XERIA can protect generated PDF files with open passwords and optional permission restrictions. You can require a password before a recipient can view a document, limit common actions such as printing, copying or editing, or combine both controls in the same workflow.
What You Will Learn
This tutorial explains how to:
- Choose the correct XERIA security mode
- Add an open password to a PDF
- Apply PDF permission restrictions
- Combine password protection and permissions
- Assign individual passwords in personalized batch workflows
- Handle recipients with missing passwords
- Generate and test protected files
- Deliver passwords more safely
- Diagnose common password and permission problems
The tutorial applies the same security concepts to single-document, folder and personalized batch workflows, while giving additional attention to recipient-specific batch production.
For the security concepts behind the workflow, see [What Is PDF Access Control?](/resources/articles/what-is-pdf-access-control/).
Understand the Two Main Password Types
XERIA recipient records can contain an **Open Password** and an **Owner Password**.
Open Password
The open password is the credential a recipient enters to open the protected PDF.
Use an open password when the primary risk is unauthorized viewing.
Without the correct open password, compatible PDF readers should not display the document contents.
Owner Password
The owner password supports PDF permission settings and protects changes to those restrictions.
It may be associated with rules governing:
- Printing
- Copying text or images
- Editing
- Page changes
- Comments and annotations
- Form-related actions
An owner password is not a replacement for an open password. If the document has permission restrictions but no open password, it may still open normally while restricted actions are limited in compatible software.
For a broader explanation, see [What Is PDF Encryption?](/resources/articles/what-is-pdf-encryption/).
Choose the Correct XERIA Security Mode
XERIA presents four practical security combinations.
| Security Mode | Opening the PDF | Printing, Copying and Editing |
|---|---|---|
| Normal | No password required | No permission restrictions applied |
| Password only | Open password required | Full permissions remain available after opening |
| Permissions only | No open password required | Selected permission restrictions are applied |
| Password + permissions | Open password required | Selected permission restrictions are also applied |
Choose the mode according to the actual risk.
Use **Password only** when unauthorized opening is the main concern.
Use **Permissions only** when recipients may open the file normally but common actions should be limited.
Use **Password + permissions** when both opening and post-opening actions require control.
Do not enable restrictions automatically without considering whether recipients need to print, copy, complete forms, add comments or sign the document.
Before You Start
Prepare:
- The approved source PDF or source folder
- The intended output location
- The required security mode
- The open password or recipient password data
- The owner password where required
- The permission profile
- A password-delivery method
- One or more test PDF readers
- A representative test file or recipient
Keep the approved source unchanged and write protected outputs to a separate location.
Avoid using real confidential documents for the first test.
Step 1: Select the XERIA Production Workflow
Open the relevant XERIA production area.
Depending on the task, you may be working with:
- A single PDF
- A folder of PDF files
- A personalized recipient list
- A previously configured batch operation
Select the approved input and confirm the output location before configuring security.
For recipient-specific production, prepare the recipient list first. The workflow is described in [Create Personalized PDFs in XERIA](/resources/articles/create-personalized-pdfs-in-xeria/).
Step 2: Open the PDF Security Options
Locate the PDF security section in the selected workflow.
The batch security area can apply:
- PDF encryption
- Permission restrictions
- Both controls together
- Neither control
Review the security summary shown by XERIA after changing the options.
The summary should correspond to one of the four modes:
- Normal
- Password only
- Permissions only
- Password + permissions
If the summary does not match the intended policy, correct the selected options before generating any files.
Step 3: Enable PDF Encryption
Enable the PDF encryption option when recipients must enter a password before opening the file.
In a recipient-specific batch, every selected recipient must have an open password.
The password can come from:
- A recipient record created inside XERIA
- An imported Excel column mapped to **Open Password**
- A password generated for a missing recipient record
- A manually assigned value
Do not begin production until the password source is clear and the recipient-to-password relationship has been verified.
Step 4: Assign Open Passwords
For a single protected output, enter the approved open password in the relevant security field.
For personalized production, review the **Open Password** value in each recipient record.
A recipient record may also contain:
- Full Name
- Company ID
- Owner Password
- Permission Profile
- Mapping Profile
If recipient data is imported from Excel, map the password columns to the correct XERIA fields.
Check for:
- Empty password cells
- Shifted spreadsheet rows
- Repeated passwords
- Leading or trailing spaces
- Passwords assigned to the wrong recipient
- Invalid recipient records
- Test passwords left in production data
A technically successful batch can still be unsafe if passwords are mapped to the wrong people.
Step 5: Handle Missing Batch Passwords
When PDF encryption is enabled for a personalized batch, XERIA checks whether every recipient has an open password.
If one or more recipients are missing passwords, XERIA provides three choices:
- **Generate Missing Passwords**
- **Edit Manually**
- **Cancel**
Generate Missing Passwords
XERIA can generate missing open passwords and save them to the recipient database.
The automatic password is a six-digit numeric value.
