Direct Secure Release Coach

Last Updated: October 08, 2026

Set Up Direct Secure Release

Complete each section in order. The next section unlocks once you finish the one before it.

0% complete
All sections complete. Direct Secure Release is ready for your users.

Before You Begin

Review the following requirements:

  • This feature requires additional licensing. Contact your Vasion representative for more details.
  • Direct Secure Release and Offline Secure Release Print (OSRP) use a one-to-one relationship, allowing you to release a print job to only the selected printer.
  • Jobs sent to Direct Secure Release printers link to the printer ID instead of the IP address. Changing the IP address of a printer object does not route Direct Secure Release jobs to a new printer.

For more details refer to Secure Release Print.

Purge settings define the time that active and held print jobs remain in the queue before the system automatically removes them. Set purge times in the Admin Console by going to Tools then Settings then Printing and scrolling down to the Purging section. Purge times support a minimum of 1 hour. Review the following settings:

Purge active print jobs after (x) hours
Print jobs remaining in the queue after the specified time period without successfully printing are automatically removed.
Purge held jobs after (x) hours
Held jobs remaining in the release system after the specified time period are automatically removed.

Admin Console showing Printing Configuration and Purging section.

Note that ChromeOS print jobs support a maximum 12-hour purge time.

With OSRP, if the device that sent the job is unreachable, the user can release a print job from a virtual print queue. This feature works with Pull Print and Direct Secure Release.

When a user holds a job, the Service Agent receives a copy and keeps it in a virtual print queue. When the user releases the job and PrinterLogic detects that the device Agent is offline, the Service Agent releases the copy to the printer.

Review the following requirements:

  • OSRP supports devices with the Windows, macOS, Linux, or Chromebook Agent installed; it also supports Android and iOS devices.
  • You need at least one Service Agent running the OSRP service on a Windows device. For more details refer to Service Agents.
    • The OSRP service uses port 31989. Open this port on the Service Agent device.
  • The OSRP Service Agent must be able to reach the printers over the network. Add additional Service Agents if printers are on different networks.

For more details refer to Offline Secure Release Print (OSRP).

This coach includes the steps for configuring OSRP.

After you configure Pull Print or Direct Secure Release, users' held jobs display in the Release Portal. You can use the printer object's Release Tab, which provides a central location to view, release, and delete held jobs for that printer.

Refer to the following topics for more information about other secure release options for users:

This coach includes optional steps for configuring and installing the CPA as a release method.

Configure Identities

If you already have a configured identity provider, this section is mostly review.

PrinterLogic authenticates users at the printer control panel through IdPs like Entra ID (Azure AD), Okta, Active Directory, and more.

Review the Supported IdPs and configure your identity provider before moving on to the next section.

  • Active Directory (AD)-based IdPs (LDAP with Identity Sync and Active Directory Query eXecutor (ADQX)) support username / password, badge, and PIN authentication at the CPA.
  • Cloud-based IdPs (Entra ID (Azure AD), Okta, Google Identity, etc.) support only badge and PIN authentication at the CPA.

For steps to set up attributes in your IdP, refer to Badge & PIN Management and the section's subtopics.

Confirm your users provisioned into PrinterLogic.

  1. In the Admin Console, go to Tools then Identity Management or Tools then Identities, depending on which features are turned on.
  2. Confirm that your provisioned users appear in the list.
  3. Select a user and verify that the badge or PIN appears.

Users in the Identity Management table can sign in to the Self-service Portal and the Agent.

Configure Secure Release Settings

This setting makes the Queue tab appear on printer objects. You use the Queue tab to view the printer queues on end user devices, and this setting makes jobs visible to the local spooler for release.

Follow these steps:

  1. In the Admin Console, go to Tools then Settings then Printing.
  2. In the Print Jobs section, select Enable queue management.

    Admin Console showing "Enable queue management" option.

  3. Select Save.

Follow these steps to turn on Direct Secure Release:

  1. In the Admin Console, go to Tools then Settings then Printing.
  2. In the Pull Printing section, select Enable Workstation Pull Printing / Secure Printing.

