Configuring SIMATIC Logon Autologin on WinCC OS Clients

David Krause12 min read
SiemensTutorial / How-toWinCC
Licensed PE Working through this on a live machine? A Maine-licensed engineer can take it from here — included with IMD hardware, by the hour for everything else. Book an engineer

1. Overview

SIMATIC Logon is the Siemens central user administration component that authenticates operators against Windows accounts and forwards role/authorization decisions to WinCC Runtime (RT Professional, RT Advanced, Comfort Panels, and OS clients in PCS 7). When properly configured, an operator seated at an OS client can start the WinCC runtime project without a manual login dialog. When the configuration is incomplete, the runtime presents a login box at startup and refuses to proceed until an interactive user is supplied.

This article documents the complete procedure for deploying a default user (the Operator in the source scenario) that is logged in automatically at runtime start. It covers:

  • Windows group provisioning (Simatic HMI)
  • WinCC User Administrator configuration (operator and coordinator groups)
  • The default-user VBScript for the SIMATIC Logon connection
  • Password storage in the SIMATIC Logon configuration database
  • Troubleshooting the most common causes of an unexpected login dialog

The reference workflow targets a WinCC OS client (single-user station) running WinCC RT Professional or PCS 7 OS with SIMATIC Logon V1.6 or later. Adjust paths and registry keys for older versions of the Logon Service.

2. SIMATIC Logon Architecture and Login Flow

SIMATIC Logon runs as a Windows service (SIMATIC Logon Service) and provides an in-process COM interface that WinCC Runtime calls to authenticate the current user. The login flow, as documented in the official Siemens TIA Portal V20 manual Central user administration using SIMATIC Logon, is:

  1. Runtime starts and reads the project-defined default user (from the Logon configuration script).
  2. Runtime invokes the SIMATIC Logon COM interface with the default user and password.
  3. SIMATIC Logon validates the credentials against the Windows Security Account Manager (SAM) or the Active Directory domain.
  4. On success, SIMATIC Logon reads the user's group memberships and returns them to the runtime.
  5. WinCC maps the Windows groups to its internal user groups (operator, coordinator, etc.) and applies the configured authorizations.
Architectural constraint: SIMATIC Logon does not store its own user database. The user must exist as a Windows account, and the Windows account must belong to a Windows group that WinCC knows about (either the built-in Simatic HMI group or a user-defined group mirrored in the WinCC User Administrator).

3. Prerequisites

Verify the following before configuring autologin:

Item Required Value Verification
SIMATIC Logon version V1.6 SP3 or later (V2.x for TIA V20) Control Panel > Programs > SIMATIC Logon
WinCC Runtime RT Professional V17 / V18 / V19 / V20, or PCS 7 OS V9.0/V9.1 WinCC Explorer > Help > About
Windows edition Windows 10 LTSC 2019/2021 or Windows Server 2016/2019/2022 winver
Windows group Simatic HMI Exists as a Security Group (local or domain) lusrmgr.msc > Groups
Domain or workgroup model Decided (local SAM is sufficient for single-station) Network properties
User account Operator Created in Windows, password set, never expires (recommended for service-style accounts) net user Operator

4. Step-by-Step Configuration

Step 1 — Create the Windows Group and User

  1. Open Computer Management (compmgmt.msc) on the OS client.
  2. Navigate to Local Users and Groups > Groups and confirm Simatic HMI exists. If not, create it as a Security Group with default scope and type.
  3. Create the Operator user (and Coordinator if you need elevated rights) under Local Users and Groups > Users.
  4. Set a non-expiring password and uncheck User must change password at next logon.
  5. Add the user to the Simatic HMI group. Right-click the user > Properties > Member Of > Add.

