1. Problem Overview
The dialog "Logon failure: Unknown user name or bad password" displayed inside SIMATIC WinCC Explorer originates from the Microsoft OLE DB provider that WinCC uses to communicate with its backing SQL Server instance. The exact error string is identical to the one documented in Microsoft SQL Server Reporting Services connectivity guides (see Troubleshoot Reporting Services database and server connection problems) because both WinCC and Reporting Services attach to a SQL Server master database through the same data-access stack (SQLOLEDB / MSOLEDBSQL).
WinCC V7.0 through V7.5 SP2 store every project configuration in the SQL Server instance WINCC installed by the WinCC setup. Each project consumes databases named CC_<projectname>, CC_<projectname>_MCP, and CC_<projectname>_RT. Windows-authenticated principals created during setup own these databases, and the runtime CCAgentHost service uses the same principal to open them. Any drift between three sources of identity surfaces as the same dialog:
- The Windows account under which WinCC Explorer is currently running (the logged-in interactive user).
- The Windows account assigned to the CCAgentHost and WinCC RT services inside
services.msc. - The SQL Server login mapped to either of the above inside the
WINCCmaster database (sys.server_principals).
If any of the three identities is invalid - because the password was rotated, the SID was deleted in Active Directory, or the DBA dropped the SQL Server login - WinCC Explorer cannot authenticate and the dialog appears before the project tree ever renders.
2. Confirmed Symptoms and Log Signatures
Engineers see this dialog in four distinct contexts. Each carries a specific log signature that confirms identity drift rather than a database or project file problem.
| Symptom | When Observed | Primary Log Source | Signature Entry |
|---|---|---|---|
| Logon dialog on every project open | First attempt to open any project immediately after Windows boot | WinCC diagnose folder %ProgramFiles(x86)%\Siemens\Automation\WinCC\Diagnose
|
OpenProject: Logon failure (provider=SQLOLEDB, server=.\WINCC) |
| New project wizard fails immediately | Selecting File > New > Single-User Project | SQL Server ERRORLOG at C:\Program Files\Microsoft SQL Server\MSSQL<inst>.WINCC\LOG
|
Error: 18456, Severity: 14, State: 8 - Login failed for user '<DOMAIN\user>'. Reason: Password did not match. |
| OS Compiler reports "cannot open project" | Staging, DO consolidation, or Compile OS right-click |
WinCC_SysLog plus OSGenerate.log
|
HResult 0x80040E07 IDispatch::Invoke - Logon failure: Unknown user name or bad password |
| WinCC Runtime starts then exits in 30 s | Power-on cycle or DCS restart | Windows Event Viewer > Application | Event 7034 from CCAgentHost - "Authentication to SQL Server failed; will retry 0 of 3." |
3. Affected Versions and SQL Server Pairings
WinCC versions pair to specific Microsoft SQL Server versions per the official release notes. The pairing determines which authentication mode WinCC uses (Windows auth only, or Windows + SQL auth fallback).
| WinCC Product | SQL Server Backend | Auth Mode | Notable Service Pack |
|---|---|---|---|
| WinCC V7.4 SP1 | SQL Server 2014 SP2 (32-bit) | Windows auth | Update 13+ |
| WinCC V7.5 | SQL Server 2016 SP2 (64-bit) | Windows auth | Update 6+ |
| WinCC V7.5 SP2 | SQL Server 2019 Standard (64-bit) | Windows auth | Update 1+ |
| WinCC Professional V16 / V17 (TIA Portal) | SQL Server 2017 Express Embedded | Windows + SQL auth | Update 5+ |
| WinCC Unified V17 / V18 (TIA Portal) | MongoDB + UMC (no SQL Server) | Not applicable | Update 4+ |
4. Root Cause Analysis
The error is a SQL Server authentication failure intercepted by WinCC. Microsoft catalogs it as Login failed for user with HResult 0x80040E07; WinCC surfaces the human-readable OLE DB message. The technical definition of state codes is documented at MSSQLSERVER_18456. The three identity layers that must agree are:
-
Windows security principal. The domain account
DOMAIN\WinCCUserstored inActive Directory Users and Computers. If the account is locked, disabled, or the password is older than the configured fine-grained password policy,winlogonrejects it before it ever reaches WinCC. -
WinCC service logon. The credential used to start
CCAgentHost,WinCC RT, and the rest of the WinCC service family inservices.msc > Log On As. WinCC services run asDOMAIN\WinCCUserby default; if the password is rotated externally (for example by group policy that pushes complexity changes), the service still holds the old password. -
SQL Server login. The principal in the
WINCCmaster databasesys.server_principalsview, mapped to the same Windows user. Dropping this login from SQL Server or detaching theCC_*databases severs WinCC's ability to bind.
