Specifications
Print Controller Design Guide for Information Security:
Page 50 of 92
• By enabling Basic Authentication, it is possible to protect the destination information. For each
destination, it is possible to assign an access level to each registered user (View, Edit, Delete, and
Full-Access). Users who have View privileges for a particular destination can select the destination
for forwarding, but cannot edit or delete the data. Users who have Full-Access privileges can
perform all functions including sending to the destination, editing and deleting data, and making
changes to access privilege settings. Users who have not been assigned any of these access
privileges cannot even view the destination list. Even when all of the above restrictions are
enabled, User Administrators have Full-Access privileges for all registered destinations. However
since User Administrators cannot use the Scanner function, they are not able to send any data.
• When logged in with Basic Authentication, users are able to perform operations with either the
forwarding feature or the TWAIN driver feature, not both. However with User Code Authentication,
there are conditions in which one operator can utilize the Scanner via the TWAIN driver even while
another operator is already logged in from the MFP operation panel (i.e. before the user logged in
from the operation panel actually initiates a job).
• With the TWAIN feature, the user is logged out automatically as soon as scanning is complete.
Also, the authenticated user and Machine Administrator are the only individuals who can interrupt a
scanning job in progress. When the Stop key is pressed to interrupt the job, the MFP prompts the
operator with the authentication dialog.
Protection of Document Server Documents
• When Basic Authentication is enabled, it is possible to assign access privilege to individual
documents when scanning them for storage in the Document Server (View, Edit, Delete, and
Full-Access). These access privileges are applied even when accessing the document from
DeskTopBinder or Desk Top Editor for Production. Users who have View privileges can both
preview and send a document, but cannot delete or make any changes to the document (including
the filename). Users who have Full-Access privileges can perform all functions including
previewing, sending, editing and deleting the document, as well as making changes to the access
privileges settings. Users who have not been assigned any of these access privileges cannot
perform any of these operations, and are also prohibited from selecting documents in the document
list screen. Even when all of the above restrictions are enabled, Document Administrators have
Full-Access privileges for all registered documents. However since User Administrators cannot use
the Scanner function, they are not able to send or store any data.