Protect PDFs with Passwords in XERIA

Use XERIA to require PDF open passwords, apply permission restrictions and assign recipient-specific security settings in personalized batches.

Contents
  1. What You Will Learn
  2. Understand the Two Main Password Types
  3. Open Password
  4. Owner Password
  5. Choose the Correct XERIA Security Mode
  6. Before You Start
  7. Step 1: Select the XERIA Production Workflow
  8. Step 2: Open the PDF Security Options
  9. Step 3: Enable PDF Encryption
  10. Step 4: Assign Open Passwords
  11. Step 5: Handle Missing Batch Passwords
  12. Generate Missing Passwords
  13. Edit Manually
  14. Cancel
  15. Step 6: Configure the Owner Password
  16. Step 7: Apply Permission Restrictions
  17. Step 8: Understand Permission Profiles and Mapping Profiles
  18. Step 9: Combine Passwords and Permissions
  19. Step 10: Configure the Rest of the Output
  20. Step 11: Run a Representative Test
  21. Step 12: Generate the Protected PDFs
  22. Step 13: Verify the Output Set
  23. Step 14: Deliver the Password Safely
  24. Step 15: Distribute and Record the Result
  25. Common Problems
  26. The PDF Opens Without a Password
  27. XERIA Reports Missing PDF Passwords
  28. The Password Works for the Wrong Recipient
  29. The PDF Requests a Password but Restrictions Are Not Applied
  30. The PDF Opens Without a Password but Printing Is Restricted
  31. A Recipient Cannot Print or Fill a Form
  32. Restrictions Work in One PDF Reader but Not Another
  33. An Automatically Generated Password Is Missing
  34. The Owner Password Was Sent to the Recipient
  35. Best Practices
  36. Frequently Asked Questions
  37. Can XERIA Require a Password to Open a PDF?
  38. Can XERIA Generate Missing Recipient Passwords?
  39. Can I Apply Permissions Without an Open Password?
  40. Can I Use a Password and Permission Restrictions Together?
  41. Should the Open Password and Owner Password Be the Same?
  42. Can PDF Permissions Completely Prevent Copying?
  43. Can Every Recipient Have a Different Password?
  44. What Happens If a Recipient Forgets the Password?
  45. Conclusion

XERIA can protect generated PDF files with open passwords and optional permission restrictions. You can require a password before a recipient can view a document, limit common actions such as printing, copying or editing, or combine both controls in the same workflow.

What You Will Learn

This tutorial explains how to:

  • Choose the correct XERIA security mode
  • Add an open password to a PDF
  • Apply PDF permission restrictions
  • Combine password protection and permissions
  • Assign individual passwords in personalized batch workflows
  • Handle recipients with missing passwords
  • Generate and test protected files
  • Deliver passwords more safely
  • Diagnose common password and permission problems

The tutorial applies the same security concepts to single-document, folder and personalized batch workflows, while giving additional attention to recipient-specific batch production.

For the security concepts behind the workflow, see [What Is PDF Access Control?](/resources/articles/what-is-pdf-access-control/).

Understand the Two Main Password Types

XERIA recipient records can contain an **Open Password** and an **Owner Password**.

Open Password

The open password is the credential a recipient enters to open the protected PDF.

Use an open password when the primary risk is unauthorized viewing.

Without the correct open password, compatible PDF readers should not display the document contents.

Owner Password

The owner password supports PDF permission settings and protects changes to those restrictions.

It may be associated with rules governing:

  • Printing
  • Copying text or images
  • Editing
  • Page changes
  • Comments and annotations
  • Form-related actions

An owner password is not a replacement for an open password. If the document has permission restrictions but no open password, it may still open normally while restricted actions are limited in compatible software.

For a broader explanation, see [What Is PDF Encryption?](/resources/articles/what-is-pdf-encryption/).

Choose the Correct XERIA Security Mode

XERIA presents four practical security combinations.

Security Mode Opening the PDF Printing, Copying and Editing
Normal No password required No permission restrictions applied
Password only Open password required Full permissions remain available after opening
Permissions only No open password required Selected permission restrictions are applied
Password + permissions Open password required Selected permission restrictions are also applied

Choose the mode according to the actual risk.

Use **Password only** when unauthorized opening is the main concern.

Use **Permissions only** when recipients may open the file normally but common actions should be limited.

Use **Password + permissions** when both opening and post-opening actions require control.

Do not enable restrictions automatically without considering whether recipients need to print, copy, complete forms, add comments or sign the document.

