Specifications

Print Controller Design Guide for Information Security:
Page 49 of 92
Protection of Data when Performing Scanning and Sending Operations
It is possible to set the MFP or related software to perform the following operations:
- Require user identification when sending to a forwarding server. By requiring the operator to select
from pre-registered email destinations and then input a protection code, it is possible to protect
against sender impersonation.
- Require user ID and password authentication before data is forwarded to an SMTP server or folder
(Basic Authentication). This makes it possible to control the sending of data for each registered
user.
- Require a numerical protection code (up to 8 digits long) when the operator selects a document
stored in the MFP for sending, which protects against unauthorized email sending.
- Perform user access restrictions and further prevent any impersonation of the sender:
When User Code Authentication or Basic Authentication is enabled, and a successfully logged-in
user performs a sending operation, this user is automatically set as the sender of the email. If this
user does not have an email address, it is not possible to send the email.
- Limit the sending of email to destinations that have already been programmed in the MFP. This
can be done using the “Restrict use of destinations” setting of the Extended Security feature.
- Require user ID and password authentication when attempting to retrieve email addresses from an
LDAP server.
- Set the MFP so that it is not possible to register email addresses in the MFP, whether obtained
from an LDAP server or entered manually.
In order for the MFP Scanner to retrieve the address book data of individual registered users from
the forwarding server, Basic Authentication must be enabled at the MFP and the forwarding server
software must be ScanRouter V2/EX or later. In all other cases, the MFP Scanner is either able to
obtain shared address book data only via port 3670 (Basic Authentication disabled, all versions of
ScanRouter), or is not able to obtain any data at all (Basic Authentication enabled, ScanRouter V1).
The data obtained from the forwarding server is then deleted at the MFP when the user logs out.
Note: Administrators cannot perform these operations.