Equivalent command line for batch provisioning:

net localgroup "Simatic HMI" Operator /add
net localgroup "Simatic HMI" Coordinator /add

Step 2 — Mirror the Groups in WinCC User Administrator

  1. Open the WinCC Explorer on the engineering station (or directly on the OS client for single-station systems).
  2. Open User Administrator from the navigation tree.
  3. Create two groups: Operator and Coordinator. These are WinCC-internal groups, not Windows groups, but the names must match the Windows groups you intend to map.
  4. Assign authorizations (area selection, value-forcing, message acknowledgement, etc.) to each group. Typical mapping:
WinCC Group Windows Group Typical Authorizations
Operator Simatic HMI HMIRuntime.Authorization_Operation, message acknowledgement
Coordinator Simatic HMI Authorization_Configuration, Authorization_ProcessControl, Authorization_Archives
  1. Add the Operator Windows user to the WinCC Operator group in the User tab. WinCC will accept the Windows user as a member if it resolves through the local SAM or domain.
Why the WinCC groups exist even when no matching Windows groups are present: The WinCC User Administrator groups are an authorization layer that is independent of the Windows groups. SIMATIC Logon bridges them by returning the user's Windows group memberships; WinCC then checks the WinCC-side group names for authorization. If you only create WinCC-side groups and not Windows-side groups, the user still authenticates, but no authorizations are granted.

Step 3 — Configure SIMATIC Logon for Central User Administration

  1. Launch SIMATIC Logon Configuration (Start > Siemens Automation > SIMATIC > SIMATIC Logon > Configuration).
  2. In the Server tab, select Use local Windows user administration for a single-station OS client, or enter the domain controller for a multi-station system.
  3. Switch to the Logon tab and confirm the SIMATIC Logon Service is running (services.msc > SIMATIC Logon Service).
  4. For a single-station setup, no additional domain configuration is required.

Step 4 — Implement the Default-User Autologin Script

The default user is supplied to SIMATIC Logon by a VBScript that WinCC executes during runtime startup. The standard Siemens template script is reproduced below with the field-tested parameters for an Operator account.

'------------------------------------------------------------------
' WinCC Runtime default user script for SIMATIC Logon autologin
' Executed by the runtime scheduler on RT startup
'------------------------------------------------------------------
Option Explicit

' HMIRuntime object
Dim hmiruntime
Set hmiruntime = HMIRuntime

' Default user credentials (Windows account)
Dim sUser, sPassword
sUser     = "Operator"
sPassword = "YourSecurePasswordHere"

' Domain or local computer name; use "." for local SAM
Dim sDomain
sDomain = "."

' Logon type 0 = standard logon, 1 = forced logon (replaces current)
Dim lLogonType
lLogonType = 1

' Call the SIMATIC Logon COM interface
Dim oLogon
Set oLogon = CreateObject("SIMATICLogon.LogOn")

' Returns 0 on success, non-zero on failure
Dim lResult
lResult = oLogon.Logon(sUser, sPassword, sDomain, lLogonType)

If lResult <> 0 Then
    ' Fallback: write to diagnostic file for troubleshooting
    Dim fso, ts
    Set fso = CreateObject("Scripting.FileSystemObject")
    Set ts = fso.OpenTextFile("C:\Siemens\Autologin_Error.log", 8, True)
    ts.WriteLine Now & " - Logon failed, code=" & lResult
    ts.Close
End If

Set oLogon = Nothing

Save the script as DefaultUserLogin.vbs under the project runtime folder, for example D:\WinCCProjects\OS_Client01\ScriptLib\DefaultUserLoginLogin.vbs (note the doubled LoginLogin suffix is intentional in some Siemens-supplied templates; the runtime scheduler strips the trailing Login to derive the event name).

  1. Open WinCC Explorer > Computer > Properties > Startup.
  2. Add the script to the Global Script Runtime startup list, or use the C script variant via the Applet scheduler.
  3. Set the script to run at runtime start (event HMIRuntimeStart or project-specific @ProjectStartup).

