Welcome to the new Schneider Electric Community

It's your place to connect with experts and peers, get continuous support, and share knowledge.

  • You may be familiar with Communities' brand new layout from SE.com.
  • Don't forget to update your bookmarks and saved links with our new address (https://community.se.com/).
  • If you encounter any issues, please contact SchneiderCommunity.Support@se.com.
Close
Sign In Help
Important Announcement: WELCOME to the Schneider Electric Community! We have moved to a new address: community.se.com — bookmark it today and contact SchneiderCommunity.Support@se.com if you have any questions!
Schneider Electric
Help
Ask the Community Community Guidelines Community User Guide How-To & Best Practices Contact Support
Login / Register
Community Menu
  • Community Home
  • Forums
    • By Topic
        • Support
          • Ask the Community
        • EcoStruxure Building
          • SmartConnector Forum
          • Field Devices Forum
        • EcoStruxure Power & Grid
          • EcoStruxure Energy Hub User Group
          • Gateways and Energy Servers
          • Metering & Power Quality
        • APC UPS, Critical Power, Cooling and Racks
          • APC UPS Data Center & Enterprise Solutions Forum
          • APC UPS for Home and Office Forum
        • EcoStruxure IT
          • EcoStruxure IT forum
        • Remote Operations
          • EcoStruxure Geo SCADA Expert Forum
          • Remote Operations Forum
        • Industrial Automation
          • Industry Automation and Control Forum
          • Industrial Edge Computing Forum
          • Alliance System Integrators Forum
          • Machine Automation Forum
          • EcoStruxure Automation Expert / IEC 61499 Forum
          • AVEVA Plant SCADA Forum
          • Modicon PAC Forum
          • Harmony Control Customization Forum
          • Level and Pressure Instrumentation Forum
          • PLC Club Indonesia
          • Fabrika ve Makina Otomasyonu Çözümleri
          • Motorabgangstechnik & Antriebstechnik Forum
          • Korea Industrial Automation Forum
        • Schneider Electric Wiser
          • Schneider Electric Wiser Forum
        • Power Distribution IEC
          • Power Distribution and Digital
          • Solutions for Motor Management
          • Paneelbouw & Energie Distributie
          • Eldistribution & Fastighetsautomation
          • Elektrik Tasarım Dağıtım ve Uygulama Çözümleri
          • Електропроектанти България
          • Specifiers Club ZA Forum
        • Power Distribution NEMA
          • Power Monitoring and Energy Automation NAM
        • Power Distribution Software
          • EcoStruxure Power Design Forum
          • LayoutFAST User Group Forum
        • Solutions for your Business
          • Solutions for your Business Forum
      • Support
        • Ask the Community
      • EcoStruxure Building
        • SmartConnector Forum
        • Field Devices Forum
      • EcoStruxure Power & Grid
        • EcoStruxure Energy Hub User Group
        • Gateways and Energy Servers
        • Metering & Power Quality
      • APC UPS, Critical Power, Cooling and Racks
        • APC UPS Data Center & Enterprise Solutions Forum
        • APC UPS for Home and Office Forum
      • EcoStruxure IT
        • EcoStruxure IT forum
      • Remote Operations
        • EcoStruxure Geo SCADA Expert Forum
        • Remote Operations Forum
      • Industrial Automation
        • Industry Automation and Control Forum
        • Industrial Edge Computing Forum
        • Alliance System Integrators Forum
        • Machine Automation Forum
        • EcoStruxure Automation Expert / IEC 61499 Forum
        • AVEVA Plant SCADA Forum
        • Modicon PAC Forum
        • Harmony Control Customization Forum
        • Level and Pressure Instrumentation Forum
        • PLC Club Indonesia
        • Fabrika ve Makina Otomasyonu Çözümleri
        • Motorabgangstechnik & Antriebstechnik Forum
        • Korea Industrial Automation Forum
      • Schneider Electric Wiser
        • Schneider Electric Wiser Forum
      • Power Distribution IEC
        • Power Distribution and Digital
        • Solutions for Motor Management
        • Paneelbouw & Energie Distributie
        • Eldistribution & Fastighetsautomation
        • Elektrik Tasarım Dağıtım ve Uygulama Çözümleri
        • Електропроектанти България
        • Specifiers Club ZA Forum
      • Power Distribution NEMA
        • Power Monitoring and Energy Automation NAM
      • Power Distribution Software
        • EcoStruxure Power Design Forum
        • LayoutFAST User Group Forum
      • Solutions for your Business
        • Solutions for your Business Forum
      • Food & Beverage
      • Healthcare
  • Knowledge Center
    • Building Automation Knowledge Base
    • Geo SCADA Knowledge Base
    • Industrial Automation How-to videos
    • Digital E-books
    • Success Stories Corner
  • Success Stories
  • Events & Webinars
    • All Events
    • Innovation Talks
    • Innovation Summit
    • Let's Exchange Series
    • Technology Partners
    • Power Events & Webinars 
    • Partner Success
    • Process Automation Talks 
  • Ideas
        • Remote Operations
          • EcoStruxure Geo SCADA Expert Ideas
          • Remote Operations Devices Ideas
        • Industrial Automation
          • Modicon Ideas & new features
  • Blogs
    • By Topic
        • EcoStruxure Power & Grid
          • Backstage Access Resources
        • Remote Operations
          • Remote Operations Blog
        • Industrial Automation
          • Industry 4.0 Blog
          • Industrie du Futur France
        • Power Distribution NEMA
          • NEMA Power Foundations Blog
        • Knowledge Center
          • Geo SCADA Knowledge Base
          • Industrial Automation How-to videos
          • Digital E-books
          • Success Stories Corner
      • EcoStruxure Power & Grid
        • Backstage Access Resources
      • Remote Operations
        • Remote Operations Blog
      • Industrial Automation
        • Industry 4.0 Blog
        • Industrie du Futur France
      • Power Distribution NEMA
        • NEMA Power Foundations Blog
      • Knowledge Center
        • Geo SCADA Knowledge Base
        • Industrial Automation How-to videos
        • Digital E-books
        • Success Stories Corner
Invite a Co-worker
Send a co-worker an invite to the Exchange portal.Just enter their email address and we’ll connect them to register. After joining, they will belong to the same company.
You have entered an invalid email address. Please re-enter the email address.
This co-worker has already been invited to the Exchange portal. Please invite another co-worker.
Please enter email address
Send Invite Cancel
Invitation Sent
Your invitation was sent.Thanks for sharing Exchange with your co-worker.
Send New Invite Close
  • Communities
  • :
  • Knowledge Center
  • :
  • Building Automation Knowledge Base
  • :
  • Integrating Windows Active Directory user accounts with EcoStruxure
How can we help?
cancel
Turn on suggestions
Auto-suggest helps you quickly narrow down your search results by suggesting possible matches as you type.
Showing results for 
Show  only  | Search instead for 
Did you mean: 
82752members
350531posts

