Assign user rights to make system policy changes
In
User Rights Assignment Policy Properties
, specify which users are permitted to:- Back up or restoreFactoryTalk Directory, the System folder, or applications
- Change theFactoryTalk Directoryserver computer
- Switch between primary and secondary servers in a redundant pair (for example, HMI servers, or data servers)
- Modify the security authority identifier
Policy settings are completely separate in the network directory and local directory. The network directory and local directory also have different default policy settings.
To assign user rights to system policy changes
- Log into theFactoryTalkdirectory.
- InFactoryTalk Administration ConsoleExplorer, expandSystem>Policies>System Policies.
- Right-clickUser Rights Assignmentand selectProperties.
- InUser Rights Assignment Policies, next to the policy to secure and to the right ofConfigure Security, selectBrowse(...).
- InConfigure Securable Action, on thePolicy Settingtab, selectAdd.Select User or Groupopens.
- (optional) Use the filter options to restrict the accounts shown in the lists.
- Choose the user or group account, then selectOK. The user or group is added to the list on thePolicy Settingtab.
- To allow the user permission to perform the action from the specified computer or group, selectAllow.
- To deny the user permissions to perform the action from the specified computer or group, selectDeny.
- To remove explicitAllowpermissions, select the user and computer and selectRemove. If no permissions are specified,Denyis implied.
- When finished, selectOKto apply the policy changes.
Provide Feedback