Step 5 — Configure Password Storage

The password passed to SIMATICLogon.LogOn is sensitive. Siemens recommends one of the following storage options, listed from least to most secure:

Method Mechanism Security Note
Plain VBScript variable Password visible in .vbs file Acceptable only for read-only kiosk stations
Encrypted text file Encrypted with sc.exe or DPAPI via the ProtectFile utility Recommended for OS clients
SIMATIC Logon password vault SIMATIC Logon stores the password and the script retrieves via GetPassword API Preferred for multi-station plants
Windows Credential Manager Generic credential stored via cmdkey OS-level protection, no script visibility

For a single OS client, the standard pattern is to put the password in the VBScript directly and restrict the file with NTFS ACLs so that only SIMATIC HMI group members and the local SYSTEM account can read it:

icacls "D:\WinCCProjects\OS_Client01\ScriptLib\DefaultUserLogin.vbs" /inheritance:r /grant:r "SYSTEM:(R)" /grant:r "Simatic HMI:(R)" /grant:r "Administrators:(F)"

Step 6 — OS Client Runtime Configuration

  1. On the OS client, open WinCC Explorer > Computer > Properties > Runtime.
  2. Under User Administration, set Authentication to SIMATIC Logon (not WinCC internal).
  3. Confirm the Autostart option is enabled so the runtime starts when the OS client boots.
  4. Disable the Login dialog on startup checkbox. In WinCC RT Professional this is controlled by the project property ShowLoginDialog; in WinCC V7 it is the checkbox Suppress login dialog under Computer > Properties > Startup.
OS client reboot behavior: After the client restarts, the runtime executes the default-user script during HMIRuntimeStart. The operator should be in the runtime within 3 to 5 seconds. If the login dialog still appears, the runtime scheduler is not invoking the script (see troubleshooting matrix below).

5. Login Flow Verification

After deployment, verify the configuration in the following order:

  1. Reboot the OS client.
  2. Confirm the WinCC Runtime starts and the operator is logged in automatically without keyboard interaction.
  3. Open SIMATIC Logon Diagnostic Tool (Start > Siemens > SIMATIC Logon > Diagnostic). The currently logged-on user must show as Operator with the correct Windows group memberships.
  4. In the WinCC Runtime, open the user information dialog. It should display Operator as the active user.
  5. Test a logout/login cycle to confirm the runtime responds to Logout and re-authenticates correctly when the script runs again.

6. Troubleshooting Matrix

Symptom Likely Root Cause Diagnostic Step Remediation
Login dialog still appears after WinCC activates Default-user script not registered as runtime startup event Check Applet > Scheduler > Global Script Add the script to the HMIRuntimeStart event
Login dialog appears, manual login works Password mismatch between script and Windows account View Autologin_Error.log Re-enter password in the script and rerun
Login succeeds but no authorizations granted WinCC groups do not match Windows group names Compare names in User Administrator and lusrmgr.msc Rename WinCC groups to match Windows group names
User authenticates, then runtime logs out immediately User account is disabled, locked, or password expired net user Operator /domain Clear account flags, set non-expiring password
Autologin works after WinCC login, fails on first boot SIMATIC Logon Service not yet running when runtime starts Check service start order in services.msc Set SIMATIC Logon Service dependency on RPCSS; set startup type to Automatic (Delayed Start)
VBScript error "ActiveX component can't create object" SIMATIC Logon not installed or COM registration broken regedit > HKCR\SIMATICLogon.LogOn Reinstall SIMATIC Logon, run regsvr32 on the COM DLL
Login dialog appears only on operator station, not engineer station OS client uses WinCC-internal auth, not SIMATIC Logon Project property Authentication Change to SIMATIC Logon and redeploy
Runtime starts but no operator screen loads Default user lacks Authorization_Operation WinCC User Administrator > Authorizations Assign Operator group to authorization 5 (area selection)