Before You Start

Prepare:

  • The approved source PDF or source folder
  • The intended output location
  • The required security mode
  • The open password or recipient password data
  • The owner password where required
  • The permission profile
  • A password-delivery method
  • One or more test PDF readers
  • A representative test file or recipient

Keep the approved source unchanged and write protected outputs to a separate location.

Avoid using real confidential documents for the first test.

Step 1: Select the XERIA Production Workflow

Open the relevant XERIA production area.

Depending on the task, you may be working with:

  • A single PDF
  • A folder of PDF files
  • A personalized recipient list
  • A previously configured batch operation

Select the approved input and confirm the output location before configuring security.

For recipient-specific production, prepare the recipient list first. The workflow is described in [Create Personalized PDFs in XERIA](/resources/articles/create-personalized-pdfs-in-xeria/).

Step 2: Open the PDF Security Options

Locate the PDF security section in the selected workflow.

The batch security area can apply:

  • PDF encryption
  • Permission restrictions
  • Both controls together
  • Neither control

Review the security summary shown by XERIA after changing the options.

The summary should correspond to one of the four modes:

  • Normal
  • Password only
  • Permissions only
  • Password + permissions

If the summary does not match the intended policy, correct the selected options before generating any files.

Step 3: Enable PDF Encryption

Enable the PDF encryption option when recipients must enter a password before opening the file.

In a recipient-specific batch, every selected recipient must have an open password.

The password can come from:

  • A recipient record created inside XERIA
  • An imported Excel column mapped to **Open Password**
  • A password generated for a missing recipient record
  • A manually assigned value

Do not begin production until the password source is clear and the recipient-to-password relationship has been verified.

Step 4: Assign Open Passwords

For a single protected output, enter the approved open password in the relevant security field.

For personalized production, review the **Open Password** value in each recipient record.

A recipient record may also contain:

  • Full Name
  • E-Mail
  • Company ID
  • Owner Password
  • Permission Profile
  • Mapping Profile

If recipient data is imported from Excel, map the password columns to the correct XERIA fields.

Check for:

  • Empty password cells
  • Shifted spreadsheet rows
  • Repeated passwords
  • Leading or trailing spaces
  • Passwords assigned to the wrong recipient
  • Invalid recipient records
  • Test passwords left in production data

A technically successful batch can still be unsafe if passwords are mapped to the wrong people.

Step 5: Handle Missing Batch Passwords

When PDF encryption is enabled for a personalized batch, XERIA checks whether every recipient has an open password.

If one or more recipients are missing passwords, XERIA provides three choices:

  • **Generate Missing Passwords**
  • **Edit Manually**
  • **Cancel**

Generate Missing Passwords

XERIA can generate missing open passwords and save them to the recipient database.

The automatic password is a six-digit numeric value.

After generation:

  • Review the updated recipient records
  • Confirm that every selected recipient has a password
  • Export or record the delivery information through the approved process
  • Keep the password data protected
  • Do not publish the passwords in ordinary processing logs

Automatic generation is convenient, but the resulting passwords must still be delivered to the correct recipients.

Edit Manually

Choose manual editing when the organization has a required password format or when passwords are assigned through another approved process.

XERIA leaves PDF encryption disabled until the missing values are completed.

Return to the recipient list, enter the missing open passwords, save the records and enable encryption again.

Cancel

Choose Cancel when the current recipient list or security policy is not ready.

Do not disable encryption merely to bypass missing-password validation if the document requires protected opening.

Step 6: Configure the Owner Password

Use an owner password when permission restrictions are applied.

The owner password should not normally be the same as the recipient’s open password.

The owner password is intended to protect the permission configuration rather than serve as the recipient’s normal opening credential.

In personalized workflows, confirm that the **Owner Password** field remains associated with the correct recipient or approved permission configuration.

Protect owner passwords carefully because exposure can weaken the intended restrictions.

Step 7: Apply Permission Restrictions

Enable **Apply Permission Restrictions** when printing, copying or editing should be limited.

Select the appropriate permission profile for the document’s purpose.

A permission profile may determine whether recipients can:

  • Print
  • Copy text or images
  • Modify the document
  • Extract or reorganize pages
  • Add comments
  • Fill forms
  • Perform signature-related changes

Grant only the actions needed for the legitimate task.

