Copiers hold a service-account password someone eventually rotates, speak SMB dialects
servers deprecate, and run firmware nobody updates until scanning breaks. For the print path
and scan-to-email, use the Printer Troubleshooting playbook instead.
Name the boundary early: hardware, consumables, jams and usually firmware are the lease
vendor's; network, credentials, shares and DNS are the desk's.
Climb the Troubleshooting Ladder base skill first: past tickets for this copier, since
scan-to-folder failures cluster after a password rotation, an SMB1 disablement or a server
migration; then the documented fleet profile — models and firmware, the scan service
account, destination share paths, the lease vendor's contract scope, panel access details.
Get the copier's own error (panel message, send log, or a code looked up for the exact
model), the scope — one destination, all, or all copiers — and the SMB dialect the server
accepts.
Branch:
1. Authentication — every destination dies at once after a credential change. The copier's
embedded SMB service account was rotated or disabled in a cleanup: confirm its state,
then update the stored credential in the panel. The durable fix is a documented
least-privilege account policy won't silently expire; flag collisions to whoever owns
identity. Scanning as individual users is a design change, not a fix: escalate.
2. SMB version — scans fail after server hardening or a migration, credentials good.
Firmware capped at SMB1 leaves two honest options: a vendor firmware update (the lease
vendor's job) or an intermediary path the client accepts. Never re-enable SMB1 as the fix
— it reopens a known attack surface, and that is the security owner's call, in writing.
3. Destination path — one fails, others work: the share moved, was renamed, or its
permissions changed. Verify the path exists and the scan account can write, then correct
the copier's entry. Permission problems underneath go to the File Share Permissions
playbook.
4. Address book — wrong, missing, or bulk changes. Small edits in the panel; for bulk, use
the vendor's export/import procedure for the model and save the export to the client's
documentation first. Directory sync is vendor-specific — the lease vendor rules on it.
5. Firmware quirks and panel errors — reboots, codes, vanished features. Match the code to
the vendor's published meaning. One mapping to a hardware subsystem goes to the lease
vendor with model and code; firmware updates on leased devices are theirs.
Never put credentials in a note; reference where they are stored. Touching hardware or
vendor firmware can void the contract. Verify with a real scan to the affected destination,
then note it (PSA Note Discipline base skill): model and firmware, code, branch, what
changed, who owns what's left, verification.