Print Server Migration to Universal Print
IT Partner retires your on-premises print servers by moving every printer to Microsoft Universal Print, the cloud print service already included in Microsoft 365 E3, E5, F3 and Business Premium and in Windows Enterprise E3 and E5. Over about 2 weeks we inventory the printers, queues and drivers on the print servers you want gone, confirm every user holds a Universal Print-eligible license and size the tenant's monthly print-job pool on measured volume, register Universal Print-ready printers directly with the service, deploy Universal Print connectors on supported Windows Server hosts — never on the Windows Server 2016 box being retired — for the printers that are not, share each printer to Microsoft Entra security groups, deploy the printers to Windows devices through Microsoft Intune, pilot with real users at every site, cut over in waves, and decommission the print role. $45 per printer plus a $1,450 tenant fee, fixed and quoted in writing, for estates of up to 299 printers whose connectors, if any are needed, sit at one site; 300 or more printers, or a connector design spanning several sites, is quoted per estate. Two boundaries up front: printer hardware, firmware and the Universal Print licenses themselves are yours, and third-party print-management platforms are confirmed compatible, not replaced or implemented.
What this engagement is
The print server is usually the last Windows Server 2016 role standing. Domain controllers get upgraded because everyone understands what they do; file shares get moved because the data is visible; the print server keeps running because printing "just works" — until a driver update takes the spooler down at eight in the morning, or until 12 January 2027, when Windows Server 2016 leaves extended support per Microsoft's product lifecycle and stops receiving security updates. The print spooler has also been one of the most-exploited Windows components of recent years, which is a poor property for a server you are about to stop patching. This service removes the server rather than upgrading it: the printers move to Microsoft Universal Print, the cloud print service that ships with the Microsoft 365 licenses most organizations already pay for, and the driver-management, Group Policy-mapped-printer, spooler-on-a-box model goes with it. Universal Print works in two ways, and the inventory decides which applies to each printer. Printers that are Universal Print-ready — recent models from Brother, Canon, Epson, HP, Konica Minolta, Kyocera, Lexmark, Ricoh, Sharp, Toshiba Tec and Xerox, among the manufacturers on Microsoft's published list — register directly with the service from their own firmware and need no on-premises server at all. Everything else — older network printers, label and receipt printers, plotters, anything without a Universal Print firmware option — is registered through the Universal Print connector, a Microsoft service that runs on a Windows Server or Windows 11 host on the same network as the printers, holds the printer installations with Microsoft's IPP class driver or the manufacturer's V4 driver, and relays jobs from the cloud to the printer. Users need a Universal Print-eligible license: Microsoft includes it in Microsoft 365 E3, E5, F3 and Business Premium, in the education A3 and A5 plans and in Windows Enterprise E3 and E5, and sells it standalone for everyone else. Each license also contributes print jobs to a tenant-wide monthly pool — 100 jobs per month per Microsoft 365 E3, E5 or Business Premium license at the time of writing, a smaller allotment for F3, Windows Enterprise and standalone licenses — and Microsoft sells volume add-on packs when the pool is too small. We count your actual monthly print volume from the print server logs before cutover, because a pool sized on headcount alone is the most common way this migration goes wrong three weeks after it ends. The engineering is in the connector design and the deployment, not in clicking Register. Each connector host must run 24x7 with sleep disabled, reach Microsoft's Universal Print endpoints outbound over HTTPS, carry .NET Framework 4.8, and be sized for the printers and volume it holds — Microsoft sets no fixed printer-per-connector limit, but the service's memory use at startup does, and a connector that runs out of memory stops printing reliably. Microsoft does not yet support the same printer behind two connectors, so we spread printers across connectors per site so that one host's outage never takes a whole floor offline, and we place connectors on Windows Server 2025 (or 2022 where that is your standard), never on the Windows Server 2016 host you are retiring. Every printer is then shared once, under a share name people will recognize, to a Microsoft Entra security group rather than to individual users — direct assignment creates a hidden group per share that surprises SharePoint administrators later — and deployed to Windows devices through Intune's Printer Provisioning settings, so a printer follows the group rather than the login script, and the Group Policy preferences and scripts that pointed at the old server are retired in the same change. Where you want it, Universal Print anywhere (Microsoft's pull-print queue) and secure release with a QR code are enabled on the printer shares in scope; both are settings of the service, not products. Who this is for: mid-size and enterprise organizations with 20 to 500 or more printers across one or many sites, Windows devices joined or hybrid-joined to Microsoft Entra ID and managed — or about to be managed — in Intune, and a print server on a Windows Server version that is leaving support. Who it is not for: a ten-person office with two printers, which needs an afternoon rather than a project; an estate whose print workflow depends on a third-party print-management platform for accounting, quotas or badge release — we confirm the platform's Universal Print integration exists and let its vendor deploy it; and workloads that print from servers rather than people, such as ERP batch jobs or label streams from a warehouse system, which are tested in discovery and given a documented path rather than a promise. If Intune is not in place yet, Microsoft Intune Initial Setup for Windows Device Management runs first; if devices still sign in only to on-premises Active Directory, the On-premises Active Directory to Microsoft Entra ID Transition is the prerequisite; if the same server also holds file shares, the file-side move is its own engagement (the personal-folder path is OneDrive for Business — Personal Document Migration from File Server); and the Windows Server 2016 End of Support Assessment and Roadmap is where an estate with several roles per host should start.
