Deployment

Multi-domain and Multi-tenant Environments

A single MyQ X installation can manage users from multiple Active Directory domains, multiple Microsoft Entra ID tenants, or a combination of identity sources.

These environments are common in mergers, shared-service deployments, staged migrations, and organizations where separate identity systems share the same MyQ infrastructure.

The main deployment challenge is making sure that users remain uniquely identifiable across all sources, both when they are synchronized into MyQ and when MyQ identifies them from print jobs or authentication requests.

Choose Your Environment

Environment

Main consideration

Multiple Active Directory domains

The same sAMAccountName can exist in different domains. MyQ must preserve the domain when synchronizing users and identifying jobs.

Multiple Microsoft Entra ID tenants

Each tenant requires its own Entra connection and, where required, its own synchronization source and authentication server.

Active Directory and Entra ID together

Plan how usernames and aliases from the different sources map to MyQ users and to identities detected in print jobs.

Plan Unique User Identities

Before synchronizing users from multiple identity sources, determine which value MyQ will use as the username and which alternative identities should be stored as aliases.

Do not assume that usernames are unique across domains or tenants. A username that is unique within one source can conflict with a user imported from another source.

Plan Job Identification

Users must also be identifiable from incoming print jobs.

The identity included with a job can vary depending on the client environment, print driver, and authentication method. Before rollout, test representative jobs from each domain, tenant, and client type and confirm that the detected identity matches the corresponding MyQ username or alias.

See also Understanding Job Detection.

Plan Authentication

If users from multiple domains or tenants authenticate against their source identity system, configure the corresponding authentication servers and make sure each MyQ user is assigned to the correct one.

In Microsoft Entra multi-tenant environments, users can be presented with multiple Microsoft sign-in options. In Active Directory multi-domain environments, authentication must resolve the user against the correct domain.