Configure a secondary security authority
Use the
Controller Properties dialog box - Security
tab to configure a secondary security authority for a project that is already protected by a primary security authority. Configure a secondary security authority to further restrict Guest Users beyond the permissions granted by the primary security authority. A secondary security authority cannot grant permissions that are denied by the primary security authority.When a project is protected by a primary security authority, this message appears at the top of the
Controller Properties dialog box - Security
tab for a Guest User:This project is secured by a Primary Security Authority, limiting permitted actions. Additional security is configured here.
To configure a secondary security authority:
- In theController Organizer, select the project name at the top of the pane and selectProperties.
- In theController Properties dialog box, select theSecuritytab.
- In theSecurity Authoritybox, select.FactoryTalk SecurityWhen selected for the Secondary Authority, additional Guest User permissions from the Secondary Authority within the project are not cached. Only Guest User permissions from the Primary Authority are stored within the project.
- To associate this project with a specific Security Authority, select theUse only the selected Security Authority for Authentication and Authorizationcheck box. When this check box is selected, users interacting with this project must be authenticated and authorized by either the primary or the secondary Security Authority.IMPORTANT:Before associating this project with a specific Security Authority,Rockwell Automationrecommends backing up theFactoryTalk Directoryand save unsecured versions of this project file in (. ACD) or (.L5X or .L5K) formats. For details about backing up aFactoryTalk Directory, seeFactoryTalkHelp:Start > Programs > Rockwell Software >.FactoryTalkTools >FactoryTalkHelp
TIP:The secondary Security Authority can only further deny permissions that are allowed by the cached Guest User permissions. The secondary Security Authority cannot grant permissions that are denied by the cached Guest User permissions. - SelectOK.
Provide Feedback