7. Common Field-Proven Pitfalls

  • Domain vs. local account confusion. If the OS client is joined to a domain, the sDomain parameter in the script must be the NetBIOS domain name or DNS name, not .. Use sDomain = "PLANT" for the PLANT domain.
  • UAC elevation. On Windows 10/11 with UAC enabled, scripts that write to Program Files or C:\Windows may fail silently. Place the script in a non-protected folder such as D:\Siemens\Scripts\.
  • Service account password change. If the Windows Operator password is rotated (Group Policy), the embedded password in the script becomes stale. Document the rotation procedure in the plant's change-management policy and update every OS client in parallel.
  • Time skew. SIMATIC Logon uses Kerberos in domain mode. A clock skew greater than 5 minutes between the OS client and the domain controller causes Logon to return -2147024891 (0x80070005 access denied). Synchronize time via NTP.
  • Multi-language OS. The default Windows group name Simatic HMI is localized in some Siemens installers (e.g., SIMATIC HMI in German builds is the same string, but Utilisateurs du Bureau à distance is not). Always check the actual group SID with wmic group where name="Simatic HMI" get sid.

8. Security and Audit Considerations

Autologin to an HMI operator account is acceptable only when the OS client is physically secured (locked cabinet, control room). For regulatory environments (21 CFR Part 11, IEC 62443), combine autologin with the following controls:

  • Electronic signature prompts for critical actions (forced setpoints, recipe changes)
  • Audit trail recording of every setpoint change with the authenticated user name
  • Session timeout that forces re-authentication after a configurable idle period
  • Restrict the OS client desktop to WinCC Runtime only via Shell Replacement (replace explorer.exe with the WinCC runtime shell in the registry HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon value Shell)

9. Verification Checklist

Check Expected Result
Runtime starts without keyboard input Operator is logged in within 5 seconds of HMIRuntimeStart
SIMATIC Logon Diagnostic shows active user Operator with group Simatic HMI
WinCC user information dialog Displays Operator as the active user
Authorization test: open a protected area Area loads without authorization error
Logout/login cycle Runtime re-authenticates successfully
Reboot test Login dialog does not appear; autologin is consistent

10. Frequently Asked Questions

Where does the Operator password come from when the autologin script calls SIMATIC Logon?

The password is supplied as the second argument to SIMATICLogon.LogOn(sUser, sPassword, sDomain, lLogonType) in the VBScript. It must match the Windows account password of the Operator user defined in Computer Management > Local Users and Groups. SIMATIC Logon does not store the password itself; it validates against the Windows SAM or Active Directory.

Do I need to create the Operator and Coordinator groups in Windows Computer Management?

Not necessarily. The WinCC User Administrator groups are an authorization layer. SIMATIC Logon authenticates the Windows user and returns their Windows group memberships (such as Simatic HMI). WinCC then checks if any of those Windows group names match a WinCC-side group. If you only use the built-in Simatic HMI Windows group, you can have a single WinCC Simatic HMI group with the correct authorizations and assign individual users to it.

Why does the login dialog still appear after I configured the default user in SIMATIC Logon?

Three common causes: (1) the default-user VBScript is not registered as a runtime startup event, (2) the password in the script does not match the Windows account, or (3) the SIMATIC Logon Service has not started before the runtime scheduler runs. Enable the diagnostic log file path in the script and check the return code from Logon.

How do I run the default-user script automatically on every runtime start?

Register the VBScript in the WinCC Explorer under Computer > Properties > Startup > Global Script Runtime and attach it to the HMIRuntimeStart event. Alternatively, use the C script SIMATICLogon_DefaultUser function block from the SIMATIC Logon script library and call it from the Applet scheduler.

Is the autologin password visible in the WinCC project?

By default, yes, it is embedded in the .vbs file. For a single-station OS client, restrict the file with NTFS ACLs so only SYSTEM and the Simatic HMI group can read it. For multi-station deployments, use the SIMATIC Logon password vault or Windows Credential Manager to avoid embedding the password in the project files.

Back to blog