Modify Computer Policy Settings
Use
Computer Policy Settings
to change these security policy properties: - Whether or not a user can connect to theFactoryTalk Directoryfrom a client computer that does not have a computer account in the network directory
- How client computers connect to theFactoryTalk Directorythrough Remote Desktop Services, and how the computer name appears in theFactoryTalk Diagnosticslog of actions.
These settings apply only to computers in the
FactoryTalk
network directory because the FactoryTalk
local directory does not permit remote access. To modify Computer Policy Settings
- InFactoryTalk Administration ConsoleExplorer, expandSystem > Policies > System Policies.
- Right-clickSecurity Policyand selectProperties.
- InSecurity Policy Properties, select+to expandComputer Policy Settings.
- To change the requirements for connecting to theFactoryTalk Directoryfrom a computer that does not have aFactoryTalkcomputer account, selectRequire computer accounts for all client machinesand select one:
- Enabled—allows users to log on toFactoryTalkonly if they are logging on from a client computer that has an account in theFactoryTalk Directory. Remote Desktop Services clients can still log on toFactoryTalk Directorywithout computer accounts if theIdentify terminal server clients using the name ofpolicy is set toServer Computer. See step 4.
- Disabled—allows users to log on toFactoryTalkfrom any client computer, even if that computer has no computer account in theFactoryTalknetwork directory.
- To determine what computer name identifies clients connecting to theFactoryTalk Directorythrough Remote Desktop Services, selectIdentify terminal server clients using the name ofand select one:
- Terminal client—Client computers must have computer accounts in theFactoryTalk Directoryto accessFactoryTalkapplications, unless theRequire computer accounts for all client machinespolicy is disabled. This combination of settings is useful for diagnostic logging because the name of the client computer where actions originate can be logged.Terminal Clientlogs actions using the name of the client computer where the user is connecting to the Remote Desktop Connection (RDC) client computer. The computer name logged inFactoryTalk Diagnosticsis different for each client connecting via Remote Desktop Services.
- Server computer—allows client computers to connect through Remote Desktop Services without requiring accounts in theFactoryTalk Directory, even if theRequire computer accounts for all client machinespolicy isEnabled.Server computerlogs actions using the name of the Remote Desktop Connection server computer. The computer name logged inFactoryTalk Diagnosticswill be the same for all users connecting via Remote Desktop Services.
- To determines if the system will force the use of the local computer name when a disconnected remote session is blocking the logon process, selectForce use of local computer name during logon processand select one:
- Enabled—allows using the local computer name to log in if the remote session is disconnected.
- Disabled—does not allow logging in to theFactoryTalk Directoryif the remote session is disconnected.
- When finished modifying Account Policy Settings, selectOK.IMPORTANT:Setting theIdentify terminal server clients using the name ofpolicy toServer Computermight affect the level of access that a Remote Desktop Services user has to theFactoryTalksystem.
Provide Feedback