Problem Overview: TIA Portal V16 WinCC Installation Failure
Installation of TIA Portal V16 with the WinCC option (Professional or Unified) can terminate with a non-zero exit code when the SIMATIC Security Controller (SECON) service cannot be registered, started, or configured. Because SECON is deployed near the end of the product setup chain, a failure at that stage leaves the workstation in a partially installed state: the engineering portal and most add-ins may launch, but licensing, user administration, and WinCC runtime authentication components will be missing or unstable.
This guide consolidates the field-proven recovery path: Windows 10 build verification, pre-installation hygiene (admin elevation, AV exclusion, installer integrity), structured setup log analysis, and the standalone re-installation of the SECON component.
SECON Component Background
SECON is the Windows service that gates TIA Portal's authorization model. It brokers access to the local user management database, enforces project protection, and is required by WinCC Unified runtime and by every TIA Portal plug-in that calls IAuthService / ILicenseService.
| Attribute | Value |
|---|---|
| Service short name | SeCon |
| Display name | SIMATIC Security Controller |
| Typical executable | C:\Program Files\Siemens\Automation\SIMATIC\Security\SeCon.exe |
| Install order in setup | Near the end (post-WinCC components) |
| Failure symptom | Setup rolls back the entire transaction; previous components are uninstalled |
| Log file (default) | %ProgramData%\Siemens\Automation\Logfiles\SeConInstall.log |
A SECON install failure is therefore almost never a "missing file" problem. It is one of three root-cause families:
-
Privilege / ACL fault – the installer cannot write to
ProgramData\Siemensor cannot create/start the service because LocalSystem rights are not available. -
Antivirus / EDR interception – a real-time AV or application-control product blocks
SeCon.exefrom being registered as a service or hooks into it before signing. - Operating-system mismatch – a Windows 10 build that is not on the V16 support matrix (notably 1709 / 1803 / 1809 / Enterprise 2019 LTSC) prevents the MSI custom action from completing.
Windows 10 Compatibility Matrix for TIA Portal V16
Only specific Windows 10 builds are listed in the TIA Portal V16 release notes. Installations on unlisted builds can succeed in core TIA Portal but fail inside SECON because of missing API contracts in advapi32.dll, bcrypt.dll, and the WfpProvider subsystem.
| Windows 10 Edition | Build | V16 supported | Notes |
|---|---|---|---|
| Pro / Enterprise | 1903 (18362) | Yes | Minimum certified build |
| Pro / Enterprise | 1909 (18363) | Yes | Recommended stable |
| Pro / Enterprise | 2004 (19041) | Yes | Supported, .NET 4.8 needed |
| Pro / Enterprise | 1709 (16299) – Creators Update | No | Setup hangs in SECON phase |
| Pro / Enterprise | 1803 (17134) | No | MSI custom action rollback |
| Pro / Enterprise | 1809 (17763) | No | WfpProvider API drift |
| Enterprise LTSC | 2019 (17763) | No | Same kernel as 1809, unsupported |
| Windows 11 | 21H2+ | Limited | Not in V16 matrix; upgrade to V17+ |
Verify the running build before touching anything else:
winver
# or
Get-ComputerInfo | Select-Object WindowsProductName, WindowsVersion, OsBuildNumber, OsHardwareAbstractionLayer
If the reported build is on the unsupported list, the correct action is to update Windows 10 to 1909 (or 2004) before retrying the V16 install. Patching V16 with hotfixes will not recover compatibility with 1709/1803/1809.
Prerequisites and Pre-Installation Hygiene
Run the following checklist before launching the V16 setup. Each item is a confirmed factor in SECON-stage failures observed in the field.
-
Local Administrator rights – the user must be a member of
BUILTIN\Administrators. UAC must allow elevation; start the setup via right-click → Run as administrator. -
Clean %TEMP% – old
_is/setupfolders from aborted installs are reused by the next setup and produce stale MSI error codes. Delete%LOCALAPPDATA%\Tempcontents for the current user. -
Antivirus / EDR exclusion – real-time scan, tamper protection, and credential guard must be off during the install. Exclude at minimum:
C:\Program Files\Siemens\ C:\ProgramData\Siemens\ C:\Users\<user>\AppData\Local\Temp\ %TEMP%\*_is* %TEMP%\SiemensInstData -
Installer integrity – the V16 delivery is either an
.isomounted to a virtual drive or an extracted folder. If extracted, the file must be on a local NTFS volume, not a network share, and not on OneDrive / DFSR. Re-download using the Siemens Online Software Delivery (OSD) portal and compare the SHA-256 of theStart.exewith the value published in the OSD manifest. - Pre-required runtimes – .NET Framework 4.7.2 (or 4.8), Visual C++ 2015-2019 redistributable (x86 and x64), SQL Server 2016 SP2 (Express is bundled and acceptable).
