Preventing Accidental Block Drag-and-Drop in SIMATIC Manager

David Krause11 min read
Best PracticesS7-300Siemens
Licensed PE Working through this on a live machine? A Maine-licensed engineer can take it from here — included with IMD hardware, by the hour for everything else. Book an engineer

Problem Overview: The Drag-and-Drop Hazard in SIMATIC Manager

Engineering workstations running SIMATIC Manager, the STEP 7 V5.x programming environment for S7-300 and S7-400 controllers, allow engineers to move, copy, and reorganize program blocks through the standard Windows drag-and-drop gesture. While this interaction model accelerates routine block management, it introduces a class of human-factor risk that cannot be eliminated through software configuration alone. A documented incident in a production plant involved an engineer who intended to drag a data block (DB) from the offline project onto PLC_X on the plant network, but released the block over PLC_Y by mistake. Because both PLCs contained DBs of the same numerical identifier, the operating CPU accepted the drop, and the DB associated with a trip function was overwritten on the wrong controller, causing an unplanned plant shutdown.

The confirming dialog that appears during online block transfer is the only built-in safeguard against this kind of error, and the safeguard is ineffective if the user dismisses it without verifying the target. The fundamental question raised by this scenario is whether the drag-and-drop gesture can be disabled at the application level, forcing engineers to use a more deliberate, multi-step transfer method that is harder to perform in error.

This technical reference documents the actual answer, the available workarounds, and the layered defense strategy that automation engineers should implement to prevent recurrence on both SIMATIC Manager and TIA Portal engineering stations.

Why SIMATIC Manager Cannot Disable Drag-and-Drop

There is no menu option, registry key, or administrative setting in SIMATIC Manager that turns off the drag-and-drop transfer of program blocks between offline project containers and online CPUs. The drag-and-drop behavior is integrated into the Windows shell extension that SIMATIC Manager registers when the software is installed. The file objects it manipulates (the offline block containers in the S7 program hierarchy) are handled through the standard OLE drag-and-drop interface, and Siemens has not exposed a switch in the Options > Customize dialog, the user-interface settings, or the registry to suppress the gesture.

Two consequences follow from this design decision:

  1. The hazard is permanent in SIMATIC Manager. Any engineer with online access to a target CPU and drag privileges in the project tree can move a block onto that CPU. The application's confirmation dialog asks whether the user wants to load the block, but it does not check the target CPU's identity, the plant area it serves, or the block's semantic role (configuration, process, or safety).
  2. Mitigation must be procedural and architectural. Because the gesture cannot be removed, control is achieved through CPU-side protection (passwords), work-instruction refinement, and environmental hardening such as multiple monitors, color-coded project names, naming conventions, and structured training.

Engineers migrating from SIMATIC Manager to TIA Portal should understand that the same risk profile exists in the newer engineering framework. TIA Portal provides additional confirmation dialogs and a centralized Go online target selector, but the underlying drag-and-drop mechanism is still available. The TIA Portal V20 documentation on copying and moving blocks describes the standard drag sequence: select the block in the project tree, drag it to the new position, and confirm the prompt that asks whether the system should overwrite the existing block or create a renamed copy.

Important: The TIA Portal V20 documentation treats drag-and-drop as a standard copy/move operation. It does not describe a safe mode that requires an additional confirmation step. The semantic safety net (i.e., blocking writes to a CPU performing a trip function) is the responsibility of the engineer, not the tool.

Workaround 1: CPU Password Protection (Access Levels)

The most effective software-side mitigation is to assign a password to every CPU that performs safety-critical or process-critical functions. STEP 7 V5.x and TIA Portal both implement the Siemens access-level model, in which a password gates online write operations to the CPU's program and data blocks. A drag-and-drop transfer that targets a password-protected CPU will fail at the authorization dialog, forcing the engineer to type the password before the write proceeds.

Access Level Concepts

Siemens S7-300 and S7-400 CPUs implement a tiered protection scheme in which higher access levels grant broader write privileges. When a password is assigned, the CPU enters the protected state immediately after the next download or power-up. The protection configuration is part of the hardware configuration and is downloaded with the rest of the project.

Level Name Online Privileges Without Password
1 Operation (HMI) HMI access, read access, no write
2 Read-only All of Level 1 plus read access to diagnostic and process data
3 Process operation All of Level 2 plus write access to process tags (no program changes)
4 Full access (configuration) All privileges including program and password changes

When a password is assigned, the operating level is implicitly raised. For example, setting a password at Level 3 means the CPU will reject any online write that requires Level 4 privileges, including block downloads, until the engineer types the password into the authorization dialog.

