Ricoh Aficio SP C821DNT1 Design Guide - Page 56

Protection of Document Server Documents

Page 56 highlights

Print Controller Design Guide for Information Security is not able to obtain any data at all (Basic Authentication enabled, ScanRouter V1). The data obtained from the forwarding server is then deleted at the MFP when the user logs out. Note: Administrators cannot perform these operations. • By enabling Basic Authentication, it is possible to protect the destination information. For each destination, it is possible to assign an access level to each registered user (View, Edit, Delete, Full-Access). Users who have View privileges for a particular destination can select the destination for forwarding, but cannot edit or delete the data. Users who have Full-Access privileges can perform all functions including sending to the destination, editing and deleting data, and making changes to access privilege settings. Users who have not been assigned any of these access privileges are not even able to view the destination list. Even when all of the above restrictions are enabled, User Administrators have Full-Access privileges for all registered destinations. However since User Administrators cannot use the Scanner function, they are not able to send any data. • When logged in with Basic Authentication, users are able to perform operations with either the forwarding feature or the TWAIN driver feature, not both. However with User Code Authentication, there are conditions in which one operator can utilize the Scanner via the TWAIN driver even while another operator is already logged in from the MFP operation panel (i.e. before the user logged in from the operation panel actually initiates a job). • With the TWAIN feature, the user is logged out automatically as soon as scanning is complete. Also, the authenticated user and Machine Administrator are the only individuals who can interrupt a scanning job in progress. When the Stop key is pressed to interrupt the job, the MFP prompts the operator with the authentication dialog. 2-3-4 Protection of Document Server Documents • When Basic Authentication is enabled, it is possible to assign access privilege to individual documents when scanning them for storage in the Document Server (View, Edit, Delete, Full-Access). These access privileges are applied even when accessing the document from DeskTopBinder or Desk Top Editor For Production. Users who have View privileges can both preview and send a document, but cannot delete or make any changes to the document (including the filename). Users who have Full-Access privileges can perform all functions including previewing, sending, editing and deleting the document, as well as making changes to the access privileges settings. Users who have not been assigned any of these access privileges cannot perform any of these operations, and are also prohibited from selecting documents in the document list screen. Even when all of the above restrictions are enabled, Document Administrators have Full-Access privileges for all registered documents. However since User Administrators cannot use the Scanner function, they are not able to send or store any data. Page 56 of 86

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86

Print Controller Design Guide for Information Security
Page 56 of 86
is not able to obtain any data at all (Basic Authentication enabled, ScanRouter V1). The data obtained
from the forwarding server is then deleted at the MFP when the user logs out.
Note:
Administrators cannot perform these operations.
By enabling Basic Authentication, it is possible to protect the destination information. For each
destination, it is possible to assign an access level to each registered user (View, Edit, Delete,
Full-Access). Users who have View privileges for a particular destination can select the destination for
forwarding, but cannot edit or delete the data. Users who have Full-Access privileges can perform all
functions including sending to the destination, editing and deleting data, and making changes to
access privilege settings. Users who have not been assigned any of these access privileges are not
even able to view the destination list. Even when all of the above restrictions are enabled, User
Administrators have Full-Access privileges for all registered destinations. However since User
Administrators cannot use the Scanner function, they are not able to send any data.
When logged in with Basic Authentication, users are able to perform operations with either the
forwarding feature or the TWAIN driver feature, not both. However with User Code Authentication,
there are conditions in which one operator can utilize the Scanner via the TWAIN driver even while
another operator is already logged in from the MFP operation panel (i.e. before the user logged in from
the operation panel actually initiates a job).
With the TWAIN feature, the user is logged out automatically as soon as scanning is complete. Also,
the authenticated user and Machine Administrator are the only individuals who can interrupt a
scanning job in progress. When the Stop key is pressed to interrupt the job, the MFP prompts the
operator with the authentication dialog.
2-3-4 Protection of Document Server Documents
When Basic Authentication is enabled, it is possible to assign access privilege to individual documents
when scanning them for storage in the Document Server (View, Edit, Delete, Full-Access). These
access privileges are applied even when accessing the document from DeskTopBinder or Desk Top
Editor For Production. Users who have View privileges can both preview and send a document, but
cannot delete or make any changes to the document (including the filename). Users who have
Full-Access privileges can perform all functions including previewing, sending, editing and deleting the
document, as well as making changes to the access privileges settings. Users who have not been
assigned any of these access privileges cannot perform any of these operations, and are also
prohibited from selecting documents in the document list screen. Even when all of the above
restrictions are enabled, Document Administrators have Full-Access privileges for all registered
documents. However since User Administrators cannot use the Scanner function, they are not able to
send or store any data.