Fixing TIA Portal V16 WinCC Setup Errors: SECON and Log Analysis

David Krause12 min read
SiemensTIA PortalTroubleshooting
Licensed PE Working through this on a live machine? A Maine-licensed engineer can take it from here — included with IMD hardware, by the hour for everything else. Book an engineer

Problem Overview: TIA Portal V16 WinCC Installation Failure

Installation of TIA Portal V16 with the WinCC option (Professional or Unified) can terminate with a non-zero exit code when the SIMATIC Security Controller (SECON) service cannot be registered, started, or configured. Because SECON is deployed near the end of the product setup chain, a failure at that stage leaves the workstation in a partially installed state: the engineering portal and most add-ins may launch, but licensing, user administration, and WinCC runtime authentication components will be missing or unstable.

This guide consolidates the field-proven recovery path: Windows 10 build verification, pre-installation hygiene (admin elevation, AV exclusion, installer integrity), structured setup log analysis, and the standalone re-installation of the SECON component.

SECON Component Background

SECON is the Windows service that gates TIA Portal's authorization model. It brokers access to the local user management database, enforces project protection, and is required by WinCC Unified runtime and by every TIA Portal plug-in that calls IAuthService / ILicenseService.

Attribute Value
Service short name SeCon
Display name SIMATIC Security Controller
Typical executable C:\Program Files\Siemens\Automation\SIMATIC\Security\SeCon.exe
Install order in setup Near the end (post-WinCC components)
Failure symptom Setup rolls back the entire transaction; previous components are uninstalled
Log file (default) %ProgramData%\Siemens\Automation\Logfiles\SeConInstall.log

A SECON install failure is therefore almost never a "missing file" problem. It is one of three root-cause families:

  1. Privilege / ACL fault – the installer cannot write to ProgramData\Siemens or cannot create/start the service because LocalSystem rights are not available.
  2. Antivirus / EDR interception – a real-time AV or application-control product blocks SeCon.exe from being registered as a service or hooks into it before signing.
  3. Operating-system mismatch – a Windows 10 build that is not on the V16 support matrix (notably 1709 / 1803 / 1809 / Enterprise 2019 LTSC) prevents the MSI custom action from completing.

Windows 10 Compatibility Matrix for TIA Portal V16

Only specific Windows 10 builds are listed in the TIA Portal V16 release notes. Installations on unlisted builds can succeed in core TIA Portal but fail inside SECON because of missing API contracts in advapi32.dll, bcrypt.dll, and the WfpProvider subsystem.

Windows 10 Edition Build V16 supported Notes
Pro / Enterprise 1903 (18362) Yes Minimum certified build
Pro / Enterprise 1909 (18363) Yes Recommended stable
Pro / Enterprise 2004 (19041) Yes Supported, .NET 4.8 needed
Pro / Enterprise 1709 (16299) – Creators Update No Setup hangs in SECON phase
Pro / Enterprise 1803 (17134) No MSI custom action rollback
Pro / Enterprise 1809 (17763) No WfpProvider API drift
Enterprise LTSC 2019 (17763) No Same kernel as 1809, unsupported
Windows 11 21H2+ Limited Not in V16 matrix; upgrade to V17+

Verify the running build before touching anything else:

winver
# or
Get-ComputerInfo | Select-Object WindowsProductName, WindowsVersion, OsBuildNumber, OsHardwareAbstractionLayer

If the reported build is on the unsupported list, the correct action is to update Windows 10 to 1909 (or 2004) before retrying the V16 install. Patching V16 with hotfixes will not recover compatibility with 1709/1803/1809.

Prerequisites and Pre-Installation Hygiene

Run the following checklist before launching the V16 setup. Each item is a confirmed factor in SECON-stage failures observed in the field.