Configuring CPU Protection in STEP 7 V5.x

The procedure in SIMATIC Manager is as follows:

  1. Open the S7 project and double-click the SIMATIC 300 Station or SIMATIC 400 Station object.
  2. Open HW Config from the station object.
  3. Select the CPU in the rack view to open the CPU Properties dialog.
  4. Click the Protection tab.
  5. Select the radio button that corresponds to the operating mode (for example, Operating mode: Process operation, password-protected).
  6. Enter the password in the Password field and confirm. The CPU now requires this password before granting the corresponding level of access.
  7. Save and compile (Station > Save and Compile), then download the hardware configuration to the target CPU.

After the next CPU restart (or RUN-to-STOP-to-RUN transition, depending on the CPU), the protection is active. A subsequent online attempt to download a block from SIMATIC Manager to the CPU will trigger the authorization dialog. The user must type the password to proceed. A drag-and-drop transfer follows the same code path, so the password gate intercepts the accidental drop.

Operational note: Password-protected CPUs also reject unauthorized diagnostic functions. Plan password escrow carefully. If the password is lost, the CPU must be returned to the factory or the memory card must be cleared, which erases the program. Store the password in a controlled vault such as the plant's password-management system, not on a sticky note attached to the engineering station.

Configuring CPU Protection in TIA Portal

In TIA Portal, open the device configuration of the CPU, navigate to Properties > Protection, and select Full access (no protection), Read access, HMI access, or Complete protection. The Password field below the access list sets the password that unlocks the selected level. After download, the CPU enforces the protection on every online operation, including drag-and-drop.

Workaround 2: Online/Offline Block Management Discipline

Because the drag-and-drop gesture cannot be removed at the application level, the next line of defense is engineering procedure. The incident described in the source involved two PLCs with overlapping DB numbering, identical-looking project trees, and an engineer working under time pressure. Each of these factors is addressable through standard controls.

Unique DB Number Ranges per CPU

Assign non-overlapping DB number ranges to each CPU in the plant. For example:

PLC Function DB Range
PLC_X Boiler 1 control DB 100 to DB 199
PLC_Y Boiler 2 control DB 200 to DB 299
PLC_Z Common interlocks DB 300 to DB 399

With this convention, a DB 150 cannot exist on PLC_Y, so an accidental drop of a DB 150 onto PLC_Y will produce a "block does not exist on target" prompt that an attentive engineer will catch. This convention is enforced at the project's library generation step, not at runtime.

Block Symbol and Comment Standards

Name blocks with the plant-area prefix. For example, B1_DB_Trip for Boiler 1, B2_DB_Trip for Boiler 2. The block title and comment fields in the SIMATIC Manager block properties should repeat the plant area. When the engineer hovers over the block before dragging, the title is visible in the tooltip or in the Details view, providing a second visual confirmation point.

Project Tree Color Coding

SIMATIC Manager allows the engineer to assign background colors to S7 program objects. Configure a standard color for each plant area (for example, blue for Boiler 1, green for Boiler 2). Engineers should be trained to verify the color of the target CPU object before releasing a drag operation.

Multi-Monitor Discipline

The incident occurred when the engineer was looking at the source project tree and the target CPU object on the same screen. Where possible, assign the offline project tree to one monitor and the online CPUs to a second monitor. The physical separation makes a misdirected drop less likely because the engineer's hand is moving across monitors, not across rows of an on-screen list.

Block Movement in TIA Portal V20

Engineers who have moved to TIA Portal benefit from incremental safety improvements, but the drag-and-drop gesture is still available. The TIA Portal V20 documentation explicitly covers the copy and move workflow, and the workflow includes overwrite prompts that the engineer must dismiss. The TIA Portal V20 reference describes the steps: select the block, drag it to the new location, then confirm the prompt that asks whether the existing block should be overwritten.

Differences from SIMATIC Manager

Feature SIMATIC Manager TIA Portal V20
Drag-and-drop block move Available Available
Disable drag-and-drop Not possible Not possible
Block overwrite confirmation Yes (single prompt) Yes (single prompt)
CPU password gate on download Yes (via HW Config Protection tab) Yes (via CPU Properties > Protection)
Go online target selector Accessible nodes list Centralized online > Accessible nodes view
Block version comparison Manual (compare blocks tool) Built-in online/offline comparison

The TIA Portal V20 online/offline comparison tool reduces risk because the engineer can review the timestamp and path-time stamp of the block on the target CPU before initiating a download. Engineers should make this comparison a mandatory step in their work instructions.

