Forum Discussion
18th Aug Update - Secure release is now broken for common Intune MAM and BYOD scenarios
Universal Print product managers, please take notice of the real-world impact created by retiring QR-code secure release from the Microsoft 365 Copilot app.
The Microsoft 365 Copilot app provided a seamless secure-release experience for staff, regardless of whether they used:
- A fully managed mobile device
- An Intune MAM-protected BYOD device
- iOS or Android
- A Windows or MacBook workstation
Users could print from their device, walk to the printer, scan the QR code within an already managed Microsoft application, and release the job. It was simple, secure and worked within existing Intune App Protection Policies.
The replacement Universal Print Portal creates a significant regression.
Microsoft has removed the only secure-release workflow that operated entirely within a managed Microsoft application. The browser-based replacement conflicts with common Intune App Protection configurations, introduces managed-browser requirements, and creates a poor experience for MacBook and BYOD users.
The iOS PWA recommendation does not solve the problem
On iOS, users are encouraged to install the Universal Print Portal as a Progressive Web App. However:
- The PWA installation experience is available through Safari.
- Our Intune MAM policies require organisational authentication and work links to use managed Microsoft Edge.
- Safari therefore cannot complete the work authentication flow.
- Edge can satisfy the MAM requirement, but it cannot provide the recommended Safari PWA installation experience.
This creates a circular and unusable experience. Safari can install the PWA but cannot authenticate. Edge can authenticate but cannot provide the equivalent installed PWA experience.
MAM and BYOD users do not necessarily want to make Edge their default browser merely to release a print job. The Microsoft 365 Copilot app avoided that problem because it was already a standalone, managed Microsoft application.
There is no replacement managed Universal Print mobile app
There is currently no equivalent Universal Print release application available through the Apple App Store or Google Play Store that can be protected through Intune MAM and provide the same experience as the Microsoft 365 Copilot app.
This affects real mixed-device workplaces containing:
- Windows and macOS computers
- iPhones and Android devices
- MAM-only BYOD devices
- Fully managed corporate devices
A MacBook user cannot conveniently scan a physical QR code using their laptop. Secure release therefore still depends on a practical mobile workflow, and Microsoft has removed the workflow that previously worked.
Requested action
Please either:
- Restore Universal Print QR-code release within the Microsoft 365 Copilot app until a suitable replacement exists; or
- Provide a dedicated Universal Print mobile app for iOS and Android that supports Intune App Protection Policies and MAM-only enrolment.
Moving secure release from the Microsoft 365 Copilot app to a web portal is not a simplification for managed enterprise environments. It is a substantial backwards step that can make secure release impractical or unusable for MAM and BYOD users.
7 Replies
- RemusDumitru
Microsoft
Thank you for clearly describing the MAM scenario. We understand that moving from an already-managed native app to a browser changes the experience, and that Safari-based installation does not fit a policy that requires managed Edge.
The Universal Print portal does not require PWA installation. For commercial customers, open https://print.cloud.microsoft directly in Intune-protected Edge, signed in with the work account, then select Secure release and scan from within the portal.
This route avoids Safari/PWA installation and the phone's native-camera/default-browser handoff. It does not require changing the device's default browser.
Your existing Intune and Conditional Access policies still apply; we are not recommending broad exclusions or reduced protections. If the complete flow does not work in managed Edge, please provide the point of failure, device/browser versions, and any sign-in error details through Microsoft Support rather than posting tenant information publicly.
This provides a browser-only option, although we recognize it is a different experience from the standalone app you used before.
- BradHBrass Contributor
This is still not a viable option, and you need to take the Microsoft hat off for a few minutes to think how users operate on their personal devices. Not everyone has Edge installed, and or have it set as their default browser an if they do, not all have the "Staff" account enabled inside Edge as their preferred browser instance. We need to think about the workflows on how users operate and you can't force a particular browser onto a personal device.
The Copilot app solves this issue. It's agnostic as a print release option and is signed in and managed under a MAM policy. We aren't forcing a particular browser on their personal devices using this method. The user goes to print, Copilot app deals with it, and you don't have an issue.
Most staff when scanning a QR code will just open their camera app and it's going to break in this above scenario as it will open in their default browser (most likely not Edge) and MAM policies will fail at that point.
I highly recommend having the Copilot app as an available option for Admins to specify for their instance so this opens via this method. Some admins might only opt for the Edge Browser option, but it's not possible in a mostly MAM mobile environment to do it as you are suggesting.
Or just make the Copilot app the default method of release again please. Otherwise, universal print secure release is basically broken in MAM.
- jeffdfield889Brass Contributor
I know it's not ideal, but can't you exclude Universal Print from your conditional access policy? That would probably fix the problem.
- BradHBrass Contributor
The scenario is as follows:
We have a bunch of users who have Copilot app installed. It's browser agnostic, it's signed in, and its supported by MAM/BYOD. They go to print and it just works because you don't have to be on Edge and in a work profile. Copilot takes that weight.
In the new scenario, staff try and release print jobs but it's going to try and do it via their default browser. Now, in this world and while Microsoft would absolutely love staff on MAM to use Edge as their default browser, there are a lot of that use Chrome, and or Safari (depending on your poison of mobile flavour) and it's going to bork if it is not in a "staff" profile.
We have MAM for a reason. We shouldn't need to disable components to make something as simple as printing to work.
- BradHBrass Contributor
Team, if you have a work around for this situation, we would be very glad to hear about this? All testing on our side, and the functionality is broken still in the above situation. MAM exists for a reason on BYOD devices.
- BradHBrass Contributor
Going to leave another reply here. This is the rollout that has broken this for us.
https://www.microsoft.com/en-us/microsoft-365/roadmap?id=561922
It's stated still as "In Development" which doesn't make any sense. We are broken at present, unable to ask staff using MAM devices to make Edge their default browser. The M365 Copilot App solves this issue. Can we have this escalated please.
- BradHBrass Contributor
Anyway, curious if we can get a reply on this?
Can we have a reasoning for the update that occurred. We have had to disable secure print unless there is a Universal Print app that staff can utilise? The M365 Copilot app worked perfectly fine especially in a mostly BYOD office space (mobile I am talking about, not the laptops)