1. Overview
SIMATIC Logon is the Siemens central user administration component that authenticates operators against Windows accounts and forwards role/authorization decisions to WinCC Runtime (RT Professional, RT Advanced, Comfort Panels, and OS clients in PCS 7). When properly configured, an operator seated at an OS client can start the WinCC runtime project without a manual login dialog. When the configuration is incomplete, the runtime presents a login box at startup and refuses to proceed until an interactive user is supplied.
This article documents the complete procedure for deploying a default user (the Operator in the source scenario) that is logged in automatically at runtime start. It covers:
- Windows group provisioning (
Simatic HMI) - WinCC User Administrator configuration (operator and coordinator groups)
- The default-user VBScript for the SIMATIC Logon connection
- Password storage in the SIMATIC Logon configuration database
- Troubleshooting the most common causes of an unexpected login dialog
The reference workflow targets a WinCC OS client (single-user station) running WinCC RT Professional or PCS 7 OS with SIMATIC Logon V1.6 or later. Adjust paths and registry keys for older versions of the Logon Service.
2. SIMATIC Logon Architecture and Login Flow
SIMATIC Logon runs as a Windows service (SIMATIC Logon Service) and provides an in-process COM interface that WinCC Runtime calls to authenticate the current user. The login flow, as documented in the official Siemens TIA Portal V20 manual Central user administration using SIMATIC Logon, is:
- Runtime starts and reads the project-defined default user (from the Logon configuration script).
- Runtime invokes the SIMATIC Logon COM interface with the default user and password.
- SIMATIC Logon validates the credentials against the Windows Security Account Manager (SAM) or the Active Directory domain.
- On success, SIMATIC Logon reads the user's group memberships and returns them to the runtime.
- WinCC maps the Windows groups to its internal user groups (operator, coordinator, etc.) and applies the configured authorizations.
Simatic HMI group or a user-defined group mirrored in the WinCC User Administrator).3. Prerequisites
Verify the following before configuring autologin:
| Item | Required Value | Verification |
|---|---|---|
| SIMATIC Logon version | V1.6 SP3 or later (V2.x for TIA V20) | Control Panel > Programs > SIMATIC Logon |
| WinCC Runtime | RT Professional V17 / V18 / V19 / V20, or PCS 7 OS V9.0/V9.1 | WinCC Explorer > Help > About |
| Windows edition | Windows 10 LTSC 2019/2021 or Windows Server 2016/2019/2022 | winver |
Windows group Simatic HMI
|
Exists as a Security Group (local or domain) | lusrmgr.msc > Groups |
| Domain or workgroup model | Decided (local SAM is sufficient for single-station) | Network properties |
User account Operator
|
Created in Windows, password set, never expires (recommended for service-style accounts) | net user Operator |
4. Step-by-Step Configuration
Step 1 — Create the Windows Group and User
- Open Computer Management (
compmgmt.msc) on the OS client. - Navigate to Local Users and Groups > Groups and confirm
Simatic HMIexists. If not, create it as a Security Group with default scope and type. - Create the
Operatoruser (andCoordinatorif you need elevated rights) under Local Users and Groups > Users. - Set a non-expiring password and uncheck User must change password at next logon.
- Add the user to the
Simatic HMIgroup. Right-click the user > Properties > Member Of > Add.
Equivalent command line for batch provisioning:
net localgroup "Simatic HMI" Operator /add
net localgroup "Simatic HMI" Coordinator /add
Step 2 — Mirror the Groups in WinCC User Administrator
- Open the WinCC Explorer on the engineering station (or directly on the OS client for single-station systems).
- Open User Administrator from the navigation tree.
- Create two groups:
OperatorandCoordinator. These are WinCC-internal groups, not Windows groups, but the names must match the Windows groups you intend to map. - Assign authorizations (area selection, value-forcing, message acknowledgement, etc.) to each group. Typical mapping:
| WinCC Group | Windows Group | Typical Authorizations |
|---|---|---|
| Operator | Simatic HMI |
HMIRuntime.Authorization_Operation, message acknowledgement |
| Coordinator | Simatic HMI |
Authorization_Configuration, Authorization_ProcessControl, Authorization_Archives |
- Add the
OperatorWindows user to the WinCCOperatorgroup in the User tab. WinCC will accept the Windows user as a member if it resolves through the local SAM or domain.
Step 3 — Configure SIMATIC Logon for Central User Administration
- Launch SIMATIC Logon Configuration (Start > Siemens Automation > SIMATIC > SIMATIC Logon > Configuration).
- In the Server tab, select Use local Windows user administration for a single-station OS client, or enter the domain controller for a multi-station system.
- Switch to the Logon tab and confirm the SIMATIC Logon Service is running (
services.msc > SIMATIC Logon Service). - For a single-station setup, no additional domain configuration is required.
Step 4 — Implement the Default-User Autologin Script
The default user is supplied to SIMATIC Logon by a VBScript that WinCC executes during runtime startup. The standard Siemens template script is reproduced below with the field-tested parameters for an Operator account.
