Toshiba CPA 2.0

Last Updated: August 10, 2026

Complete the requirements, and follow the steps below to install the second-generation Control Panel Application (CPA) on a Toshiba printer. For a list of supported devices, refer to Supported Printers for Printer Apps.

Installation Requirements

Complete all Universal Requirements, and ensure functionality prior to CPA setup. Toshiba also requires the following:

  • Firmware version SY0W1700 or later is recommended. The installation process uses PrinterLogic Output service application programming interfaces (APIs) that might not be included in older firmware, which can cause the installation to fail on Toshiba devices.
  • Turn on Secure Sockets Layer (SSL) or Transport Layer Security (TLS) in the printer's web interface by going to Administration then Setup then Network then HTTP. For the Enable SSL/TLS option, select Enable.
  • Set the IP Address or Hostname field on the Service Agent's General tab to the Fully Qualified Domain Name (FQDN) of the Service Agent host. Using an IP address in this field causes CPA functionality issues.
  • All devices, including the Service Agent, printers, etc., must be allowed to reach the Domain Name System (DNS) and resolve names.

Additional Port Information

CPA installation and uninstallation occur between the Service Agent and the printer over TCP ports 10443, 49629, and 49630.

CPA operation requires two main communication paths:

Everyday print communication occurs from the device to the printer over TCP 9100 or TCP 515 for Line Printer Remote (LPR) queues.

Communication for Simplified Scanning features occurs over TCP 50083 between the printer and the Service Agent.

By default Certificate Revocation List (CRL) checks occur over TCP 80 from the Service Agent. The installation might fail if the CRL check cannot complete over port 80.

USB Badge Reader Settings

If you use a USB badge reader, turn on the keyboard emulation.

Turn On the Keyboard Emulation

Follow these steps:

  1. Press and hold the reset and start buttons simultaneously to restart the device. Release the buttons when they light up.
  2. Enter "#1048#" as the password.
  3. Now that the device is in service mode, select 08 Settings Mode, and select the Next button.
  4. Select the Classic button at the top of the screen.
  5. Enter the value "3500." Then select the Start button.
  6. Set the value to "60001." Then select the OK button.
  7. Restart the device.

Simplified Scanning Settings

Scan To features require the following setting configurations.

To configure the Remote Scan / WS-Scan option:

  1. Go to User Management then Role Management then Guest then Scan Function.
  2. Set the Remote Scan / WS-Scan option to Pull.

To enable SSL or TLS in the printer's web interface:

  1. Go to Administration then Setup then Network then WSD.
  2. For the Enable SSL / TLS option, select Enable.

To check if the Guest User Profile is set to Available:

  1. Go to User Management then User Accounts.
  2. Locate the Guest account in the list and check the Status column.
  3. If it is not set to Available:
    1. In TopAccess, go to Administration then Security then Authentication.
    2. Open the User Authentication Setting.
    3. Set the User Authentication dropdown to Enable.

      While User Authentication is set to Disable, the rest of the settings on this page, including the Enable Guest User checkbox, are greyed out and cannot be changed.

    4. Select the Enable Guest User checkbox, and save any changes.
  4. Return to User Management then User Accounts and confirm the Guest User Profile now shows Available.

General Authentication Options

The authentication options on the TCP / IP printer determine what the CPA shows to the end user. If you use the same authentication options for all printers, you can use the default settings. If you want to set specific methods by printer, you can choose which printer-specific options you want available for setup on individual printers.

Default Settings

Note that default authentication settings vary, depending on the identity provider (IdP). Lightweight Directory Access Protocol (LDAP) settings differ from settings available for an IdP, such as Okta and Entra ID (Azure AD).

For provider-specific attribute mapping, refer to LDAP Badge & PIN Attributes, Entra ID (Azure AD) Badge & PIN Attributes, Okta Badge & PIN Attributes, or Google Badge & PIN Attributes.

Cloud IdPs like Entra ID and Okta support badge and PIN authentication. The username and password option is not available.

In the Admin Console, go to Tools then Settings then General, and scroll down to the Identity Provider Settings. Follow the appropriate steps below for your provider.

Username and password is the default authentication method. Users sign in with their network credentials or the same credentials they use to sign in to the device. This method requires no additional setup beyond your Lightweight Directory Access Protocol (LDAP) Identity Sync configuration since it uses the credentials already defined there.

To verify this LDAP option:

  1. In the Identity Provider Settings section, select LDAP, and ensure that you correctly configured your LDAP credentials.

    Admin Console showing General settings and Identity Provider Settings section.

  2. Scroll down to CPA Specific Settings section and verify / turn on Enable Username/Password Authentication.

  3. Select Save in the upper-right corner.

CPA Login screen showing Scan Badge icon and fields for User sign-in option.

PIN authentication requires the end user to enter a user ID and PIN at the CPA.

CPA Login screen showing Scan Badge icon and fields for PIN sign-in option.

Badge scan authentication requires the end user to scan a badge, card, or dongle at the CPA. For LDAP, the first time users scan their badge, the CPA prompts them for their network credentials.

CPA Login screen showing Scan Badge icon and fields for PIN sign-in option.

