Computer accounts

If the
Require computer accounts for all client machines
security policy is enabled
FactoryTalk
users must log in using a computer that has an account in the
FactoryTalk
network directory.
Add computer accounts to a
FactoryTalk
network directory
to allow the computers to access the
FactoryTalk
system. After adding the computer account, specify security settings for the computer to allow or deny access to parts of the
FactoryTalk
system from the computer. Permissions can be granted to allow or deny the use of computers to perform specific actions. If the computer has the same security requirements as other computers in the
FactoryTalk
system, consider using a computer group account to control the security settings.
Even if the
Require computer accounts for all client machines
security policy is disabled, computer accounts are required for any computers hosting servers — for example, Terminal Servers,
Rockwell Automation
Device Servers (
FactoryTalk Linx
),
OPC
data servers, Tag Alarm and Event Servers, or HMI servers. Without the server computer accounts, configuration of the servers from client computers on the network will not be possible because the
FactoryTalk
network directory server cannot locate these servers on the network without their computer accounts.
Running the
Specify
FactoryTalk
Directory Location
utility on the computer hosting the
FactoryTalk
Network Directory Server automatically creates the required computer account for the
FactoryTalk
Network Directory Server.
IMPORTANT:
Do not use
Windows
Remote Desktop
where line-of–sight security is required because the location of the computer from which the user is operating the system cannot be established reliably. This can have unexpected results. For example, if the security policy restricts write security for the remote user’s computer, the local user could be denied access unexpectedly because the remote computer’s session persists after the remote user has logged off.
Computer and computer group accounts are not linked to
Windows
computer account.
FactoryTalk Directory
computer accounts can be created for computers that do not yet exist in
Windows
. If the name of the computer changes in
Windows
, the name of the corresponding
FactoryTalk Directory
computer account must be changed manually.
Provide Feedback
Have questions or feedback about this documentation? Please submit your feedback here.
Normal