When any single layer drifts, the SQL Server ERRORLOG records Error 18456, State 8 (password mismatch), or State 5 (login does not exist), or State 1 (login cannot be resolved). The WinCC Explorer dialog then inherits the OLE DB provider text. Identification is straightforward once you know which state is logged.
5. Diagnostic Step Sequence
Run the following checks in order. Stop as soon as one identifies the broken layer; everything downstream is fixable without reinstallation.
-
Open SQL Server Management Studio on the WinCC server (or on the workstation hosting WinCC) and connect to
.\WINCCusing Windows authentication as the sameDOMAIN\WinCCUserused by the service. If SSMS reports the same 18456 dialog, the SQL Server login is broken. If SSMS connects cleanly, the SQL login is intact and the drift is at the WinCC service level. -
Check the SQL Server ERRORLOG under
C:\Program Files\Microsoft SQL Server\MSSQLxx.WINCC\MSSQL\Log. The latest entry will contain the date and time of the first WinCC Explorer login attempt, the state code, and the SID that failed. -
Check the WinCC diagnose folder at
%ProgramFiles(x86)%\Siemens\Automation\WinCC\Diagnose. Look forWinCC_SysLog_<date>.log. Lines beginning withHResult 0x80040E07confirm the OLE DB rejection; lines starting withOpenProject: Logon failureconfirm a project open failure rather than a database-attach failure. -
Inspect service logon for CCAgentHost and WinCC RT in
services.msc→ Properties → Log On. If the password stored there does not matchActive Directory Users and Computers→ Account options → Reset password with show selected, the service logon is the broken layer. - Validate the SIMATIC Logon Database. When SIMATIC Logon (formerly known as SIMATIC Logon Server) is configured, it caches credentials in a SQL table on the central logon server. If only that table is unreadable, the WinCC Runtime service authentication fails locally even though all other paths are healthy.
6. Resolution Path A — WinCC Service Password Synchronization
Use this path when the SQL Server login is intact (SSMS connects cleanly), but the WinCC services still hold the old cached password.
- Open
services.mscon the affected workstation. - For each of the following services, right-click → Properties → Log On → This account → enter the latest password twice:
CCAgentHostWinCC RTWinCC Alarm LoggingWinCC Tag Logging-
WinCC OS (Picture)orWinCC Graphicsdepending on the version -
SIMATIC Logon(when a centralized SIMATIC Logon Server is in use)
- Restart the services in reverse order (Graphics → Alarm Logging → Tag Logging → RT → CCAgentHost). Each service should report
Starting; the previously failing Logon failure dialog will not appear when WinCC Explorer is reopened.
7. Resolution Path B — SQL Server Login Repair
Use this path when SSMS itself cannot connect to .\WINCC with the current Windows account, or when the DBA has confirmed a dropped login.