    Admin Console showing Printing Configuration and Pull Printing section.

  3. Select Save.

Review the options in the Default per-printer Secure Release settings section. Most are optional, but the prompt settings directly impact Direct Secure Release. Decide which options to turn on before you continue.

The following are additional options:

Allow End-Users to Override
This option lets the user set their release printers and turn on prompts to hold or print, which are accessible from the system tray icon and the secure print settings in the operating system (OS) menu. For more details refer to the Secure Print Settings Guide.
Back End Release: Automatically release held jobs to printers with Yes (Prompt) set

With this option selected, when the user sends a print job to a printer with Yes (Prompt) selected, the job automatically releases to the printer rather than being held. You typically use this option in environments in which the printer is in a secure location, such as a private office.

This option appears only for customers using PrinterLogic Output.

Enable Offline Secure Release Printing
This option requires a Service Agent. When a user holds a print job, the Service Agent creates a copy. If the user's device is offline or the user is signed out, they can still release their held job to the printer, which prints the copy from the Service Agent. For more details refer to Offline Secure Release Print (OSRP).

Release Prompt Settings

The release prompt that appears when a user prints differs depending on how you configure the Secure Release Print settings for the printer. You select from the following options:

  • No: Jobs print immediately and cannot be held.
  • Yes (Always): Jobs automatically hold and require the user to release them.
  • Yes (Prompt): The user is prompted to select either Hold or Print Now.

Configure prompt settings globally or per-printer.

Follow the steps in the chosen section below to turn on Direct Secure Release globally or on a per-printer basis.

Turn on globally

Follow these steps:

  1. In the Default per-printer Secure Release settings section, use the prompt option dropdown to select one of the following:
    1. Yes (Always): Print jobs sent to Direct Secure Release printers automatically hold.
    2. Yes (Prompt): Print jobs sent to Direct Secure Release printers always prompt the user to hold or print the job.
    3. No: Direct Secure Release is not turned on for printers by default.
  2. (Optional) Select any of the following settings:
    1. Allow End-Users to Override. This option turns on the user options explained in the Secure Print Settings Guide.
    2. Back End Release: Automatically release held jobs to printers with Yes (Prompt) set.
    3. Enable Offline Secure Release Printing.
  3. Select Save.

Admin Console showing "Default per-printer Secure Release settings" section.

Turn on per-printer

Follow these steps:

  1. In the Default per-printer Secure Release settings section, use the prompt dropdown to select No: Direct Secure Release is not turned on for printers by default.
  2. (Optional) Select any of the following settings:
    1. Allow End-Users to Override. This option turns on the user options explained in the Secure Print Settings Guide.
    2. Back End Release: Automatically release held jobs to printers with Yes (Prompt) set.
    3. Enable Offline Secure Release Printing.
  3. Select Save.

Admin Console showing "Default per-printer Secure Release settings" section.

For the printer-specific configuration, you must complete the following steps on each printer object to turn on Direct Secure Release:

  1. Select the printer object in the tree structure.
  2. Select the Printing tab.
  3. In the Pull Printing section, select Use printer-specific Secure Release settings.

  4. For Allow secure release jobs to be sent to this printer, select one of the following:
    1. Yes (Always): Print jobs sent to Direct Secure Release printers automatically hold.
    2. Yes (Prompt): Print jobs sent to Direct Secure Release printers always prompt the user to hold or print the job.
  5. (Optional) Select Allow Users to Override.
  6. Select Save.
  7. Repeat these steps for any additional printer objects.

Admin Console showing printer object's Printing tab and Pull Printing section.

Configure the Service Agent

If you use only Direct Secure Release through the Release Portal or PrinterLogic mobile app, not the CPA, mark this section as complete to continue.

This section covers configuring a Service Agent, which installs Vasion apps and features on a printer, like Direct Secure Release, Copy / Scan Tracking, and more.

