Please ensure Javascript is enabled for purposes of website accessibility
Powered by Zoomin Software. For more details please contactZoomin

AVEVA™ InTouch HMI

Configuring Users and Groups

  • Last UpdatedApr 22, 2025
  • 2 minute read

The Security dialog allows configuration of users and groups to be members of either the InTouchDevelopers or InTouchOperators roles.

To add and configure users and groups

  1. Launch the Application Manager as an Administrator.

  2. In the Tools menu, on the Tools tab, click Security.

    Security option in Tools tab

    The Security screen appears.

  3. Click the + Domain users and groups or + Local Users.

    The Select Users or Groups or Select Users dialog appears respectively.

    Note: Windows Active Directory (AD) users and groups, and Windows local users are supported. Windows local groups are not supported and may not be added.

  4. Enter the user or group name, and click OK.

    Note: You can search for users and groups by object name, type, or location. Click Check Name to ensure the selected object resolves to the AD name or group.

    The entered user or group appears in the Users and Groups grid.

  5. To assign the user/group as an InTouch Developer, select the checkbox in the InTouchDevelopers column.

  6. To assign the user/group as an InTouch Operator, select the checkbox in the InTouchOperators column.

  7. Click Save.

    Assign security users and groups

    By default, NT SERVICE\AIGWebServer and the current logged on user are added as members and NT SERVICE\aahSearchIndexer is added to InTouchOperators group.

    Security tab in new application properties

To delete users and groups:

  1. In the Users and Groups grid, select the entry to be deleted.

  2. Click the - icon.

    The selected user/group is deleted.

    Additional information

    • InTouchDevelopers and InTouchOperators are maintained as a local group on the machine.

    • InTouchDevelopers and InTouchOperators security permissions are not applied to NAD applications. Any application which is on a network path or mapped network drive is considered as a NAD application.

    • Any users added in the Security dialog from above will be added to the corresponding group.

    • Those groups are given access to each of the application folders for the Standalone InTouch Applications.

    • If a new application is created with the feature enabled, it will update the Access Control Lists of the folder with appropriate access for InTouchDevelopers and InTouchOperators.

    • Applications that are migrated will have the security permissions applied during the migration process.

    • If you open the application folder and view the folder properties, you may open the Security tab to view the access permissions that were applied.

    TitleResults for “How to create a CRG?”Also Available in