages, counting is based on the number of sides received, not the number of sheets printed.
The communication frequency does not take into account the following communications.
Entering a number using the keypad, or using on-hook/off-hook
Using an address for which billing information has not been registered
When placing calls (included calls made before communications)
Fax Billing
The following actions are not charged.
Entering a number using the keypad and dialing the number
Communications to an address for which billing information has not been registered
When manually receiving, sending and polling
When placing calls
Services that Allow Usage Limit or Accounting Settings for Authentication/Accounting Mode
Services that allow Usage Limit and Accounting settings to be configured are as follows.
When Using [Local] as Authentication/Accounting Mode
✓: Available; -: Not available
Service |
Usage Limit by User |
Aggregation by User |
|
---|---|---|---|
Usage Limit by Feature |
Account Limit |
||
[Copy] |
✓ |
✓ |
✓ |
[Print] |
✓ |
✓ |
✓ |
[Scan] |
✓ |
✓ |
✓ |
[Fax] |
✓ |
- |
✓ |
When Using [Network] as Authentication/Accounting Mode
✓: Available; -: Not available
- Usage Limit can be configured in our products (sold separately).
- This can be processed in our products (sold separately).
When Using [Remote] as Authentication/Accounting Mode
✓: Available; -: Not available
- Usage Limit can be configured in our products (sold separately).
- This can be processed in our products (sold separately).