If you already have a configured Service Agent, still review the requirements and steps below before continuing to the next sections.

Device Requirements

Review the following requirements:

  • Device:
    • Windows 10 or 11 and Server 2016, 2019, 2022, or 2025.
      • Visual C++ Redistributable for Visual Studio 2015-2022 package or later.
        • You must install both the x86 and x64 redistributable packages. You can download these packages from the Windows Download Center.
        • The Service Agent cannot be a Windows device using an ARM processor.
    • macOS with an Intel processor.
    • Ubuntu Long Term Support (LTS) 22.04, 24.04, or 26.04.
  • Dual-core processor.
  • 20 GB of available hard drive space.
  • 8 GB of RAM.
  • PrinterLogic Agent installed and authorized.
  • The device, such as server, virtual machine, or workstation, must have network access to target printers.
  • The device must remain powered on because shutting it down stops all services.

Additional CPA Requirements

The number of printers with the CPA An app installed on a compatible multifunction device (MFD) that aids in the release of held print jobs, supports authentication for secure printing, and provides simple scanning functionality. installed that a single Service Agent or Independent Service Manager (ISM) can support depends on the device's resources and operating system (OS). Windows and Linux devices that follow the CPA requirements below support around 1,000 printers. If you have a large environment with 1,000 or more printers using the CPA, consider adding an additional Service Agent or ISM.

Requirements for the CPA Printer Apps service include the following:

  • The device running the Printer Apps service must be on the same network as the printers it manages.
  • For every 100 printers, add an additional 2 GB of RAM to the minimum listed above.
  • If your environment uses Single Sign-On (SSO), monitor RAM usage and increase the RAM as needed to handle increased memory usage during check-ins.
  • On macOS and Linux, the Service Agent running the PrinterLogicServicePrinterApp.exe service must have OpenSSL 3.5 or later installed. On Windows, the Service Agent installation already includes this requirement, so no separate installation is needed. For more details refer to OpenSSL Documentation.

For more details refer to Service Agents.

You must install and authorize the Agent on the device acting as your Service Agent before you define it in the Admin Console.

If the Agent is already installed and authorized on this device, you can mark this step complete and move on.

For more details refer to Install the Agent & Web Extension.

Follow these steps to create a new Service Agent:

  1. Sign in to the Admin Console.
  2. Select the folder in which you want to place the Service Agent.
  3. Select the New button at the top of the tree structure.

    Admin Console showing New button and Service Client option.

    1. Alternatively, you can right-click the folder and select New then Service Agent.

      Admin Console showing context menu with New and Service Client options.

  4. In the Name field, give the Service Agent object an identifiable name.
  5. In the IP Address or Hostname field, enter the IP address or Fully Qualified Domain Name (FQDN) The complete domain name for a specific device or host on a network, consisting of the hostname, the domain name, and the top-level domain. of the device that hosts the Service Agent.
  6. Select Add Service Client.

    Service Agent modal showing name and IP address or hostname information.

The name can be anything descriptive. For hostnames, use the FQDN, for example printserver01.example.com.

With the Service Agent object created, turn on the Printer Apps service.

Follow these steps:

  1. Go to the Service Agent's Printer Apps tab.
  2. Select Enable Printer Apps.

    Admin Console showing Service Agent's Printer Apps tab and Enable Printer Apps option selected.

  3. Select Save.
  4. Access the device designated as the Service Agent.
  5. Use the system tray icon or Start menu to refresh configurations.
  6. Open the Task Manager, and select the Details tab.
  7. In the Search field, enter printer to locate the Agent services.
  8. Confirm that the following services are running:
    1. Agent services, which include VasionClient.exe, PrinterInstallerClient.exe, PrinterInstallerClientInterface.exe, and PrinterInstallerClientLauncher.exe.
    2. PrinterLogicServiceManager.exe.
    3. PrinterLogicServicePrinterApp.exe.

Other active services on the Service Agent also appear.