Which one applies to you
Every printer on the inventory gets one of three dispositions before anything is registered. This service delivers the first two end to end and documents the third honestly.
| Universal Print-ready (registered directly) | Connector-attached (registered through a connector) | Stays on a non-Universal Print path | |
|---|---|---|---|
| What it covers | Printers whose firmware supports Universal Print natively — current models from the manufacturers on Microsoft's Universal Print-ready list — registered from the device's own admin panel. | Everything else with a Windows print driver: older network printers, label and receipt printers, plotters and multifunction devices without a Universal Print firmware option. | Printers Universal Print cannot serve in your estate: server-side or raw-stream printing an application depends on, a print-management platform without Universal Print integration, or a device with no usable IPP or V4 driver. |
| Infrastructure | None on premises. The printer talks to the service directly — no server, no connector. | One or more Universal Print connectors per site on Windows Server 2025 or 2022 (or Windows 11) hosts running 24x7, sized on printer count and volume, with printers spread across connectors for resilience. | Whatever it runs on today, documented — including the case for a small, patched Windows Server 2025 print host if one is genuinely needed. |
| Drivers | None on clients or servers — Universal Print supplies the print experience. | Microsoft's IPP class driver or the manufacturer's V4 driver on the connector host only; nothing on clients. | Manufacturer drivers as today, listed in the closeout as a maintained exception with an owner. |
| Our role | We register, share, set defaults and deploy through Intune — this page. | We design, deploy and size the connectors, register the printers, share, set defaults and deploy through Intune — this page. | We name the printer and the reason, propose the path, and scope any work on it separately. |
The disposition comes from the inventory and a test print, not from a preference — a printer that prints correctly through the connector in the pilot is a connector printer, whatever the datasheet says.
Success criteria
What you receive
How the work unfolds
Confirm scope, sites, the print servers in play and the date driving the move. Export printers, drivers, ports, shares and job counts from every in-scope server with PowerShell, check each printer model against Microsoft's Universal Print-ready list, and collect the licensing and Intune facts we need.
Assign every printer a disposition, size the monthly job pool against measured volume and name the add-on packs if any, design the connectors per site, and hand your firewall and server teams the host specifications and outbound endpoints. You approve the design before anything is registered.
Assign print roles and licenses, register Universal Print-ready printers directly, build the connector hosts, install printers on them with IPP class or V4 drivers, register them, and test-print every printer.
Create the printer shares against Microsoft Entra groups, set printer defaults, enable Universal Print anywhere and secure release where chosen, and build and assign the Intune Printer Provisioning policies to the pilot groups.
Pilot users at each site print from Windows and, where in scope, macOS to both kinds of printer; we fix what the pilot finds, confirm the old queues are gone from pilot devices, and adjust the wave plan.
Cut sites over in the agreed windows — shares opened to production groups, Intune policies assigned, old queues unshared, Group Policy and script mappings removed — validate each wave, decommission the print role after the soak period, and close with the report and the decommission checklist. Estates of several hundred printers extend this stage; the wave plan states the real dates.
Prerequisites
Who does what
IT Partner
- Export and reconcile the inventory, produce the disposition map, the licensing and pool check and the connector design, and keep them current as decisions are made.
- Assign print roles, register printers directly and through connectors, build and configure the connector hosts, and test-print every printer.
- Create the shares, group access, printer defaults, job-release settings and the Intune Printer Provisioning policies, and verify them on test devices.
- Run the pilot, fix registration, driver, share and policy issues within scope, and execute the wave cutovers including removal of the old mappings.
