Fixing SIMATIC Logon Change Logon Button Not Responding in ALM

David Krause9 min read
SiemensTIA PortalTroubleshooting
Licensed PE Working through this on a live machine? A Maine-licensed engineer can take it from here — included with IMD hardware, by the hour for everything else. Book an engineer

Problem: SIMATIC Logon "Change Logon" Button Has No Effect in Automation License Manager

Symptom: A user opens Automation License Manager (ALM), attempts to invoke Change Logon from a SIMATIC Logon entry to create or modify an account, and nothing happens. The dialog does not appear, no error is raised, and the system returns to its previous state. The same condition can occur when an engineer selects Options > Access Protection > Enable inside the legacy SIMATIC Manager and the dialog silently closes without applying protection.

Affected environment observed in the field:

  • Automation License Manager V5.0 + SP1, 32-bit edition
  • SIMATIC Logon runtime component shipped with WinCC V7.x / TIA Portal V13-V20
  • Windows 7 SP1 / Windows 10 LTSC workstations joined to a local workgroup (no domain)

This article explains the architectural reason the dialog does nothing and provides the correct procedure for creating SIMATIC Logon users. The recommended fix is independent of ALM build because ALM is never the correct tool for user administration.

Root Cause: ALM Is a License Tool, Not a User Store

Automation License Manager exists to manage, transfer, and validate Siemens software licenses (Floating, Single, Rental, Trial). It is not designed to hold user accounts, role assignments, or password hashes. The Change Logon entry visible inside ALM corresponds to the Windows service account that owns the ALM process; it does not create SIMATIC Logon identities.

SIMATIC Logon uses two stores:

  1. Windows User Management - the authoritative source of users and groups. Located under Computer Management > System Tools > Local Users and Groups (workgroup) or Active Directory Users and Computers (domain).
  2. WinCC User Administration - the runtime map that grants WinCC/TIA Portal permissions to the Windows groups.

If you only clicked Change Logon in ALM, no user is created because ALM has no schema for users. Access Protection in SIMATIC Manager requires a valid Windows group with the Logon_ prefix already present on the workstation; otherwise the toggle closes silently because the validation step finds no eligible principal.

Architectural rule: A user is a Windows principal. A role is a Windows group whose name begins with Logon_. A SIMATIC Logon authorization is the mapping of that group to a permission set inside WinCC User Administration. Skip any one of these three layers and the change button "does nothing."

SIMATIC Logon Architecture and Identity Flow

SIMATIC Logon is the central user-administration component for WinCC Runtime, WinCC Professional (RT Professional), Panels, Comfort Panels, and PC-based HMI systems. Central user administration using SIMATIC Logon keeps user credentials outside the HMI project so the same user account can authenticate to multiple runtime instances, panels, and engineering stations.

Identity flow at runtime:

  1. Operator enters username/password on the panel or RT client.
  2. The runtime calls the SIMATIC Logon service (SLSS) on the engineering station or domain controller.
  3. SLSS validates the principal against Windows (local SAM or Active Directory).
  4. The service returns the user's group memberships to the runtime.
  5. WinCC compares the groups against its permission table and grants the configured authorization.

Because step 3 depends entirely on Windows, ALM is excluded from this path. Configuring SIMATIC Logon is documented in the official SIMATIC Logon help PDF and the TIA Portal V20 user-administration manual:

Prerequisites Before Creating Users

Component Required State
Windows account performing setup Member of local Administrators
Workstation role Joined to a Windows domain or standalone with local SAM
Automation License Manager Installed; valid license for SIMATIC Logon present
SIMATIC Logon Service (SLSS) Running (services.msc > SIMATIC Logon Service > Started, Automatic)
WinCC User Administration editor Accessible from WinCC Explorer or TIA Portal project
TIA Portal project (if applicable) User administration editor compiled with project
The Logon_ prefix is mandatory. Groups named Administrators, Manager, or Operators will be ignored by the runtime even if the user is a member. WinCC only honors groups whose names start exactly with the string Logon_ (case-sensitive on localized builds).

