Set area permissions

Set permissions on an area in order to control whether a user-computer pair can:
  • See the area or its contents (
    Read)
  • Modify the properties of any item in the area (
    Write
    )
  • Add areas or data servers to the area (
    Create Children
    )
  • Change the security settings of the area (
    Configure Security
    )
  • View the contents of the area (
    List Children
    )
  • Delete the area or any item within it (
    Delete
    )
  • Write tags in data servers (
    Write Value
    )
  • Perform other product-specific actions
  • Perform actions defined in user action groups
For example, set
Read
and
Write
permissions to the Ingredients area within an application to allow the operators of the Ingredients machinery to read and write values to and from controllers in their own area, but only when using computers located within sight of the equipment.
If a resource grouping is associated with the area, the networks or devices in the resource grouping inherit the security permissions of the area.
TIP:
  • Denying
    Read
    does not prevent users from reading tag values from data servers in the area.
  • Denying
    Write
    prevents users from modifying the properties of any item in the area. However, if
    Create Children
    is allowed, users can add areas or data servers within the area.
  • The
    Write Value
    action does not prevent users from writing values to tags in specific hardware devices.
Prerequisites
Setting area permissions requires these security permissions:
  • Common > Read
  • Common > Configure Security
To set area permissions
  1. In
    FactoryTalk Administration Console
    Explorer
    , expand the application, right-click the area to secure, and select
    Security
    .
  2. In
    Security Settings
    , in the
    Permissions
    tab, either:
    • Set permissions by user:
      • Select
        User
        .
      • In
        Users and Computers
        , select a user and computer.
      • In
        Action
        , expand the category that contains the action to secure, and select the action.
    • Set permissions by action:
      • Select
        Action
        .
      • In
        Action
        , expand the category that contains the action to secure, and select the action. If the list of actions is blank, add users and computers first.
      • In
        Users and Computers
        , select a user and computer.
  3. Select
    Allow
    or
    Deny
    , or clear both. Clear both
    Allow
    and
    Deny
    to make the area inherit its security settings from a resource higher in the
    FactoryTalk Directory
    tree.
  4. (optional) To control access to the action by another user or group, select
    Add.
    In
    Select User and Computer,
    select the user or group, and computer or group to add, and select
    OK
    .
  5. When finished configuring security for the area, select
    OK
    .
Provide Feedback
Have questions or feedback about this documentation? Please submit your feedback here.
Normal