- Power options – disable sleep, hibernation, and screen lock for the duration. A SECON rollback that loses its 60-second custom-action window is the typical symptom of a sleep/standby transition.
- No concurrent setup – confirm no Microsoft Office Click-to-Run, Windows Update, or SCCM job is in the foreground. Concurrent MSI transactions will deadlock with the Siemens custom actions.
SeConCustomAction.dll cannot extract its payload to %TEMP% and silently aborts the transaction.Setup Log Locations and Analysis
When the installer GUI shows "An error occurred" without detail, the actual fault is in the MSI log. Always enable verbose logging on the first retry:
Start.exe /silent /log "%USERPROFILE%\Desktop\TIA_V16_install.log" /debuglog
If the GUI is the only viable entry point, look for these files after a failed run:
| Log file | Default location | What it contains |
|---|---|---|
| Setup log (MSI) | %LOCALAPPDATA%\Temp\SiemensInstData\<product>\Logs\ |
Full MSI verbose log per package |
| SeCon install log | %ProgramData%\Siemens\Automation\Logfiles\SeConInstall.log |
SECON service register/start, ACL setup |
| Setup summary | %LOCALAPPDATA%\Temp\SiemensInstData\SetupSummary.log |
Per-component exit code |
| Windows Installer events | Event Viewer → Application (Source: MsiInstaller) | Event ID 10005, 1001, 1033 |
| Application event log | Event Viewer → Application (Source: Application Error) | Faulting module name for SECON custom action |
Reading the MSI Log
Search the log for the V16 SECON package identifier. The package GUID is stable across V16 updates:
findstr /i "SeCon SecurityController" "%USERPROFILE%\Desktop\TIA_V16_install.log"
Common SECON-related return codes observed in TIA Portal V16 setups:
| Return code | Hex | Typical cause | Field action |
|---|---|---|---|
| 1603 | 0x80070643 | Fatal error during install; most often ACL/AV block on SeCon.exe | Disable AV, rerun as admin |
| 1719 | 0x80070429 | Windows Installer service not reachable; SECON custom action cannot contact msiserver |
net start msiserver and retry |
| 1923 | 0x800703E7 | Service 'SIMATIC Security Controller' could not be registered | Check LocalSystem rights on the account; see ACL section |
| 1925 | 0x800703ED | User not permitted to install/start SECON | Elevation failure; re-launch as administrator |
| 1935 | 0x800736B3 | WinSxS assembly manifest error; often a Windows 10 1809 side-by-side issue |
sfc /scannow then upgrade Windows build |
| -2147024891 | 0x80070005 | E_ACCESSDENIED writing ProgramData\Siemens
|
Take ownership or run as admin from elevated cmd |
| -2147021886 | 0x8007007A | ERROR_NOACCESS on SeCon.exe path |
Antivirus lock; release and exclude |
The phrase SeConCustomAction followed by a FAIL marker inside the verbose log is the most reliable signal that the failure originates in the SECON package rather than in WinCC itself.
Step-by-Step Recovery Procedure
-
Confirm Windows build. Open
winver. If build is < 18362, plan a Windows feature update to 1909 before continuing. - Disable protection stack. Suspend real-time AV, tamper protection, Defender ATP, BitLocker pre-boot, and any credential guard components. Document the AV product and version for the change record.
