How do employees print securely from different locations?
23/09/2026
Zero-trust printing applies a simple principle to the print workflow: access should be verified rather than assumed.
For print management, this means that being connected to a corporate network or using a familiar device does not release a document by itself. With MyQ X Pull Print, a print job can remain held on the MyQ server until the user authenticates at the printing device. The user can then release the job on an authorized device within the print system.
MyQ X supports several authentication methods depending on the configuration, including PIN, ID card, username and password, QR code, and two-factor authentication. Users can also authenticate through Microsoft Entra ID in supported MyQ X environments.
The result is a print workflow where access to the document is tied to user authentication rather than simply the location of the printer.
How do employees print securely from different locations?
With MyQ X Pull Print, employees can submit a document to a MyQ print queue and release it later from a capable device. The job does not have to be released immediately at the printer to which it was originally submitted.
The basic workflow is:
- Submit the print job. The employee sends the document to a MyQ print queue.
- Hold the job. The document remains stored until the user is ready to release it.
- Authenticate. The employee identifies themselves at the device using an available authentication method.
- Release the document. The authenticated user releases the job from the device.
This prevents documents from being printed and left unattended in an output tray. Pull Print can also allow the employee to use another capable device if the original printer is unavailable or they are working elsewhere in the organization.
MyQ X Mobile Client provides another option for users who need to manage printing from mobile devices. It supports secure login, secure pull printing, and printing from zero-trust networks.
Authentication can follow the organization’s existing identity setup
MyQ X supports Microsoft Entra ID integration for authentication and user synchronization. With Entra ID SSO, supported MyQ Desktop Client users can authenticate using their existing organizational identity, including silent authentication on eligible domain-joined or Entra ID joined devices.
How does MyQ protect print jobs while they move through the environment?
Secure printing is not only about authentication at the printer. Communication and stored print data also need protection.
MyQ X supports encrypted communication between its components and other network services. Its security documentation describes encryption for user authentication data and print file content across network communication. MyQ X also supports encryption of stored print jobs and other stored data.
For particularly confidential documents, private queues can automatically delete print jobs after release, reducing the amount of time sensitive documents remain stored on the system.
This creates several layers of protection:
- Identity: the user authenticates before accessing the job.
- Secure release: the document is held rather than immediately appearing in the output tray.
- Communication security: network communication can be encrypted.
- Stored-data protection: print jobs and other data can be protected while stored.
- Accountability: MyQ provides audit logging for administrative activity and access-related events.
How does MyQ fit into a cloud identity and hybrid IT environment?
Cloud identity does not necessarily mean that every part of the print infrastructure has to move to the cloud.
MyQ X supports Microsoft Entra ID integration and can also be deployed in cloud infrastructure such as Microsoft Azure, AWS, and Google Cloud through supported configurations. MyQ documents these environments using cloud virtual machines and secure connections to on-premises resources such as printers and authentication servers.
This supports hybrid environments where identity and infrastructure may be cloud-based while physical printing devices remain across offices and locations.
For organizations using Microsoft Entra ID, MyQ X can synchronize users and provide authentication through the organization’s existing identity environment.
Where does MyQ Roger fit?
MyQ Roger takes a different architectural approach from MyQ X. MyQ Roger is a cloud-native print and document management platform. Its security capabilities include end-to-end data transfer using TLS 1.3, end-to-end job encryption, two-factor authentication, granular access control, and SSO with 2FA. It also supports mobile printing and secure device login through methods such as dynamic QR codes and NFC/Bluetooth.
Why does this matter for IT and security teams?
Distributed work makes location a less useful security boundary. Employees may work from different offices, use different devices, or submit jobs remotely before arriving at a printer. A print environment therefore needs to maintain control over who can access a document without relying solely on where the employee or printer is located.
MyQ provides the controls to support this model through user authentication, secure job release, encrypted communications, mobile printing, identity integration, and centralized print management.
The practical objective is straightforward: the employee should be able to print where they need to, while the organization retains control over when and where the document is released.
Secure printing should follow the user, not the location
A distributed workforce does not have to mean a less controlled print environment. MyQ X can hold print jobs until authentication, allow users to release documents at capable devices across the print environment, integrate with Microsoft Entra ID, and support secure printing from mobile devices.
MyQ Roger provides a cloud-native alternative for organizations looking for a cloud-based print and document management architecture.
Together, these capabilities provide a practical approach to secure printing across offices, devices, and working environments without making the printer’s physical location the primary security control.
Security is no longer just an IT responsibility. It’s a business requirement.
MyQ X
4 min read
Behind what appears to be a small convenience sits a cluster of security risks, operational inefficiencies, financial exposure, and staff burden that most organizations underestimate.
MyQ Roger
6 min read
In this hybrid, multi-device world, users expect their core infrastructure tools to work seamlessly everywhere. There is growth in adoption of ARM-based devices to improve efficiency, mobility, and sustainability.
News & Updates
2 min read