Two-Factor Authentication (2FA) combines two independent credentials – something the user has and something they know, or something they are – to verify identity before granting access. For print environments handling sensitive documents, 2FA at embedded terminals provides an important security control.
MyQ supports several stronger authentication patterns. At embedded terminals, users can authenticate with card-based 2FA methods or QR code login through the Mobile Client. For Desktop Client and Mobile Client sign-in, MFA can also be enforced by the external identity provider, such as Entra ID, when Microsoft sign-in is used.
Authentication at Embedded Terminals
Users can authenticate with 2FA at embedded terminals using one of two card-based methods, or by scanning a QR Code with the Mobile Client.
Configure embedded terminal login methods per terminal configuration profile in Settings > Printers & Terminals.
ID Card + PIN
The user presents their ID card to the reader, then enters their PIN to confirm. This is a common implementation. PIN codes can also be issued as temporary, which can reduce the risk of long-lived PIN misuse.
ID Card + Password
The user presents their ID card to the reader, then enters their password to confirm. This method is appropriate where your password policy already meets your security requirements and you prefer not to manage a separate PIN population.
QR Code Authentication with Mobile Client
The MyQ X Mobile Client can provide a stronger terminal-authentication option where users already have managed mobile devices and app access. Users sign in to the mobile app with their MyQ credentials – or via an authentication server such as Entra ID or Active Directory – and authenticate at the terminal by scanning a QR code displayed on the device screen.
Where biometric lock is enabled, the user must unlock the Mobile Client with Face ID or fingerprint recognition before using the app. This combines the enrolled mobile device, biometric app unlock, and the terminal QR code, while avoiding the need to issue cards or PINs for that terminal-login workflow.
This model can fit Entra ID environments where users sign in to the Mobile Client with Microsoft accounts. If Entra ID MFA is enforced, users complete that MFA step during Microsoft sign-in. After that, the Mobile Client can act as the terminal login method, so users do not enter a MyQ-specific credential at the device for this workflow.
Where users authenticate to the Mobile Client against an LDAP authentication server, such as Active Directory or OpenLDAP, those credentials are validated against the remote identity provider and are not stored in MyQ. Document this behavior where credential-storage requirements are part of the deployment review.
Two-Factor Authentication in Desktop Client
Organizations using Microsoft 365 can enable Sign in with Microsoft in the Desktop Client configuration profile. When users authenticate through Microsoft sign-in, any MFA required by Entra ID is handled by Entra ID during the sign-in flow. No separate MyQ 2FA setting is required for that Microsoft sign-in step.
Configure Desktop Client login methods in Settings > MyQ Desktop Client, in the relevant configuration profile.
Planning Considerations
Stronger authentication can add steps to terminal use, such as a card tap, PIN entry, or phone unlock. For most users in most environments this is acceptable, but it is worth considering:
-
In high-volume environments, card-only authentication with a longer session timeout may reduce friction, but it should be treated as a security/usability trade-off.
-
The Mobile Client QR code model requires all users to have a compatible smartphone and the app installed. Plan the rollout and user communication accordingly.
-
ID cards need to be issued, registered, and managed. Factor card provisioning into your deployment timeline, particularly in larger environments or those with high staff turnover.
-
If cards are lost, define a fallback authentication method. Otherwise, users who rely only on card authentication may be unable to use devices until a replacement card is issued.