Configure security for PI Data Archive
- Last UpdatedJul 29, 2025
- 1 minute read
- PI System
- Interfaces
If you are running PI Data Archive 3.4.380.36 or later, you can take advantage of its support for Windows Integrated Security by running the interface service using a Windows account that has the required permissions on the PI Data server. To configure Windows Integrated Security, use PI System Management Tools (PI SMT) to define a mapping that assigns a PI identity that has the required permissions to the user or user's group.
For pre-3.4.380.36 versions of the PI Data Archive, you must create a PI trust for the user who runs the interface and configuration tool. For tightest security, limit the trust to the hostname or IP address of the interface node and the application name (BIFConfig.exe for the PI Event Frames Interface Manager).
If you are installing the interface on a node other than the PI Data server, you must create trusts to ensure that the configuration tool and the interface have access to the server.
-
To create a trust, launch PI System Management Tools and connect to the target server.
-
Select Security.
-
Select Mappings & Trusts.
-
Right-click within the Trusts tab.
-
Select New Trust to launch the Add Trust wizard.
-
Enter a meaningful name and description for the trust.
-
Configure the following settings:
Program
Type of Trust
Application Name
PI Event Frames Interface Manager
PI-API application
BIFConfig.exe
Interface executable
AF SDK application
Executable name