Syncing users from Microsoft Entra ID or Google Workspace — overview
Syncing from Microsoft Entra ID (formerly Azure AD) or Google Workspace allows your organization to do the following:
- Connect PaperCut Hive or Pocket to your identity provider, ensuring that your user list is always up-to-date and matches your source of truth.
- Automatically add, update, and delete users and user attributes, including full name, email address, department, access codes, and access card numbers. (Note that the ability to delete users and map user attributes depends on the chosen sync method.)
- Start using custom Groups to manage your users in PaperCut Hive or Pocket. Note that custom groups are only available when users are synced via the User and group sync feature. Other methods of adding users, such as email address or a user sync add-on, are not compatible with custom groups.
You can sync via the User and groups sync feature or via a user sync add-on for each identity provider. For most organizations, User and Group Sync is the best choice — particularly because it allows Groups to be enabled in PaperCut Hive and Pocket. However, the add-on versions might still be best suited for:
- some long-term organizations already using the add-on versions
- Microsoft Entra ID-using organizations that specifically require SCIM provisioning.
The rest of this article is focused on the User and group sync feature.
Understanding the two different uses of groups in PaperCut Hive and Pocket
In PaperCut Hive and Pocket, the user sync process is separated from the Group management process, even though both use groups sourced from your identity provider.
The groups you use to import your users do not have to be the same groups that you use to manage them in PaperCut Hive and Pocket.
Here’s how to distinguish between these two types of groups:
- User source group: selected while setting up a sync configuration in User and group sync. Defines which users and data are imported into PaperCut Hive and Pocket during a sync. Also creates these users as PaperCut Hive and Pocket users. In short, the User source groups define “who gets to print”. Generally, organizations will select “All users” or very large organizational units/administrative units as their user source for sync.
- User management group: added in Groups (only available if at least one identity provider is connected via User and group sync). Applies memberships from the identity provider to users in PaperCut Hive and Pocket, allowing large-scale management of policies, permissions, reports, and more.
After you import users via User and group sync, you can then go to the Groups section to select groups to use for managing those users in PaperCut Hive or Pocket. When you add a group into the Groups page, it will provide you with group-based user management and reporting — but it will not impact the users being synced into PaperCut Hive or Pocket.
The rest of this article is only about User and group sync and its related User source groups.
Common scenarios for User and group sync in PaperCut Hive and Pocket
User and group sync suits a wide range of scenarios.
Small organization syncing all users
Small organizations (such as small-to-medium businesses with a single office) frequently have a simple setup, such as a single identity provider, and want all of their users to be able to use PaperCut Hive or Pocket. This type of organization would set up a sync configuration and add its users to the sync configuration’s User source.
This way, all user accounts in the identity provider are synced into PaperCut Hive or Pocket. The setup is simple, with minimal administrative effort and maintenance required.
Large organization syncing a subset of users
Some larger organizations only want a portion of their users to use PaperCut Hive or Pocket. Common examples of this type of organization include universities and large enterprises with multiple departments.
This type of organization would set up a sync configuration and add selected groups into the sync configuration’s User source.
The recommended way to manage this is to set up a single “Print users” group in the identity provider that contains everyone you want to be able to print, and add it into the sync configuration’s User source in PaperCut Hive or Pocket. This approach reduces unnecessary users, providing PaperCut Hive or Pocket access only to relevant users.
Centralized identity provider with many organizations (one identity provider to many tenants)
A more complex scenario is a large organization with a single identity provider containing all users, but multiple subsidiary organizations that each require only their own subset of users. This might be, for example, a government education department overseeing many schools, and those schools share a single identity provider.
In this situation, each subsidiary organization syncs users by adding specific groups (for example, School A Students, School A Staff) to the sync configuration’s User source in PaperCut Hive or Pocket. This enables PaperCut Hive and Pocket-side segmentation within a shared identity provider.
Multiple PaperCut Hive or Pocket instances (organizations) connected to one identity provider
There may also be organizations that require multiple PaperCut Hive or Pocket instances to connect to the same identity provider, for example, separate school instances connecting to a single, central identity provider.
To manage this, each PaperCut Hive or Pocket instance selects different groups from the User source in its sync configuration. This supports independent environments with a shared identity infrastructure.
Multiple identity providers connected to one PaperCut Hive or Pocket instance (organization)
Some organizations use more than one identity provider (for example, separate identity providers for staff and students, or different office sites). PaperCut Hive or Pocket supports these kinds of organizations by allowing multiple sync configurations.
Complex syncing between multiple identity providers and multiple PaperCut Hive or Pocket instances (organizations)
Some enterprise organizations are very complex and require syncing of multiple identity providers and multiple PaperCut Hive or Pocket instances (organizations). While this is supported, we recommend PaperCut Hive customers discuss their plans and requirements with a PaperCut Hive Accredited Reseller before implementation.
