Computer accounts
If the
Require computer accounts for all client machines
security policy is enabled FactoryTalk
users must log in using a computer that has an account in the FactoryTalk
network directory.Add computer accounts to a
FactoryTalk
network directory to allow the computers to access the FactoryTalk
system. After adding the computer account, specify security settings for the computer to allow or deny access to parts of the FactoryTalk
system from the computer. Permissions can be granted to allow or deny the use of computers to perform specific actions. If the computer has the same security requirements as other computers in the FactoryTalk
system, consider using a computer group account to control the security settings.Even if the
Require computer accounts for all client machines
security policy is disabled, computer accounts are required for any computers hosting servers — for example, Terminal Servers, Rockwell Automation
Device Servers (FactoryTalk Linx
), OPC
data servers, Tag Alarm and Event Servers, or HMI servers. Without the server computer accounts, configuration of the servers from client computers on the network will not be possible because the FactoryTalk
network directory server cannot locate these servers on the network without their computer accounts.Running the
Specify
utility on the computer hosting the FactoryTalk
Directory Location FactoryTalk
Network Directory Server automatically creates the required computer account for the FactoryTalk
Network Directory Server.
IMPORTANT:
Do not use where line-of–sight security is required because the location of the computer from which the user is operating the system cannot be established reliably. This can have unexpected results. For example, if the security policy restricts write security for the remote user’s computer, the local user could be denied access unexpectedly because the remote computer’s session persists after the remote user has logged off.
Windows
Remote DesktopComputer and computer group accounts are not linked to
Windows
computer account. FactoryTalk Directory
computer accounts can be created for computers that do not yet exist in Windows
. If the name of the computer changes in Windows
, the name of the corresponding FactoryTalk Directory
computer account must be changed manually.Provide Feedback