The folder structure creation for the new service takes a minute. After the Agent creates the folder structure, the service begins running and you can view it in Task Manager or similar management apps.

If the service does not start or does not create the folder structure after 2 minutes, select Reauthorize on the General tab of the Service Agent object, then refresh the Agent on the Service Agent device.

Install the CPA

If you use only Direct Secure Release through the Release Portal or PrinterLogic mobile app, not the CPA, mark this section as complete to continue.

Review the following requirements:

  • These are universal requirements. Note that each printer manufacturer has additional requirements that you must review before installation.

  • Have admin login access to the printer. Installing the app is equivalent to changing printer settings, which requires login verification.
  • The printer should have the latest firmware version.
  • Turn on the Printer Apps service on the Service Agent, and confirm that the PrinterLogicServicePrinterApp.exe service is running.

    For Windows Service Agents, install the Visual C++ Redistributable for Visual Studio 2015-2022 package or later. You must install both the x86 and x64 redistributable packages. You can download these packages from the Windows Download Center.

  • Confirm that the HTTPS certificate matches the Service Agent device hostname or IP address. For more details refer to Service Agent Setup.
  • The Service Agent running the PrinterLogicServicePrinterApp.exe service must have OpenSSL 3.5 or later. Windows and macOS should have OpenSSL by default, but you might need to manually update the version for Ubuntu.
  • Turn on Simple Network Management Protocol (SNMP) status monitoring. For more details refer to SNMP Status Monitoring.
  • All devices must be able to reach the Domain Name System (DNS) server and resolve names.

Identity & Authentication

  • Active Directory: LDAP domain with Identity Sync configured.
  • IdP: Users must have email addresses assigned. CPA authentication fails without them.

Certificates

  • If you use self-signed certificates, verify that the root Certificate Authority (CA) is installed on the printer. Some manufacturers have additional certificate requirements.

Each printer manufacturer might include additional installation steps for the CPA. Keep the manufacturer topic open during the installation process.

Do not skip this step. Manufacturer-specific requirements might include additional firmware settings, certificate configurations, or printer-side setup that you must complete before the CPA can install successfully.

Review the port requirements closely in your manufacturer's documentation. There are specific ports that must be open between the Service Agent and the printer for installation and operation to succeed.

Manufacturer CPA Topics

Select the topic for your manufacturer:

The CPA has global settings that apply to each printer. These settings include the default credentials that install the CPA, whether you use Single Sign-On (SSO), and which authentication options users have at the printer, for example, badge authentication, username / password, or User ID and PIN.

Select the appropriate section to set up or review your authentication settings before moving on to the next steps.

Users sign in with their network credentials or the same credentials they use to sign in to the device. This method requires no additional setup beyond your LDAP Identity Sync configuration since it uses the credentials already defined there.

To verify this LDAP option:

  1. In the Identity Provider Settings section, select LDAP.

    Admin Console showing General settings and Identity Provider Settings section.

  2. Scroll down to the CPA Specific Settings section and turn on Enable Username/Password Authentication.

    CPA settings showing the different authentication options.

  3. Select Save in the upper-right corner.

CPA Login screen showing "Scan Badge" icon and fields for user sign-in.

PIN authentication requires the end user to enter a User ID and PIN at the CPA.

CPA Login screen showing "Scan Badge" option and fields for PIN sign-in.

Badge scan authentication requires the end user to scan a badge, card, or dongle at the CPA. For LDAP, the first time users scan their badge, the CPA prompts them for their network credentials.

CPA Login screen showing "Scan Badge" option and fields for PIN sign-in.

Global Install Credentials, Security, & SSO

Go to the Control Panel Application section on Tools then Settings then General to set global installation credentials if the username and password to access the printer's UI are the same. Adjust credentials per printer on the Apps tab or through the CPA Manager.

The Control Panel Application section also includes the global settings for SSO and the Enable higher security setting. Most of the CPA 2.0 apps support SSO with an IdP. With SSO, you can choose Provider or Listener mode.

