secure print
1 Topic18th Aug Update - Secure release is now broken for common Intune MAM and BYOD scenarios
Universal Print product managers, please take notice of the real-world impact created by retiring QR-code secure release from the Microsoft 365 Copilot app. The Microsoft 365 Copilot app provided a seamless secure-release experience for staff, regardless of whether they used: A fully managed mobile device An Intune MAM-protected BYOD device iOS or Android A Windows or MacBook workstation Users could print from their device, walk to the printer, scan the QR code within an already managed Microsoft application, and release the job. It was simple, secure and worked within existing Intune App Protection Policies. The replacement Universal Print Portal creates a significant regression. Microsoft has removed the only secure-release workflow that operated entirely within a managed Microsoft application. The browser-based replacement conflicts with common Intune App Protection configurations, introduces managed-browser requirements, and creates a poor experience for MacBook and BYOD users. The iOS PWA recommendation does not solve the problem On iOS, users are encouraged to install the Universal Print Portal as a Progressive Web App. However: The PWA installation experience is available through Safari. Our Intune MAM policies require organisational authentication and work links to use managed Microsoft Edge. Safari therefore cannot complete the work authentication flow. Edge can satisfy the MAM requirement, but it cannot provide the recommended Safari PWA installation experience. This creates a circular and unusable experience. Safari can install the PWA but cannot authenticate. Edge can authenticate but cannot provide the equivalent installed PWA experience. MAM and BYOD users do not necessarily want to make Edge their default browser merely to release a print job. The Microsoft 365 Copilot app avoided that problem because it was already a standalone, managed Microsoft application. There is no replacement managed Universal Print mobile app There is currently no equivalent Universal Print release application available through the Apple App Store or Google Play Store that can be protected through Intune MAM and provide the same experience as the Microsoft 365 Copilot app. This affects real mixed-device workplaces containing: Windows and macOS computers iPhones and Android devices MAM-only BYOD devices Fully managed corporate devices A MacBook user cannot conveniently scan a physical QR code using their laptop. Secure release therefore still depends on a practical mobile workflow, and Microsoft has removed the workflow that previously worked. Requested action Please either: Restore Universal Print QR-code release within the Microsoft 365 Copilot app until a suitable replacement exists; or Provide a dedicated Universal Print mobile app for iOS and Android that supports Intune App Protection Policies and MAM-only enrolment. Moving secure release from the Microsoft 365 Copilot app to a web portal is not a simplification for managed enterprise environments. It is a substantial backwards step that can make secure release impractical or unusable for MAM and BYOD users.79Views1like2Comments