Xerox CPA 2.0
Last Updated: August 10, 2026
Complete the requirements, and follow the steps below to install the second-generation Control Panel Application (CPA) on a Xerox printer. For a list of supported devices, refer to Supported Printers for Printer Apps.
Installation Requirements
Complete all Universal Requirements, and ensure functionality prior to CPA setup. Xerox also requires the following:
- Ensure that the printer is using the most recent firmware version. Older Extensible Interface Platform (EIP) levels do not support some CPA features.
- Ensure that the Xerox Web Services is turned on; this is usually on by default.
- Ensure that Simple Object Access Protocol (SOAP) is turned on; this is usually on by default.
- Turn on Transport Layer Security (TLS) 1.2 on the Multifunction Printer (MFP).
- If you have a Versalink device, you might need to add a driver if you use a badge reader.
- Ensure that the Domain Name System (DNS) information on the MFP is correct.
- Some printer models and installations using Single Sign-On (SSO) mode or a badge reader require Simple Network Management Protocol (SNMP) v2 or v3 configuration.
- SNMP v3 configurations require Message-Digest Algorithm (MD5) authentication protocol.
- SNMP SET and GET properties are both needed.
Additional Port Information
CPA installation and uninstallation occur between the Service Agent and the printer over TCP 443.
CPA operation requires two main communication paths:
- From the printer to the Service Agent object over TCP 31988.
- From the printer to the PrinterLogic instance, cpp-ui.app.printercloud.com and cpa-api.app.printercloud.com adjusted for your region, over TCP 443.
Everyday print communication occurs from the device to the printer over TCP 9100 or TCP 515 for Line Printer Remote (LPR) queues.
By default Certificate Revocation List (CRL) checks occur over TCP 80 from the Service Agent. The installation might fail if the CRL check cannot complete over port 80.
Badge Reader Settings
If your environment uses badging, you must configure SNMP v2 or v3, and confirm that Xerox Secure Access is turned on.
Simplified Scanning Settings
For Simplified Scanning without SSO, do the following for the features to function:
- Xerox Altalink: Go to Properties
Apps
Workflow Scanning
Remote Scan Start. Set the EIP Scanning option to On. - Xerox Workcentre: Go to Properties
Services
Workflow Scanning
Remote Start (TWAIN). Set the Start Program via Remote option to On. - Xerox Versalink: Go to Permissions
Guest Account
Device User Role
Custom Permissions
Setup. Set the Remote Scanning option to Allow.- Or go to Permissions
Guest Account
Device User Role
Custom Permissions. Turn on the Access All option. - Some models may be: Properties
Services
Workflow Scanning
Remote Start (TWAIN). Set the Start Program via Remote option to On.
- Or go to Permissions
Be aware, the paths above can change depending on the device's firmware.
General Authentication Options
The authentication options on the TCP / IP printer determine what the CPA shows to the end user. If you use the same authentication options for all printers, you can use the default settings. If you want to set specific methods by printer, you can choose which printer-specific options you want available for setup on individual printers.
Default Settings
Note that default authentication settings vary, depending on the identity provider (IdP). Lightweight Directory Access Protocol (LDAP) settings differ from settings available for an IdP, such as Okta and Entra ID (Azure AD).
For provider-specific attribute mapping, refer to
Cloud IdPs like Entra ID and Okta support badge and PIN authentication. The username and password option is not available.
In the Admin Console, go to Tools
Settings
General, and scroll down to the Identity Provider Settings. Follow the appropriate steps below for your provider.
- Username & Password
- User ID & PIN
- Badge Scan
Username and password is the default authentication method. Users sign in with their network credentials or the same credentials they use to sign in to the device. This method requires no additional setup beyond your Lightweight Directory Access Protocol (LDAP) Identity Sync configuration since it uses the credentials already defined there.
To verify this LDAP option:
PIN authentication requires the end user to enter a user ID and PIN at the CPA.