Integrating Windows Active Directory user accounts with EcoStruxure

Back to Building Automation Knowledge Base
Options
  • Article History
  • Bookmark
  • Subscribe
  • Email to a Friend
  • Printer Friendly Page
  • Report Inappropriate Content
0 Likes
7163 Views
Trying to translate this page to your language?
Select your language from the translate dropdown in the upper right. arrow
Translate to: English
  • (Français) French
  • (Deutsche) German
  • (Italiano) Italian
  • (Português) Portuguese
  • (Русский) Russian
  • (Español) Spanish
Share

Integrating Windows Active Directory user accounts with EcoStruxure

Picard Product_Support
‎2020-11-04 03:42 PM

Last Updated: Spock RobertAndriolo Spock ‎2021-10-11 04:49 PM

Issue

Setting up, using, and troubleshooting Windows Active Directory with Building Operation Workstation and WebStation.

Product Line

EcoStruxure Building Operation

Environment

  • Building Operation Enterprise Server
  • Building Operation WebStation
  • Windows Active Directory
  • Windows Server

Cause

When integrating EcoStruxure with Windows Active Directory, NO user accounts need to be created in EcoStruxure, all that needs to be done is map the EcoStruxure User Account Group(s) with the Windows group(s) that will be used. 

  • You can map Windows Active Directory groups to Building Operation user account groups if Building Operation runs on a network that uses this directory to manage users and user account groups.
  • A Building Operation user account group that includes a Windows account group can also be a member of another Building Operation user account group.
  • Mapping Windows Active Directory account groups to Building Operation user account groups has advantages both for administrators and operators. Administrators can manage the user accounts in the Windows Active Directory, rather than managing the accounts in two places. Any changes are instantly implemented to the mapped Building Operation user account group. Operations only have to remember the Windows login. Once logged in to a Windows user account that is mapped to a Building Operation account, the user is authenticated to access WorkStation without having to log in a second time.

Note:

  • The Building Operation domain used to map the Windows Active Directory user account groups must be a member of the Windows domain where the Active Directory is located.
  • Windows Active Directory account groups can only be mapped on servers that are based upon Microsoft Windows operating system. Automation Servers, cannot map Windows Active Directory groups. For example, the Windows Active Directory user account groups Main Admin and Main User are mapped to the Building Operation user account groups Administrators and External Users. The External Users user account group is a member of the Operator user account group. The Administrators account group, which is a member of the External Users, inherits access to the Operation workspace.
  • The user will then log into Windows on the PC where the WorkStation is installed. When logging into EcoStruxure Workstation the authentication is automatically done from the Windows user account.