-
Remove partial install. Run the V16 setup once more and choose Modify / Uninstall. If the GUI itself cannot start, manually remove via:
msiexec /x {<V16-Product-GUID>} /l*v uninstall.log # Then delete orphaned folders: rmdir /s /q "%ProgramData%\Siemens\Automation\Logfiles\SeConInstall.log" rmdir /s /q "%ProgramFiles%\Siemens\Automation\SIMATIC\Security" -
Clean %TEMP%.
del /q /f "%TEMP%\*" 2>nul rmdir /s /q "%LOCALAPPDATA%\Temp\SiemensInstData" -
Mount / re-verify installer. Mount the official
.isoor copy the extracted tree toC:\Install\TIA_V16\. Re-download if the SHA-256 ofStart.exedoes not match the OSD manifest. -
Launch elevated.
powershell -Command "Start-Process 'C:\Install\TIA_V16\Start.exe' -Verb RunAs" - Run the setup. Choose the products (TIA Portal, WinCC Professional V16, WinCC Unified V16 if applicable). On Configuration screens, leave WinCC Unified User Management at the default local database until SECON is verified to be installed cleanly.
-
Inspect the post-install state. If the GUI reports an error, do not re-run the setup yet. Open
SeConInstall.logand locate the return code line. Cross-reference with the table above.
Standalone Re-installation of the SECON Component
The SECON package is delivered as a stand-alone MSI inside the V16 installer tree. Running it directly bypasses the full-product rollback and is the fastest way to repair a partially installed workstation.
- Open the V16 installer media. Navigate to:
(Exact path varies; the file is always named\Support\SeCon\SeConSetup.msiSeConSetup.msiorSIMATIC_Security_Controller.msi.) - Open an elevated command prompt in the same directory and run:
msiexec /i SeConSetup.msi REINSTALL=ALL REINSTALLMODE=omus /l*v secon_repair.log - Verify the service:
sc query "SeCon" # Expected: STATE : 4 RUNNING # Display name: SIMATIC Security Controller - Verify the executable path and signature:
The signature must be issued by Siemens AG with a valid timestamp.where SeCon.exe sigcheck -a -s "C:\Program Files\Siemens\Automation\SIMATIC\Security\SeCon.exe"
If the standalone repair fails with the same return code, capture the full secon_repair.log and the corresponding Application Error event from the Windows event log; the event is what to attach to the support ticket.
Repairing the WinCC Unified User Administration Layer
Because WinCC Unified depends on SECON for its user administration, a clean SECON install does not automatically populate the UMAC (User Management and Access Control) database. After SECON is verified, re-establish UMAC by running the WinCC Unified configuration tool:
"C:\Program Files\Siemens\Automation\WinCCUnified\UMC\SimaticUmc.exe" --reconfigure
Confirm the umac service is registered:
sc query "SimaticUMC"
Verification Checklist
Run all checks before declaring the install successful:
- Open TIA Portal V16 → Help → Installed software. The version string should read
V16.0 + Upd 1(or the highest applied update). - Launch WinCC Professional V16 from Start → Siemens Automation. The runtime configurator should open without a "Security Controller not available" dialog.
- Open Project tree → Runtime settings → Authorization. Add a test user. If the dialog accepts the new user and writes to the local user management, SECON is fully operational.
- From a command prompt:
The service must be RUNNING, started automatically, and its binary path must match the freshly signedsc query SeCon sc qc SeCon | findstr BINARY_PATH_NAMESeCon.exe. - Check the Reliability Monitor for any post-install crash attributable to
SeCon.exein the 10 minutes following the install. - Reboot the workstation. Re-check that
SeConstarts without manual intervention. A service that requires manual start after every reboot points to a dependency problem (typicallyRPCSSorEventLognot being ready when SECON attempts to register).
Common Error Scenarios and Field-Proven Fixes
| Symptom | Likely root cause | Fix |
|---|---|---|
| Setup fails at ~85% with no dialog detail | SECON custom-action ACL failure | Elevate; remove any non-default ACL on ProgramData\Siemens
|
| Setup fails immediately on Windows 10 1809 | Unsupported Windows build | Upgrade to 1909 or 2004 |
| Setup fails twice in a row, identical return code | Antivirus quarantine of SeCon.exe
|
Restore from quarantine, add AV exclusion, rerun |
| SECON service "StartPending" forever | Dependency on a removed service |
sc qc SeCon to view dependencies; restore missing parent |
| SECON installed but TIA Portal reports "no license server" | Reinstall needed; binaries are present but the license adapter registration is missing | Reinstall WinCC component; do not reinstall full product |
MSI log shows ERROR_NOACCESS on SeCon.exe
|
File in use by another process (often OneDrive sync) | Suspend OneDrive, exclude Program Files\Siemens from sync |
Setup finishes but SeConInstall.log ends in <1 KB |
Setup crashed before reaching SECON; the real failure is upstream | Re-open the full V16 MSI log and search for the first FAIL line |
Anti-virus and EDR Interference Map
Application-control products (e.g. AppLocker, Windows Defender Application Control) and behavior-based EDR will block SeCon.exe registration even if file-write access is allowed. The error in the MSI log is generic (1603 or 1923); the AV product's own log holds the truth.
