Note
Access to this page requires authorization. You can try signing in or changing directories.
Access to this page requires authorization. You can try changing directories.
This article is for printer administrators who want to enable the Universal Print portal for secure release with QR code.
The Universal Print portal is a multi-tenant, first-party Microsoft app. It's already registered and available in your Microsoft Entra ID, so no deployment steps are required.
Verify your printers are registered in Universal Print
The portal works with printers that are already registered in the Universal Print admin portal. No changes to printers or QR codes are needed.
Ensure users can reach the portal
Before rollout, verify that managed devices in your tenant can open the Universal Print portal. It's served from Microsoft's consolidated cloud.microsoft domain, so any network filtering, proxy, or allowlist rules should permit cloud.microsoft and its subdomains (*.cloud.microsoft).
Users sign in with Microsoft Entra ID, so check that your Conditional Access policies don't unintentionally block the portal — particularly controls that require a compliant or managed device, because secure release is often done from a personal phone at the printer.
Government cloud environments
Universal Print is available in the US Government clouds (GCC, GCC High, and DoD). GCC uses the same portal domain as the worldwide commercial environment, while GCC High and DoD use government-specific portal domains. Allowlist the portal URL and domains for your cloud:
| Cloud | Portal URL | Domains to allow |
|---|---|---|
| GCC | https://print.cloud.microsoft |
cloud.microsoft, *.cloud.microsoft |
| GCC High | https://print.usgovcloud.microsoft |
usgovcloud.microsoft, *.usgovcloud.microsoft |
| DoD | https://dod.print.usgovcloud.microsoft |
usgovcloud.microsoft, *.usgovcloud.microsoft |
GCC High and DoD are served from Azure Government (usgovcloud.microsoft). For more about Universal Print in these clouds, see Universal Print in Government.
Set Conditional Access policies
If you have Conditional Access enabled for your tenant, create a Conditional Access policy to allow use of the Universal Print portal:
- Go to Microsoft Entra ID > Security > Conditional Access.
- Create a policy that targets the Universal Print User Portal application.
- App (client) ID:
59984c1b-c1d9-4c63-a6d5-5084caebcaf2
- App (client) ID:
- Apply your desired authentication requirements.
- Save the new Conditional Access policy.
The portal has its own dedicated app ID, separate from Microsoft 365 apps. This means you can apply specific authentication policies — for example, allowing passwordless phone sign-in for print job release while enforcing phishing-resistant multifactor authentication for other apps.
Communicate the change to your users
Starting August 18, 2026, the QR code-based secure release experience in the Microsoft 365 Copilot app is retired and replaced by the new Universal Print portal experience. Let your users know that scanning the printer's Universal Print QR code now opens a browser-based portal instead of the Microsoft 365 Copilot app.
For an end-user walkthrough you can share, see Release a print job using the Universal Print portal.