After generation:
- Review the updated recipient records
- Confirm that every selected recipient has a password
- Export or record the delivery information through the approved process
- Keep the password data protected
- Do not publish the passwords in ordinary processing logs
Automatic generation is convenient, but the resulting passwords must still be delivered to the correct recipients.
Edit Manually
Choose manual editing when the organization has a required password format or when passwords are assigned through another approved process.
XERIA leaves PDF encryption disabled until the missing values are completed.
Return to the recipient list, enter the missing open passwords, save the records and enable encryption again.
Cancel
Choose Cancel when the current recipient list or security policy is not ready.
Do not disable encryption merely to bypass missing-password validation if the document requires protected opening.
Step 6: Configure the Owner Password
Use an owner password when permission restrictions are applied.
The owner password should not normally be the same as the recipient’s open password.
The owner password is intended to protect the permission configuration rather than serve as the recipient’s normal opening credential.
In personalized workflows, confirm that the **Owner Password** field remains associated with the correct recipient or approved permission configuration.
Protect owner passwords carefully because exposure can weaken the intended restrictions.
Step 7: Apply Permission Restrictions
Enable **Apply Permission Restrictions** when printing, copying or editing should be limited.
Select the appropriate permission profile for the document’s purpose.
A permission profile may determine whether recipients can:
- Copy text or images
- Modify the document
- Extract or reorganize pages
- Add comments
- Fill forms
- Perform signature-related changes
Grant only the actions needed for the legitimate task.
For example:
| Recipient Need | Suitable Direction |
|---|---|
| Read-only confidential briefing | Restrict printing, copying and editing |
| Form that must be completed | Allow form filling while limiting unrelated modification |
| Review copy | Allow comments while limiting page editing |
| Document intended for printing | Allow the required print level |
| Archive copy | Apply restrictions according to the archive policy |
The exact behavior of PDF permissions depends on the recipient’s PDF software. Test the selected profile before distribution.
Step 8: Understand Permission Profiles and Mapping Profiles
Recipient records may contain both a **Permission Profile** and a **Mapping Profile**.
The permission profile expresses the security rule assigned to the recipient.
The mapping profile is generated or maintained in coordination with the selected permission profile in the XERIA recipient workflow.
When importing recipient data:
- Select a valid permission profile
- Verify that the related mapping is created correctly
- Avoid typing unsupported profile names
- Confirm that different recipient groups receive the intended restrictions
- Review records after import
Do not assume that one permission profile is appropriate for every recipient or document type.
Step 9: Combine Passwords and Permissions
To require a password and apply restrictions after opening:
- Enable PDF encryption
- Confirm the open password
- Enable permission restrictions
- Confirm the owner password where required
- Select the appropriate permission profile
- Review the XERIA security summary
- Generate a test output
The summary should indicate **Password + permissions**.
This mode is appropriate when the PDF should not open without a credential and recipients should also have limited actions after opening.
Remember that permission restrictions cannot prevent every screenshot, photograph or manual reproduction.
Step 10: Configure the Rest of the Output
Complete the non-security settings required by the workflow.
These may include:
- Source PDF
- Output folder
- Output filename
- Watermark text
- Recipient tokens
- Trace code
- QR trace element
- Page range
- Email settings
Security settings must remain aligned with the correct source, recipient and output file.
A password-protected PDF sent to the wrong recipient is still a security incident.
For a wider protection workflow, see [How to Protect Confidential PDF Documents](/resources/articles/how-to-protect-confidential-pdf-documents/).
Step 11: Run a Representative Test
Generate a test file before processing the complete job.
For personalized batches, test records should include:
- A recipient with a manually assigned password
- A recipient with an automatically generated password
- A recipient with a permission profile
- A long recipient name
- A non-Latin recipient name
- A file that contains forms or annotations
- A file that should permit printing
- A file that should restrict copying or editing
Open the generated PDF in the software used by the intended recipients.
Verify:
- The file requests the correct open password
- An incorrect password is rejected
- The correct password opens the file
- The watermark and recipient identity are correct
- The owner password is not exposed
- Printing behaves as expected
- Copying behaves as expected
- Editing behaves as expected
- Forms and comments behave as intended
- The PDF remains readable and undamaged
Test more than one PDF reader when compatibility matters.
Step 12: Generate the Protected PDFs
After the test succeeds, start the intended production operation.
For personalized production, select the approved recipients and use **Generate PDF**.
Monitor:
- Total items
- Current item
- Completed items
- Failed items
- Skipped items
- Output location
- Security-related warnings
- Missing-password warnings
Do not ignore a precondition warning about recipients without open passwords.
A completed progress indicator confirms that processing finished; it does not prove that every password and permission assignment is correct.
Step 13: Verify the Output Set
After generation, reconcile:
- Input file count
- Selected recipient count
- Generated file count
- Failed and skipped records
- Output filenames
- Open password assignments
- Owner password assignments
- Permission profiles
- Recipient watermarks
- Trace codes
Open samples from different parts of the batch.
For a high-risk batch, verify every recipient-to-file and recipient-to-password relationship before distribution.
Do not include passwords in filenames.
Step 14: Deliver the Password Safely
The protected PDF and its password should not automatically travel through the same channel.
