Pharos Cloud 4.5 Release Notes - May 2026

Prev Next

This release represents the latest version of Pharos Cloud. This update includes several important new features, enhancements, and bug fixes.

Security Enhancements

  • New Customer Enterprise Key Management (Preview)

  • New System User Password Expiration Options

  • Masked Private Data Fields in the web console

  • Claims Mapping for SSO (Preview)

Print Analytics and Accounting

Merge Print Analytics data with Job Accounting (Education Edition)

Platform Updates

  • Centralized Mobile App Access Controls

  • Email Notification Management

  • Enhanced Print Scout Managements in the Web Console

  • Discover On-Demand for Device Scout

Direct Print Enhancements

  • Bulk Location Import via CSV

  • Enhanced Devices Import

  • New “Queue Profiles” for Direct Print

Print Scout Updates

  • Jobs and Accounts data correlation support (Education Edition)

  • Naming and Icon Standardization

  • Mobile Registration follows new Mobile Access setting

  • Enhanced Print Scout and Device Scout Logs

  • New “About” option in the Pharos Print desktop app

  • Print Scout Bugfixes

Pharos Sentry Print Service Updates

  • New QR Sign In (HP Devices Only)

  • Admin-Managed Certificates for Sentry Print Service (On-Prem Only)

Security Enhancements

Pharos Cloud 4.5 enhances security, identity, and compliance with new capabilities that strengthen data protection and identity management.

New Customer Enterprise Key Management (Preview)

Pharos Cloud 4.5 introduces Enterprise Key Management (EKM) on top of Pharos Cloud’s standard encryption, allowing organizations to use customer‑managed encryption keys (such as AWS KMS) instead of Pharos‑managed keys to encrypt cloud‑stored print data.

EKM gives customers control over key ownership, rotation, and revocation and can be enabled or disabled under Account Settings > Settings > Advanced Encryption. When disabled, Pharos Cloud’s standard encryption remains in effect.

For more details, see Configuring Enterprise Key Management

New System User Password Expiration Options

Administrators can now enforce password expiration policies for internal (system) users. This allows tighter control over how often passwords must be changed and helps organizations meet internal security requirements.

. With this update, administrators can

  • Enable or disable password expiration for internal users.

  • Configure how often passwords must be changed (between 1 and 365 days).

  • Immediately expire all internal user passwords, forcing a change on next login.

Administrators can manage password policy in the Password Expiration section under Account Settings > Settings tab in the web console.

For more details, see Password Expiration

Masked Private Data Fields in the Web Console

Pharos Cloud 4.5 improves how sensitive configuration values are handled in the web console reducing the risk of exposure in shared, open, or screen‑shared environments.

The following sensitive configuration fields are now masked by default and displayed as hidden characters instead of showing the full value.

  • Site Encryption Key

  • API Authorization Key

  • OAuth API Client Secret

Claim Mapping for SSO (Preview)

Claim mapping is now available (Preview) for OpenID Connect and SAML authentication. It lets administrators define how identity provider claims map to user identity fields such as email address, username, or UPN directly from the web console, helping resolve common identity mismatches without requiring changes at the identity provider level.

A new Advanced option has been added to the Authentication Provider configuration page
(Account Settings > Settings > Authentication Providers). This option provides access to the Claim Mapping interface where administrators can control which incoming identity provider (IdP) claims are mapped to key Pharos Cloud user identity fields.

Platform Updates

Centralized Mobile App Access Controls

Centralized controls are now available for managing end-user access to the Secure Release mobile app. A new Mobile section under Secure Settings gives administrators a single location to enable or disable mobile app access across their tenant.

The Enable Mobile Access toggle controls whether users can register and use the mobile app. The section also includes a read-only Mobile Features list showing which capabilities are currently active based on your configuration and licensing giving administrators a clear view of what end users can access without navigating multiple settings areas.

Note: This feature requires the latest version of Print Scout (v8.3.10 for Windows) and (2.31 for macOS).

