Universal Print
TYPE: TS/PVFA Operated Service
STATUS: Limited Deployment, January 2026
CLEAR: NOT CLEARed
BCP/DRP: N/A
Universal Print allows centralized cloud-managed printing through Microsoft 365 without requiring traditional on-prem print deployment methods such as Group Policy printer mapping or VPN connectivity.
Management RACI
| PVFA | TSPVFA | TSSAS | |
|---|---|---|---|
| Operating System/Infrastructure Management | |||
| Patching/Upgrades | I | I | R/A |
| Security Monitoring | I | I | R/A |
| Baseline Configuration | I | I | R/A |
| Backups/Recovery | I | I | R/A |
| Access Control | I | I | R/A |
| Application Management | |||
| Patching/Upgrades | I | I | R/A |
| Security Monitoring | I | I | R/A |
| Baseline Configuration | I | R/A | R/A |
| Backups/Recovery | I | I | R/A |
| Access Control | I | R/A | I |
Prerequisites
Before configuring Universal Print, ensure the following are in place:
Licensing
- Role Security Group (RSG) with:
- Microsoft A5 Student License
- Universal Print licensing assigned
The RSG group creation is currently handled by the IT Enterprise Architect.
Submit a ticket to helpdesk@tamu.edu.
Required Roles
Administrators should have:
- Printer Administrator
- AU-UEM
- Directory permissions
- Cloud Device Administrator
- Required for device and connector management
Recommended Administrative Unit:
AU-<Department>-Devices
Example: AU-PVFA-Devices
Infrastructure Access
- Access to Microsoft Entra ID
- Eligible PIM roles assigned:
- Printer Administrator
- Cloud Device Administrator (recommended)
- Ability to activate roles in Azure Privileged Identity Management (PIM)
You must activate required PIM roles before signing into the Universal Print Connector.
If roles are not activated, authentication into the connector will fail.
Connector Setup
Step 1. Activate PIM Roles
Before installing or signing into the connector:
- Go to Azure Privileged Identity Management (PIM)
- Activate required roles:
- Printer Administrator
- Cloud Device Administrator
- Wait for activation to complete
Step 2. Install the Universal Print Connector
Install the connector on the print server: Universal Print Connector installation guide
Step 3. Sign in to the Connector
After installation:
- Launch the Universal Print Connector
- Sign in using an account with activated PIM roles

- In the Connector name field, enter a connector name
Recommended naming format:
UP-Connector-<Department>
- Click Register

After registration completes, the connector displays a list of available printers ready to be registered with Universal Print.
Configure Your Connector
There are two connector settings that should be reviewed during setup:

The Universal Print Connector can automatically collect and send diagnostic data to Microsoft when errors occur to help troubleshoot issues and improve product security. This setting can be disabled if you prefer to manually send diagnostic data only when needed.
Enable Hybrid AD Configuration
When enabled, the connector uses Active Directory information to submit print jobs using the identity of the user who initiated the print job.
If disabled, print jobs are sent using the local system account on the connector machine instead.
This setting requires additional Active Directory prerequisites.
Registering Printers
After signing into the connector:
- Under Available Printers, select the desired printers
- Click Register

The printers will then appear in:
- Azure Portal
- Universal Print Connector Registered printers list

Sharing Printers
Share a Printer
To share a single printer:
- Navigate to the Printer Shares list
- Click Add

- Specify:
- Share name
- Printer to share
- Users and groups that should have access
Recommended standard group:
02 - College Staff/Faculty <College Name>

- Click Share Printer
Share Multiple Printers Simultaneously
If multiple printers need to be shared with the same users or groups:
- Navigate to the Printers list
- Select two or more printers
- Click Share
- Select users and groups to assign access
The same access settings will be applied to all selected printer shares.

Additional Printer Share Management
For advanced printer sharing tasks, including:
- Adding or removing printer shares
- Managing user and group access
- Bulk printer sharing
- Deleting printer shares
Refer to Microsoft documentation:
Share printers using Azure Portal
End User Experience
Adding the Printer
Once shared, users can add the printer directly from Windows without VPN or traditional print server mappings.
Users can:
- Search for printers in Windows
- Install directly from available devices
- Print through Microsoft cloud services
Internal documentation:
Operational Notes / Common Issues
Connector Login Failure
Common causes include:
- PIM roles not activated before login
- No license assigned to the RSG group
Printers Not Visible to Users
Verify the following:
- Printer is shared
- Correct security groups are assigned
- User licensing is valid