Request to add Papercut Hive to Software inventory

Hi Team I’d love if papercut hive was in the software inventory.
It contains two parts
The edge node and the print client

PaperCut Hive Deployment via ImmyBot (edge node + per-user tray client)

Overview

One ImmyBot software and one deployment install both parts of PaperCut Hive: the edge node machine-wide, and the tray client for every user at their next sign-in. No user needs to be logged on when ImmyBot runs.
Component
Installs as
Location
Purpose
Edge node
SYSTEM (ImmyBot install script)
C:Program FilesPaperCut Hive
Registers the device in the Hive admin console, hosts the PaperCut Printer queue
Print client (tray app)
Each user, at sign-in (Active Setup)
%LOCALAPPDATA%ProgramsPaperCut Hive
Tray icon; captures jobs and links the device to the user

Applies to: Windows 10/11 workstations managed by ImmyBot. Tested on Windows 11.

Prerequisites

  • PaperCut Hive admin console access for the client org.

  • The generic installer from Edge Mesh > Add edge nodes > Manually deploy edge nodes > Download for Windows (papercut-hive.exe).

  • The systemKey (same page, command line string).

  • The userkey and orgId from Add-ons > Desktop App deployment with Microsoft Intune > View setup process > Install user component. Adding the add-on does not connect Intune.

How it works

When run by hand, the installer does both parts because it runs as a real logged-in user. Under ImmyBot it runs as SYSTEM, so the tray client is handed off to Windows Active Setup instead.

flowchart LR
    A[ImmyBot run<br/>SYSTEM] --> B[Print prereqs<br/>Spooler + IPP client]
    B --> C[Edge node install<br/>systemKey]
    C --> D[Stage installer<br/>C:\ProgramData\PaperCutHive]
    D --> E[Register Active Setup<br/>HKLM]
    E --> F[User signs in]
    F --> G[Tray client installs<br/>userkey + orgId]

Active Setup runs the user install once per user profile, at that user’s next sign-in. Raising the Version value re-runs it for everyone.

ImmyBot software configuration

Create one Local Software named PaperCut Hive and one deployment targeting the client’s workstations and portable devices.
Setting
Value
Software type
Local Software (uploaded installer)
Installer
papercut-hive.exe (generic download, not the org-linked file)
Version
The DisplayVersion a test install writes (tested: 2026.9.9.810)
Detection
Registry, display name contains “PaperCut Hive”
Install script
Section below, execution context System
Uninstall script
Section below, execution context System
Deployment scope
Client tenant only (keys are client-specific)

Version note: the registry DisplayVersion does not match the release number in the DisplayName, and it has varied between installs (2026.09.09.0810 and 2026.09.10.0607). ImmyBot treats a newer installed version as compliant, so Hive’s self-updater will not trigger reinstalls. Always read the DisplayVersion from a test machine before setting the software version.

Do not reuse this software for another client. The install script contains that client’s keys. Clone it and swap in the new client’s keys.

Install script

Paste into the software’s Install Script field, execution context System, then save the software. Replace the three placeholders with the client’s keys from the Hive admin console. The systemKey is in the command line string under Edge Mesh > Add edge nodes > Manually deploy edge nodes (step 2). The userkey and orgId are in the install command under Add-ons > Desktop App deployment with Microsoft Intune > View setup process > Install user component. A successful run ends with the line Done - tray app will install at each user's next sign-in.