| Product | Symptom | Where to confirm |
|---|---|---|
| Windows Defender | Event ID 1126 in Microsoft-Windows-Windows Defender/Operational | Event Viewer |
| Trend Micro Apex One | Quarantine of SeCon.exe with policy ID <number> |
Apex Central console |
| Symantec Endpoint Protection | Application control denial, log under Symantec Endpoint Protection Client | SEPM dashboard |
| CrowdStrike Falcon | Detection type: Suspicious Service Registration | Falcon console → Detections |
| Sophos Intercept X | Event "Service creation blocked" with PID of msiexec | Sophos Central → Events |
Post-Install Hardening
Once SECON is operational, lock down the install:
- Re-enable AV and add the Siemens folders to the permanent exclusion list.
- Apply the latest TIA Portal V16 hotfix (search the Siemens Support portal, entry ID
109769320for the V16 update collection). - Schedule a weekly
sc query SeConhealth check via a small PowerShell script and Task Scheduler. A non-running SECON after reboot is a common silent failure that surfaces only when a user tries to open a protected project. - Document the install baseline in the CMDB: V16 build number, applied hotfix, SECON service version, Windows build, AV product and exclusion scope.
When to Escalate
Escalate to Siemens Technical Support with a Support Request (SR) if any of the following is true after the steps above:
- The MSI log shows a return code outside the table above, with no AV/EDR match.
- The
SeCon.exesignature is invalid or the binary has been digitally altered. - The same workstation reproduces the failure on a clean Windows 10 1909 image with no third-party AV.
- Two consecutive TIA Portal V16 minor updates (e.g. V16 + Upd 4 → V16 + Upd 5) both fail at SECON stage on a fleet of identical workstations.
Attach the TIA_V16_install.log, the SeConInstall.log, the last 50 lines of the Application and System event logs in .evtx format, and the output of msinfo32 /report.
FAQ
What does the SECON service do in TIA Portal V16?
SECON (SIMATIC Security Controller) is the Windows service that authenticates TIA Portal users, manages project protection, and is required for WinCC Unified user administration. It runs as SeCon.exe under LocalSystem and is the last major component installed by the V16 setup.
Can I install TIA Portal V16 on Windows 10 1809 or Enterprise LTSC 2019?
No. The V16 release notes list Windows 10 build 1903 (18362) or later, 1909 (18363), and 2004 (19041) as supported. Builds 1709, 1803, 1809, and Enterprise 2019 LTSC are not on the matrix and will fail in the SECON stage. Upgrade the OS to 1909 before installing V16, or move the workload to TIA Portal V17/V18 which has a wider Windows 10/11 support window.
Where is the TIA Portal V16 setup log stored?
The full MSI verbose log is written to %LOCALAPPDATA%\Temp\SiemensInstData\<product>\Logs\. The SECON-specific log is %ProgramData%\Siemens\Automation\Logfiles\SeConInstall.log. To force a verbose log, launch the setup with Start.exe /log "path\to\file.log" /debuglog.
Is it safe to re-run the TIA Portal V16 setup after a SECON failure?
Yes, but only after cleaning %TEMP%, deleting the partial %ProgramFiles%\Siemens\Automation\SIMATIC\Security folder, disabling AV, and re-launching from an elevated command prompt. A repeated failure with the same MSI return code is a signal to read the log, not to keep retrying.
Can I install SECON separately from the main TIA Portal V16 setup?
Yes. The SeConSetup.msi is shipped inside the V16 media under a Support\SeCon (or product-named) folder. Run msiexec /i SeConSetup.msi REINSTALL=ALL REINSTALLMODE=omus /l*v secon_repair.log from an elevated command prompt to repair or install just the SECON component without affecting the rest of the TIA Portal installation.