For example:

Recipient Need Suitable Direction
Read-only confidential briefing Restrict printing, copying and editing
Form that must be completed Allow form filling while limiting unrelated modification
Review copy Allow comments while limiting page editing
Document intended for printing Allow the required print level
Archive copy Apply restrictions according to the archive policy

The exact behavior of PDF permissions depends on the recipient’s PDF software. Test the selected profile before distribution.

Step 8: Understand Permission Profiles and Mapping Profiles

Recipient records may contain both a **Permission Profile** and a **Mapping Profile**.

The permission profile expresses the security rule assigned to the recipient.

The mapping profile is generated or maintained in coordination with the selected permission profile in the XERIA recipient workflow.

When importing recipient data:

  • Select a valid permission profile
  • Verify that the related mapping is created correctly
  • Avoid typing unsupported profile names
  • Confirm that different recipient groups receive the intended restrictions
  • Review records after import

Do not assume that one permission profile is appropriate for every recipient or document type.

Step 9: Combine Passwords and Permissions

To require a password and apply restrictions after opening:

  • Enable PDF encryption
  • Confirm the open password
  • Enable permission restrictions
  • Confirm the owner password where required
  • Select the appropriate permission profile
  • Review the XERIA security summary
  • Generate a test output

The summary should indicate **Password + permissions**.

This mode is appropriate when the PDF should not open without a credential and recipients should also have limited actions after opening.

Remember that permission restrictions cannot prevent every screenshot, photograph or manual reproduction.

Step 10: Configure the Rest of the Output

Complete the non-security settings required by the workflow.

These may include:

  • Source PDF
  • Output folder
  • Output filename
  • Watermark text
  • Recipient tokens
  • Trace code
  • QR trace element
  • Page range
  • Email settings

Security settings must remain aligned with the correct source, recipient and output file.

A password-protected PDF sent to the wrong recipient is still a security incident.

For a wider protection workflow, see [How to Protect Confidential PDF Documents](/resources/articles/how-to-protect-confidential-pdf-documents/).

Step 11: Run a Representative Test

Generate a test file before processing the complete job.

For personalized batches, test records should include:

  • A recipient with a manually assigned password
  • A recipient with an automatically generated password
  • A recipient with a permission profile
  • A long recipient name
  • A non-Latin recipient name
  • A file that contains forms or annotations
  • A file that should permit printing
  • A file that should restrict copying or editing

Open the generated PDF in the software used by the intended recipients.

Verify:

  • The file requests the correct open password
  • An incorrect password is rejected
  • The correct password opens the file
  • The watermark and recipient identity are correct
  • The owner password is not exposed
  • Printing behaves as expected
  • Copying behaves as expected
  • Editing behaves as expected
  • Forms and comments behave as intended
  • The PDF remains readable and undamaged

Test more than one PDF reader when compatibility matters.

Step 12: Generate the Protected PDFs

After the test succeeds, start the intended production operation.

For personalized production, select the approved recipients and use **Generate PDF**.

Monitor:

  • Total items
  • Current item
  • Completed items
  • Failed items
  • Skipped items
  • Output location
  • Security-related warnings
  • Missing-password warnings

Do not ignore a precondition warning about recipients without open passwords.

A completed progress indicator confirms that processing finished; it does not prove that every password and permission assignment is correct.

Step 13: Verify the Output Set

After generation, reconcile:

  • Input file count
  • Selected recipient count
  • Generated file count
  • Failed and skipped records
  • Output filenames
  • Open password assignments
  • Owner password assignments
  • Permission profiles
  • Recipient watermarks
  • Trace codes

Open samples from different parts of the batch.

For a high-risk batch, verify every recipient-to-file and recipient-to-password relationship before distribution.

Do not include passwords in filenames.

Step 14: Deliver the Password Safely

The protected PDF and its password should not automatically travel through the same channel.

Approved delivery methods may include:

  • A separate email message
  • A verified phone or SMS channel
  • An authenticated portal
  • An organization-approved password manager
  • A previously agreed recipient-specific method

The appropriate method depends on organizational policy and document sensitivity.

Before delivering a password:

  • Verify the recipient
  • Confirm the destination
  • Avoid group messages
  • Avoid public or shared channels
  • Do not expose the owner password
  • Do not store plaintext passwords in ordinary logs
  • Record only the operational evidence required by policy

If the password is exposed, treat it as compromised and generate a replacement file or password according to the applicable workflow.

Step 15: Distribute and Record the Result

After the protected files pass review, distribute them through the approved channel.