'------------------------------------------------------------------
' WinCC Runtime default user script for SIMATIC Logon autologin
' Executed by the runtime scheduler on RT startup
'------------------------------------------------------------------
Option Explicit
' HMIRuntime object
Dim hmiruntime
Set hmiruntime = HMIRuntime
' Default user credentials (Windows account)
Dim sUser, sPassword
sUser = "Operator"
sPassword = "YourSecurePasswordHere"
' Domain or local computer name; use "." for local SAM
Dim sDomain
sDomain = "."
' Logon type 0 = standard logon, 1 = forced logon (replaces current)
Dim lLogonType
lLogonType = 1
' Call the SIMATIC Logon COM interface
Dim oLogon
Set oLogon = CreateObject("SIMATICLogon.LogOn")
' Returns 0 on success, non-zero on failure
Dim lResult
lResult = oLogon.Logon(sUser, sPassword, sDomain, lLogonType)
If lResult <> 0 Then
' Fallback: write to diagnostic file for troubleshooting
Dim fso, ts
Set fso = CreateObject("Scripting.FileSystemObject")
Set ts = fso.OpenTextFile("C:\Siemens\Autologin_Error.log", 8, True)
ts.WriteLine Now & " - Logon failed, code=" & lResult
ts.Close
End If
Set oLogon = Nothing
Save the script as DefaultUserLogin.vbs under the project runtime folder, for example D:\WinCCProjects\OS_Client01\ScriptLib\DefaultUserLoginLogin.vbs (note the doubled LoginLogin suffix is intentional in some Siemens-supplied templates; the runtime scheduler strips the trailing Login to derive the event name).
- Open WinCC Explorer > Computer > Properties > Startup.
- Add the script to the Global Script Runtime startup list, or use the C script variant via the Applet scheduler.
- Set the script to run at runtime start (event
HMIRuntimeStartor project-specific@ProjectStartup).
Step 5 — Configure Password Storage
The password passed to SIMATICLogon.LogOn is sensitive. Siemens recommends one of the following storage options, listed from least to most secure:
| Method | Mechanism | Security Note |
|---|---|---|
| Plain VBScript variable | Password visible in .vbs file |
Acceptable only for read-only kiosk stations |
| Encrypted text file | Encrypted with sc.exe or DPAPI via the ProtectFile utility |
Recommended for OS clients |
| SIMATIC Logon password vault | SIMATIC Logon stores the password and the script retrieves via GetPassword API |
Preferred for multi-station plants |
| Windows Credential Manager | Generic credential stored via cmdkey
|
OS-level protection, no script visibility |
For a single OS client, the standard pattern is to put the password in the VBScript directly and restrict the file with NTFS ACLs so that only SIMATIC HMI group members and the local SYSTEM account can read it:
icacls "D:\WinCCProjects\OS_Client01\ScriptLib\DefaultUserLogin.vbs" /inheritance:r /grant:r "SYSTEM:(R)" /grant:r "Simatic HMI:(R)" /grant:r "Administrators:(F)"
Step 6 — OS Client Runtime Configuration
- On the OS client, open WinCC Explorer > Computer > Properties > Runtime.
- Under User Administration, set Authentication to SIMATIC Logon (not WinCC internal).
- Confirm the Autostart option is enabled so the runtime starts when the OS client boots.
- Disable the Login dialog on startup checkbox. In WinCC RT Professional this is controlled by the project property
ShowLoginDialog; in WinCC V7 it is the checkbox Suppress login dialog under Computer > Properties > Startup.
HMIRuntimeStart. The operator should be in the runtime within 3 to 5 seconds. If the login dialog still appears, the runtime scheduler is not invoking the script (see troubleshooting matrix below).5. Login Flow Verification
After deployment, verify the configuration in the following order:
- Reboot the OS client.
- Confirm the WinCC Runtime starts and the operator is logged in automatically without keyboard interaction.
- Open SIMATIC Logon Diagnostic Tool (Start > Siemens > SIMATIC Logon > Diagnostic). The currently logged-on user must show as
Operatorwith the correct Windows group memberships. - In the WinCC Runtime, open the user information dialog. It should display Operator as the active user.
- Test a logout/login cycle to confirm the runtime responds to
Logoutand re-authenticates correctly when the script runs again.
