SCADA Engineering · Technical Blog

WinCC SCADA User Administration and Security: Roles, Rights and Audit Trail

A SCADA station sits in a control room where anyone can reach it. This lesson configures the WinCC User Administrator, applies authorisation levels to screen objects, and turns on the audit trail that records who did what.

2,500+ engineers trained 4.9/5 Google rating 21+ years, Chinchwad, Pune Next batch: contact for dates
Quick answer

In WinCC, rights are numbered authorisation levels created in the User Administrator and assigned to user groups. Each object in Graphics Designer has an Operator authorisation property that references one of those levels. Add automatic logout, a password policy through SIMATIC Logon where required, and enable operation messages so every command is written to the alarm archive with the user name.

  • Authorisation levels are numbers assigned to groups; plan the numbering before you create fifty of them.
  • An automatic logout time is what actually enforces the rights you configured.
  • Operation messages turn the alarm archive into an audit trail at no extra engineering cost.

The WinCC User Administrator

Open User Administrator from WinCC Explorer. It holds user groups, users and the numbered authorisation levels that everything else references.

Create the authorisation levels first and keep the list short. A workable scheme for most plants:

LevelNameGranted to
1User administrationEngineering only
2Value inputSetters and above
3Process controlOperators and above
4Manual operationMaintenance and above
5Alarm acknowledgementOperators and above
6Archive and report accessSupervisors and above
7Configuration and runtime exitEngineering only

Then create groups such as Operator, Setter, Maintenance, Supervisor and Engineering, tick the levels each group holds, and add users to groups. Never grant levels to individual users directly; when someone leaves you want to delete a user, not audit fifty screen objects.

Each user also carries a logout time and, where configured, web access rights for Web Navigator clients.

Applying Authorisation to Screen Objects

An authorisation level does nothing until an object references it. In Graphics Designer, every object has an Operator authorisation property under Miscellaneous. Select the level that should be required to operate it.

Decide what to protect by consequence:

  • Always protect: manual and jog commands, mode changes, setpoint entry, counter and totaliser resets, recipe download, alarm suppression, runtime exit.
  • Usually protect: parameter screens, archive deletion, report configuration.
  • Leave open: screen navigation, trend viewing, alarm reading, report printing.

Locking navigation is a common overreach. An operator who cannot open a diagnostic screen phones maintenance for information that was on the screen all along.

Use the object's Enable property with a dynamic on the logged-in level so protected buttons appear greyed out rather than rejecting a login the operator will never have. The dynamics options are compared in WinCC Explorer operator controls.

Login, Logout and SIMATIC Logon

Runtime login can be triggered from a button calling the login dialog, from a hotkey, or from a chip card reader on stations that use one.

Automatic logout

Set a logout time per user, typically five to ten minutes for elevated groups. Without it, an engineering login stays active for the rest of the shift on an unattended station, and every right you configured is effectively public.

SIMATIC Logon

Where the site requires enforced password policy, WinCC can delegate authentication to SIMATIC Logon, which uses Windows user groups. That gives you central account management, password expiry, complexity rules and lockout after failed attempts, handled by IT rather than duplicated in the SCADA project.

RequirementHandled by
Simple operator groups on a standalone stationWinCC User Administrator alone
Central accounts shared with plant ITSIMATIC Logon with Windows groups
Password expiry and complexity rulesSIMATIC Logon and Windows policy
Electronic signature on critical actionsSIMATIC Logon with the audit option
Who changed a setpoint and whenOperation messages in the alarm archive

Set up WinCC security properly

SCADA sessions cover user administration, SIMATIC Logon, audit trails and handover documentation.

Book a Free Demo Class

Audit Trail and System Hardening

Enable the operation message on I/O fields and buttons that change the process. WinCC then writes a message to the alarm archive on every operation, recording the old value, the new value, the time and the logged-in user. That archive becomes your audit trail with no additional engineering.

Beyond user rights, a production SCADA station needs a few practical measures:

  • Disable runtime exit for everyone except engineering, and hide the Windows desktop and task bar behind the runtime.
  • Keep the engineering system on a separate machine from the runtime server where the licence permits.
  • Back up the project, the user administration data and the user archives, and test a restore before handover.
  • Control USB and remote access; a SCADA server is not a general-purpose PC.
  • Document the groups, levels, accounts and the date of the last restore test in the machine file.

The equivalent configuration at panel level is covered in HMI user administration and runtime settings.

Hands-On Lab: Secure a WinCC Station and Prove the Audit Trail

Hands-on
Before you start
  • WinCC Explorer with an existing project containing commands and setpoints
  • Rights to create users and groups on the station
  • Simulation only, no live plant control
  • Estimated time: 40 minutes
1

Create authorisation levels

In User Administrator, create the numbered levels for value input, process control, manual operation and user administration.

All levels are available for assignment to groups.
2

Create groups and users

Create Operator, Maintenance and Engineering groups with the appropriate levels, then add one user to each.

Each user inherits only the levels of its group.
3

Protect the objects

Set Operator authorisation on a jog button, a setpoint field and the runtime exit button.

Logging in as Operator leaves the jog button and setpoint unusable.
4

Set automatic logout

Give the Maintenance and Engineering users a five minute logout time and leave the station idle.

The session ends automatically and protected objects lock again.
5

Enable operation messages

Turn on the operation message for the setpoint field, change the value, and open the alarm archive.

The archive shows the old value, new value, time and user name.
Checkpoint—how to know you did it right

Rights come from groups, protected objects reject an unauthorised user, idle sessions log out on their own, and every setpoint change is recorded with a user name in the archive.

Frequently asked questions

How are rights structured in WinCC?

As numbered authorisation levels created in User Administrator and granted to user groups. Screen objects reference a level through their Operator authorisation property.

What does SIMATIC Logon add over the WinCC User Administrator?

Central authentication against Windows user groups, with password expiry, complexity rules and lockout handled by IT, plus the electronic signature option for regulated environments.

How do I create an audit trail in WinCC?

Enable operation messages on the objects that change the process. Each operation is written to the alarm archive with the old value, new value, timestamp and user name.

Why is automatic logout important on a SCADA station?

Because a control room PC is physically accessible. Without a logout time, an elevated login stays active after the engineer leaves, and the configured rights stop meaning anything.

Reviewed by Bhawesh Kumar SinghIndustrial Automation Trainer and Industry 4.0 Consultant · Softwell Automation · 21+ years industry experience

Get the full syllabus + free demo class

Share your details—a Softwell training advisor will contact you with batch dates, fees and hardware-practice options.

No spam. Used only to share course details for this enquiry.

Learn with practical industrial examples

Join live online, Pune classroom or corporate in-plant automation training.

Request Course Details
Verified learning pathway

Discuss WinCC SCADA User Administration

Explore practical curriculum, software, hardware and batch options for this technology.

Content reviewed: 09 September 2026

Siemens PLC & TIA Portal Learning Path

Continue with the related Siemens PLC tutorials in this practical learning series.

  1. SCL vs Ladder Logic
  2. Upload PLC Program
  3. TIA Selection Tool
  4. Analog Input Scaling
  5. PLC Counters
  6. PLC Timers
  7. Addressing & Data Types
  8. Hardware & PLC Tags
  9. OB, FB, FC & DB
☎ Call WhatsApp ✉ Email Enquire Now