Procedural Controls and Plant Engineering Standards

Engineering managers should document the block transfer procedure in the plant's Engineering Work Instruction. The instruction should explicitly prohibit drag-and-drop for online block transfer and require a three-step verification:

  1. Verify the source block. Open the block in the offline project, read the title and comment, and confirm the block number matches the intent.
  2. Verify the target CPU. Read the target CPU's rack/slot designation, MPI/PROFINET node address, and plant-area tag. Confirm with the work permit or change ticket.
  3. Use the explicit download path. Right-click the target CPU, choose Download to Target System or the equivalent PLC > Download menu, and follow the dialog. Do not use drag-and-drop for online transfers.
Management observation: Drag-and-drop is acceptable for offline-to-offline block reorganization within the project tree. The procedure should restrict drag-and-drop to the offline project and require an explicit download action for any online transfer. This is a procedural control, not a software one, and it is enforceable through audit.

Training and Competency Development

Siemens offers the SITRAIN curriculum for SIMATIC automation systems, with courses covering STEP 7 V5.x, TIA Portal, and the safe operation of S7-300 and S7-400 controllers. New engineers should complete the appropriate programming course and the safety systems course before being granted online access to trip-class CPUs. The curriculum is available through the Siemens regional training portal.

Beyond formal training, the engineering manager should conduct a toolbox talk after any near-miss or incident involving a wrong-target block transfer. The toolbox talk should walk through the exact mouse movements that led to the error, identify the procedural gap (for example, no CPU password, no plant-area prefix, or no work-instruction enforcement), and assign a corrective action with a due date.

Verification and Commissioning Checks

After implementing CPU password protection and the procedural controls, verify the safeguards with the following checks before signing off the change:

  1. Password test. Attempt an online block transfer to a password-protected CPU without entering the password. The transfer must be rejected. Document the rejection in the change ticket.
  2. Drag-and-drop test. Perform a drag-and-drop from the offline project tree to the target CPU. The transfer must trigger the password prompt. Cancel the prompt and confirm no block was written.
  3. Block overwrite test. Enter the password and complete the drag-and-drop. Verify that the block was written to the correct CPU by reading the block back from the target and comparing the title, comment, and timestamp.
  4. Audit trail. Confirm that the CPU's diagnostic buffer recorded the online download event. The buffer entry should include the operator station identifier and the time stamp.
  5. Work-instruction review. Confirm that the engineering work instruction has been updated to prohibit drag-and-drop for online transfer and that the change has been communicated to all engineers with online access.

Frequently Asked Questions

Can I disable the drag-and-drop feature in SIMATIC Manager?

No. SIMATIC Manager does not expose a setting, registry entry, or command-line option to disable the drag-and-drop transfer of program blocks. The gesture is integrated into the Windows shell extension that SIMATIC Manager registers, and Siemens has not published a method to remove it.

What is the most effective workaround for the drag-and-drop hazard?

Assign a password to every CPU that performs process-critical or safety-critical functions. The password is configured in HW Config > CPU Properties > Protection in STEP 7 V5.x or in CPU Properties > Protection in TIA Portal. A password-protected CPU rejects any online write, including drag-and-drop, until the engineer types the password into the authorization dialog.

Does TIA Portal V20 allow me to disable drag-and-drop?

No. The TIA Portal V20 documentation treats drag-and-drop as a standard copy and move operation and does not describe a safe mode or a disable option. TIA Portal does provide an online/offline block comparison tool that the engineer can use to verify the target before initiating a download.

What happens if I lose the CPU password?

A lost password requires the CPU to be returned to the factory or the memory card to be cleared, which erases the program. The CPU cannot be unlocked remotely. Store the password in the plant's controlled password-management system and document the recovery procedure in the engineering work instruction.

Should I block drag-and-drop through a procedural rule or a software rule?

Both. The software rule (CPU password) intercepts the gesture at runtime, and the procedural rule (engineering work instruction that prohibits drag-and-drop for online transfer) enforces the practice at the engineering level. The procedural rule is enforceable through audit and toolbox talks; the software rule is enforceable at every online attempt. Layer the two controls for the strongest defense.

Back to blog