The MP377 accepted the password in the restored ProSave backup after rejecting it following a WinCC Flexible transfer and OS update. Treat the backup and the WinCC Flexible project as separate records of panel state: a ProSave restore returns the panel to the state captured when that backup was made, while the project transfer applies project data according to the selected transfer scope.
The MP377 state represented by each transfer
A password mismatch after a project transfer does not, by itself, identify whether the project contains the wrong credentials, whether the panel’s user administration changed after the backup, or whether a login restriction is involved. The key distinction is between the saved WinCC Flexible project and the panel state captured by ProSave.
In this case, restoring the earlier ProSave backup made the password active again. That confirms the restored panel state accepted that password; it does not prove why the preceding transfer left the expected password unusable. The OS update occurred during the upload sequence, but the sequence alone does not establish that the OS update caused the password change.
Use the following decision path before making another transfer:
- Identify which credentials should be active: those in the current project, or those from the ProSave snapshot.
- Check whether panel user administration could have changed after the snapshot.
- Check the transfer scope used for the current project.
- If the expected administrator still cannot log in, investigate whether failed-login lockout applies to this panel configuration.
Credential changes after the ProSave snapshot
Read the backup date and compare it with the last known user-administration change. A panel can have credentials that differ from an older project if an operator or administrator changed them through a user-management screen after the project or backup was created. The evidence for that branch is a known password change, a user-management screen in the HMI application, or a mismatch between the intended credentials in the project and the credentials accepted by the restored panel.
If the panel’s current user administration is the intended authority, do not use an older backup as proof that the current project has correct credentials. If the backup’s credentials are intended, restore that known snapshot and test its login before transferring another project. Record which state you are choosing so that a later restore does not silently undo a newer password change.
Transfer scope and the password list
Read the transfer option selected in WinCC Flexible. The password list is not transferred when the program is transferred without Transfer all; the reported MP377 case used Transfer all and still did not activate the expected new password. Therefore, the transfer-scope check is necessary, but it is not sufficient to diagnose every password failure.
Do not treat Compile and rebuild all as equivalent to Transfer all. Compilation rebuilds the project; the transfer choice determines what is sent to the panel. In the reported case, both compile/rebuild and Transfer All were selected, yet the expected password remained inactive. After confirming the scope, check the project’s administrator definition and the panel’s current user state rather than repeating the same build alone.
Project administrator definition
Read the administrator account and password configured in the current WinCC Flexible project. If the project’s intended credentials are uncertain, create at least one administrator with a new, known password in the project, then transfer using Transfer all. This provides a controlled credential for the next test rather than relying on an unverified password remembered from an earlier panel state.
Before transferring, check whether the HMI application includes a screen that opens the User Management dialog. If it does, determine whether that screen can change the user or password on the running panel. A password set or changed in panel user administration after an earlier backup may not match the project’s current definition. Keep the project-side credential and the intended panel-side credential aligned when the application’s design requires it.
Failed-login lockout branch
Read the panel configuration for a failed-login counter before making repeated login attempts. A related MP277 configuration in WinCC Flexible 2008 had this feature enabled by default, with a default lockout after three failed attempts; attempts did not need to be consecutive. Those details apply to the cited MP277 configuration, not automatically to an MP377. For the MP377, inspect its project and user-management settings to determine whether a counter is configured and what threshold applies.
If a lockout is configured, a correct password may still fail while the account remains locked. The MP277 account described in the related case was reset by downloading the HMI program with the option to overwrite user administration selected. On an MP377, verify the applicable setting and recovery behavior before relying on that remedy. A full project transfer and an overwrite of user administration can replace panel-side user data, so confirm that this is the intended recovery action.
Observed symptoms and the next diagnostic
| Observed reading | What it indicates | Next check |
|---|---|---|
| Password works after restoring ProSave | The restored snapshot contains a panel state that accepts those credentials. | Compare snapshot date with subsequent user-administration changes. |
Password fails after project transfer without Transfer all
|
The project password list was not transferred. | Confirm project administrator details, then use Transfer all if project credentials should take effect. |
Password fails after Transfer all
|
Transfer scope alone does not explain the failure; the MP377 case had this outcome. | Check the project administrator, user-management changes, and any configured login lockout. |
| Repeated failures or a locked account indication | A failed-login counter may be blocking access, depending on the panel configuration. | Read the MP377 counter and recovery settings; do not assume MP277 defaults apply. |
Controlled recovery and verification
Choose the resolving branch based on the state you want to retain. If the goal is to restore the known backup state, restore that ProSave snapshot and verify its credentials. If the goal is to make the current project’s credentials active, set a known administrator in the project and send the full project with user administration included.
- Record whether the target state is the ProSave snapshot or the current WinCC Flexible project.
- For project credentials, define at least one administrator with a known new password in WinCC Flexible.
- Compile and rebuild the project, then transfer it using
Transfer all. - If the account remains inaccessible, inspect the MP377’s user-management and failed-login settings before attempting further logins or another transfer.
- Log in with the defined administrator and password, then record the accepted credentials and make a fresh ProSave backup of the verified panel state.
Numbered verification checks:
- Administrator login: enter the administrator and password defined for the selected target state. Expected reading: the panel accepts the login.
- User-management state: inspect the user-management screen, if present. Expected reading: the intended administrator is present and the credentials correspond to the selected project or restored snapshot.
- Recovery baseline: create and label a ProSave backup after successful verification. Expected reading: the backup represents the working panel state, not an earlier state with unknown credentials.
Frequently asked questions
Can I use a ProSave restore to check the WinCC Flexible project password?
No. A ProSave restore returns the panel to the state captured when that backup was created. A successful login after restoring it verifies the restored state, not the credentials currently defined in the WinCC Flexible project.
Does Transfer All include the password list?
The password list is not transferred without Transfer all. If Transfer All was already used and the password still fails, check the project administrator and panel user administration rather than assuming transfer scope is the only cause.
Can Compile and Rebuild All activate a new HMI password?
Compilation alone does not establish that the password list was sent to the panel. Use the transfer option that includes all project data, then verify the defined administrator by logging in.
Does the MP377 lock an account after three failed logins?
Three failed attempts was the default reported for a related MP277 setup, not a confirmed MP377 value. Read the MP377’s configured failed-login counter and threshold before treating lockout as the cause.
How do I verify the new MP377 password?
After transferring the project with Transfer all, log in using the administrator and password defined in that project; the final verification reading is a successful panel login.