- Decommission the print role after the soak period and deliver the closeout report, as-built documentation, usage reporting for your admins and the decommission checklist.
- Say plainly when a printer or workflow should not move to Universal Print, and what should happen to it instead.
Your team
- Provide administrative access, connector host capacity, firewall changes and printer admin credentials, and apply or approve printer firmware updates.
- Own the licenses: assign or buy Universal Print-eligible plans, standalone seats and any volume add-on packs the pool sizing requires — Microsoft's subscriptions, billed by Microsoft or through your CSP, never through our fee.
- Decide the share naming standard, the group model, printer defaults, and which printers get pull-print or secure release.
- Nominate pilot users and site contacts and make them available; communicate the change to staff with the wording we provide.
- Own the print-management platform relationship where one exists, and any application-side change for server-driven printing.
- Approve the soak period and the shutdown of servers that host nothing else; servers carrying other roles keep running with the print role removed and are retired through their own engagements.
What's not included
Limitations & technical notes
Frequently asked questions
Why replace the print server instead of upgrading it to Windows Server 2025?
Because most of what the print server did is now a service you already pay for. A print server exists to hold drivers, queue jobs and map printers to users; Universal Print holds the printers in your Microsoft 365 tenant, Intune maps them by group, and clients need no drivers at all. What you lose is a single point of failure, a spooler that has been a favourite target for attackers, a login script that breaks when the server name changes, and one more box to patch — and remote users print to the office without a VPN. Upgrading is still the right answer for a handful of cases: applications that print from the server, a print-management platform without Universal Print integration, or devices with no usable IPP or V4 driver. The disposition names those, and where a small print host is genuinely needed the Windows Server 2016 to 2025 Upgrade Service builds it properly instead of keeping the old one alive.
Which Microsoft 365 licenses include Universal Print?
At the time of writing Microsoft includes Universal Print in Microsoft 365 E3, E5, F3 and Business Premium, in the education A3 and A5 plans, and in Windows Enterprise E3 and E5; anyone else needs the standalone Universal Print subscription. Each license also adds print jobs to a tenant-wide monthly pool — 100 per E3, E5 or Business Premium license, five per F3, Windows Enterprise or standalone license — and Microsoft sells volume add-on packs of 500 and 10,000 jobs when the pool is short. We check every printing user's assignment during the licensing check; the licenses are Microsoft's subscriptions at Microsoft's price and are not part of our fee.
What is a Universal Print connector, and do we still need a server?
Only if you have printers that are not Universal Print-ready. The connector is a Microsoft service you install on a Windows Server or Windows 11 machine on the same network as those printers; the printers are installed on that host with Microsoft's IPP class driver or the manufacturer's V4 driver, the connector registers them with Universal Print, and jobs flow from the cloud through the connector to the printer. If every printer in the estate registers directly from its own firmware, there is no on-premises print infrastructure left at all. If some do not, the connector host is a small, ordinary server — we put it on Windows Server 2025 or 2022, never on the 2016 machine you are retiring — that must run 24x7 with sleep disabled and reach Microsoft's endpoints outbound over HTTPS.
How do you make the connectors resilient?
By design, because the product does not do it for you yet. Microsoft supports one connector per printer — the same printer cannot sit behind two — and has said redundancy is planned. So we spread the printers at each site across two or more connectors, sized on Microsoft's guidance about memory use at startup, so that one host failing takes out some printers rather than the whole floor; we never clone a connector host, which Microsoft warns will interfere with the original; and we hand your team the as-built list of which printer sits behind which connector so a failure is a ten-minute re-registration, not an investigation.
How do printers get onto users' computers?
Through Intune. Each printer share has a cloud device ID, a shared ID and a share name; an Intune settings-catalog policy under Printer Provisioning carries those values with the action Install, and every device in the assigned group installs the printer without the user doing anything — with a default printer where you want one. Users can also add any printer shared to them from Settings, and Universal Print anywhere gives a single pull-print queue for people who move between sites. The Group Policy preferences and login scripts that mapped the old server's queues are removed in the same wave, which is what makes the old server safe to switch off.
Can people print from home, from a Mac, or from Azure Virtual Desktop?
From home, yes — the device talks to Universal Print over the internet and the connector or the printer pulls the job from the cloud, so no VPN is involved; a job sent from a kitchen table prints at the office when the printer is reachable. macOS is supported through Microsoft's Universal Print app from the Mac App Store, generally available for commercial tenants at the time of writing, and we include Mac users in the pilot where they are in scope. Azure Virtual Desktop and Windows 365 session hosts on Windows 11 multi-session are supported clients — printing from a cloud desktop is one of the cases Universal Print handles better than a print server ever did. Mobile and Linux printing are scoped only where Microsoft documents a supported path.