-
In the Identity Provider Settings section, select LDAP.
-
In the CPA Specific Settings section select Enable PIN Authentication with UserID.
- Select the PIN storage option:
- PrinterLogic Database: Enter the The field name containing UserID.
- Active Directory (AD): Enter The field name containing UserID and The field name containing PIN.
- Select Save in the upper-right corner.
If you select the Database option, users set their PIN in the Self-service Portal. For more details refer to PIN Self-Registration.
-
In the Identity Provider Settings section, select IdP.
-
In the Control Panel Application (CPA) Authentication section select Enable PIN Authentication.
- If you do not use your IdP to map and manage PINs, select Enable self registration of PIN for IdPs.
- Select Save in the upper-right corner.
Do not select Enable self registration of PIN for IdPs for IdPs if you already have a PIN attribute mapped through your IdP.
If you select the Enable self registration of PIN for IdPs option, users set their PIN in the Self-service Portal. For more details refer to PIN Self-Registration.
Badge scan authentication requires the end user to scan a badge, card, or dongle at the CPA. For LDAP, the first time users scan their badge, the CPA prompts them for their network credentials.
-
In the Identity Provider Settings section, select LDAP.
-
Scroll down to the CPA Specific Settings section and select Enable Badge Scan Authentication.
- Set badges to store in either the PrinterLogic Database or Active Directory (AD). For AD, provide the field name that contains the badge ID attribute.
- Select Save in the upper-right corner.
If you select the Database option, badge registration becomes mandatory.
- Individually manage badges on the Badge Management page, or refer to Import Badges into PrinterLogic.
- Or the user can set up their badge in the Self-service Portal. For more details refer to Badge Self-Registration.
-
In the Identity Provider Settings section, select IdP.
-
In the Control Panel Application (CPA) Authentication section select Enable Badge Scan Authentication.
- If you do not use your IdP to map and manage badges, select Enable managing of badges in PrinterLogic instead of in IdP.
- Select Save in the upper-right corner.
Do not select Enable managing of badges in PrinterLogic instead of in IdP for IdPs if you already have a badge attribute mapped through your IdP.
If you select the Enable managing of badges in PrinterLogic instead of in IdP option, users set their badge in the Self-service Portal. For more details refer to Badge Self-Registration.
Global Install Credentials, Security, & Single Sign-On (SSO)
In the Control Panel Application section on Tools
Settings
General set global installation credentials if the username and password to access the printer's UI are the same. Installation credentials can be adjusted per printer on the Apps tab or through the CPA Manager.
This section also includes the global Enabled or Disabled settings for SSO
- In provider mode you can lock the printer so that a user must authenticate before they can access the printer's control panel.
- In listener mode PrinterLogic listens for when another app acting as the SSO provider authenticates a user and passes that user information to the CPA. The user can then select PrinterLogic on the CPA's control panel.
- To review and understand the Enable higher security options and impact, refer to Transport Layer Security (TLS) Settings
To set global installation credentials or turn on SSO
- Go to the Control Panel Application section.
-
Use the Username and Password fields to set the global installation credentials.
The credentials must have admin rights to the printer.
-
Turn SSO on or off using the Enabled and Disabled options.
- Turn on higher security using the Enable higher security checkbox.
- Select Save in the upper-right corner.
Install the CPA
These steps are for installing the CPA on a single printer using the printer's Apps tab. To install the CPA on multiple printers at once, refer to CPA Manager.
Follow these steps:
- From the Admin Console tree structure, select the printer on which you want to install the CPA.
- Select the Apps tab.
-
From the Manufacturer menu, select the printer manufacturer.
- Select the Service Agent that you want to use to install the CPA.
- In the Install Embedded Application section, select the Secure Release option.
- Select the checkboxes for any additional apps that you want to install:
If you select the Copy/scan tracking option, you can make adjustments in the Accounting Prompts section.
