Shared Operator account for windows login and individual operator accounts.

I would like to know the pros and cons of having one shared Windows and Deltav database account for operators without DeltaV keys specifically in OWS hosted by Thin Clients.

The goal is that the shift operators can seamlessly log in and log off using their accounts without the need to fully log off from Windows.

2 Replies

  • I have seen this done in many plants. I do not know of any downsides. Most plants have just one operator account in Windows and DV... operators never have to log in and out. I'm not saying this is the best, but it is quite common.
  • I'd say that's a common approach and supported by Emerson. The Windows log on provides you file security access on the computer. All DeltaV accounts are in the DeltaV group and the normal applications like Explorer, Diagnostics, Operate/Live, PHV etc can all be launched if the Windows user is in the DeltaV group. Some applications may require you to log on as a higher privileged user, or to "Run As Administrator" at which point you provide the elevated credentials without having to log off and back on as that user. Supervisors, other operators, Technicians, engineers can all log on to their DeltaV user to get their respective DeltaV privileges without having to log off the windows account.

    A non-privileged DeltaV user is also often used to auto logon and launch DeltaV HMI bring the console up to the default HMI screens ready for an operator to log on.

    Generally, operators are responsible for their consoles and anything done on them. If you choose to not have individual accounts, responsibility falls on the personnel at site during the shift. Individual logons allow individuals to secure the consoles if they have to leave them, and allows all changes to be attributed to the user identified in the event records. Cybersecurity best practices are to have individual users log on to make changes and for consoles to be locked when not actively used/monitored. The Screen saver of the console can be used to log off the current user and log on a view only user while keeping the HMI screens visible. It all depends on what works for each customer.

    Andre Dicaire