Imprivata
Last Updated: May 21, 2026
Use this topic to configure Vasion Print to work with Imprivata Enterprise Access Management (EAM) for badge-based secure print release. Configuration involves steps in both the Vasion and Imprivata Admin Consoles.
Requirements
Review the Requirements before configuring this feature.
Configure the Imprivata Integration
1. Enable API Access in Imprivata
Enable API access for Vasion in the Imprivata portal so that the CPA can authenticate badge credentials against Imprivata. You must also configure a procedure code so Imprivata notifies the Vasion Client when a user logs in.
Enable API Access
To enable API access:
- Sign in to the Imprivata portal.
-
Select the Settings icon, then API Access.
-
Select Allow Full API Access via Confirm ID.
- Select Save.
Configure a Procedure Code
To configure the procedure code:
-
In the Imprivata portal, select the Settings icon, then Extensions.
-
Select View / Edit next to Procedure Code, then select Add.
- Enter a name for the procedure code.
-
Select the event trigger: when User Login or Desktop Unlocked.
-
Set the file extension to BAT and enter the following script:
Copy CodeProcedure Code
"C:\Program Files (x86)\Imprivata\OneSign Agent\ISXRunAs.exe" "C:\Program Files (x86)\Printer Properties Pro\Printer Installer Client\PrinterInstallerClient.exe" "silentrefresh" - Select Save.
- Go to Computers, then Computer Policies and open the applicable computer policy.
-
On the Extensions tab, select Enable Procedure Code Extension Object.
- Select Save.
2. Create a Custom SAML Application in Vasion
Create a SAML application in Vasion to connect to Imprivata.
- In the Vasion Admin Console, go to Tools
Settings
General. - Scroll down to the Identity Provider Settings section.
- Select IdP, and then select Add.
- Select Imprivata from the IdP Template dropdown menu.
- Select SAML2 in the Authentication Protocol section.
-
In the Provisioning section, if you are using Systems for Cross-domain Identity Management (SCIM), leave the JIT option deselected.
By default, the Admin Console assumes that you are using SCIM for provisioning. Only select JIT if you are not using SCIM.
- In the Name field, enter the name that you want to appear on the login button for users. For example, My Company, Login, or Acme Corp.
- Scroll down, and select the desired settings:
- Enable for End User Login: Allows end users to log in using this IdP. (Self-service Portal)
- Enable for Admin Login: Allows admins to log in using this IdP. (Admin Console)
- You can select both checkboxes when you are using a single IdP or the admin and end users use the same IdP to log in.
Keep the IdP Settings modal open so that the Service Provider Information section at the bottom is available for the following steps.
3. Create Imprivata App
To create the Imprivata app:
-
In the Imprivata EAM portal, go to Applications
Single sign-on application profiles. -
Use the Add App Profile dropdown to select Application using SAML.
- Give the application a profile and user-friendly name.
-
In the Identity Provider (IdP) metadata section:
-
Select View and copy Imprivata (IdP) metadata.
- Copy the SSO URL (redirect) and paste it into the Vasion SSO URL field.
- Press tab to autopopulate the Issuer ID and Issuer URL fields.
- In the Imprivata IdP SAML Metadata modal, download the Imprivata IdP certificate.
-
Open in the text editor of your choice and copy the value, including the Being and End Certificate headers.
- Paste the value in the Vasion X-509 Certificate field.
- Close the Imprivata IdP SAML Metadata modal.
-
- Copy the Vasion Identifier (Entity ID).
- Select Apply in the Vasion modal.
- Select Save in the upper-right corner.
If you do not apply and save the IdP Settings modal, the metadata collection via URL in the next section will not work.
4. Add SAML Metadata
To add the SAML metadata:
- In the Imprivata Service Provider (SP) metadata section:
- Select the Get SAML metadata button.
-
Select From URL and paste the Identifier (Entity ID) into the field.
- Select OK.
- In the same section verify or adjust the following:
- Adjust the NameID format preference to Unspecified.
- Adjust the Returned attribute to User logon name - Pre W2k (sAMAccountName).
- Select Save at the bottom of the Imprivata screen.
5. Confirm CPA Settings
To confirm the badge authentication method:
- Back in Vasion, in the Identity Provider Settings section, confirm IdP is selected.
- In the CPA Specific Settings section, select Enable Badge Scan Authentication.
- Select Save in the upper-right corner.
Do not select Enable managing of badges in PrinterLogic instead of in IdP. Imprivata owns the badge database. Enabling this setting creates a conflict between the two systems.
6. Enable Imprivata Badge Authentication
With this setting enabled, only Imprivata badge authentication will work on devices with the CPAs installed from this Service Client, other user authentication methods will not.
To enable Imprivata badge authentication:
- In Vasion, go to the Service Client running the Printer Apps service.
- Select the Printer Apps tab.
- In the Imprivata Badge Authentication section, select Enable Imprivata Badge Auth.
-
Enter the Imprivata Appliance URL in the field provided.
- Select Save in the upper-right corner.
The Imprivata Appliance URL is the full address of your Imprivata admin console login page. Enter the complete URL, including the path. For example, https://example.com/sso/administrator.htm. Do not enter only the base domain.
7. Enable Identity Sync
Identity Sync provisions users into the Vasion instance where they are associated with the Imprivata IdP connection.
On the same Service Client:
- Select the Identity Sync tab.
- Select Enable LDAP Identity Sync.
- Use the dropdown next to Associate Groups and Users with to select your Imprivata configuration.
- Confirm the identity linking attribute is set to sAMAccountName.
- Select Save in the upper-right corner.
8. Deploy Imprivata
To finish and deploy the Imprivata connection:
- Back on the Imprivata Single Sign-On application profiles page, select your app.
-
Select the Deploy option from the menu.
- On the Deploy application page, select Deploy This Application?
- Select Deploy to All Users and Groups?, or deselect and choose specific users and groups.
- Select Save when finished.
After you configure the connection, clinicians can badge in at the MFP using their Imprivata proximity badge to view and release their print jobs. If badge authentication fails, a manual login option is available at the MFP.
Next Steps
- Direct Secure Release (If not already configured).


















