Configure for RSLogix products using a domain

These instructions assume that the FactoryTalk AssetCentre agent software has been installed
and that all RSLogix software programs that will be used in the system have also been installed on each agent computer. The status bar in the FactoryTalk AssetCentre desktop client shows the number of agent computers currently in the system. For complete instructions on adding an agent, select
Help > Installation Guide
to see the
FactoryTalk AssetCentre Installation Guide
.
To configure for security-enabled RSLogix products using a domain
  1. Create a domain account for the FactoryTalk AssetCentre AgentController and Verification Agent services to run as. This is generally performed by someone in your Information Technology department. This account must be used exclusively for the service, not by users.
    • Add the new domain account to the Administrator user group in Windows.
    • Configure both services to run as the new domain account. To do so, open the Services utility in Microsoft Windows, find the FactoryTalk AssetCentre AgentController service and edit its properties to log on as the new domain account. Find the Verification Agent service and edit its properties to log on as the new domain account.
  2. On any computer in the system, open the FactoryTalk Administration Console (logging on to the Network directory using a FactoryTalk Administrator account) and add the new domain account as a new Windows-linked user.
  3. Grant this user read access to the FactoryTalk Directory. To do so, right-click the
    Network
    node and select
    Security
    . On the
    Permissions
    tab, select the domain account and then expand the
    Common
    permissions group. Make sure the
    Read
    permission is set to
    Allow
    .
  4. Set permissions for RSLogix software (depending on what type of processors you are using). Under
    System
    in the
    Explorer
    pane, right-click
    Networks and Devices
    and select
    Security
    . On the
    Permissions
    tab, select the new domain user. Expand the permissions group for the RSLogix software and set the following permissions to
    Allow
    :
    • For RSLogix 5 grant Offline Program File Monitoring, Save, and Upload.
    • For RSLogix 500 grant Offline Program File Monitoring, Save, and Upload.
    • For RSLogix 5000 grant Project: Open, Project: Save, Project: Go Online, Project: Upload, and Project: Export. (Use this group for Logix Designer application and grant the same permissions.)
  5. Configure FactoryTalk Security to use single sign-on. Still in the FactoryTalk Administration Console, navigate to
    System > Policies > System Policies
    in the
    Explorer
    pane. Double-click
    Security Policy
    . Set the
    Use single sign-on
    policy to
    Enabled
    .
Provide Feedback
Have questions or feedback about this documentation? Please submit your feedback here.
Normal