Add a cloud-based authentication group
Add user groups from the cloud-based authentication services to the FactoryTalk system to
allow user accounts in the group to access the FactoryTalk system. FactoryTalk Services
Platform supports Microsoft® Entra ID (as known as Azure AD) and OpenID
Connect (OIDC) Identity Provider (IDP) authentication services by retrieving information
from Microsoft Entra ID and OIDC groups. The cloud OIDC IDPs include OKTA, MyRockwell, and
on-premises OIDC IDP. Security permissions are set at the group level.
IMPORTANT:
Microsoft renamed Azure Active Directory (Azure AD) to Microsoft Entra ID.
Prerequisites
- Obtain these permissions in the User Groups folder inFactoryTalkAdministration Console Explorer:
- Common > Create Children
- Common > List Children
- Common > Read
- Configure authentication sites of the desired type, like Microsoft Entra ID, OKTA, MyRockwell, and on-premises OIDC.
To add a cloud-based authentication group
- In the FactoryTalk Administration ConsoleExplorerpane, go toSystem > Users and Groups > User Groups.
- Right-clickUser Groups, selectNew, and then selectCloud-based Authentication Group.
- InNew Cloud-based Authentication Group, selectAdd.
- InSelect Groups, underSelect cloud-based OIDC and Azure AD sites, select a site.
- (optional) In theNamebox, enter the keywords to filter the associated groups.
- SelectSearch.The results will show after you sign in, and you can turn pages to find more groups by clicking
under
Search. The maximum number of groups returned in a search is 200 items for Microsoft Entra ID and 50 for OKTA per page. - On the sign-in page, enter your account and password.TIP:For the Microsoft Entra ID group, inStay signed in to all your apps, selectNo, sign in to this app onlyto limit Windows to remember your account and access only the configured Microsoft Entra ID application. SelectOKto allow Windows to remember your account and automatically sign in to all your applications and websites on this device.
- UnderSelect user groups, select a user group, and then selectOK.TIP:When listing Microsoft Entra ID groups, an error appears if the server doesn’t retrieve the user group information successfully. In the FactoryTalk Administration ConsoleExplorerpane, go toSystem > Policies > System Policies > Security Policyto specify the Web authentication timeout and Web authentication retry count. The default timeout value is 100 seconds, and the default retry count is 3.
- InNew Cloud-based Authentication Group, review the group list.
- To remove any groups added unintentionally, select the groups, and then selectRemove.
- To add more groups, repeat step 3 to step 8.
- SelectOK.
Provide Feedback