For more information, refer to Mobile App Access Control

Email Notification Management

A new Email Notification section under Account Settings gives administrators a single place to control which system-generated emails are sent and to whom.

Notifications are organized by audience Print Users and Administrators covering passcode emails, registration notices, admin logs, and login-related messages. Each category can be enabled or disabled individually.

Notifications required for core functionality, such as Secure Release, Guest Print, External Proximity Card, and Scan to Office 365, are marked as Always On and cannot be disabled.

For more details, see Email Notification

Enhanced Print Scout Management in the Web Console

The Pharos Cloud web console has been updated with new capabilities that make it easier for administrators to centrally manage Print Scouts, review status and diagnostics, and adjust configuration settings at scale.

Archive Print Scouts

Archive and Archived Print Scouts actions are now available on the Discover > Print Scout page, allowing administrators to archive Print Scouts to maintain a cleaner, more manageable view of the Print Scout screen.  Administrators can also export filtered data to help identify outdated Print Scouts.

For more details, see Archive Print Scouts

New Columns in the Print Scout tab

Pharos Cloud 4.5 adds new and updated columns to the Discover > Print Scout tab to improve visibility into Print Scout status, health, and activity.

  • Scout Health (renamed)

  • Active in Last 30 Days (new)

  • Support Level (new)

For detailed information, see Print Scout Columns

New CSV Export

A new CSV Export button has been added to the Discover > Print Scout tab, allowing administrators to export Print Scout data to a CSV file for external analysis, reporting, or sharing with other teams.

Discover On-Demand for Device Scout

Administrators can now initiate a Device Scout discovery scan on demand directly from the web console, without waiting for the next scheduled scan or accessing the Device Scout host.

A new Discover On Demand action is available under Discover > Device Scout. When triggered, Pharos Cloud sends an on‑demand scan request to a selected, installed Device Scout. The Device Scout scans the specified network addresses and reports discovery progress and results back to the cloud in real time.

Note: This feature requires Device Scout version 1.25.4.100 or later.

For more details, see Discover Devices on Demand

Direct Print Enhancements

Pharos Cloud 4.5 introduces significant enhancements to Direct Print, simplifying administrator management and streamlining initial setup through bulk import of queues and locations.

Bulk Location Import via CSV

The new Location Import feature allows administrators to import locations and location mappings into HP Insights using a CSV file, instead of manually creating and editing locations in the web console. This is particularly useful for large or complex environments, where managing locations individually can be time consuming and error prone.

A new CSV Location Import button is available under Direct > Direct Printers > Locations. Selecting this option opens the Location and Configuration Import dialog, where administrators can upload a CSV file to import location data in bulk.

Pharos Cloud automatically processes the file and creates the locations in the Locations tree.

For details, see Bulk Location Import via CSV

Enhanced Devices Import

The existing Devices Import in the Direct > Direct Printers has been updated to support two additional properties:

  • Queue Name (formerly Printer Label)

  • Profile Override

New “Queue Profiles” for Direct Print

This release introduces Queue Profiles, a new rule‑based approach to creating and managing print queues for Direct Print.

Queue Profiles allow administrators to define matching rules (such as printer make/model, IP range, or location) and queue templates that determine what type of queues are created for matching devices. When applied, queues are created automatically based on these profiles, reducing the need for manual queue configuration.

Pharos Cloud includes built‑in Queue Profiles that provide a default Direct Print configuration out of the box. Queue Profiles also integrate with Devices Import, where administrators can optionally specify a Queue Name or apply a Profile Override to force a specific profile for individual devices.

New “Create Queues from Profile”

A new Create Queues from Profile action (in the Direct > Direct Printers tab) lets administrators automatically generate print queues based on defined Queue Profiles.

When this action is run, Pharos Cloud evaluates selected devices against enabled Queue Profiles and creates queues using the profile’s matching rules and queue templates. Profile priority determines which configuration is applied, with the first matching profile used for each device.

