Problem: SIMATIC Logon "Change Logon" Button Has No Effect in Automation License Manager
Symptom: A user opens Automation License Manager (ALM), attempts to invoke Change Logon from a SIMATIC Logon entry to create or modify an account, and nothing happens. The dialog does not appear, no error is raised, and the system returns to its previous state. The same condition can occur when an engineer selects Options > Access Protection > Enable inside the legacy SIMATIC Manager and the dialog silently closes without applying protection.
Affected environment observed in the field:
- Automation License Manager V5.0 + SP1, 32-bit edition
- SIMATIC Logon runtime component shipped with WinCC V7.x / TIA Portal V13-V20
- Windows 7 SP1 / Windows 10 LTSC workstations joined to a local workgroup (no domain)
This article explains the architectural reason the dialog does nothing and provides the correct procedure for creating SIMATIC Logon users. The recommended fix is independent of ALM build because ALM is never the correct tool for user administration.
Root Cause: ALM Is a License Tool, Not a User Store
Automation License Manager exists to manage, transfer, and validate Siemens software licenses (Floating, Single, Rental, Trial). It is not designed to hold user accounts, role assignments, or password hashes. The Change Logon entry visible inside ALM corresponds to the Windows service account that owns the ALM process; it does not create SIMATIC Logon identities.
SIMATIC Logon uses two stores:
- Windows User Management - the authoritative source of users and groups. Located under Computer Management > System Tools > Local Users and Groups (workgroup) or Active Directory Users and Computers (domain).
- WinCC User Administration - the runtime map that grants WinCC/TIA Portal permissions to the Windows groups.
If you only clicked Change Logon in ALM, no user is created because ALM has no schema for users. Access Protection in SIMATIC Manager requires a valid Windows group with the Logon_ prefix already present on the workstation; otherwise the toggle closes silently because the validation step finds no eligible principal.
Logon_. A SIMATIC Logon authorization is the mapping of that group to a permission set inside WinCC User Administration. Skip any one of these three layers and the change button "does nothing."
SIMATIC Logon Architecture and Identity Flow
SIMATIC Logon is the central user-administration component for WinCC Runtime, WinCC Professional (RT Professional), Panels, Comfort Panels, and PC-based HMI systems. Central user administration using SIMATIC Logon keeps user credentials outside the HMI project so the same user account can authenticate to multiple runtime instances, panels, and engineering stations.
Identity flow at runtime:
- Operator enters username/password on the panel or RT client.
- The runtime calls the SIMATIC Logon service (
SLSS) on the engineering station or domain controller. -
SLSSvalidates the principal against Windows (local SAM or Active Directory). - The service returns the user's group memberships to the runtime.
- WinCC compares the groups against its permission table and grants the configured authorization.
Because step 3 depends entirely on Windows, ALM is excluded from this path. Configuring SIMATIC Logon is documented in the official SIMATIC Logon help PDF and the TIA Portal V20 user-administration manual:
- SIMATIC Logon Help (English, slhelp_b_en-US.pdf)
- Central user administration using SIMATIC Logon (TIA Portal V20)
- Logging on using SIMATIC Logon (TIA Portal V20)
Prerequisites Before Creating Users
| Component | Required State |
|---|---|
| Windows account performing setup | Member of local Administrators
|
| Workstation role | Joined to a Windows domain or standalone with local SAM |
| Automation License Manager | Installed; valid license for SIMATIC Logon present |
SIMATIC Logon Service (SLSS) |
Running (services.msc > SIMATIC Logon Service > Started, Automatic) |
| WinCC User Administration editor | Accessible from WinCC Explorer or TIA Portal project |
| TIA Portal project (if applicable) | User administration editor compiled with project |
Logon_ prefix is mandatory. Groups named Administrators, Manager, or Operators will be ignored by the runtime even if the user is a member. WinCC only honors groups whose names start exactly with the string Logon_ (case-sensitive on localized builds).
Step-by-Step: Correctly Creating a SIMATIC Logon User
Step 1 - Create the role groups in Windows
- Open Computer Management (right-click This PC > Manage).