Step-by-Step: Correctly Creating a SIMATIC Logon User

Step 1 - Create the role groups in Windows

  1. Open Computer Management (right-click This PC > Manage).
  2. Navigate to System Tools > Local Users and Groups > Groups.
  3. Create one group per role. Use the prefix exactly as shown:
Logon_Administrator
Logon_Manager
Logon_Operator
Logon_Viewer

4. Add the appropriate Windows users to each group as required.

Step 2 - Mirror the groups inside WinCC User Administration

  1. In the WinCC project, open User Administration (WinCC Explorer) or Runtime Settings > User administration (TIA Portal).
  2. Create a group entry with the identical name you used in Windows, including the Logon_ prefix.
  3. Assign the operator-level authorizations to the group:
Windows Group Typical WinCC Authorizations
Logon_Administrator User administration, Configuration, Process controlling
Logon_Manager Process controlling, Acknowledge alarms, Change values
Logon_Operator Process controlling, Acknowledge alarms
Logon_Viewer Monitor only

Step 3 - Create the Windows user

  1. Under Local Users and Groups > Users, create the operator account (example: seaf).
  2. Set a strong password and clear User must change password at next logon.
  3. Add the user as a member of one or more Logon_ groups (for example, seaf → Logon_Manager).

Step 4 - Enable SIMATIC Logon in the runtime

In TIA Portal V20 (or compatible WinCC):

  1. Open the project tree > Runtime settings > User administration.
  2. Check Enable SIMATIC Logon.
  3. Select Windows domain if the station is joined to Active Directory, otherwise select Windows workgroup.
  4. Compile and download the project to the panel or RT station.

Step 5 - Configure the SIMATIC Logon service

  1. Launch Start > SIMATIC > SIMATIC Logon > Configure SIMATIC Logon.
  2. Enter the logon credentials of a Windows administrator.
  3. Confirm that the SLSS service is registered and started.

Why "Enable Access Protection" in SIMATIC Manager Does Nothing

Legacy SIMATIC Manager projects (STEP 7 V5.x) include an Access Protection toggle under Options. When enabled, the project requires the active Windows user to be a member of a defined group. If no project-level group is configured, or if no user with that membership opens the project, the toggle reverts silently. The dialog does not display an error because STEP 7 internally considers the request fulfilled once the validation passes against an empty principal set.

To make Access Protection active:

  1. Open the S7 project in SIMATIC Manager.
  2. Right-click the project > Properties > Protection.
  3. Set the password and define the authorized user/group.
  4. Save and reopen the project - the login prompt now appears.

Compatibility Matrix for SIMATIC Logon Components

SIMATIC Logon Version TIA Portal WinCC Windows ALM Required
V1.5 V13-V15.1 WinCC V7.3 / 7.4 7 SP1, Server 2008 R2 V5.2
V1.6 V15-V17 WinCC V7.5 / 7.5 SP1 10 1607, Server 2016 V6.0
V2.0 V17-V18 WinCC V8.0 10 21H2, Server 2019/2022 V6.4
V2.5 V19-V20 WinCC V8.1, RT Professional V20 10 22H2, 11 23H2, Server 2022 V6.5
Verify the exact compatibility set for your target WinCC/TIA Portal version using the Siemens "Compatibility Tool" before deploying SIMATIC Logon on Windows Server 2022 or Windows 11 24H2 - newer OS releases can require ALM 6.5 + HF03 or later.

Automation License Manager V5.0 + SP1 - What "Change Logon" Actually Does

On ALM V5.0 + SP1 (32-bit), the Change Logon menu modifies the account under which the almservice runs. This is unrelated to SIMATIC Logon users and is required only when:

  • Floating licenses must be returned to a license server across a service restart boundary.
  • The ALM service must impersonate a domain user that owns the license file.
  • Service account passwords are rotated and ALM must re-bind.

If none of those apply, leave ALM running under the default LocalSystem account and perform all user administration in Windows + WinCC as described above.

