Manage user groups
Add
FactoryTalk
user, Windows
-linked user, cloud-based
authentication group, and LDAP-linked user group accounts to FactoryTalk
user
group accounts. Windows
-linked user groups, and the user accounts they
contain, can move from one domain to another while keeping security permissions for the
group accounts intact.FactoryTalk Services Platform
includes these built-in user groups:Group Name | Description |
---|---|
Administrators | Add user accounts to the Administrators user group to grant those user accounts
full control of areas, applications, users, and groups in the FactoryTalk Directory . These permissions are defined by default. |
Engineers | No users or permissions are defined by default in FactoryTalk Services Platform .
Other software may use this group to establish permission sets. |
Maintenance | No users or permissions are defined by default in FactoryTalk Services Platform .
Other software may use this group to establish permission sets. |
Key points about user groups:
- User group accounts exist only in theFactoryTalk Directoryin which created.
- FactoryTalkuser accounts cannot be members ofWindows-linked user groups.
- TheWindows-linked user group, individualWindows-linked user, cloud-based authentication group, LDAP-linked user group accounts can be members ofFactoryTalkuser groups. This allows use ofFactoryTalkuser groups when setting permissions.
- AFactoryTalkuser account orWindows-linked user account can be a member of more than oneFactoryTalkuser group and cannot be a member of cloud-based authentication group and LDAP-linked user group.
- Cloud-based authentication group and LDAP-linked user group can be a member of more than one FactoryTalk user group, but cannot be members of Windows-linked user groups.IMPORTANT:
- Managing user groups requires explicit permissions. To verify permissions, inFactoryTalk Administration ConsoleExplorer, expandSystem, then right-clickUsers and Groupsand selectSecurity.Confirm the permissions listed in the prerequisites for the task are present with the logged in user account.
- If an action is set toDenyfor the user in any one group, then theDenytakes precedence over anyAllowsetting in a different group of which the user is a member.
Provide Feedback