Where XERIA email delivery is used:

  • Confirm recipient-to-file matching
  • Prepare the email template
  • Review attachment mapping
  • Keep the password delivery separate where required
  • Send the approved files
  • Review the **Mail Log**

Record successful deliveries, failures and retries according to policy.

Email delivery requires the relevant licensed feature and is unavailable in trial mode.

Common Problems

The PDF Opens Without a Password

Confirm that PDF encryption is enabled, not only permission restrictions.

Generate a new test file after changing the setting.

XERIA Reports Missing PDF Passwords

One or more selected recipients do not have an open password.

Generate the missing passwords, edit the recipient records manually or cancel the operation.

The Password Works for the Wrong Recipient

Stop distribution immediately.

Review recipient records, imported rows, output filenames and password mapping.

Regenerate affected files after correcting the data.

The PDF Requests a Password but Restrictions Are Not Applied

Confirm that **Apply Permission Restrictions** is enabled and that a valid permission profile is assigned.

The PDF Opens Without a Password but Printing Is Restricted

This is the expected behavior of the **Permissions only** mode.

Enable PDF encryption as well when an open password is required.

A Recipient Cannot Print or Fill a Form

The selected permission profile may be too restrictive.

Choose a profile that permits the required action and generate a new file.

Restrictions Work in One PDF Reader but Not Another

PDF permission enforcement can vary by software.

Test with supported recipient applications and treat permissions as supporting controls.

An Automatically Generated Password Is Missing

Return to the recipient record and confirm that the generated password was saved.

Do not distribute the related PDF until the password can be delivered reliably.

The Owner Password Was Sent to the Recipient

Treat the owner password as exposed.

Review the affected security configuration and regenerate the file with new approved credentials where necessary.

Best Practices

  • Classify the document before selecting security settings.
  • Use an open password when unauthorized viewing is a risk.
  • Use permission restrictions only when they match the recipient’s task.
  • Combine encryption and permissions for layered protection.
  • Use different open and owner passwords where practical.
  • Assign recipient-specific passwords for sensitive batches.
  • Verify every recipient-password mapping.
  • Use XERIA’s missing-password validation.
  • Review automatically generated passwords before distribution.
  • Protect recipient and password data.
  • Do not place passwords in filenames.
  • Avoid sending the password with the protected attachment.
  • Keep plaintext passwords out of ordinary logs.
  • Run a representative test.
  • Test with the recipient’s PDF reader.
  • Verify printing, copying, editing, forms and comments.
  • Reconcile input, recipient and output counts.
  • Regenerate files after changing passwords or permission profiles.
  • Review Mail Log results after email delivery.
  • Keep the source PDF unchanged.
  • Store protected outputs in an approved location.
  • Document the response to exposed or forgotten passwords.

Frequently Asked Questions

Can XERIA Require a Password to Open a PDF?

Yes. Enable PDF encryption and provide an open password. In personalized batches, every selected recipient must have an open password.

Can XERIA Generate Missing Recipient Passwords?

Yes. When batch encryption detects missing open passwords, XERIA can generate six-digit numeric passwords and save them to the recipient database.

Can I Apply Permissions Without an Open Password?

Yes. The PDF can open without a password while selected printing, copying or editing restrictions are applied.

Can I Use a Password and Permission Restrictions Together?

Yes. Enable both PDF encryption and permission restrictions. XERIA identifies this configuration as Password + permissions.

Should the Open Password and Owner Password Be the Same?

They serve different purposes. Using different values is generally preferable when the workflow permits it.

Can PDF Permissions Completely Prevent Copying?

No. Their enforcement depends on compatible software, and visible content can still be reproduced through screenshots, photography or manual methods.

Can Every Recipient Have a Different Password?

Yes. Store or import the appropriate open password in each recipient record and verify the mapping before generation.

What Happens If a Recipient Forgets the Password?

Follow the organization’s identity-verification and replacement procedure. Avoid sending an existing password without first verifying the requester.

Conclusion

XERIA supports four practical PDF security modes: normal, password only, permissions only, and password plus permissions.

For a single document, choose the required mode, assign the approved credentials, generate a test file and verify the behavior before distribution.

For personalized batches, every selected recipient must have the correct open password and permission profile. XERIA can detect missing passwords, generate six-digit values or direct you to manual editing.

A reliable workflow combines correct recipient data, appropriate encryption, proportionate permissions, representative testing, secure password delivery and careful verification of every generated file.

Protect and distribute PDFs with XERIA

Add visible watermarks, recipient-specific information, passwords and controlled delivery options to PDF documents.

Download XERIA