Review the following information:

  • In Provider mode you can lock the printer so that a user must authenticate before they can access the printer's control panel.
  • In Listener mode PrinterLogic listens for when another app acting as the SSO provider authenticates a user and passes that user information to the CPA. The user can then select PrinterLogic on the control panel.
  • To review and understand the Enable higher security options and impact, refer to Transport Layer Security (TLS) Settings.

To set global installation credentials or turn on SSO or higher security:

  1. Go to the Control Panel Application section.
  2. Use the Username and Password fields to set the global installation credentials.

    The credentials must have admin rights to the printer.

  3. Turn SSO on or off using the Enabled and Disabled options.

    Admin Console showing General settings and Control Panel Application section.

  4. Turn on higher security using the Enable higher security checkbox.
  5. Select Save in the upper-right corner.

With requirements and authentication settings complete, install the Secure Release Print CPA. This app lets users release held jobs at the device.

These steps are for installing the CPA on a single printer using the printer's Apps tab. To install the CPA on multiple printers at once, refer to CPA Manager.

Follow these steps:

  1. From the Admin Console tree structure, select the printer on which you want to install the CPA.
  2. Select the Apps tab.
  3. From the Manufacturer menu, select the printer manufacturer.

  4. Select the Service Agent that you want to use to install the CPA.
  5. In the Install Embedded Application section, select the Secure Release option.
  6. Select the checkboxes for any additional apps that you want to install:
    1. Copy / Scan Tracking.
    2. QR Code Display.
    3. Scan to Storage.
    4. Scan to Email.
    5. Scan to Workflow.

Admin Console showing printer object's Apps tab and expanded Manufacturer menu.

Review each feature's requirements before you install it. Some features listed require additional licensing and may not appear as options.

Installation Credentials

If your printers do not share the default username and password, defined on Tools then Settings then General in the Control Panel Application section, follow these steps to set printer-specific credentials:

  1. Go to the Apps tab, Credentials to use when installing PrinterLogic applications on this printer section.
  2. Select Use printer-specific administration credentials.
  3. Enter the admin username and password for that printer.

Admin Console showing printer object's Apps tab and section about credentials.

The credentials must have admin rights to the printer.

CPA Authentication Options

The options below appear depending on what you select in the CPA Specific Settings section. Note that authentication features vary depending on the printer manufacturer.

The CPA supports only badge and PIN authentication for cloud IdPs.

For SSO, select from the following options:

  • Disabled: Normal CPA authentication without SSO.
  • Enabled as a Provider: Users authenticate through the CPA screen before accessing apps.
  • Enabled as a Listener: Users authenticate through another SSO provider and the CPA listens in the background and accepts the authorization.

For CPA Authentication, select from one of the options you turned on in the General Authentication Options.

The Extended debug section is for troubleshooting and contains the following:

  • Certificates to download the PrinterLogic CA.
  • PrinterLogic Control Panel Application manual install URL.

Admin Console showing printer object's Apps tab and Single Sign On, CPA Authentication, and "Extended debug" sections.

The installation process might trigger a device restart once complete.

Install the App

With your settings in place, select Save to start the installation.

If the installation fails, do the following:

  1. Note the error message, and check the Printer Apps logs. For more details refer to PrinterLogic Log File Locations.
  2. Review and adjust your configuration to verify that it meets all requirements.
  3. Select the Try Again button to restart the installation.

Admin Console showing printer object's Apps tab, error message, and Try Again button.

Monitor installation status from the CPA Manager on the Service Agent's Printer Apps tab, or directly on the printer's Apps tab: Look for the status indicator next to the Secure Release checkbox, which updates as the installation progresses.

Configure OSRP

This section is required only if you configure OSRP. If you do not use OSRP, mark the steps in this section as complete to continue.

Follow these steps:

  1. In the Admin Console, go to Tools then Settings then Printing.
  2. In the Pull Printing section, select Enable Offline Secure Release Printing.
  3. (Optional) Select Prioritize Workstation Release.

