User rights assignment policies
In
FactoryTalk
, administrators control the rights that users have to access the system. Settings that apply to the entire FactoryTalk
directory are especially important to secure. User rights assignment policies specify which users are permitted to perform:- Back up or restoreThe default setting allows all users to back up and restore the directory and its contents. Securing backup and restore operations prevents an unauthorized user from:FactoryTalk Directory, the System folder, or applications.
- Copying applications or user account information in theFactoryTalksystem
- Intentionally or inadvertently overwriting the contents ofFactoryTalk Directory, including applications, user, computer, and group accounts, passwords, policy settings, and security settings
- Change theFactoryTalk Directoryserver computer.The default setting allows administrators to change the directory server. The policy appears in onlyFactoryTalknetwork directory. Verify the permissions to change the directory on the current computer and the computer being switched to.
- Switch between primary and secondary servers in a redundant pair. In theFactoryTalknetwork directory, the default setting allows all users to switch between primary and secondary servers (such as HMI servers or data servers). Because redundancy is available in only theFactoryTalknetwork directory, this policy setting appears in only theFactoryTalknetwork directory.
- Modify the security authority identifier.The default setting allows all users to modify the identifier.
Policy settings are completely separate in the network directory and local directory. The network directory and local directory also have different default policy settings.
Provide Feedback