AirPrint
The AirPrint policy configuration transfers AirPrint-capable printers to iOS and iPadOS devices via a configuration profile. The printers defined there then appear in the device’s print dialog without having to be discovered on the local network via Bonjour.
Use case
AirPrint printers are discovered via Bonjour (mDNS) by default. Bonjour announcements, however, do not cross subnet or VLAN boundaries — in school and corporate networks with separate segments for devices and printers, the printers are therefore often not visible in the print dialog. The AirPrint configuration specifies the printer’s address directly, so the device can reach it in a targeted way.
The configuration is also available for devices with User Enrollment and is offered in macOS policies as well as in iOS and iPadOS policies (see AirPrint for macOS →).
Prerequisites
- An AirPrint-capable printer or print server (e.g. CUPS) reachable via IPP or IPPS.
- Network connectivity between device and printer on the port used (IPP default:
631); firewalls between network segments must allow this port. - Host name or IP address and the resource path of the printer.
Configuration
The configuration is created under Devices → Policies in an iOS policy via Add Configuration → AirPrint. The General section lists the printers in a table; Add opens the Add printer dialog. A configuration can contain any number of printers; it can only be saved once at least one printer has been entered.
The following fields are available per printer:
| Field | Required | Description |
|---|---|---|
| Host Name or IP Address | yes | Address of the printer or print server, e.g. 192.168.10.25 or printer01.example.com. |
| Port | no | Port of the IPP service (0–65535). If left empty, the default port is used. |
| Resource Path | yes | Resource path of the print queue, e.g. ipp/print for many network printers or printers/<queue> for CUPS servers. |
| Use TLS | no | Enforces a TLS-encrypted connection (IPPS) to the printer. Disabled by default. |
Printers already entered can be changed via Edit or removed via Delete in the table’s context menu; several printers can be deleted at once using multi-selection.
rp. On a Mac in the same network as the printer, it can be read with dns-sd -B _ipp._tcp (browse for printers) followed by dns-sd -L "<printer name>" _ipp._tcp. Alternatively, it is often shown in the printer’s web interface.Related restrictions
In addition to the AirPrint configuration, the Restrictions policy configuration contains further AirPrint-related options in the Restrictions of settings section, including Allow AirPrint, Allow AirPrint credentials storage, Allow iBeacon discovery of AirPrint printers and Require trusted TLS for AirPrint. If Allow AirPrint is disabled, printing is not available on the device even with printers configured.