HP Commercial LaserJet Printers and MFPs - Imaging and Printing Security Best Practices

Chapter 7 HP LaserJet and Color LaserJet MFP Security Checklist 85
Disable EWS Config. Disabling EWS Config removes the EWS from the network. They
become unavailable to everyone. This eliminates many risks to security.
Since all of the EWS configuration settings are available in Web Jetadmin, there is no need to
have them available anywhere else. Keep in mind, though, that disabling EWS Config also
eliminates the affected settings from Web Jetadmin. Thus, you will have to enable EWS Config
temporarily to make changes to the configurations, and then disable it again.
With EWS Config disabled, the MFPs will not provide the EWS on the network. Web
browsers will return with no such web site found. This removes some conveniences that EWS
provide, but all of the functions that you would want to provide to users are available using the
MFP drivers or the control panels.
Overall Limitations
This overall configuration provides a high level of network security for HP MFPs. At the same time, it
introduces some limitations to the conveniences designed into the MFPs. Here are some known
affects of this overall configuration:
Extra steps to use MFPs: Users will be required to provide usernames and passwords at the
control panels before they can use the MFPs.
No access to control panel configuration menus: The control panels block access to
configuration settings for anyone. Configuration settings will be available only on Web
Jetadmin. Some settings will have to be enabled using Web Jetadmin before they can be
accessed.
No way to cancel print jobs from the control panel: The MFPs will not allow a user to cancel
the print jobs of other users. The user would have to go to the person who submitted the job
and ask that person to cancel it.
No way to cancel a fax job: The maximum lock setting on the control panel includes removing
the fax job cancelling options. Once a user selects Send, there is no way to stop an outgoing
fax (other than disconnecting the phone line). You can enable fax cancelling by configured
Control Panel Access Lock to Intermediate Lock.
Extra steps for printing faxes: A user will be required to provide a fax PIN before printing a
fax.
No Embedded Web Servers: Disabling EWS Config disables the entire EWS feature.
No way to change the From Address on email send jobs: Depending on the capabilities of your
network, the MFPs will place either a default from address or the user's email address of the user
who logged into the MFP. It will provide no method to change it.