Verification Checklist

  1. Open Computer Management > Local Users and Groups and confirm the Logon_ groups exist.
  2. Open WinCC User Administration and confirm each Windows group has a mirror entry with the correct authorizations.
  3. Log on to the runtime as the test user. The login dialog should accept the Windows credentials.
  4. In WinCC, check Tools > User Administration > Status - the user's groups and their assigned authorizations must be listed.
  5. Verify SLSS event log is free of warnings: Event Viewer > Applications and Services Log > SIMATIC Logon.
  6. Stop and restart the runtime - the logon must succeed without re-entering credentials when the user is already cached.

Troubleshooting Matrix

Symptom Likely Cause Corrective Action
Change Logon in ALM does nothing ALM is not the user store Use Windows User Management + WinCC User Administration
Access Protection toggle in SIMATIC Manager does nothing No project-level group defined Set protection group and password in project properties
Login rejected: "User not known" Group name missing Logon_ prefix Rename group in Windows and WinCC
Login rejected: "Insufficient authorization" Group exists but no WinCC permissions mapped Open WinCC User Administration and assign authorizations to the group
SLSS service not starting License missing in ALM Install SIMATIC Logon license in ALM; restart service
Panel cannot reach engineering station Firewall blocks TCP 49153 (SIMATIC Logon) Open inbound TCP 49153 on engineering station and domain controller
Domain user fails login on workgroup panel Offline cache empty Log on once while connected, then verify offline list

Field-Proven Caveats

  • Domain controllers must be reachable on UDP 389 (LDAP) and TCP 88 (Kerberos) during the first login of a session. Subsequent logons use cached Kerberos tickets.
  • If the panel is in a workgroup and the user account is local, the username must be entered in the form HOSTNAME\username or .\username.
  • Do not delete the Logon_ group from Windows while a WinCC project is running - the runtime holds open handles and may crash when re-validating.
  • Long-running WinCC projects that upgrade from WinCC V7 to WinCC V8 must recreate the WinCC-side group entries even when Windows groups are unchanged. The internal authorization IDs change between major versions.
  • If you enable Secure communication on a Comfort Panel with firmware V14 or earlier, SIMATIC Logon V1.5 fails - upgrade panel firmware to V15.0 or later.

Quick Reference: Command-Line and Service Names

Item Identifier
SIMATIC Logon Service executable SLSS.exe
Service display name SIMATIC Logon Service
Configuration UI shortcut Start > SIMATIC > SIMATIC Logon > Configure SIMATIC Logon
Default SIMATIC Logon TCP port 49153
ALM service executable almservice.exe
ALM UI executable ALM.exe

FAQ

Why does the "Change Logon" button in Automation License Manager do nothing when I try to create a SIMATIC Logon user?

Because ALM is a license manager, not a user store. SIMATIC Logon users must be created in Windows User Management (Computer Management > Local Users and Groups) and then mirrored as groups inside WinCC User Administration. The ALM "Change Logon" only changes the service account that runs ALM itself.

What is the mandatory naming rule for SIMATIC Logon groups?

Every Windows group that participates in SIMATIC Logon must start with the exact prefix Logon_ (for example, Logon_Administrator, Logon_Manager, Logon_Operator). WinCC ignores groups that do not carry this prefix, even if the user is a member of them.

Which Automation License Manager version is required for SIMATIC Logon V1.x?

SIMATIC Logon V1.5 typically pairs with ALM V5.2; SIMATIC Logon V1.6 with ALM V6.0; and SIMATIC Logon V2.0/V2.5 with ALM V6.4 or later. Your reported environment of ALM V5.0 + SP1 is sufficient for SIMATIC Logon V1.5 deployments but should be upgraded for current TIA Portal projects.

Can I create users directly inside WinCC without Windows groups?

No. WinCC User Administration only stores authorizations and group names. The actual authentication always happens against Windows (local SAM or Active Directory). A user must exist in Windows and be a member of a Logon_ group before WinCC will accept them.

Why does enabling Access Protection in SIMATIC Manager close immediately without applying?

STEP 7 only persists Access Protection when a project-level group is defined and at least one user is a member. If no group is configured, the toggle is silently discarded. Open the project's Properties > Protection tab, set a password, and assign the authorized Windows group.

Back to blog