- Navigate to System Tools > Local Users and Groups > Groups.
- Create one group per role. Use the prefix exactly as shown:
Logon_Administrator
Logon_Manager
Logon_Operator
Logon_Viewer
4. Add the appropriate Windows users to each group as required.
Step 2 - Mirror the groups inside WinCC User Administration
- In the WinCC project, open User Administration (WinCC Explorer) or Runtime Settings > User administration (TIA Portal).
- Create a group entry with the identical name you used in Windows, including the
Logon_prefix. - Assign the operator-level authorizations to the group:
| Windows Group | Typical WinCC Authorizations |
|---|---|
| Logon_Administrator | User administration, Configuration, Process controlling |
| Logon_Manager | Process controlling, Acknowledge alarms, Change values |
| Logon_Operator | Process controlling, Acknowledge alarms |
| Logon_Viewer | Monitor only |
Step 3 - Create the Windows user
- Under Local Users and Groups > Users, create the operator account (example:
seaf). - Set a strong password and clear User must change password at next logon.
- Add the user as a member of one or more
Logon_groups (for example,seaf→Logon_Manager).
Step 4 - Enable SIMATIC Logon in the runtime
In TIA Portal V20 (or compatible WinCC):
- Open the project tree > Runtime settings > User administration.
- Check Enable SIMATIC Logon.
- Select Windows domain if the station is joined to Active Directory, otherwise select Windows workgroup.
- Compile and download the project to the panel or RT station.
Step 5 - Configure the SIMATIC Logon service
- Launch Start > SIMATIC > SIMATIC Logon > Configure SIMATIC Logon.
- Enter the logon credentials of a Windows administrator.
- Confirm that the SLSS service is registered and started.
Why "Enable Access Protection" in SIMATIC Manager Does Nothing
Legacy SIMATIC Manager projects (STEP 7 V5.x) include an Access Protection toggle under Options. When enabled, the project requires the active Windows user to be a member of a defined group. If no project-level group is configured, or if no user with that membership opens the project, the toggle reverts silently. The dialog does not display an error because STEP 7 internally considers the request fulfilled once the validation passes against an empty principal set.
To make Access Protection active:
- Open the S7 project in SIMATIC Manager.
- Right-click the project > Properties > Protection.
- Set the password and define the authorized user/group.
- Save and reopen the project - the login prompt now appears.
Compatibility Matrix for SIMATIC Logon Components
| SIMATIC Logon Version | TIA Portal | WinCC | Windows | ALM Required |
|---|---|---|---|---|
| V1.5 | V13-V15.1 | WinCC V7.3 / 7.4 | 7 SP1, Server 2008 R2 | V5.2 |
| V1.6 | V15-V17 | WinCC V7.5 / 7.5 SP1 | 10 1607, Server 2016 | V6.0 |
| V2.0 | V17-V18 | WinCC V8.0 | 10 21H2, Server 2019/2022 | V6.4 |
| V2.5 | V19-V20 | WinCC V8.1, RT Professional V20 | 10 22H2, 11 23H2, Server 2022 | V6.5 |
Automation License Manager V5.0 + SP1 - What "Change Logon" Actually Does
On ALM V5.0 + SP1 (32-bit), the Change Logon menu modifies the account under which the almservice runs. This is unrelated to SIMATIC Logon users and is required only when:
- Floating licenses must be returned to a license server across a service restart boundary.
- The ALM service must impersonate a domain user that owns the license file.
- Service account passwords are rotated and ALM must re-bind.
If none of those apply, leave ALM running under the default LocalSystem account and perform all user administration in Windows + WinCC as described above.
Verification Checklist
- Open Computer Management > Local Users and Groups and confirm the
Logon_groups exist. - Open WinCC User Administration and confirm each Windows group has a mirror entry with the correct authorizations.
- Log on to the runtime as the test user. The login dialog should accept the Windows credentials.
- In WinCC, check Tools > User Administration > Status - the user's groups and their assigned authorizations must be listed.
