Xerox CPA 2.0

Last Updated: September 11, 2026

Complete the requirements, and follow the steps below to install the second-generation Control Panel Application (CPA) on a Xerox printer. For a list of supported devices, refer to Supported Printers for Printer Apps.

Installation Requirements

Complete all Universal Requirements, and ensure functionality prior to CPA setup. Xerox also requires the following:

  • Ensure that the printer is using the most recent firmware version. Older Extensible Interface Platform (EIP) levels do not support some CPA features.
  • Ensure that the Xerox Web Services is turned on; this is usually on by default.
  • Ensure that Simple Object Access Protocol (SOAP) is turned on; this is usually on by default.
  • Turn on Transport Layer Security (TLS) 1.2 on the multifunction printer (MFP).
  • The Service Agent accepts only Elliptic Curve Diffie-Hellman Ephemeral (ECDHE) cipher suites on TCP 31988.
    • Firmware xx.71.21 and newer turns on ECDHE cipher suites by default.
    • On firmware older than xx.71.21, go to the printer's Embedded Web Server:
      • Then System then Security then Feature Enablement.
      • Enter the ECDHE Enablement Key for your model. Xerox recommends firmware xx.61.23 or later before you turn on ECDHE cipher suites.
    • Find key codes in the Xerox VersaLink Product Enhancements Document for your model family. Each VersaLink model family has its own version of this document.
  • If you have a Versalink device, you might need to add a driver if you use a badge reader.
  • Ensure that the Domain Name System (DNS) information on the MFP is correct.
  • Some printer models and installations using Single Sign-On (SSO) mode or a badge reader require Simple Network Management Protocol (SNMP) v2 or v3 configuration.
    • SNMP v3 configurations require Message-Digest Algorithm (MD5) authentication protocol.
    • SNMP SET and GET properties are both needed.

Additional Port Information

CPA installation and uninstallation occur between the Service Agent and the printer over TCP 443.

CPA operation requires two main communication paths:

  • From the printer to the Service Agent object over TCP 31988.
  • From the printer to the PrinterLogic instance, cpp-ui.app.printercloudnow.com and cpa-api.app.printercloudnow.com, over TCP 443.

Everyday print communication occurs from the device to the printer over TCP 9100 or TCP 515 for Line Printer Remote (LPR) queues.

By default Certificate Revocation List (CRL) checks occur over TCP 80 from the Service Agent. The installation might fail if the CRL check cannot complete over port 80.

Badge Reader Settings

If your environment uses badging, you must configure SNMP v2 or v3, and confirm that Xerox Secure Access is turned on.

Simplified Scanning Settings

For Simplified Scanning without SSO, do the following for the features to function:

  • Xerox Altalink: Go to Properties then Apps then Workflow Scanning then Remote Scan Start. Set the EIP Scanning option to On.
  • Xerox Workcentre: Go to Properties then Services then Workflow Scanning then Remote Start (TWAIN). Set the Start Program via Remote option to On.
  • Xerox Versalink: Go to Permissions then Guest Account then Device User Role then Custom Permissions then Setup. Set the Remote Scanning option to Allow.
    • Or go to Permissions then Guest Account then Device User Role then Custom Permissions. Turn on the Access All option.
    • Some models may be: Properties then Services then Workflow Scanning then Remote Start (TWAIN). Set the Start Program via Remote option to On.

Be aware, the paths above can change depending on the device's firmware.

General Authentication Options

The authentication options on the TCP / IP printer determine what the CPA shows to the end user. If you use the same authentication options for all printers, you can use the default settings. If you want to set specific methods by printer, you can choose which printer-specific options you want available for setup on individual printers.

Default Settings

Note that default authentication settings vary depending on the identity provider (IdP). Lightweight Directory Access Protocol (LDAP) settings differ from settings available for a cloud IdP, such as Okta and Entra ID (Azure AD).

For provider-specific attribute mapping, refer to LDAP Badge & PIN Attributes, Entra ID (Azure AD) Badge & PIN Attributes, Okta Badge & PIN Attributes, or Google Badge & PIN Attributes.

Cloud IdPs like Entra ID and Okta support badge and PIN authentication. The username and password option is not available.

In the Admin Console, go to Tools then Settings then General, and scroll down to the Identity Provider Settings. Follow the appropriate steps below for your provider.

Users sign in with their network credentials or the same credentials they use to sign in to the device. This method requires no additional setup beyond your Lightweight Directory Access Protocol (LDAP) Identity Sync configuration since it uses the credentials already defined there.

To verify this LDAP option:

  1. In the Identity Provider Settings section, select LDAP, and ensure that you correctly configured your LDAP credentials.

    Admin Console showing General settings and Identity Provider Settings section.

  2. Scroll down to CPA Specific Settings section and verify / turn on Enable Username/Password Authentication.

  3. Select Save in the upper-right corner.

CPA Login screen showing Scan Badge icon and fields for User sign-in option.

PIN authentication requires the end user to enter a user ID and PIN at the CPA.

CPA Login screen showing Scan Badge icon and fields for PIN sign-in option.

