earth_america
user_standard Log on
earth_america
Log on to rate and give feedback 1 2 3 4 5 Log on to rate
0
How to

How to


Products: Enterprise Central, Enterprise Server, Esmi Sense FDP
Functionalities: User Management
12/3/2024

Editing Command Permissions of User Account Groups

You editcommand permissions of user account groups to modify access and user operations in the EcoStruxure Building Operation software.

Show More
action_close

You use command permissions to configure exceptions from path permissions. You can set the following permissions for a command: no setting, deny, allow.

  • No Setting: ​No Setting is the default command permission setting. No Setting means that the Command property in the path permission, for the folder where the object is located, decides whether the user has permission to modify the object or not.

  • Deny: Users are not allowed to use the command.

  • Allow: Users are allowed to use the command.

Examples

You allow a user account group only to add comments to trend log records. All other command permissions for trend logs have the Deny permission. Users with the Deny command permission can comment on existing records but are not allowed to perform other actions such as adding records or clearing the trend log. This assumes that the users have path permission to access the trend logs.

In another example, the user account group has the path permissions read, write, create, delete, edit, force, and command to a folder that contains BACnet objects. To prevent the users in the user account group from ​updating the BACnet firmware, you use the Deny command permission for this action. All other command permissions are changed to No Setting. Due to the full set of path permissions, the users can perform all commands on BACnet devices, but not update the firmware.

 
action_zoom_plus_stroke The user account group has full permission to open and modify BacNet objects, beside performing firmware update.
Figure: The user account group has full permission to open and modify BacNet objects, beside performing firmware update.

In afinal example, the user account group has the path permission Read to the Enterprise Server. To enable the users in the user account group to perform all commands on trend logs in the system, you change all the command permissions on the Trends category to Allow.

A user account can be a member of several user account groups with different permissions. The priority between different permissions follow a set of permission rules. You can use these permission rules to manage the type of data and commands the user has access to within a workspace, panel, or domain. For more information, see Software Permissions Rules Management .

To edit command permissions of a user account group
  1. In WorkStation, in the System Tree pane, select the EcoStruxure BMS server you want to configure.

  2. Click the Control Panel tab.

  3. Click Account management .

  4. In the account management control panel, in the Domain list box, select the domain the user account group belongs to.

  5. In the User Account Groups list box, select the user account group, you want to edit command permissions of.

  6. In the User Account Groups area, click Software permissions .

  7. In the Permissions tab, in the Command Permissions area, in the Category column, select a category that you want to edit permissions for.

  8. In the Command column, select a command.

  9. In the Permission list for the command, select a permission.

  10. Click the Save button

     
    action_zoom_plus_stroke
    .

  • Command Permissions
  • Command Permissions Rules
  • Software Permissions, User Accounts, and User Account Groups
  • Assigning Command Permissions to User Account Groups
  • Removing Command Permissions from User Account Groups