Global Install Credentials, Security, & Single Sign-On (SSO)

In the Control Panel Application section on Tools then Settings then General set global installation credentials if the username and password to access the printer's UI are the same. Installation credentials can be adjusted per printer on the Apps tab or through the CPA Manager.

This section also includes the global Enabled or Disabled settings for SSO and the Enable higher security setting. Most of the CPA 2.0 apps support SSO with an IdP. With this functionality, you can choose provider or listener mode.

  • In provider mode you can lock the printer so that a user must authenticate before they can access the printer's control panel.
  • In listener mode PrinterLogic listens for when another app acting as the SSO provider authenticates a user and passes that user information to the CPA. The user can then select PrinterLogic on the CPA's control panel.
  • To review and understand the Enable higher security options and impact, refer to Transport Layer Security (TLS) Settings

To set global installation credentials or turn on SSO or higher security:

  1. Go to the Control Panel Application section.
  2. Use the Username and Password fields to set the global installation credentials.

    The credentials must have admin rights to the printer.

  3. Turn SSO on or off using the Enabled and Disabled options.

    Admin Console showing General settings and Control Panel Application section.

  4. Turn on higher security using the Enable higher security checkbox.
  5. Select Save in the upper-right corner.

Install the CPA

These steps are for installing the CPA on a single printer using the printer's Apps tab. To install the CPA on multiple printers at once, refer to CPA Manager.

Follow these steps:

  1. In the Admin Console tree structure, select the Service Agent that you want to run the app service.
  2. On the General tab, enter the FQDN in the IP Address or Hostname field, and then select Save.

    Using an IP address in this field causes CPA functionality and installation issues. Use only an FQDN for the Service Agent.
  3. Return to the tree structure, and select the printer on which you want to install the CPA.
  4. Select the Apps tab.
  5. From the Manufacturer menu, select the printer manufacturer.

    Admin Console showing printer object's Apps tab and expanded Manufacturer menu.

  6. Select the Service Agent that you want to use to install the CPA.
  7. In the Install Embedded Application section, select the Secure Release option.

    Admin Console showing printer object's Apps tab and Install Embedded Application section.

  8. Select the checkboxes for any additional apps that you want to install:

After installation the device goes to sleep as part of the deployment process. The device restarts after installation completes. The MDS settings configuration can take 5 or more minutes prior to start-up. Until the app is completely installed, error messages might appear on the screen.

Installation Credentials

In the section about credentials, select one of the following:

  • Use default printer administration credentials: Select this option if your printers share the same administrator credentials. Set default credentials on Tools then Settings then General in the Control Panel Application section.
  • Use printer-specific administration credentials: Select this option if your printers do not share the same administrator credentials. Enter the printer-specific credentials in the fields provided.

Admin Console showing printer object's Apps tab and section about credentials.

The credentials must have admin rights to the printer.

CPA Authentication Options

The options below appear depending on what you select in the IdP settings. Note that authentication features vary depending on the printer manufacturer.

If you use an IdP, the Control Panel Application (CPA) supports only badge and PIN authentication.

The following can appear:

  • Single Sign On: Use this section to lock the printer so that the end user must authenticate before accessing the device's control panel. Select from the following options:
    • Disabled: The device does not require authentication.
    • Enabled as a Provider: The device shows the default PrinterLogic CPA screen, which requires the user to authenticate.
    • Enabled as a Listener: The CPA runs in the background. When the user authenticates using another device app, they can select the PrinterLogic option from the device's control panel.
    • Don't Modify Printer Permissions: This option is for only Xerox printers. When you install the CPA, other apps on the home screen are available, which is helpful for certain features, such as guest login. When you uninstall the CPA, the authentication method and user permissions to access other apps on the printer do not change.
  • In the CPA Authentication section, you can select from the following:

    • Enable Username/Password Authentication: This option requires the user to enter their username and password.
    • Enable User ID with PIN Authentication: This option requires the user to enter their user ID and PIN.
    • Enable Badge Scan Authentication: This option requires the user to scan their badge, card, or dongle.

      The first time a user scans their badge, they are prompted for their network credentials.

      • Require PIN (beta): This option requires the user to enter their PIN after scanning a badge.

        This feature is incompatible if you turn on SSO.

  • Enable extended debug: (Optional) If you turn on this setting, the following become available:
    • Certificates: Use this link to download the PrinterLogic CA.
    • PrinterLogic Control Panel Application manual install URL.

Select Save to start the installation.

Admin Console showing printer object's Apps tab and Single Sign On, CPA Authentication, and "Extended debug" sections.

The installation process may trigger a device restart once complete.

Do the following if installation fails:

  1. Note the error message, and check the Printer Apps logs. For more details refer to PrinterLogic Log File Locations.
  2. Review and adjust your configuration to ensure that it meets all requirements.
  3. Select the Try Again button to restart the installation.

Admin Console showing printer object's Apps tab, error message, and Try Again button.

Uninstall the CPA

Follow these steps:

  1. In the Admin Console, select the Apps tab for the printer from which you want to remove the CPA.
  2. Deselect the options in the Install Embedded Application section.

    Admin Console showing printer object's Apps tab and Install Embedded Application section.

  3. Select Save.

After an uninstall the device is put to sleep as part of the process. The device will reboot after the uninstall is completed.

Troubleshooting Help