Badge scan authentication requires the end user to scan a badge, card, or dongle at the CPA. For LDAP, the first time users scan their badge, the CPA prompts them for their network credentials.

CPA Login screen showing Scan Badge icon and fields for PIN sign-in option.

Global Install Credentials, Security, & Single Sign-On (SSO)

In the Control Panel Application section on Tools then Settings then General set global installation credentials if the username and password to access the printer's UI are the same. Installation credentials can be adjusted per printer on the Apps tab or through the CPA Manager.

This section also includes the global Enabled or Disabled settings for SSO and the Enable higher security setting. Most of the CPA 2.0 apps support SSO with an IdP. With this functionality, you can choose Provider or Listener mode.

  • In Provider mode you can lock the printer so that a user must authenticate before they can access the printer's control panel.
  • In Listener mode PrinterLogic listens for when another app acting as the SSO provider authenticates a user and passes that user information to the CPA. The user can then select PrinterLogic on the control panel.
  • To review and understand the Enable higher security options and impact, refer to Transport Layer Security (TLS) Settings

To set global installation credentials or turn on SSO or higher security:

  1. Go to the Control Panel Application section.
  2. Use the Username and Password fields to set the global installation credentials.

    The credentials must have admin rights to the printer.

  3. Turn SSO on or off using the Enabled and Disabled options.

    Admin Console showing General settings and Control Panel Application section.

  4. Turn on higher security using the Enable higher security checkbox.
  5. Select Save in the upper-right corner.

Install the CPA

These steps are for installing the CPA on a single printer using the printer's Apps tab. To install the CPA on multiple printers at once, refer to CPA Manager.

Follow these steps:

  1. From the Admin Console tree structure, select the printer on which you want to install the CPA.
  2. Select the Apps tab.
  3. From the Manufacturer menu, select the printer manufacturer.

  4. Select the Service Agent that you want to use to install the CPA.
  5. In the Install Embedded Application section, select the Secure Release option.
  6. Select the checkboxes for any additional apps that you want to install:
    1. Copy / Scan Tracking.
    2. QR Code Display.
    3. Scan to Storage.
    4. Scan to Email.
    5. Scan To Workflow.

Admin Console showing printer object's Apps tab and expanded Manufacturer menu.

If you select the Copy/scan tracking option, you can make adjustments in the Accounting Prompts section.

Admin Console showing printer object's Apps tab and Accounting Prompts section.

Installation Credentials

If your printers do not share the default username and password, defined on Tools then Settings then General in the Control Panel Application section, to access the printer's UI:

  1. Go to the Apps tab, Credentials to use when installing... section.
  2. Select Use printer-specific administration credentials.
  3. Enter in the printer's username and password.

Admin Console showing printer object's Apps tab and section about credentials.

The credentials must have admin rights to the printer.

CPA Authentication Options

The options below appear depending on what you select in the CPA Authentication settings. Note that authentication features vary depending on the printer manufacturer.

If you use an IdP, the Control Panel Application (CPA) supports only badge and PIN authentication.

For SSO, select from:

  • Disabled: Normal CPA authentication without SSO.
  • Enabled as a Provider: Users authenticate through the CPA screen before accessing apps.
  • Enabled as a Listener: Users authenticate through another SSO provider and the CPA listens in the background and accepts the authorization.

For CPA Authentication, select from the option(s) you enabled in the General Authentication Options section above.

The Extended debug section is more for troubleshooting and contains:

  • Certificates to download the PrinterLogic CA.
  • PrinterLogic Control Panel Application manual install URL.

Admin Console showing printer object's Apps tab and Single Sign On, CPA Authentication, and "Extended debug" sections.

Start the Installation

With your settings in place:

  1. Select Save to start the installation.

Do the following if installation fails:

  1. Note the error message, and check the Printer Apps logs. For more details refer to PrinterLogic Log File Locations.
  2. Review and adjust your configuration to ensure that it meets all requirements.
  3. Select the Try Again button to restart the installation.

Admin Console showing printer object's Apps tab, error message, and Try Again button.

The installation process may trigger a device restart once complete.

Uninstall the CPA

Follow these steps:

  1. In the Admin Console, select the Apps tab for the printer from which you want to remove the CPA.
  2. Deselect the options in the Install Embedded Application section.

    Admin Console showing printer object's Apps tab and Install Embedded Application section.

  3. Select Save.

Uninstall Using the Embedded Web Server or Web Interface

Follow these steps:

  1. Access the printer's embedded web server or web interface.
    1. You can access this interface in the Admin Console by going to the printer object's General tab and selecting the Web Interface link.
  2. Got to Properties then Apps then Custom Apps then Weblet Management.

    This path might vary between models.

  3. Locate the PrinterLogic CPA.
  4. Select Delete.

Uninstall Using a Printer

Follow these steps:

  1. Access the device's control panel.
  2. Go to Tools then App Settings then Weblet Settings then Weblet Management.

    This path might vary between models.

  3. Locate the PrinterLogic CPA.
  4. Select Delete.

Troubleshooting Help