6. Troubleshooting Matrix
| Symptom | Likely Root Cause | Diagnostic Step | Remediation |
|---|---|---|---|
| Login dialog still appears after WinCC activates | Default-user script not registered as runtime startup event | Check Applet > Scheduler > Global Script | Add the script to the HMIRuntimeStart event |
| Login dialog appears, manual login works | Password mismatch between script and Windows account | View Autologin_Error.log
|
Re-enter password in the script and rerun |
| Login succeeds but no authorizations granted | WinCC groups do not match Windows group names | Compare names in User Administrator and lusrmgr.msc
|
Rename WinCC groups to match Windows group names |
| User authenticates, then runtime logs out immediately | User account is disabled, locked, or password expired | net user Operator /domain |
Clear account flags, set non-expiring password |
| Autologin works after WinCC login, fails on first boot | SIMATIC Logon Service not yet running when runtime starts | Check service start order in services.msc | Set SIMATIC Logon Service dependency on RPCSS; set startup type to Automatic (Delayed Start) |
| VBScript error "ActiveX component can't create object" | SIMATIC Logon not installed or COM registration broken | regedit > HKCR\SIMATICLogon.LogOn |
Reinstall SIMATIC Logon, run regsvr32 on the COM DLL |
| Login dialog appears only on operator station, not engineer station | OS client uses WinCC-internal auth, not SIMATIC Logon | Project property Authentication | Change to SIMATIC Logon and redeploy |
| Runtime starts but no operator screen loads | Default user lacks Authorization_Operation | WinCC User Administrator > Authorizations | Assign Operator group to authorization 5 (area selection) |
7. Common Field-Proven Pitfalls
-
Domain vs. local account confusion. If the OS client is joined to a domain, the
sDomainparameter in the script must be the NetBIOS domain name or DNS name, not.. UsesDomain = "PLANT"for thePLANTdomain. -
UAC elevation. On Windows 10/11 with UAC enabled, scripts that write to
Program FilesorC:\Windowsmay fail silently. Place the script in a non-protected folder such asD:\Siemens\Scripts\. -
Service account password change. If the Windows
Operatorpassword is rotated (Group Policy), the embedded password in the script becomes stale. Document the rotation procedure in the plant's change-management policy and update every OS client in parallel. -
Time skew. SIMATIC Logon uses Kerberos in domain mode. A clock skew greater than 5 minutes between the OS client and the domain controller causes
Logonto return-2147024891(0x80070005 access denied). Synchronize time via NTP. -
Multi-language OS. The default Windows group name
Simatic HMIis localized in some Siemens installers (e.g.,SIMATIC HMIin German builds is the same string, butUtilisateurs du Bureau à distanceis not). Always check the actual group SID withwmic group where name="Simatic HMI" get sid.
8. Security and Audit Considerations
Autologin to an HMI operator account is acceptable only when the OS client is physically secured (locked cabinet, control room). For regulatory environments (21 CFR Part 11, IEC 62443), combine autologin with the following controls:
- Electronic signature prompts for critical actions (forced setpoints, recipe changes)
- Audit trail recording of every setpoint change with the authenticated user name
- Session timeout that forces re-authentication after a configurable idle period
- Restrict the OS client desktop to WinCC Runtime only via Shell Replacement (replace
explorer.exewith the WinCC runtime shell in the registryHKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\WinlogonvalueShell)
9. Verification Checklist
| Check | Expected Result |
|---|---|
| Runtime starts without keyboard input | Operator is logged in within 5 seconds of HMIRuntimeStart
|
| SIMATIC Logon Diagnostic shows active user |
Operator with group Simatic HMI
|
| WinCC user information dialog | Displays Operator as the active user |
| Authorization test: open a protected area | Area loads without authorization error |
| Logout/login cycle | Runtime re-authenticates successfully |
| Reboot test | Login dialog does not appear; autologin is consistent |
10. Frequently Asked Questions
Where does the Operator password come from when the autologin script calls SIMATIC Logon?
The password is supplied as the second argument to SIMATICLogon.LogOn(sUser, sPassword, sDomain, lLogonType) in the VBScript. It must match the Windows account password of the Operator user defined in Computer Management > Local Users and Groups. SIMATIC Logon does not store the password itself; it validates against the Windows SAM or Active Directory.
Do I need to create the Operator and Coordinator groups in Windows Computer Management?
Not necessarily. The WinCC User Administrator groups are an authorization layer. SIMATIC Logon authenticates the Windows user and returns their Windows group memberships (such as Simatic HMI). WinCC then checks if any of those Windows group names match a WinCC-side group. If you only use the built-in Simatic HMI Windows group, you can have a single WinCC Simatic HMI group with the correct authorizations and assign individual users to it.
Why does the login dialog still appear after I configured the default user in SIMATIC Logon?
Three common causes: (1) the default-user VBScript is not registered as a runtime startup event, (2) the password in the script does not match the Windows account, or (3) the SIMATIC Logon Service has not started before the runtime scheduler runs. Enable the diagnostic log file path in the script and check the return code from Logon.
How do I run the default-user script automatically on every runtime start?
Register the VBScript in the WinCC Explorer under Computer > Properties > Startup > Global Script Runtime and attach it to the HMIRuntimeStart event. Alternatively, use the C script SIMATICLogon_DefaultUser function block from the SIMATIC Logon script library and call it from the Applet scheduler.
Is the autologin password visible in the WinCC project?
By default, yes, it is embedded in the .vbs file. For a single-station OS client, restrict the file with NTFS ACLs so only SYSTEM and the Simatic HMI group can read it. For multi-station deployments, use the SIMATIC Logon password vault or Windows Credential Manager to avoid embedding the password in the project files.