  1. Local Administrator rights – the user must be a member of BUILTIN\Administrators. UAC must allow elevation; start the setup via right-click → Run as administrator.
  2. Clean %TEMP% – old _is / setup folders from aborted installs are reused by the next setup and produce stale MSI error codes. Delete %LOCALAPPDATA%\Temp contents for the current user.
  3. Antivirus / EDR exclusion – real-time scan, tamper protection, and credential guard must be off during the install. Exclude at minimum:
    C:\Program Files\Siemens\
    C:\ProgramData\Siemens\
    C:\Users\<user>\AppData\Local\Temp\
    %TEMP%\*_is*
    %TEMP%\SiemensInstData
  4. Installer integrity – the V16 delivery is either an .iso mounted to a virtual drive or an extracted folder. If extracted, the file must be on a local NTFS volume, not a network share, and not on OneDrive / DFSR. Re-download using the Siemens Online Software Delivery (OSD) portal and compare the SHA-256 of the Start.exe with the value published in the OSD manifest.
  5. Pre-required runtimes – .NET Framework 4.7.2 (or 4.8), Visual C++ 2015-2019 redistributable (x86 and x64), SQL Server 2016 SP2 (Express is bundled and acceptable).
  6. Power options – disable sleep, hibernation, and screen lock for the duration. A SECON rollback that loses its 60-second custom-action window is the typical symptom of a sleep/standby transition.
  7. No concurrent setup – confirm no Microsoft Office Click-to-Run, Windows Update, or SCCM job is in the foreground. Concurrent MSI transactions will deadlock with the Siemens custom actions.
Critical: Do not run the V16 setup from inside a compressed or encrypted folder (e.g. a 7z archive opened with PeaZip). The custom action SeConCustomAction.dll cannot extract its payload to %TEMP% and silently aborts the transaction.

Setup Log Locations and Analysis

When the installer GUI shows "An error occurred" without detail, the actual fault is in the MSI log. Always enable verbose logging on the first retry:

Start.exe /silent /log "%USERPROFILE%\Desktop\TIA_V16_install.log" /debuglog

If the GUI is the only viable entry point, look for these files after a failed run:

Log file Default location What it contains
Setup log (MSI) %LOCALAPPDATA%\Temp\SiemensInstData\<product>\Logs\ Full MSI verbose log per package
SeCon install log %ProgramData%\Siemens\Automation\Logfiles\SeConInstall.log SECON service register/start, ACL setup
Setup summary %LOCALAPPDATA%\Temp\SiemensInstData\SetupSummary.log Per-component exit code
Windows Installer events Event Viewer → Application (Source: MsiInstaller) Event ID 10005, 1001, 1033
Application event log Event Viewer → Application (Source: Application Error) Faulting module name for SECON custom action

Reading the MSI Log

Search the log for the V16 SECON package identifier. The package GUID is stable across V16 updates:

findstr /i "SeCon SecurityController" "%USERPROFILE%\Desktop\TIA_V16_install.log"

Common SECON-related return codes observed in TIA Portal V16 setups:

Return code Hex Typical cause Field action
1603 0x80070643 Fatal error during install; most often ACL/AV block on SeCon.exe Disable AV, rerun as admin
1719 0x80070429 Windows Installer service not reachable; SECON custom action cannot contact msiserver net start msiserver and retry
1923 0x800703E7 Service 'SIMATIC Security Controller' could not be registered Check LocalSystem rights on the account; see ACL section
1925 0x800703ED User not permitted to install/start SECON Elevation failure; re-launch as administrator
1935 0x800736B3 WinSxS assembly manifest error; often a Windows 10 1809 side-by-side issue sfc /scannow then upgrade Windows build
-2147024891 0x80070005 E_ACCESSDENIED writing ProgramData\Siemens Take ownership or run as admin from elevated cmd
-2147021886 0x8007007A ERROR_NOACCESS on SeCon.exe path Antivirus lock; release and exclude

The phrase SeConCustomAction followed by a FAIL marker inside the verbose log is the most reliable signal that the failure originates in the SECON package rather than in WinCC itself.