Installation Credentials
In the section about credentials, select one of the following:
- Use default printer administration credentials: Select this option if your printers share the same administrator credentials. Set default credentials on Tools
Settings
General in the Control Panel Application section. -
Use printer-specific administration credentials: Select this option if your printers do not share the same administrator credentials. Enter the printer-specific credentials in the fields provided.
The credentials must have admin rights to the printer.
CPA Authentication Options
The options below appear depending on what you select in the IdP settings. Note that authentication features vary depending on the printer manufacturer.
If you use an IdP, the Control Panel Application (CPA) supports only badge and PIN authentication.
The following can appear:
- Single Sign On: Use this section to lock the printer so that the end user must authenticate before accessing the device's control panel. Select from the following options:
- Disabled: The device does not require authentication.
- Enabled as a Provider: The device shows the default PrinterLogic CPA screen, which requires the user to authenticate.
- Enabled as a Listener: The CPA runs in the background. When the user authenticates using another device app, they can select the PrinterLogic option from the device's control panel.
- Don't Modify Printer Permissions: This option is for only Xerox printers. When you install the CPA, other apps on the home screen are available, which is helpful for certain features, such as guest login. When you uninstall the CPA, the authentication method and user permissions to access other apps on the printer do not change.
-
In the CPA Authentication section, you can select from the following:
- Enable Username/Password Authentication: This option requires the user to enter their username and password.
- Enable User ID with PIN Authentication: This option requires the user to enter their user ID and PIN.
-
Enable Badge Scan Authentication: This option requires the user to scan their badge, card, or dongle.
The first time a user scans their badge, they are prompted for their network credentials.
-
Require PIN (beta): This option requires the user to enter their PIN after scanning a badge.
This feature is incompatible if you turn on SSO.
-
- Enable extended debug: (Optional) If you turn on this setting, the following become available:
- Certificates: Use this link to download the PrinterLogic CA.
- PrinterLogic Control Panel Application manual install URL.
Select Save to start the installation.
The installation process may trigger a device restart once complete.
Do the following if installation fails:
- Note the error message, and check the Printer Apps logs. For more details refer to PrinterLogic Log File Locations.
- Review and adjust your configuration to ensure that it meets all requirements.
- Select the Try Again button to restart the installation.
Uninstall the CPA
Follow these steps:
- In the Admin Console, select the Apps tab for the printer from which you want to remove the CPA.
-
Deselect the options in the Install Embedded Application section.
- Select Save.
Uninstall Using the Embedded Web Server or Web Interface
Follow these steps:
- Access the printer's embedded web server or web interface.
- You can access this interface in the Admin Console by going to the printer object's General tab and selecting the Web Interface link.
-
Got to Properties
Apps
Custom Apps
Weblet Management.This path might vary between models.
- Locate the PrinterLogic CPA.
- Select Delete.
Uninstall Using a Printer
Follow these steps:
- Access the device's control panel.
-
Go to Tools
App Settings
Weblet Settings
Weblet Management.This path might vary between models.
- Locate the PrinterLogic CPA.
- Select Delete.
Troubleshooting Help
Is an Identity Provider Configured?
The CPA requires the use of an IdP. This can be LDAP or another IdP such as Entra ID (Azure AD), Okta, etc.
Check the Default Printer Admin Credentials
Are the default printer admin credentials correct?CPA installations can fail if the admin username and password are incorrect. You can resolve this issue by modifying the credentials used for CPA installation. With the Modify option in the CPA Manager, update the credentials for multiple printers as long as they are the same brand. Often, the default admin name and password are the same multiple manufacturers.
Is There a Self-signed Certificate?
At a minimum, the printer requires a self-signed certificate. If an Amazon Root CA 1 certificate is not installed, refer to Amazon Root CA 1 Cert for the steps to obtain the certificate so you can manually install it on the printer.
Is There a Time Difference Between the Service Agent and the Printer?