- Start SQL Server Management Studio as a member of
sysadminon the WinCC server. - Connect to
.\WINCCwith Windows authentication (use a domain admin or local Administrator). - Open Security → Logins. Locate the missing principal (typically
DOMAIN\WinCCUserorDOMAIN\<machine>$). If absent, recreate it:
CREATE LOGIN [DOMAIN\WinCCUser] FROM WINDOWS WITH DEFAULT_DATABASE=[master];
4. Re-map the new login to the existing CC_* databases:
USE [CC_<projectname>];
CREATE USER [DOMAIN\WinCCUser] FOR LOGIN [DOMAIN\WinCCUser];
ALTER ROLE [db_owner] ADD MEMBER [DOMAIN\WinCCUser];
GO
USE [CC_<projectname>_MCP];
CREATE USER [DOMAIN\WinCCUser] FOR LOGIN [DOMAIN\WinCCUser];
ALTER ROLE [db_owner] ADD MEMBER [DOMAIN\WinCCUser];
GO
5. Repeat for _RT if the project is also running the OS Runtime.
6. Detach and re-attach the databases in SQL Server Management Studio to revalidate the SID linkage (Tasks → Detach → Re-Attach).
- Restart
CCAgentHostand reopen WinCC Explorer. The dialog should not return.
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Siemens\WinCC\SQL → InstName; confirm that the value matches the active .\WINCC instance name.8. Resolution Path C — Project Restore from Archive
If both SQL Server and service paths fail to clear the dialog, the MCP file itself can become corrupted. This is rare but reproducible when the project was edited while the WinCC service was running detached from its database.
- Confirm the local copy or network archive opens cleanly on a different VM in the same domain. This validates that the project files are not project-level corruption.
- Export the project from the working copy using the
WinCC Project Migrator(found on the start menu under Siemens Automation → WinCC → Tools):- Run
CCProjectMigrator.exe /Source:\<archive> /Target:\<working copy> /Mode:Standard
- Run
- Stop all WinCC services on the failed workstation.
- Detach the existing
CC_*databases in SQL Server Management Studio. - Delete the
*.MCPand*.LDFfiles from the project path (defaultC:\WinCCProjects\<project>). - Restore the archived project files.
- Re-attach the databases using the restored
*.MDF/*.LDFfiles. - Restart the WinCC services and reopen the project.
9. WinCC UserAdmin and SIMATIC Logon Reconfiguration
After resolving SQL Server authentication, the WinCC internal user database must be reconciled. This is the most-frequently missed step in field service.
- Open WinCC Explorer → Tools → User Administrator.
- For each operator that previously logged in to WinCC RT, click Properties → Password and re-enter the same password set in the Windows account. WinCC hashes each password internally using its own AES config; if the hash is stale (older than a re-encryption cycle), runtime logon fails even when the SQL path is healthy.
- If the project uses SIMATIC Logon for central user management, open SIMATIC Logon Console and confirm that the logon server is reachable. Clear the ticket cache (Actions → Clear Ticket Cache) so that no stale ticket survives.
- If the WinCC project uses UMC (User Management Component) (typically on WinCC Unified or TIA Portal configurations), open the
WinCC Unified Configurationand re-bind the WinCC Unified Database connection. The sameLogon failureerror can come from a wrong connection string here even after a perfect SQL repair.
10. Verification Checklist
Confirm every item before declaring the workstation healthy. A single missed layer means the next project open will fail again.
| Check | Method | Pass Criterion |
|---|---|---|
| SSMS to .\WINCC as DOMAIN\WinCCUser | Open SSMS, connect with Windows auth | Object Explorer renders |
| SQL Server log free of state 8 | Open most recent ERRORLOG | No 18456 entries after restart |
| CCAgentHost service starts | sc query CCAgentHost |
STATE: 4 RUNNING |
| WinCC Explorer opens project | File → Open → <project> | Project tree loads, logon dialog does not appear |
| OS Compile completes | Right-click OS → Compile OS | Compiler reports success in < 60 s |
| Runtime activates | Activate Runtime on the test image | Runtime window appears, no logon prompt |
| WinCC_SysLog clean | Inspect today's diagnose file | No 0x80040E07 entry |
| WinCC UserAdmin authenticates | User Admin → Change Password | Accepts new password, hash stored |
11. Preventive Measures
Once the dialog is cleared, three engineering controls prevent recurrence on the next Windows password rotation cycle.