Approved delivery methods may include:
- A separate email message
- A verified phone or SMS channel
- An authenticated portal
- An organization-approved password manager
- A previously agreed recipient-specific method
The appropriate method depends on organizational policy and document sensitivity.
Before delivering a password:
- Verify the recipient
- Confirm the destination
- Avoid group messages
- Avoid public or shared channels
- Do not expose the owner password
- Do not store plaintext passwords in ordinary logs
- Record only the operational evidence required by policy
If the password is exposed, treat it as compromised and generate a replacement file or password according to the applicable workflow.
Step 15: Distribute and Record the Result
After the protected files pass review, distribute them through the approved channel.
Where XERIA email delivery is used:
- Confirm recipient-to-file matching
- Prepare the email template
- Review attachment mapping
- Keep the password delivery separate where required
- Send the approved files
- Review the **Mail Log**
Record successful deliveries, failures and retries according to policy.
Email delivery requires the relevant licensed feature and is unavailable in trial mode.
Common Problems
The PDF Opens Without a Password
Confirm that PDF encryption is enabled, not only permission restrictions.
Generate a new test file after changing the setting.
XERIA Reports Missing PDF Passwords
One or more selected recipients do not have an open password.
Generate the missing passwords, edit the recipient records manually or cancel the operation.
The Password Works for the Wrong Recipient
Stop distribution immediately.
Review recipient records, imported rows, output filenames and password mapping.
Regenerate affected files after correcting the data.
The PDF Requests a Password but Restrictions Are Not Applied
Confirm that **Apply Permission Restrictions** is enabled and that a valid permission profile is assigned.
The PDF Opens Without a Password but Printing Is Restricted
This is the expected behavior of the **Permissions only** mode.
Enable PDF encryption as well when an open password is required.
A Recipient Cannot Print or Fill a Form
The selected permission profile may be too restrictive.
Choose a profile that permits the required action and generate a new file.
Restrictions Work in One PDF Reader but Not Another
PDF permission enforcement can vary by software.
Test with supported recipient applications and treat permissions as supporting controls.
An Automatically Generated Password Is Missing
Return to the recipient record and confirm that the generated password was saved.
Do not distribute the related PDF until the password can be delivered reliably.
The Owner Password Was Sent to the Recipient
Treat the owner password as exposed.
Review the affected security configuration and regenerate the file with new approved credentials where necessary.
Best Practices
- Classify the document before selecting security settings.
- Use an open password when unauthorized viewing is a risk.
- Use permission restrictions only when they match the recipient’s task.
- Combine encryption and permissions for layered protection.
- Use different open and owner passwords where practical.
- Assign recipient-specific passwords for sensitive batches.
- Verify every recipient-password mapping.
- Use XERIA’s missing-password validation.
- Review automatically generated passwords before distribution.
- Protect recipient and password data.
- Do not place passwords in filenames.
- Avoid sending the password with the protected attachment.
- Keep plaintext passwords out of ordinary logs.
- Run a representative test.
- Test with the recipient’s PDF reader.
- Verify printing, copying, editing, forms and comments.
- Reconcile input, recipient and output counts.
- Regenerate files after changing passwords or permission profiles.
- Review Mail Log results after email delivery.
- Keep the source PDF unchanged.
- Store protected outputs in an approved location.
- Document the response to exposed or forgotten passwords.
Frequently Asked Questions
Can XERIA Require a Password to Open a PDF?
Yes. Enable PDF encryption and provide an open password. In personalized batches, every selected recipient must have an open password.
Can XERIA Generate Missing Recipient Passwords?
Yes. When batch encryption detects missing open passwords, XERIA can generate six-digit numeric passwords and save them to the recipient database.
Can I Apply Permissions Without an Open Password?
Yes. The PDF can open without a password while selected printing, copying or editing restrictions are applied.
Can I Use a Password and Permission Restrictions Together?
Yes. Enable both PDF encryption and permission restrictions. XERIA identifies this configuration as Password + permissions.
Should the Open Password and Owner Password Be the Same?
They serve different purposes. Using different values is generally preferable when the workflow permits it.
Can PDF Permissions Completely Prevent Copying?
No. Their enforcement depends on compatible software, and visible content can still be reproduced through screenshots, photography or manual methods.
Can Every Recipient Have a Different Password?
Yes. Store or import the appropriate open password in each recipient record and verify the mapping before generation.
What Happens If a Recipient Forgets the Password?
Follow the organization’s identity-verification and replacement procedure. Avoid sending an existing password without first verifying the requester.
Conclusion
XERIA supports four practical PDF security modes: normal, password only, permissions only, and password plus permissions.
For a single document, choose the required mode, assign the approved credentials, generate a test file and verify the behavior before distribution.
For personalized batches, every selected recipient must have the correct open password and permission profile. XERIA can detect missing passwords, generate six-digit values or direct you to manual editing.
A reliable workflow combines correct recipient data, appropriate encryption, proportionate permissions, representative testing, secure password delivery and careful verification of every generated file.