Exercise 7: Selectively Secure PI AF Elements

Document created by jkim Employee on May 31, 2018
Version 1Show Document
  • View in full screen mode

Exercise 7 - After watching Create, Map, & Grant Permissions to Custom Identities in AF Server 2015, open PI System Explorer on the PISRV01 (or on a client node) and use it to connect to the PI Asset Framework Server on PIAF01. Once you've connected, demonstrate your understanding of PI AF security by configuring security in the following way:


The active directory group 'All Company' should be able to see the element 'Company Finances', and both 'Production Line' elements within the 'PaperCo' parent.

The active directory group 'Consultants' should be able to see and edit both of the 'Production Line' elements, but not even be able to see the 'Company Finances' element.


To test your configuration you log in to PI System Explorer using the following two accounts:

  • pischool\iuser as a member of the active directory group 'All Company'.
  • pischool\sconsultant as a member of the active directory group 'Consultants'.


If you are not using the Configuring PI Data Archive Security - Cloud Environment, use domain accounts and active directory groups that you're familiar with to customize access to different elements in an AF database.