This feature reduces the need for manual queue creation and enables consistent, scalable queue deployment across large printer environments.

For details, see Queue Profiles for Direct Print

Merge Print Analytics data with Job Accounting (Education Edition)

Pharos Cloud 4.5 links Print Analytics and Billing Account data at the individual job level using a shared ActivityCorrelationID. This allows administrators to accurately match print jobs with billing records for improved reporting and cost visibility. For customers with an Accounts license, the CorrelationId is also visible in the Print Analytics Documents view.

Limitations:

  • Requires the latest Print Scout version

  • Jobs released via older scouts or outside Billing Accounts workflows will not have a correlation ID.

Jobs and Accounts data correlation support (Education Edition)

Print Scout now reports a shared ActivityCorrelationID during print job submission and release. This identifier is included in both Print Analytics job records and Billing Accounts activity records, allowing the same print job to be consistently identified across both systems.

By reporting this shared identifier, Print Scout enables job‑level correlation between usage data and accounting records when the Analytics data merge feature is in use. This ensures administrators can accurately associate individual print jobs with their related billing activities, improving traceability and supporting more reliable reporting and cost analysis.

Note: This feature requires Print Scout Windows 8.3.10 or Mac Scout 2.31.

Naming and Icon Standardization

The Pharos Print application name, publisher details, and icons have been standardized across Windows for a more consistent experience.

  • Print Scout renamed to Pharos Print in Windows system listings

  • The publisher name updated to Pharos Systems International

  • The yellow torch icon is now shown for the Pharos Print app. It appears in Control Panel and Settings > Apps > Installed Apps.

  • The Pharos Print app now shows the purple Pharos icon, which appears in the Start menu, system tray, About dialog, and the taskbar when the app is open.

Mobile Registration follows new Mobile Access setting

Print Scout updates the “Register a Mobile Device” option in the Pharos Print app to respect the new Mobile Access setting configured in the Pharos Cloud web console. The Register a Mobile Device context menu entry is visible and functional when Mobile Access is enabled. The option is hidden when Mobile Access is disabled.

Note: This feature requires Print Scout Windows 8.3 or Mac Scout 2.31.

Enhanced Print Scout and Device Scout Logs

Email notifications for Print Scout and Device Scout log requests have been improved to provide clearer, more actionable failure messages. Emails now clearly indicate when log retrieval fails and outline the next practical steps, such as confirming that the Scout is online and retrying the request.

New “About” option in the Pharos Print desktop app

A new About option has been added to the Pharos Print desktop app, allowing users to view the installed Print Scout version and registration details directly from the app’s main menu, without access to the Configuration app.

  • Print Scout offline after Wi-Fi restart or reconnection.

    Fixed an issue where Print Scout could remain offline for several minutes after a restart or Wi‑Fi reconnection when the computer was using Wi‑Fi only with Pharos Cloud. Print Scout now comes online much faster after network changes

  • Microsoft Universal Print – Windows 11 24H2 compatibility issues
    Resolved a printing error seen when users on Windows 11 24H2/25H2 sent jobs to Microsoft Universal Print queues integrated with Secure Release, caused by stricter Mopria capability validation.

  • Data Privacy Region (DPR) cannot be reverted to default - After changing a user's Data Privacy Region to a specific region in the Print Scout Configuration UI, it is not possible to switch it back to the customer default. The save operation fails when attempting to reselect the default option.

  • Deleted printers remain available for printing - Deleting a printer from the Device Inventory tab in the web console does not fully remove the printer record. The printer still exists in the Document Management Service and can still receive and release print jobs.

  • Direct Print default printer selection does not work correctly with duplicate queue names - When multiple Direct Print queues share the same name but have different IP addresses, setting one as the default printer incorrectly marks all matching queues as default. Once this occurs, the default selection cannot be changed. Printing is not affected, Users can still print to either queue by manually selecting it, but the default printer shortcut will not work as expected.