Resolution

NOTE: Active Directory association cannot be achieved using the inbuilt Local Domain

  1. Create a new EBO Domain and associate it with your active windows Domain.AD Domain.png
    NOTE:
    It is best to only use the Domain (Netbios) name (as shown above) when adding the Windows Domain name to this property.  Using the full DNS Domain name, for example, eur.gad.schneider-electric.com will cause issues when utilizing other features that require active directory authentication.  One example where this has been identified is with Change Control.  
  2. Create an EBO Domain Group within that new Domain and associate it with the Windows Domain Group in which the Windows Active Directory user(s) reside.Ad Group.png
  3. Log in using Windows Username, Password, and Domain rather than EBO credentials. When logged on to the Enterprise Server PC as a Domain User it is also possible to select the "Log on as" box.

See WebHelp:

  • How to Create and Configure a Domain
  • Conceptual Information on Windows Active Directory User Groups
  • How to Create User Account Groups

Troubleshooting Windows Active Directory with Workstation

  1. Log in Error: Wrong user name or password
    Wrong password.png
  2. If the EcoStruxure Building Operation Domain has the same name as the Windows Active Directory domain name, it will expect the user account to exist locally in the Building Operation domain.
    EBO_Domain.png
  3. Log in Error: "User account not associated with a group. Contact your Administrator."
    Missing Group.png
  4. Verify that the Windows user is a part of the Windows group configured in the Building Operation Group settings. In order to identify every group that the current windows user belongs to, run the command: whoami /groups
    whoami_groups.png
  5. Once the Windows user has been confirmed as a member of the configured Windows group, try changing the Log On as credentials for the Enterprise Server service. The default user that is used when installed is the "Local System account". The Windows account used to run the Enterprise Server service needs "read access" to all places (e.g. OUs) in the Active Directory where user groups potentially involved in an EBO Windows log-on can be found.

    Note: By default, all domain users in an Active Directory have read access to Active Directory "Users and Computers" objects so it is the sites that have restricted this in some way that may face issues. You do not need to use “domain admin” type accounts for this as they are granted way too much authority in general. An account that has read access to sufficient parts of the AD while having only normal local user privileges on the machine where the Enterprise Server is running will suffice.
    1. From the Windows Start menu, launch Computer Management. In Computer Management go to Services and Application > Services.
    2. Find Building Operation X.X Enterprise Server, select it and Stop the service.
      Services.png
    3. Right-click on Building Operation X.X Enterprise Server and go to Properties. Select the Log On tab.
    4. Under Log On as select "This account". Enter a Windows user login that has sufficient Windows rights for the Enterprise Server to log on as.
      Service_Account.png
    5. Click OK and then start the service again.
    6. Log in to Workstation again using Active Directory.

Troubleshooting Windows Active Directory with WebStation

From version 1.5.0 and up, using Windows Domain accounts is supported in WebStation. However, the following must be done in order to log in.

  1. Must use HTTPS.
  2. Must enter your Windows username and password.
  3. Must enter the domain as the Windows domain as defined within Building Operation.  See below:

    AD_DNSDomainName.png

    An example log-on format is shown below when using the above configuration when using WebStation:
    WebStationLoginExample.png  
    Alternatively, if the following is configured in Building Operation:
    AD-WindowsDomain#2.png

    WebStation log-on will look as follows: 
    AD_WebStationLogon.png

Download a TVDA for Single Sign-On Instructions

Labels (1)
Labels:
  • EcoStruxure Building Operation
Attachments
Tags (6)
  • Find more articles tagged with:
  • 12985
  • CraigEllis20
  • DavidKendrick19
  • JonathanHernandez20
  • RobertAndriolo20
  • RobertAndriolo21
Was this article helpful? Yes No
100% helpful (6/6)
Share

Related Forums

  • Field Devices Forum
Previous Next
Contributors
  • RandyDavis
    RandyDavis
  • RobertAndriolo
    RobertAndriolo
  • David_Kendrick
    David_Kendrick
  • Jonathan
    Jonathan
  • DavidFisher
    DavidFisher
  • CraigEl
    CraigEl
  • Product_Support
    Product_Support
  • Derrick_Ratliff
    Derrick_Ratliff
  • Alan_Wood
    Alan_Wood
  • StephenYang
    StephenYang
  • Benji
    Benji
Invite a Colleague
Found this content useful? Share it with a Colleague!
Invite a Colleague

Forums

  • APC UPS Data Center Backup Solutions
  • EcoStruxure IT
  • EcoStruxure Geo SCADA Expert
  • Metering & Power Quality
  • Schneider Electric Wiser

Knowledge Center

Events & webinars

Ideas

Blogs

Get Started

  • Ask the Community
  • Community Guidelines
  • Community User Guide
  • How-To & Best Practices
  • Experts Leaderboard
  • Contact Support
 
  • twitter
  • facebook
  • linkedin
  • youtube
  • blog
  • instagram
Subscribing is a smart move!
You can subscribe to this forum after you log in or create your free account..

Create your free account or log in to subscribe to the forum - and gain access to more than 10,000+ support articles along with insights from experts and peers.

Register today for FREE

Register Now

Already have an account?Login

Privacy Notice Terms of Use Customize Preferences
© 2022, Schneider Electric