$SystemKey = "<systemKey from Manually deploy edge nodes>"
$UserKey   = "<userkey from Install user component>"
$OrgId     = "<orgId from Install user component>"

# --- 1. Printing prereqs (fixes "could not find print queue") ---
$spooler = Get-Service Spooler
if ($spooler.StartType -eq 'Disabled') { Set-Service Spooler -StartupType Automatic }
if ($spooler.Status -ne 'Running') { Start-Service Spooler; Start-Sleep -Seconds 5 }
$ipc = Get-WindowsOptionalFeature -Online -FeatureName Printing-Foundation-InternetPrinting-Client
if ($ipc.State -ne 'Enabled') {
    Enable-WindowsOptionalFeature -Online -FeatureName Printing-Foundation-InternetPrinting-Client -All -NoRestart | Out-Null
    Restart-Service Spooler -Force; Start-Sleep -Seconds 5
}

# --- 2. Install edge node (machine-wide) ---
$log = Join-Path (Split-Path $InstallerFile) 'PaperCutHive-system.log'
$args = @('/VERYSILENT','/SUPPRESSMSGBOXES','/NORESTART','/SP-',"/systemKey=`"$SystemKey`"","/LOG=`"$log`"")
$p = Start-Process $InstallerFile -ArgumentList $args -Wait -PassThru -NoNewWindow
if (Test-Path $log) { Get-Content $log -Tail 25 }
if ($p.ExitCode -ne 0) { throw "Edge node install exited with code $($p.ExitCode)" }

# --- 3. Keep a copy of the installer for users (do not delete) ---
$stageDir = 'C:\ProgramData\PaperCutHive'
New-Item $stageDir -ItemType Directory -Force | Out-Null
$staged = Join-Path $stageDir 'papercut-hive.exe'
Copy-Item $InstallerFile $staged -Force

# --- 4. Active Setup: installs tray app for each user at their next sign-in ---
$asKey = 'HKLM:\SOFTWARE\Microsoft\Active Setup\Installed Components\PaperCutHiveUserClient'
New-Item $asKey -Force | Out-Null
$stub = "`"$staged`" /VERYSILENT /SUPPRESSMSGBOXES /NORESTART /CURRENTUSER /userkey=`"$UserKey`" /orgId=`"$OrgId`""
Set-ItemProperty $asKey -Name '(Default)'   -Value 'PaperCut Hive User Client'
Set-ItemProperty $asKey -Name 'StubPath'    -Value $stub
Set-ItemProperty $asKey -Name 'Version'     -Value '2026,9,9,810'
Set-ItemProperty $asKey -Name 'IsInstalled' -Value 1 -Type DWord
Write-Host "Done - tray app will install at each user's next sign-in"

The prereq block only changes machines where the Print Spooler is off or the Internet Printing Client feature is missing. Without it, the installer aborts with could not find print queue after 10s and exit code 1.

Uninstall script

Paste into the software’s Uninstall Script field, execution context System. It removes Active Setup first, so users do not get the client reinstalled at their next sign-in.

# Remove Active Setup so the client stops reinstalling at logon
Remove-Item 'HKLM:\SOFTWARE\Microsoft\Active Setup\Installed Components\PaperCutHiveUserClient' -Recurse -Force -ErrorAction SilentlyContinue
Remove-Item 'C:\ProgramData\PaperCutHive' -Recurse -Force -ErrorAction SilentlyContinue

# Uninstall the edge node
$u = 'C:\Program Files\PaperCut Hive\unins000.exe'
if (Test-Path $u) {
    $p = Start-Process $u -ArgumentList '/VERYSILENT','/SUPPRESSMSGBOXES','/NORESTART' -Wait -PassThru
    if ($p.ExitCode -ne 0) { throw "Edge node uninstall exited with code $($p.ExitCode)" }
}

This does not remove the tray client from profiles that already have it. To remove it for one user, run as that user: "%localappdata%\Programs\PaperCut Hive\unins000.exe" /VERYSILENT. Also remove the device from Edge Mesh in the Hive admin console.

User sync and sign-in

Sync users from an Entra ID group with invitation emails turned off. Users link their account from the tray icon instead of an email.