    Admin Console showing Prioritize Workstation Release option.

    This setting introduces a short delay, which lets the service check whether the device Agent is online to release the job before releasing it through the OSRP service.

  4. Below Select which users/clients will use this feature, select Show Filter.

    Admin Console showing Show Filter button.

  5. Select the Add button.
  6. Select the object type, use the Add modal to select the object, and then select OK.
  7. Select Save.

Users and groups that you add to the filter can print using OSRP.

Admin Console showing Printing Configuration, "Default per-printer Secure Release settings," and filter.

Turn on the OSRP service on the Windows Service Agent. The Service Agent must be able to reach printers over the network. Printers on different networks require another Service Agent that can reach them.

Follow these steps:

  1. Select the Service Agent in the tree structure.
  2. Select the Offline Printing tab.
  3. Select Enable Offline Secure Release Printing.
  4. Select Save.
  5. Access the physical device designated as the Service Agent.
  6. Use the system tray icon or Start menu to refresh configurations.
  7. Open the Task Manager, and select the Details tab.
  8. In the Search field, enter printer to locate the Agent services.
  9. Confirm that the following services are running:
    1. Agent services, which include VasionClient.exe, PrinterInstallerClient.exe, PrinterInstallerClientInterface.exe, and PrinterInstallerClientLauncher.exe.
    2. PrinterLogicServiceManager.exe.
    3. PrinterLogicServiceOfflinePrint.exe.

Other active services on the Service Agent also appear.

Task Manager showing Service Agent services running.

After you configure OSRP and the service runs, the Service Agent sends a copy to the printer if a user’s workstation is unavailable when they release a held print job. For environments with multiple sites, Vasion recommends using a preferred Service Agent.

This option assigns the Service Agent that users in an IP address range use when printing with OSRP. This configuration is helpful in large environments. With an OSRP Service Agent selected on the IP address range object, when a user who is in the range prints, the copy of the print job goes to that specific Service Agent.

For details on creating an IP address range object, refer to IP Address Ranges.

Follow these steps:

  1. In the Admin Console, select the IP address range object.
  2. On the General tab, use the Preferred service client dropdown menu to select the Service Agent.

    Admin Console showing "Preferred service client" menu.

  3. Select Save.

Install and Test

This section is for testing purposes. After successfully testing this feature, select the box to complete the coach and reveal additional resources.

Follow these steps to test this feature:

  1. Install a Secure Release Print printer from the Self-service Portal or through Printer Deployment.
  2. After installing, print a job and select the printer as the destination.
  3. (Optional) To test OSRP, lock or turn the workstation off after printing.
Already installed? Right-click the PrinterLogic Agent in the system tray and select Refresh Configurations to apply any settings that you just configured.

Use the applicable release method to test printing the held job. For more details refer to Release Held Jobs.

If the job appears but the username is wrong, right-click the PrinterLogic Agent on the workstation that sent the job and verify that the Agent is signed in as the correct user.

Admin Console
  1. In the Admin Console, select the printer's Release tab.
  2. Select the held print job.
  3. Select the Release button in the upper-right corner.
  4. Search or browse for the printer destination and select it.
  5. Select the Release button.

The held job prints to the destination location.

Release Portal
  1. Go to your Release Portal.
  2. Select the held print job.
  3. Select the Select Printer button.
  4. Use the side-modal to search or browse for the printer destination and select it.
  5. Select the Release button.

The held job prints to the destination location.

PrinterLogic mobile app
  1. Access and authenticate to the PrinterLogic mobile app on your phone.
  2. Select the Print Release tab.
  3. Select the held print job.
  4. Select Print.

The held job prints to the destination location.

CPA
  1. Go to one of the printers with this feature installed.
  2. Authenticate to the CPA.
  3. Select the Print or Release tab, depending on the CPA version.
  4. Select the held print job.
  5. Select the Print icon Print icon..

The held job prints to the destination location.

This completes the Direct Secure Release configuration. You have finished every step in this guide.

Refer to the following resources: