When to disable single sign-on

If multiple users are sharing the same
Windows
user account, but have different
FactoryTalk
user accounts, it might be necessary to disable single sign-on. This is because with single sign-on enabled, the last user that logged on to
FactoryTalk
is automatically logged on to all subsequent
FactoryTalk
products. If the ability to distinguish the actions of individual users is necessary, disable single sign-on to force all users to identify themselves to each
FactoryTalk
product they use.
There is no way to log all users off all
FactoryTalk
products simultaneously. This is because some products might need to run without interruption in the background. To log all users off all
FactoryTalk
products simultaneously, log off
Windows
. Logging off
Windows
also shuts down all
FactoryTalk
products that were started in the
Windows
session, regardless of how many users were logged on.
Also disable single sign-on when logging on to
FactoryTalk
through Remote Desktop Services using the name of the Remote Desktop Connection
server
computer. Alternatively, change the security policy
Identify terminal server clients using the name of
to allow Remote Desktop Services users to connect using the name of the Remote Desktop Connection
client
computer.
If single sign-on still does not seem to be working properly, the
FactoryTalk
product in use may not support the single sign-on capability. Some
FactoryTalk
products always require users to log on, even if single sign-on is enabled.
Provide Feedback
Have questions or feedback about this documentation? Please submit your feedback here.
Normal