Define Whether any Permissions are Restricted

You use the Permission Restrictions settings on the Server Configuration Tool to control access on a server-wide basis. For example, you can remove the Acknowledge Alarms permission for every client that is connected to the server.

The Permission Restrictions settings are grouped as follows:

The main advantages of using the Permission Restrictions settings are that they allow you to:

The Permission Restrictions settings override other security settings. So, if you have enabled the Configure permission in a ViewX user account, but you have also selected the Configure check box for ViewX in the Permission Restrictions, that user will be unable to configure database items. Users can only access features for which their user accounts provide sufficient permissions and that are not restricted via the Permission Restriction settings.

We recommend that you assess which permission restrictions are appropriate for each server, based on its role in your system and the system's operational requirements, and then configure the required restrictions accordingly.

To configure the Permission Restrictions settings:

  1. Access the Geo SCADA Expert Server Configuration Tool.
  2. Expand the required system and node.
  3. Expand the System Configuration branch.
  4. Select the Permission Restrictions entry. 

    On a Permanent Standby server, only configure these settings if they are not inherited from the Permanent Standby Permission Restrictions settings on the Main server.

    The settings will be inherited if, in the Partners section on the Main server, the Enabled check box is selected in the Permission Restrictions section of the Permanent Standby tab for the Permanent Standby server. For more information, see Specify Whether a Permanent Standby Server Inherits its Permission Restriction Settings and see Permanent Standby Permission Restrictions Tab.

  5. In the Server Denied Permissions section, select the check boxes for those permissions that are to be denied on each type of client that accesses the system via the server, including ViewX and Virtual ViewX clients, and Original WebX clients. Features that are denied in this section do not appear in the security properties for any item in the database. By default on new installations, four permissions are restricted via the Server Denied Permissions section of the tool (Unacknowledge Alarms, Assign Alarm Responsibility, Off/On Scan, and Cancel Request). Depending on the role of the installed server, these restrictions may, or may not, be appropriate. For example, it is likely that you may want to remove the 'Cancel Request' restriction from those servers that might go Main, but leave it in place for Permanent Standby servers.

    For improved security, we recommend that you restrict other permissions in accordance with your operational requirements. However, take care when denying permissions in this section, as you may accidentally prevent users from being able to work with your Geo SCADA Expert system.

  6. In the ViewX User Denied Permissions section, select the check boxes for those permissions that are to be denied on ViewX clients that are connected to the server. For example, if you select the Exclusive Control permission, ViewX users will be unable to access the Exclusive Control features, even if their user accounts allow them to use Exclusive Control features.

  7. In the Virtual ViewX User Denied Permissions section, select the check boxes for those permissions that are to be denied on Virtual ViewX clients that are connected to the server. This section only applies when the Virtual ViewX server is running in Full Virtual ViewX mode (see Mode of Operation of a Virtual ViewX Server). When running in this mode, users with the relevant permissions and access can make database configuration changes using Virtual ViewX clients (see Differences Between the Virtual ViewX Client and ViewX).

  8. In the WebX/Operator ViewX User Denied Permissions section, select the check boxes for those permissions that are to be denied on Virtual ViewX and Original WebX clients that are connected to the server. These permissions only apply to Virtual ViewX clients when the Virtual ViewX server is running in Limited Virtual ViewX/Operator mode (see Mode of Operation of a Virtual ViewX Server).

    NOTE: Certain features are not available in Original WebX. If you select the Control permission, Original WebX users will be unable to issue controls even if their user accounts allow them to issue controls (see Configuring Security and Connection Settings for Original WebX Clients).

  9. In the Standard Pick Menu Denied Permissions section, select the check boxes for those permissions that are to be denied for standard pick action menu options. The permissions you select will affect the standard pick action menu on ViewX and Virtual ViewX clients that are connected to the server. For example, if you select the Acknowledge Alarms permission, the Acknowledge Alarms action will be unavailable via the standard pick action menu on both ViewX and Virtual ViewX.

  10. When you have completed the required sections, right-click on the system icon in the Server Configuration Tool and select the Apply Changes option from the context-sensitive menu.
  11. Restart the server.
  12. Repeat this procedure for each system as required.

You cannot restrict the Read, Browse, Security, or System Admin permissions via the Permission Restrictions settings (as incorrect use of these permissions could result in users being unable to access key features or view the database). However, you can assign or deny the Read, Browse, Security and System Admin permissions on a per item basis via each item’s Security window.

You can configure Permanent Standby servers to inherit their Permission Restrictions from the Permanent Standby Permission Restrictions settings that are configured on the Main server (see Permanent Standby Permission Restrictions Tab). In such cases, Geo SCADA Expert ignores the settings that exist in the Permission Restrictions section of the Server Configuration Tool on those Permanent Standby servers.

Further Information

For information about the permissions themselves, see Permissions for Database Items.

View the current status of a server's server-wide Permission Restrictions: see Privileges.


Disclaimer

Geo SCADA Expert 2022