Step-by-Step Recovery Procedure

  1. Confirm Windows build. Open winver. If build is < 18362, plan a Windows feature update to 1909 before continuing.
  2. Disable protection stack. Suspend real-time AV, tamper protection, Defender ATP, BitLocker pre-boot, and any credential guard components. Document the AV product and version for the change record.
  3. Remove partial install. Run the V16 setup once more and choose Modify / Uninstall. If the GUI itself cannot start, manually remove via:
    msiexec /x {<V16-Product-GUID>} /l*v uninstall.log
    # Then delete orphaned folders:
    rmdir /s /q "%ProgramData%\Siemens\Automation\Logfiles\SeConInstall.log"
    rmdir /s /q "%ProgramFiles%\Siemens\Automation\SIMATIC\Security"
  4. Clean %TEMP%.
    del /q /f "%TEMP%\*" 2>nul
    rmdir /s /q "%LOCALAPPDATA%\Temp\SiemensInstData"
  5. Mount / re-verify installer. Mount the official .iso or copy the extracted tree to C:\Install\TIA_V16\. Re-download if the SHA-256 of Start.exe does not match the OSD manifest.
  6. Launch elevated.
    powershell -Command "Start-Process 'C:\Install\TIA_V16\Start.exe' -Verb RunAs"
  7. Run the setup. Choose the products (TIA Portal, WinCC Professional V16, WinCC Unified V16 if applicable). On Configuration screens, leave WinCC Unified User Management at the default local database until SECON is verified to be installed cleanly.
  8. Inspect the post-install state. If the GUI reports an error, do not re-run the setup yet. Open SeConInstall.log and locate the return code line. Cross-reference with the table above.

Standalone Re-installation of the SECON Component

The SECON package is delivered as a stand-alone MSI inside the V16 installer tree. Running it directly bypasses the full-product rollback and is the fastest way to repair a partially installed workstation.

  1. Open the V16 installer media. Navigate to:
    \Support\SeCon\SeConSetup.msi
    (Exact path varies; the file is always named SeConSetup.msi or SIMATIC_Security_Controller.msi.)
  2. Open an elevated command prompt in the same directory and run:
    msiexec /i SeConSetup.msi REINSTALL=ALL REINSTALLMODE=omus /l*v secon_repair.log
  3. Verify the service:
    sc query "SeCon"
    # Expected: STATE : 4 RUNNING
    # Display name: SIMATIC Security Controller
  4. Verify the executable path and signature:
    where SeCon.exe
    sigcheck -a -s "C:\Program Files\Siemens\Automation\SIMATIC\Security\SeCon.exe"
    The signature must be issued by Siemens AG with a valid timestamp.

If the standalone repair fails with the same return code, capture the full secon_repair.log and the corresponding Application Error event from the Windows event log; the event is what to attach to the support ticket.

Repairing the WinCC Unified User Administration Layer

Because WinCC Unified depends on SECON for its user administration, a clean SECON install does not automatically populate the UMAC (User Management and Access Control) database. After SECON is verified, re-establish UMAC by running the WinCC Unified configuration tool:

"C:\Program Files\Siemens\Automation\WinCCUnified\UMC\SimaticUmc.exe" --reconfigure

Confirm the umac service is registered:

sc query "SimaticUMC"

Verification Checklist

Run all checks before declaring the install successful:

  1. Open TIA Portal V16 → Help → Installed software. The version string should read V16.0 + Upd 1 (or the highest applied update).
  2. Launch WinCC Professional V16 from Start → Siemens Automation. The runtime configurator should open without a "Security Controller not available" dialog.
  3. Open Project tree → Runtime settings → Authorization. Add a test user. If the dialog accepts the new user and writes to the local user management, SECON is fully operational.
  4. From a command prompt:
    sc query SeCon
    sc qc SeCon | findstr BINARY_PATH_NAME
    The service must be RUNNING, started automatically, and its binary path must match the freshly signed SeCon.exe.
  5. Check the Reliability Monitor for any post-install crash attributable to SeCon.exe in the 10 minutes following the install.
  6. Reboot the workstation. Re-check that SeCon starts without manual intervention. A service that requires manual start after every reboot points to a dependency problem (typically RPCSS or EventLog not being ready when SECON attempts to register).

Common Error Scenarios and Field-Proven Fixes

Symptom Likely root cause Fix
Setup fails at ~85% with no dialog detail SECON custom-action ACL failure Elevate; remove any non-default ACL on ProgramData\Siemens
Setup fails immediately on Windows 10 1809 Unsupported Windows build Upgrade to 1909 or 2004
Setup fails twice in a row, identical return code Antivirus quarantine of SeCon.exe Restore from quarantine, add AV exclusion, rerun
SECON service "StartPending" forever Dependency on a removed service sc qc SeCon to view dependencies; restore missing parent
SECON installed but TIA Portal reports "no license server" Reinstall needed; binaries are present but the license adapter registration is missing Reinstall WinCC component; do not reinstall full product
MSI log shows ERROR_NOACCESS on SeCon.exe File in use by another process (often OneDrive sync) Suspend OneDrive, exclude Program Files\Siemens from sync
Setup finishes but SeConInstall.log ends in <1 KB Setup crashed before reaching SECON; the real failure is upstream Re-open the full V16 MSI log and search for the first FAIL line

Anti-virus and EDR Interference Map

Application-control products (e.g. AppLocker, Windows Defender Application Control) and behavior-based EDR will block SeCon.exe registration even if file-write access is allowed. The error in the MSI log is generic (1603 or 1923); the AV product's own log holds the truth.

