Security model differences: PI AF and Data Archive
- Last UpdatedMay 21, 2025
- 1 minute read
- PI System
- PI Server 2024 R2
- PI Server
Although the PI Asset Framework (AF) security model is similar to that which Data Archive uses, there are a number of differences:
-
The Deny privilege is supported. See Scenarios for using the Deny permission option.
-
A more expansive set of access permissions is available. See List of access permissions.
-
The equivalent of PI user and PI group identities are not supported.
-
PI trusts and PI explicit logins are not supported.
-
The concept of an undeletable flag on an identity or mapping is not supported.
-
Mappings cannot be disabled. Only PI AF identities can be disabled.
-
A single Windows user identity can be mapped to more than one PI AF identity.
-
An Identity provider role can be mapped to multiple PI AF identities.
-
A different built-in set of identities is installed: Administrators, Engineers, and World.