- Decouple WinCC service logon from user passwords by using a Group Managed Service Account (gMSA). The system rotates the password automatically and the WinCC service updates without manual intervention. This is the Microsoft-supported path documented for SQL Server 2016+; see MSSQLSERVER_18456 for the state codes that gMSA automatically prevents.
- Set Maximum password age off for the WinCC service account in your domain Group Policy. Common policy is 42 days; an unmonitored rotation is exactly what strands the WinCC service.
-
Schedule a WinCC service logon sanity check every 90 days. Open
services.msc→ Properties → Log On for each WinCC service and confirm the password matches the value cached inActive Directory Users and Computers. - Archive the project weekly using WinCC Project Migrator so that Path C (Restore from Archive) is always available with a known-good MCP file. This is the shortest path back to runtime if the database becomes unsynced.
12. Related Fault Signatures
When the dialog persists after the above steps, the failure is no longer a Windows or SQL authentication problem. The following correlated errors indicate deeper issues and should be opened with Siemens technical support:
| Diagnostic Marker | Likely Cause | Recommended Escalation |
|---|---|---|
CC_Error 0x80004005 in OSCompile.log |
Project MCP file signed with mismatched assembly | Re-sign the assembly, recompile |
SQL Server does not exist or access denied (state 08001) |
Named pipes or TCP/IP protocol disabled | Enable TCP/IP in SQL Server Configuration Manager |
| Event 4624 then 4625 with status 0xC0000234 | Trusted-for-delegation flag missing | Set TRUSTED_FOR_DELEGATION in AD Users and Computers |
CCRuntime.exe -1073741819 on startup |
Missing user rights assignment for service account | Grant Log on as a service via Group Policy |
FAQ
Why does WinCC Explorer show "Logon failure: Unknown user name or bad password" after a Windows password change?
WinCC services such as CCAgentHost and WinCC RT cache credentials in services.msc > Log On. Rotating the Windows password externally leaves those cached values stale, and the SQL Server login mapped to the same Windows account receives the old hash. Open services.msc and reset the password for every WinCC service using the latest credential. Verify with SQL Server Management Studio connected to .\WINCC using Windows authentication.
Is this error related to the SQL Server sa password?
Only if WinCC was reconfigured to use SQL authentication instead of Windows authentication. WinCC V7.4 and V7.5 default to Windows authentication only; the sa password is not used. WinCC Professional V16/V17 in TIA Portal can use SQL authentication in test installations. Check HKLM\SOFTWARE\WOW6432Node\Siemens\WinCC\SQL to see whether the UseSQLAuth value is set.
Can I clear the dialog without reinstalling WinCC?
Yes. The dialog is an OLE DB rejection and the WinCC installation is intact. Run the diagnostic sequence in section 5, identify the broken identity layer, and apply Path A, B, or C from sections 6 to 8. Reinstallation is only required when both the SQL login and the project MCP are corrupted.
Does WinCC Unified V18 or V19 PC Runtime have this error?
No. WinCC Unified stores configuration in a MongoDB instance managed by the WinCC Unified Configuration Service. If a Unified station displays the same dialog, the source is the SQL-backed UMC (User Management Component) used for centralized user management, not WinCC Explorer. Recreate the UMC connection string inside the Unified Configuration client.
What is the difference between HResult 0x80040E07 and SQL Server error 18456?
SQL Server error 18456 is the engine-level authentication failure (with state codes 1, 5, 7, 8, etc.). Microsoft documents the full state-code list at MSSQLSERVER_18456. HResult 0x80040E07 is the OLE DB provider wrapper that translates 18456 into the WinCC Explorer dialog. The two strings describe the same failure at different abstraction levels; fixing the underlying 18456 state clears the OLE DB dialog.