Product Symptom Where to confirm
Windows Defender Event ID 1126 in Microsoft-Windows-Windows Defender/Operational Event Viewer
Trend Micro Apex One Quarantine of SeCon.exe with policy ID <number> Apex Central console
Symantec Endpoint Protection Application control denial, log under Symantec Endpoint Protection Client SEPM dashboard
CrowdStrike Falcon Detection type: Suspicious Service Registration Falcon console → Detections
Sophos Intercept X Event "Service creation blocked" with PID of msiexec Sophos Central → Events
Important: Simply turning the AV off is not sufficient on every product. CrowdStrike and Defender for Endpoint require a temporary policy-group move to a "build" group with relaxed application-control rules.

Post-Install Hardening

Once SECON is operational, lock down the install:

  1. Re-enable AV and add the Siemens folders to the permanent exclusion list.
  2. Apply the latest TIA Portal V16 hotfix (search the Siemens Support portal, entry ID 109769320 for the V16 update collection).
  3. Schedule a weekly sc query SeCon health check via a small PowerShell script and Task Scheduler. A non-running SECON after reboot is a common silent failure that surfaces only when a user tries to open a protected project.
  4. Document the install baseline in the CMDB: V16 build number, applied hotfix, SECON service version, Windows build, AV product and exclusion scope.

When to Escalate

Escalate to Siemens Technical Support with a Support Request (SR) if any of the following is true after the steps above:

  • The MSI log shows a return code outside the table above, with no AV/EDR match.
  • The SeCon.exe signature is invalid or the binary has been digitally altered.
  • The same workstation reproduces the failure on a clean Windows 10 1909 image with no third-party AV.
  • Two consecutive TIA Portal V16 minor updates (e.g. V16 + Upd 4 → V16 + Upd 5) both fail at SECON stage on a fleet of identical workstations.

Attach the TIA_V16_install.log, the SeConInstall.log, the last 50 lines of the Application and System event logs in .evtx format, and the output of msinfo32 /report.

FAQ

What does the SECON service do in TIA Portal V16?

SECON (SIMATIC Security Controller) is the Windows service that authenticates TIA Portal users, manages project protection, and is required for WinCC Unified user administration. It runs as SeCon.exe under LocalSystem and is the last major component installed by the V16 setup.

Can I install TIA Portal V16 on Windows 10 1809 or Enterprise LTSC 2019?

No. The V16 release notes list Windows 10 build 1903 (18362) or later, 1909 (18363), and 2004 (19041) as supported. Builds 1709, 1803, 1809, and Enterprise 2019 LTSC are not on the matrix and will fail in the SECON stage. Upgrade the OS to 1909 before installing V16, or move the workload to TIA Portal V17/V18 which has a wider Windows 10/11 support window.

Where is the TIA Portal V16 setup log stored?

The full MSI verbose log is written to %LOCALAPPDATA%\Temp\SiemensInstData\<product>\Logs\. The SECON-specific log is %ProgramData%\Siemens\Automation\Logfiles\SeConInstall.log. To force a verbose log, launch the setup with Start.exe /log "path\to\file.log" /debuglog.

Is it safe to re-run the TIA Portal V16 setup after a SECON failure?

Yes, but only after cleaning %TEMP%, deleting the partial %ProgramFiles%\Siemens\Automation\SIMATIC\Security folder, disabling AV, and re-launching from an elevated command prompt. A repeated failure with the same MSI return code is a signal to read the log, not to keep retrying.

Can I install SECON separately from the main TIA Portal V16 setup?

Yes. The SeConSetup.msi is shipped inside the V16 media under a Support\SeCon (or product-named) folder. Run msiexec /i SeConSetup.msi REINSTALL=ALL REINSTALLMODE=omus /l*v secon_repair.log from an elevated command prompt to repair or install just the SECON component without affecting the rest of the TIA Portal installation.

Back to blog