What about label printers, plotters and our ERP's batch printing?
They are the exceptions we look for first. Label and receipt printers driven by raw streams, wide-format devices, and applications that print from a Windows Server without a person at a keyboard — ERP, warehouse, pharmacy, badge systems — may not have an IPP or V4 driver and may not be served by a Windows client print path at all. We inventory them, test them through a connector in the pilot, and give each a written disposition: connector-attached where it prints correctly, or a documented non-Universal Print path where it does not — which sometimes means a small, patched Windows Server 2025 print host for a handful of devices. What we will not do is declare the migration complete while a warehouse quietly keeps printing to a server that is supposed to be gone.
We use PaperCut (or Pharos, YSoft, Dispatcher Paragon). Does this still work?
Usually, but through the vendor. Several print-management platforms publish Universal Print integrations for secure release, accounting and quotas; we confirm one exists for your product and version, design the shares and groups so the platform can sit in front of the printers, and coordinate the cutover with it. Deploying or reconfiguring the platform itself is the vendor's work or a separate engagement, and if there is no integration for your version we say so at disposition time rather than after cutover. If badge release is all you need, Universal Print's own secure release with a QR code may replace the platform — a decision we lay out with the trade-offs, not one we make for you.
How is the monthly print-job pool sized, and what if we run out?
On measured volume, not headcount. We read a representative month of job counts from the print servers' logs, compare it with the pool your licenses create — 100 jobs per E3, E5 or Business Premium license per month at the time of writing, five per F3, Windows Enterprise or standalone license — and state before cutover whether the pool covers it with headroom or which volume add-on packs (500 or 10,000 jobs) to buy. The pool resets monthly. Microsoft's own description of what happens when it is exhausted has changed between versions of its documentation, so we check the current behaviour during design rather than repeat either version here, and we size the pool so you never test it.
Is it secure to send print jobs through the cloud?
Per Microsoft's data-handling documentation, job data is encrypted in transit and at rest, stored in the geography your tenant was created in, and held only until it prints or expires — unclaimed jobs are aborted after three days and cleared within ten. Access is by Microsoft Entra identity and group, the same model as your files and mail, which is stronger than a print server's share permissions and a lot stronger than an open IPP port. Secure release adds the physical step: a job prints only when the person scans the printer's QR code. And you remove a spooler service from a server that has been a recurring target for attackers. Where a regulator or a contract forbids documents leaving the site even encrypted, we keep that printer on a local path and record why.
How much does it cost?
$45 per printer plus a $1,450 tenant fee, fixed, quoted in writing before work begins; you pay after you approve delivery. Fifty printers come to $3,700, one hundred and twenty to $6,850. The fixed price covers up to 299 printers with a connector design at one site; 300 or more printers, or connectors at several sites, are quoted per estate because connector count and site paths drive the work more than printer count does. Universal Print licenses, add-on packs, connector hosts and printer hardware are yours and are not in the fee.
How long does it take, and what will users notice?
About 2 weeks for a typical estate: inventory and design in the first four days, registration and sharing by day 8, pilot by day 10, wave cutovers and decommission by day 14; several hundred printers or many sites extend the last stage and the wave plan states the real dates. Users notice new printer names appearing on their computers without a visit from IT, the old ones disappearing, and — where you enabled it — a QR code to scan before a confidential job prints. We give you the announcement wording so nobody learns about it from a missing printer.
What happens to the old print server?
After each wave we leave the old queues in place but unshared for an agreed soak period, so anything we missed shows up as a call rather than a loss. Then the queues are removed, the spooler service is disabled and the Print and Document Services role is uninstalled. If the server hosted nothing else it is shut down and its DNS and Active Directory objects cleaned up per the checklist; if it also carries file shares, DHCP, certificate services or an application, the print role is gone but the server stays until those roles move through their own engagements — the Windows Server 2016 End of Support Assessment and Roadmap sequences them, and for the interim Windows Server ESU Enrollment through Azure Arc keeps it patched past January 2027.
Who owns this service at IT Partner?
Roman Sotnik is the service owner. IT Partner has been a Microsoft partner since 2006, holds the Solutions Partner designation for Modern Work, and delivers this alongside its Intune setup and managed Intune practice — so the people who deploy your printers are the people who already manage the devices they land on.