Set area permissions
Set permissions on an area in order to control whether a user-computer pair can:
- See the area or its contents (Read)
- Modify the properties of any item in the area (Write)
- Add areas or data servers to the area (Create Children)
- Change the security settings of the area (Configure Security)
- View the contents of the area (List Children)
- Delete the area or any item within it (Delete)
- Write tags in data servers (Write Value)
- Perform other product-specific actions
- Perform actions defined in user action groups
For example, set
Read
and Write
permissions to the Ingredients area within an application to allow the operators of the Ingredients machinery to read and write values to and from controllers in their own area, but only when using computers located within sight of the equipment.If a resource grouping is associated with the area, the networks or devices in the resource grouping inherit the security permissions of the area.
TIP:
- DenyingReaddoes not prevent users from reading tag values from data servers in the area.
- DenyingWriteprevents users from modifying the properties of any item in the area. However, ifCreate Childrenis allowed, users can add areas or data servers within the area.
- TheWrite Valueaction does not prevent users from writing values to tags in specific hardware devices.
Prerequisites
Setting area permissions requires these security permissions:
- Common > Read
- Common > Configure Security
To set area permissions
- InFactoryTalk Administration ConsoleExplorer, expand the application, right-click the area to secure, and selectSecurity.
- InSecurity Settings, in thePermissionstab, either:
- Set permissions by user:
- SelectUser.
- InUsers and Computers, select a user and computer.
- InAction, expand the category that contains the action to secure, and select the action.
- Set permissions by action:
- SelectAction.
- InAction, expand the category that contains the action to secure, and select the action. If the list of actions is blank, add users and computers first.
- InUsers and Computers, select a user and computer.
- SelectAlloworDeny, or clear both. Clear bothAllowandDenyto make the area inherit its security settings from a resource higher in theFactoryTalk Directorytree.
- (optional) To control access to the action by another user or group, selectAdd.InSelect User and Computer,select the user or group, and computer or group to add, and selectOK.
- When finished configuring security for the area, selectOK.
Provide Feedback