Sentry Print Service Updates

New QR Sign In (HP Devices Only)

QR Sign‑In provides a passwordless way for users to sign in at a secure printer. Instead of entering credentials on the printer panel, users authenticate by scanning a QR code with the Pharos Secure Release mobile app, which securely signs them in and gives access to their print jobs.

QR SignIn works alongside existing signin methods, such as keyboard signin, card readers, etc.

Notes:

  • Supported with Pharos Sentry Site Service 2604.1607.829 and DDU version 2.2.1.

  • QR Sign In is supported only on HP devices.

QR Sign In is disabled by default. It can be enabled in Secure > Settings > Secure Release Settings under “Printer Sign In Options.”

When securing a printer, QR Sign In is available as an additional printer sign in option, allowing users to authenticate by scanning a QR code with the Secure Release mobile app.

For more details, see Configuring QR Sign In

Admin-Managed Certificates for Sentry Print Service (On-Prem Only)

Administrators of on-premises Pharos Sentry Print Service now have the option to use custom TLS/SSL certificates and server aliases, replacing the default Pharos certificate and hostname.

A new Certificate Manager app is now included with Sentry Print Service. This application guides administrators through selecting and applying a certificate to the Sentry Print Service, as well as configuring the server name used by clients and printers.

Following the installation or upgrade of Sentry Print Service, administrators should access the Certificate Manager application on the Sentry Print Service host. The application can be found at C:\Program Files (x86)\PharosSystems\Sentry Print Service\Configurator.

The Certificate Manager app allows administrators to:

  • Select a personal certificate from the local system certificate store for use by all Sentry Print Service listeners.

  • Automatically bind the selected certificate to port 4321.

  • Export the selected certificate for distribution to clients and printers.

Note: Existing environments can continue using the default certificate if desired; adopting admin-managed certificates is optional but recommended for customers with stricter PKI and aliasing requirements.

For more details, see Certificate Manager

Sentry Print Service Bugfixes

  • Copy and Scan unlock behavior corrected – Copy and Scan are now automatically unlocked when the Lock Device setting is turned off, resolving an issue where they remained locked after the setting was disabled.

  • Enhanced card reader authentication – Resolved issues that caused authentication failures when multiple card types were configured. Card readers now work reliably with up to three configured card types, and card swipe authentication now behaves consistently.

  • Secure Scan username handling fixed – Secure Scan now correctly supports usernames containing apostrophes, resolving failures caused by special characters.

  • Device inactivity logout fixed – The device inactivity auto‑logout timer now functions correctly, automatically logging users out after the configured period of inactivity.

  • Improved reliability for Scan to Microsoft 365 – Resolved an issue that could cause Scan to Office 365 jobs to fail. Scan to OneDrive jobs, including large multi-page documents, now complete successfully without interruption, ensuring users can send documents reliably without errors.

Known Limitation – Scan to Email (Office 365)

When using Scan to Email via Office 365, the Max File Size setting configured in Device Profiles is not currently enforced. Instead, the maximum attachment size is determined by the limit configured in the customer’s Office 365 environment.

Component Release Versions

This release includes the following software components and release versions.

Software Component

Release Version

Build Date

Device Scout

1.25.4.100

May 2026

Print Scout (Windows)

8.3.10.100

May 2026

Print Scout (Mac)

2.31.3.100

May 2026

Print Scout (Linux)

2.2.0 (Not Updated)

May 2025

Secure Print Site Service – Local Connector

2604.1607.829 (tagged version)

26.4.23468.0 (MSI version)

May 2026

Secure Print Site Service – Cloud Connector

2604.1607.829

May 2026

Device Discovery and Deployment Utility (DDU)

2.2.1

May 2026

Chrome extension

4.8.0

November 2024

Secure Release mobile app (Android)*

3.0.0

March 2026

Secure Release mobile app (iOS)*

3.0.0

March 2026

*Note: Secure Release mobile apps and the Chrome extension are published after the Cloud Services are updated.