Add a Windows-linked user group
To move
Windows
accounts from one domain to another, create Windows
-linked user group accounts instead of individual Windows
-linked user accounts. Windows
-linked user group accounts, and the user accounts they contain, can move from one domain to another while keeping security permissions for the group accounts intact. Add user groups from a
Windows
domain or workgroup to the FactoryTalk
system to allow the user accounts in the group to access the FactoryTalk
system. To modify the properties of a Windows
-linked user group, (for example the group's name, or which user accounts are group members), modify these properties in Windows
.When adding a
Windows
-linked user group account, all user accounts in the Windows
user group have access to the FactoryTalk
system. To prevent some users in a Windows
-linked group from accessing the FactoryTalk
system, create Windows
-linked user accounts for those users, and set permissions to deny access to those user accounts.Prerequisites
- Connect the computer to theWindowsdomain containing the user groups to add to theFactoryTalk Directory.
- Obtain these permissions in theUser Groupsfolder inFactoryTalk Administration ConsoleExplorer:
- Common > Create Children
- Common > List Children
- Common > Read
To add a
Windows
-linked user group account- InFactoryTalk Administration ConsoleExplorer, expandSystem>User Groups.
- Right-click theUser Groupsfolder, point toNew, and selectWindows-LinkedUser Group.
- InNew, selectWindows-Linked User GroupAdd.
- InSelect Groups, select theWindowsgroups, and selectOK.
- If known, type the names of the user group accounts in the text box. For domain accounts, use the formatDOMAIN\groupname, for workgroup accounts use the formatCOMPUTERNAME\groupname. To validate the names, selectCheck Names. Correct any errors, and then selectOK.
- To search for group by name or description, or to select multiple groups, selectAdvanced.
- InSelect Groups, selectLocationsand select the domain or workgroup from which to select groups.
- UnderCommon Queries, complete the information with which to search the directory:
- Name: Choose whether to search for a name that starts with the specified values or is an exact match to the specified value and then type the search string.
- Description: Choose whether to search for a description that starts with the specified values or is an exact match to the specified value and then type the search string
- Disabled accounts: Select to include disabled accounts when searching.
- Non expiring password: Select to include accounts that have passwords that never expire when searching.
- Days since last logon: Specify to look for accounts based on how long it has been since the account successfully logged on/
- SelectFind Now.
- In the list of groups, select the group accounts to add, and selectOKto closeAdvanced Select Groups.
- The groups selected are listed underEnter the object name to select. SelectCheck Namesto verify the names and then selectOKto closeSelect Groups.
- InNew, review the list of groups.Windows-Linked User Group
- To remove any groups added unintentionally, select the groups, and selectRemove.
- To add more groups, repeat steps 3 and 4.
- SelectOK.TIP:Use a password for allWindowsaccounts in aWindows-linked group, otherwise intermittent security failures or an inability to log on may occur. To follow good security practice, do not use blank passwords with accounts. To avoid using a password forWindows-linked accounts, on the local computer disable theWindowslocal security policyAccounts: Limit local account use of blank passwords to console logon only.
Provide Feedback