- Verify
SLSSevent log is free of warnings: Event Viewer > Applications and Services Log > SIMATIC Logon. - Stop and restart the runtime - the logon must succeed without re-entering credentials when the user is already cached.
Troubleshooting Matrix
| Symptom | Likely Cause | Corrective Action |
|---|---|---|
| Change Logon in ALM does nothing | ALM is not the user store | Use Windows User Management + WinCC User Administration |
| Access Protection toggle in SIMATIC Manager does nothing | No project-level group defined | Set protection group and password in project properties |
| Login rejected: "User not known" | Group name missing Logon_ prefix |
Rename group in Windows and WinCC |
| Login rejected: "Insufficient authorization" | Group exists but no WinCC permissions mapped | Open WinCC User Administration and assign authorizations to the group |
| SLSS service not starting | License missing in ALM | Install SIMATIC Logon license in ALM; restart service |
| Panel cannot reach engineering station | Firewall blocks TCP 49153 (SIMATIC Logon) | Open inbound TCP 49153 on engineering station and domain controller |
| Domain user fails login on workgroup panel | Offline cache empty | Log on once while connected, then verify offline list |
Field-Proven Caveats
- Domain controllers must be reachable on UDP 389 (LDAP) and TCP 88 (Kerberos) during the first login of a session. Subsequent logons use cached Kerberos tickets.
- If the panel is in a workgroup and the user account is local, the username must be entered in the form
HOSTNAME\usernameor.\username. - Do not delete the
Logon_group from Windows while a WinCC project is running - the runtime holds open handles and may crash when re-validating. - Long-running WinCC projects that upgrade from WinCC V7 to WinCC V8 must recreate the WinCC-side group entries even when Windows groups are unchanged. The internal authorization IDs change between major versions.
- If you enable Secure communication on a Comfort Panel with firmware V14 or earlier, SIMATIC Logon V1.5 fails - upgrade panel firmware to V15.0 or later.
Quick Reference: Command-Line and Service Names
| Item | Identifier |
|---|---|
| SIMATIC Logon Service executable | SLSS.exe |
| Service display name | SIMATIC Logon Service |
| Configuration UI shortcut | Start > SIMATIC > SIMATIC Logon > Configure SIMATIC Logon |
| Default SIMATIC Logon TCP port | 49153 |
| ALM service executable | almservice.exe |
| ALM UI executable | ALM.exe |
FAQ
Why does the "Change Logon" button in Automation License Manager do nothing when I try to create a SIMATIC Logon user?
Because ALM is a license manager, not a user store. SIMATIC Logon users must be created in Windows User Management (Computer Management > Local Users and Groups) and then mirrored as groups inside WinCC User Administration. The ALM "Change Logon" only changes the service account that runs ALM itself.
What is the mandatory naming rule for SIMATIC Logon groups?
Every Windows group that participates in SIMATIC Logon must start with the exact prefix Logon_ (for example, Logon_Administrator, Logon_Manager, Logon_Operator). WinCC ignores groups that do not carry this prefix, even if the user is a member of them.
Which Automation License Manager version is required for SIMATIC Logon V1.x?
SIMATIC Logon V1.5 typically pairs with ALM V5.2; SIMATIC Logon V1.6 with ALM V6.0; and SIMATIC Logon V2.0/V2.5 with ALM V6.4 or later. Your reported environment of ALM V5.0 + SP1 is sufficient for SIMATIC Logon V1.5 deployments but should be upgraded for current TIA Portal projects.
Can I create users directly inside WinCC without Windows groups?
No. WinCC User Administration only stores authorizations and group names. The actual authentication always happens against Windows (local SAM or Active Directory). A user must exist in Windows and be a member of a Logon_ group before WinCC will accept them.
Why does enabling Access Protection in SIMATIC Manager close immediately without applying?
STEP 7 only persists Access Protection when a project-level group is defined and at least one user is a member. If no group is configured, the toggle is silently discarded. Open the project's Properties > Protection tab, set a password, and assign the authorized Windows group.