Using FactoryTalk View security codes with HMI project components
If you install FactoryTalk View SE with the standard FactoryTalk Directory mode, the user
group account, All Users, is created automatically at the FactoryTalk Local Directory and
Network Directory. When you create a local or network distributed application, the account
is added automatically to the Runtime Security accounts list for the application. By
default, the All Users account is granted all FactoryTalk View runtime security codes (A -
P), and all FactoryTalk Security actions at the root directory node.
In FactoryTalk View, you can restrict runtime access to commands and macros, graphic displays, OLE object verbs, and HMI tags. To do this, you assign FactoryTalk View security codes to the components you plan to restrict access to, then set up individual users or user groups and assign the access codes they will need to have access to the secured components.
Also, for the All Users account, you will have to remove the codes you do not want all users to have access to.
There are 16 FactoryTalk View runtime security codes, A through P, and the asterisk symbol (*), that can be assigned to components. The asterisk represents all sixteen security codes. When it is assigned to a component, it means that all users who have been assigned any security code have access to the component.
To modify the security codes assigned to users and user groups:
- InFactoryTalk View SE, in theExplorerwindow, double-clickRuntime Security.
- In theRuntime Securitydialog box, clickSecurity Accounts.
- In theSecurity Settingsdialog box, in thePermissionstab, theUserview is selected by default. This displays the users and user groups that have been added to the Runtime Security editor, and, for network distributed applications, the computer or computer group they have access to.
- Click a user or group to select it. The security permissions that are currently assigned to the selected user are shown inPermissions forfield at the bottom section of thePermissionstab.
- Click the box besideFactoryTalk View Security Codesto expand the list.
- Check or clear the Allow check boxes beside security codes in the list to change the security code permissions for the user or group.
To add a user or group account to the Runtime Security editor:
- In theSecurity Settingsdialog box,in the Permissionstab, clickAdd.
- In theSelect User and Computerdialog box you add users and user groups for a network distributed application.If you are working with a local station application, the dialog box is calledSelect User or Group.
Remarks
- If you plan to use FactoryTalk Security to secure actions such as creating and opening applications, creating and editing HMI project components, writing to tags, and so on, you will have to set up these permissions on the folders in the Explorer window using FactoryTalk Security.
- For more information about common actions and how to allow or deny access to them, see theFactoryTalk Services Platform Help.
- For more information about how these features are used in FactoryTalk View, and for examples of assigning FactoryTalk Security permissions to FactoryTalk View users and user groups, see Chapter 5 in theFactoryTalk View Site Edition User's Guide.
Provide Feedback