  1. In the Hive admin console, set up User and group sync for Microsoft Entra ID (the Graph API option). It is the only option that supports Groups and deletes users removed from Entra. (PaperCut docs)

  2. Sync only the group of users who print.

  3. Turn off invitation emails in the sync settings before the first full sync.

  4. Test with a small group first: confirm no email arrives and the user can sign in from the tray.

Sign-in method: users click the tray icon and sign in with the Microsoft button. Hive matches the account to the synced user by email. Confirm the client’s UPN and primary email match before the full sync. SAML SSO is only needed if the client wants Hive sign-ins under Conditional Access.

Invitations already sent cannot be recalled. Those users can ignore the email and sign in from the tray.

End-user experience

Users see the PaperCut tray icon after their next sign-in or reboot, then sign in once with their work account.

  • Users already signed in when ImmyBot runs get the client at their next sign-out/in or reboot.

  • On the first sign-in the client may not start, or may show two icons. One more sign-out/in or a reboot fixes both. This happens once per user.

  • On Windows 11 the icon may sit under the ^ hidden-icons arrow.

Sample staff notice (send before rollout):

Subject: New printing app on your computer

Over the next few days, a PaperCut icon will appear in the system tray (bottom-right, near the clock) after you sign in to your computer. If you don’t see it, click the ^ arrow to show hidden icons.

The first time, click the icon and select Log in to print, then sign in with your work account. You only need to do this once.

If you see two PaperCut icons the first time, sign out and back in. That’s expected and only happens once.

Verification and troubleshooting

ImmyBot compliance only checks the edge node; confirm the tray client separately. Run this as the signed-in user (not SYSTEM), since checks 3 to 5 read that user’s profile.

"1. HKLM Active Setup key:"
Test-Path 'HKLM:\SOFTWARE\Microsoft\Active Setup\Installed Components\PaperCutHiveUserClient'
"2. Staged installer:"
Test-Path 'C:\ProgramData\PaperCutHive\papercut-hive.exe'
"3. HKCU key (Active Setup ran for this user):"
Get-ItemProperty 'HKCU:\SOFTWARE\Microsoft\Active Setup\Installed Components\PaperCutHiveUserClient' -ErrorAction SilentlyContinue | Select Version
"4. Client installed in profile:"
Test-Path "$env:LOCALAPPDATA\Programs\PaperCut Hive\pc-print-client-service.exe"
"5. Client processes running:"
Get-Process pc-* -ErrorAction SilentlyContinue | Select Name, Id, Path

Symptom
Cause
Fix
Install output lacks the Done - tray app... line
Old script ran; new one not saved
Paste into the Install Script field, save the software, re-run
papercut-hive.exe is not recognized
Script calls the bare filename
Use $InstallerFile
could not find print queue after 10s, exit code 1
Spooler off or Internet Printing Client missing
Keep the prereq block; check the PrintService/Admin event log if it persists
Verify fails, “desired version NOT found”
Software version doesn’t match DisplayVersion
Set the version to the DisplayVersion a test install reports
Check 1 or 2 False
Active Setup part of the script didn’t run
Review Install stage output in ImmyBot
Check 3 empty
Active Setup hasn’t run for this user yet
Sign out and back in
Check 3 has a version, check 4 False
User install failed
Run the StubPath command by hand with /LOG="$env:TEMP\hive-user.log" and read the log
Check 4 True, no icon
Client installed but not started
Sign out/in again, or check under the ^ arrow
Two tray icons
First-sign-in launch plus startup entry
Sign out/in or reboot; cosmetic
Device missing from Hive console
Wrong or empty systemKey
Confirm the key in the script matches the client’s Hive org

Updating to a new installer

Hive updates itself on devices, so a new upload is only needed for new installs. When you do upload one, change two values.

  1. Download the new papercut-hive.exe from the Hive admin console and upload it as a new version of the software.

  2. Install on one test machine and read the DisplayVersion from the registry.

  3. Set the ImmyBot software version to that exact DisplayVersion.

  4. In the install script, raise the Active Setup Version line (for example 2026,10,x,x). This re-runs the tray client install for every user at their next sign-in.

  5. Re-run on the test machine, then let the deployment roll out.