Deciding which identity provider groups to sync: best practices
One of the main decisions to make when selecting an import User source within a User and group sync configuration is “which groups should I sync in?” This can be a difficult decision, depending on how your organization is structured.
Generally, when it comes to User source groups, the best practice is to use large groups (ideally a single group) that contain all the users that you want to allow access to your print services. This kind of group is generally at the “Administrative Unit” or “Organizational Unit” level in your identity provider. This makes it easier in the long run for an administrator to manage.
For many organizations, syncing all users from their identity provider is the simplest option.
However, for organizations that only want specific users across a number of existing groups to have print access (for example, only giving a subset of teachers access to printing), it’s best to create a new, specific group in your identity provider that contains all these users. Common names for this specific group include “Print Users” or “PaperCut Users”.
Both of the above solutions allow you to easily manage importing users from the identity provider without constantly adding or removing groups to ensure the relevant people have print access.
Example high school identity provider structure
|
|
Understanding the group structure
Teachers in the school all belong to the “Teachers” group and at least one additional group, based on their specialisation.
Students all belong to the Students group, plus their appropriate year level group.
Office Staff all belong to the Office Staff group, plus one additional group based on their role.
Recommended identity provider sync approach
There are two likely scenarios:
- Recommended: Create and use a new group (such as “Print Users”) in the identity provider. Add all users you want to have print access into the Print Users group. As time passes, all you need to do is maintain this single group, for example by adding new starter teachers or students.
- Use the higher level administrative units or organizational units (Teachers, Students, Office Staff, Information Technology) as the User source groups in the sync configuration. On sync, these users will be added into PaperCut Hive or Pocket. This allows any new students or staff that join the school to be automatically added to PaperCut Hive or Pocket for print access on the next sync.
After the sync configuration (with the appropriate User source) is set up in PaperCut Hive or Pocket, you can navigate to the Groups page in the PaperCut Hive or Pocket admin console to configure more fine-grained groups for user management. By adding additional groups as user management groups (for example, Maths, Science, Year 11, Reception, etc), the Administrator has greater control around reporting and restrictions for users with membership of these groups.
Identity provider attributes overview
Part of syncing an identity provider is mapping its attributes to PaperCut Hive or Pocket attributes. At minimum, Email and Username must be mapped; all other attributes are optional.
If Access code is not mapped, PaperCut Hive or Pocket will auto-generate access codes for all new users and all existing users who don’t have an access code, then send a notification email to those users to let them know what their access code is.
If you store sensitive data, such as access card numbers and access codes, in another system, it can also be imported into PaperCut Hive or Pocket via the User data import tool (CSV).
Migrating from a user sync Add-on to User and group sync
It’s possible to migrate from a user sync Add-on to User and group sync.
- Organizations that previously used the Google Workspace user sync Add-on should disconnect the add-on, and set up a sync configuration in User and group sync.
- Organizations that previously used a Microsoft Entra ID user sync Add-on should be aware that there are some slight differences in how PaperCut Hive and Pocket Microsoft Entra ID user sync Add-on and User and group sync handle the Email field in Attribute Mapping. Before changing to User and group sync, check if the following scenarios apply.
Specific instructions and scenarios for migration are included in the procedures for syncing from each identity provider. Ensure that you review these procedures in full before migrating:
How to sync from Microsoft Entra ID or Google Workspace into PaperCut Hive or Pocket via User and group sync
Refer to the specific instructions for your identity provider:
How to edit a User and group sync identity provider configuration
-
Log in to the PaperCut Hive or Pocket admin console.
-
In the left navigation bar, select Settings. The Settings page is displayed.
-
Select the User and group sync tab. The User and group sync page is displayed.
-
Select the identity provider configuration you would like to edit. The Edit sync configuration page is displayed.
-
Edit the sync configuration as required.
-
Select Save. The changes are applied.

Previously set up configurations are editable in the User and group sync page
How to delete a User and group sync identity provider configuration
- Log in to the PaperCut Hive or Pocket admin console.
- In the left navigation bar, select Settings. The Settings page is displayed.
- Select the User and group sync tab. The User and group sync page is displayed.
- Select the three dot menu on the sync configuration you want to delete. The Delete sync source popup is displayed.
- In the popup field, enter DELETE in capital letters. You do not need to include the quotation marks.
- Select Delete configuration. The sync configuration is deleted.
Frequently asked questions
I already use a user sync Add-on without groups functionality. Can I use Groups in PaperCut Hive or Pocket?
Yes, but you will have to change how you sync. Groups functionality is only available when set up via Groups in the admin console and when user syncing has been set up via User & Group Sync. It is not available via a user sync add-on.
Organizations using a user sync add-on for Microsoft Entra ID or Google Workspace must migrate to the built-in User & Group Sync before they can use groups.
Can I use a user sync Add-on at the same time as User and group sync?
No. This might cause data clashes.
Can I change from a user sync add-on to User and group sync?