If a certificate did not authorize, it could be because a printer is in a different time zone than the Service Agent hosting the Printer Apps. When the Service Agent pushes out the CPA application with the certificate, due to the time difference, the certificate may be expired.
You can reach the info page to check the timezone in two ways:
- Log in to the CPA, then tap on the PrinterLogic logo at the top.
- Install the CPA with Extended Debug mode enabled, then tap on the PrinterLogic logo at the top (without the need to log in first).
Check the Network Settings
- Verify that the IP address assigned to the printer is accurate within the Admin Console.
- Ensure that you can successfully ping the printer from the Service Agent machine.
Are You Using a Universal Print Driver?
Sometimes printer-specific drivers can cause installation issues for the CPA. Use a universal print driver to ensure a smooth and successful installation.
This is a generic communication error. A few things to check are:
- The Service Agent is not listening over port 31988. Update the configuration to allow listening over port 31988.
- The printer does not trust the PrinterLogic certificate. Register or upload a new certificate.
Fuji Xerox Specific
In the printer settings, configure the Domain Name within the DNS Configuration settings to see if it resolves.
The CPA requires a Service Agent to install apps to the printer. Check that the Service Agent machine is not shut down or in an error state.
On the machine, open the Task Manager and select the Details tab. In the Search field, type "printer" to locate the Agent processes.
If neither the PrinterLogicServiceManager.exe nor PrinterLogicServicePrinterApp.exe process is running on the Service Agent device, verify the Agent installation and / or Service Agent installation.
Verify the Client Installation
Verify the Agent is installed, authorized, and pointing to the correct instance. A quick test is to click the system tray icon to open the Self-service Portal. If it opens to the correct URL, and you can sign in and see / install printers from the portal, then the Agent is authorized.
If you are prompted for an authorization code in the Self-service Portal, refer to Device Authorization for steps on how to create one.
If the Self-service Portal opens to an incorrect URL, you need to set the home URL. Refer to Update the Home URL.
Verify the Service Agent Configuration
Navigate to C:\Program Files (x86)\Printer Properties Pro\Printer Installer Client\ServiceHost. and check the following:
If the Service Host folder is not created, check the machine's hostname or IP address and compare with what you entered for the Service Agent in the Admin Console.
If the folder is created, check the config folder in it. A token.json file is saved here when the Service Agent is authorized.
If the folder is created, but the token.json file is not there, you need to reauthorize the Service Agent, refer to Reauthorization Steps. Please note that the Service Agent authorization is different from the Agent authorization.
By default, the Visual C++ Redistributable for Visual Studio 2015 (32-bit/64-bit) or newer is typically already installed. However, both the x86 and x64 redistributable packages must be installed on the Service Agent to generate the items required for a successful installation. Without the packages, the Service Agent cannot initiate the app service. You can find these packages in the Microsoft Download Center.
The CPA requires an email address associated with each IdP user, which it uses as the username when logging in. This scenario occurs when an email address has not been associated with the user within the IdP.
You can find the log file on the Service Agent machine at the following path:
Windows:
C:\Program Files (x86)\Printer Properties Pro\Printer Installer Client\ServiceClientLogs\PrinterLogicServicePrinterApp.log
Mac/Linux:
/opt/printerinstallerclient/log/printerlogicserviceprinterapp.log
If the installation fails with an InvalidSolutionsKeyError, update the printer's region in the firmware settings.
Some devices do not support these characters by default. Install the related language packs for the characters and fonts on the printer.
In this topic:
The CPA can show text in the following languages. For more details refer to Supported Languages.
- Dutch: 0413.
- English: 0409.
- French: 040C.
- German: 0407.
- Italian: 0410.
- Japanese: 0411.
- Polish: 0415.
- Portuguese: 0416.
- Simplified Chinese: 0404.
- Spanish: 040A.
- Swedish: 0409.
- Thai: 041E.
- Turkish: 041F.













