Set System folder permissions

Set permissions on the
System
folder to control whether a user-computer pair can:
  • See the System folder or its contents (
    Read
    )
  • Modify the properties of any item in the System folder (
    Write
    )
  • Add user, user group, computer, or computer group accounts (
    Create Children
    )
  • Change the security settings of the System folder (
    Configure Security
    )
  • View the contents of the System folder
    (List Children
    )
  • Delete the System folder or any item within it (
    Delete
    )
  • Write tags in data servers (
    Write Value
    )
  • Perform other product-specific actions
  • Perform actions defined in user action groups
    TIP:
    • Denying
      Read
      does not prevent users from reading tag values for devices in the
      Networks and Devices
      tree.
    • Denying
      Write
      prevents users from modifying the properties of any item in the
      System
      folder. Denying
      Write
      also prevents deleting user and group accounts, if the accounts have group memberships associated with them.
    • Denying
      Create Children
      has no effect on policies.
    • If a user, computer, or group account has group memberships associated with it, deleting the account also requires
      Write
      permission, because updating the group memberships of accounts is controlled by the Write action.
    • The
      Write Value
      action does not prevent users from writing values to tags in specific hardware devices.
Prerequisites
Obtain the following security permissions for the
System
folder:
  • Common > Read
  • Common > Configure Security
To set System folder permissions
  1. In
    FactoryTalk Administration Console
    Explorer
    , right-click the
    System
    folder or the subfolder to secure, and select
    Security
    .
  2. In
    Security Settings,
    in the
    Permissions
    tab, either:
    • Set permissions by user:
      • Select
        User
        .
      • In
        Users and Computers
        , select a user and computer.
      • In
        Action
        , expand the category that contains the action to secure, and select the action.
    • Set permissions by action:
      • Select
        Action
        .
      • In
        Action
        , expand the category that contains the action to secure, and select the action. If the list of actions is blank, add users and computers first.
      • In
        Users and Computers
        , select a user and computer.
  3. Select
    Allow
    or
    Deny
    , or clear both. Clear both
    Allow
    and
    Deny
    to make the
    System
    folder inherit its security settings from the
    FactoryTalk Directory
    folder.
  4. (optional) To control access to the action by another user or group, select
    Add
    , and in
    Select User and Computer,
    select the user or group, and computer or group to add, and select
    OK
    .
  5. When finished configuring security for the
    System
    folder, select
    OK
    .
Provide Feedback
Have questions or feedback about this documentation? Please submit your feedback here.
Normal