Yes, you can change from a user sync add-on to User and group sync. You'll need to disconnect the user sync add-on, create a sync configuration in User and group sync, then start syncing again. Ensure you check that your sync configuration's attribute mapping is completed for all fields you want synced.
The User and group sync configuration will "take over" where your user sync add-on left off — plus you'll be able to start using the Groups feature in PaperCut Hive or Pocket.
Before migrating, organizations which previously used the Microsoft Entra ID user sync Add-on will also need to review the migration guide.
How often does PaperCut Hive or Pocket sync with my identity provider? When does the syncing start?
As part of setting up User and group sync in PaperCut Hive and Pocket, you’ll select whether you want to sync manually (ad hoc, on demand, when you press the Sync now button in the admin console) or whether you want to automatically sync on a weekly, or monthly schedule.
The sync will start at the next time the schedule is triggered.
To immediately sync your sync configuration, you can always Sync now.
User restrictions and balances aren’t synced attributes, and I’m migrating from PaperCut NG/MF. How do I get these into PaperCut Hive or Pocket?
To import existing balances and restricted status against your migrated users:
Set up User and group sync, and complete a sync.
Use the Import user data (CSV) tool to export the user list from PaperCut NG/MF.
Re-import the CSV/TSV file containing the email, balance, and restricted status columns into PaperCut Hive or Pocket.
What happens if an error prevents PaperCut Hive or Pocket from synchronizing with my identity provider?
When a sync can't start due to an error, no changes are made to the PaperCut Hive or Pocket organization. In this situation, check the Activity Log for an error message.
If a sync fails partway through, PaperCut Hive or Pocket will attempt to process as much information as possible. Some information may not be available to process. Check the Activity Log for an error message and try re-syncing later.
If a sync fails or partially fails due to data errors (for example, multiple users with the same access code), go to the Activity Log and download the report. Review any errors in the report, amend the data in the identity provider, and sync again.
Does User and group sync support just-in-time provisioning (on demand provisioning)?
No. We may consider this in the future.
How can I test User and group sync?
Set up a User and group sync configuration with:
User source: a test group/administrative unit/organizational unit with test users in it that do not already exist in your PaperCut Hive or Pocket Users list
Sync frequency: manual.Select Sync now.
After the sync completes, check the Activity Log for a report, and check how the users were imported into your PaperCut Hive or Pocket organization.
When you're ready, you can change your User source to your real users, and change your Sync frequency if desired.
If you need tips and assistance, contact your Accredited Reseller for support.
If the sync fails, what error messages will I see and where can I find them?
If a sync fails, you can view the details in Logs > Activity Log.
How do I delete users during a sync?
If you deleted users in your connected identity provider, and want those users deleted from your PaperCut Hive or Pocket Users list, perform a manual sync and choose to delete these users. Be careful — after this data has been deleted, it can't be recovered.
To perform a manual destructive sync:
In the admin console, go to Settings > User and group sync and locate the correct sync configuration.
Select Sync now.
In If users are deleted in the synced user source: select Delete the users in PaperCut Hive (or Pocket).
Select Start sync.
Here are some common scenarios of deleting users and/or groups, either in the IdP and/or in PaperCut Hive or Pocket:
Identity provider source | Selection in sync configuration User source | Change and outcome |
|---|---|---|
Some users are deleted | All users | If users are deleted in the identity provider source, they will be deleted in PaperCut Hive or Pocket on a destructive sync. |
Some teachers are deleted | Teachers | If users are deleted in "Teachers" in the identity provider, on next destructive sync, those same users will be deleted in PaperCut Hive or Pocket. |
Teachers; Students | Teachers; Students | If "Teachers" is removed as a sync configuration User source, on next sync, all users only associated with "Teachers" are deleted in PaperCut Hive or Pocket. |
All staff; Teachers; Students | All staff; Teachers; Students | If "Teachers" is removed as a sync configuration User source, on next destructive sync, no changes are made to the PaperCut Hive or Pocket user list. This is because members of the "Teachers" group are also members of "All staff". They are still included in a user source. |
What happens to blank, changed, or deleted user attributes?
The user attributes you have configured in PaperCut Hive or Pocket are synced during a sync.
If a user attribute is blank, on sync, any user data in the matching field in PaperCut Hive or Pocket is not changed. No new data is imported.
If a user attribute is changed in PaperCut Hive or Pocket, any user data linked to that attribute will be imported into the PaperCut Hive or Pocket user profile for users during the next sync.
If a user attribute is deleted, it will not sync again. No changes are made to existing user data.
What happens to suspended/disabled accounts in my identity provider?
If your sync configuration's connected identity provider User Source includes suspended or disabled accounts, they are synced into PaperCut Hive or Pocket in a suspended state. This means that they can't access MFD functions like printing and copying, and they also can't log in. The ability to exclude suspended users from a sync is coming soon.
Are archived users included during a Google Workplace sync?
No, archived users are not synced from Google Workspace to PaperCut Hive or Pocket.
Comments