Modify the Members of a Security Role
- Last UpdatedSep 12, 2025
- 3 minute read
The Security Roles page under Plant SCADA in Configurator lists the available Plant SCADA Roles, depending on the components you have selected during Plant SCADA installation.
By default, the Windows® User Groups created by the Plant SCADA installer are associated with these roles (see the information on Windows User Groups and Security Roles in the topic Installation Information).
If required, you can change the members that are associated with each security role. You can also delete the default groups and replace them with your own.
Add local or domain groups to a security role:
-
Open the Configurator.
-
From left side panel, select Plant SCADA | Security Roles.
-
Select a security role displayed in the table. The existing members associated with the role will be listed in the Members of... section.

-
To add more members to the security role, click Add. The Select Users or Groups dialog box opens.
-
Under Enter the object names to select type the name of local or domain group, that you want to assign to the role, and then click OK.

You can use the Check Names button to verify if the entered names are valid.
Note: You can add a maximum of 10 members to a security role. To manage the memberships through normal Windows group management practices, it is recommended that you add a minimal number of members per security role. It is ideal to have one domain group per role.
Remove local or domain groups from a security role:
-
From left side panel of the Configurator, select Plant SCADA | Security Roles.
-
Select a security role from the table. The existing members associated with that role will be listed in the Members of... section.
-
Select the member that you want to remove from the role.
-
Click Remove.
The Plant SCADA Runtime Manager service account is not removable from the Server Users role.
Note: When removing members from the security roles, make sure that each role has at least one member before you apply the changes.
Applying the Changes in Security Roles:
After modifying the members of a security role, stop all the other Plant SCADA processes and services, then click Configure to apply the changes. This will update the security on Plant SCADA's folders and registry keys to match the new members of each role.
Note: If the Configurator displays the error message "security roles could not be updated as one or more processes are running”, you can double-click on it to see all the applications that need to be manually closed and started, as well as any services that need to be restarted.
Resetting the Members of Security Roles:
To reset all security roles to their default members, click Reset All from the Security Roles page. Stop all the other Plant SCADA processes and services, then click Configure to apply the changes. Any default user groups that no longer exist will be recreated.
Discarding the Changes in Security Roles:
If you have not applied the changes after any modification and want to undo them, click Close and Exit Configurator.