Resolving SIMATIC Unified HMI Default Login and Factory Reset

David Krause12 min read
HMI / SCADASiemensTroubleshooting
Licensed PE Working through this on a live machine? A Maine-licensed engineer can take it from here — included with IMD hardware, by the hour for everything else. Book an engineer

Resolving SIMATIC Unified HMI Default Login and Factory Reset

The SIMATIC Unified Comfort and Unified Basic HMI panels ship with the Control Panel password protection deactivated by default. In some deployment scenarios—particularly when panels have been pre-provisioned, bench-tested, or shipped through a non-standard distribution channel—the Service and Commissioning menu (formerly Control Panel on Comfort Panels) prompts for a username and password on first power-up. This article documents the root cause, the official Siemens default credentials for WinCC Unified Runtime, and the two recovery paths to regain access: a TIA Portal–driven factory reset and an on-device reset sequence.

1. Problem Description

On first power-up of a SIMATIC Unified HMI panel, the operator navigates through the standard commissioning flow to reach Service and Commissioning. On units that have been previously configured, transferred, or had their image staged by a system integrator, the panel presents a credential dialog before allowing access to display parameters, transfer channel settings, or backup/restore operations. The default expectation—that the panel ships unlocked with no credentials—does not hold, and the operator is locked out of the device.

Symptoms observed in field reports:

  • Service and Commissioning entry screen shows a username and password field.
  • Touching any control icon on the left rail of the Control Panel produces an authentication prompt.
  • Default guess combinations (empty, admin, admin12345) are rejected.
  • The project download from TIA Portal fails with transfer errors because the panel is in an undefined or modified runtime state.

2. Affected Products and Firmware Versions

Product Family Order Numbers (typical) Image Version WinCC Unified Version
SIMATIC Unified Comfort 7" 6AV2 128-3GB06-0AX0 (MTP700 Unified Comfort) V17.0+ WinCC Unified V17 / V18 / V19 / V20
SIMATIC Unified Comfort 10" 6AV2 128-3KE06-0AX0 (MTP1000 Unified Comfort) V17.0+ WinCC Unified V17 / V18 / V19 / V20
SIMATIC Unified Comfort 12" 6AV2 128-3MB06-0AX0 (MTP1200 Unified Comfort) V17.0+ WinCC Unified V17 / V18 / V19 / V20
SIMATIC Unified Comfort 15" 6AV2 128-3QB06-0AX0 (MTP1500 Unified Comfort) V17.0+ WinCC Unified V17 / V18 / V19 / V20
SIMATIC Unified Comfort 19" 6AV2 128-3UB06-0AX0 (MTP1900 Unified Comfort) V17.0+ WinCC Unified V17 / V18 / V19 / V20
SIMATIC Unified Comfort 22" 6AV2 128-3XB06-0AX0 (MTP2200 Unified Comfort) V17.0+ WinCC Unified V17 / V18 / V19 / V20
SIMATIC Unified Basic 4" 6AV2 128-3AB06-0AX0 (MTP400 Basic) V17.0+ WinCC Unified V17 / V18 / V19 / V20
SIMATIC Unified Basic 7" 6AV2 128-3BB06-0AX0 (MTP700 Basic) V17.0+ WinCC Unified V17 / V18 / V19 / V20
SIMATIC Unified Basic 10" 6AV2 128-3CB06-0AX0 (MTP1000 Basic) V17.0+ WinCC Unified V17 / V18 / V19 / V20
SIMATIC Unified Basic 12" 6AV2 128-3DB06-0AX0 (MTP1200 Basic) V17.0+ WinCC Unified V17 / V18 / V19 / V20
The MTP Unified Comfort panels use the same WinCC Unified Runtime engine as the PC Runtime and the SIMATIC WinCC Unified Station. User management is centralized and persisted in the runtime database. Default credentials are therefore consistent across the family.

3. Root Cause Analysis

The Control Panel password is deactivated on delivery per Siemens factory configuration. The panel will present a credential dialog only if one of the following has occurred:

  1. Pre-staged image: The system integrator loaded a project that included a configured user administration (SIMATIC Logon / Local User Management) before shipment.
  2. Bench test residue: A previous engineer enabled password protection in the Control Panel or in the project user management and did not clear it before power-down.
  3. Project transfer with active UMC: The downloaded project included a User Management Component (UMC) configuration with a non-empty local user database.
  4. Corrupted user database: A failed firmware update or interrupted write cycle has restored a non-default user list.

Per Siemens' official documentation, the Unified Comfort and Unified Basic panels do not require a password until one is set in the Control Panel or via a project transfer. If a password dialog appears out of the box, the panel image is not in factory-fresh state.

4. Default WinCC Unified Credentials Reference

The following table lists the documented default credentials for WinCC Unified Runtime as of TIA Portal V20. Siemens does not publish a hard-coded factory password for the Control Panel access because it is intended to be disabled at delivery. The credentials below are the runtime-level default user accounts created by the WinCC Unified Runtime installer or by the panel image on first boot.

Account Username Default Password Role / Scope
Administrator (default) admin admin UMC administrator — full runtime access
Administrator (TIA default) admin admin12345 UMC administrator — WinCC Unified V17+ default
Anonymous Anonymous (no password) Read-only public access
The username admin is reserved by the runtime and cannot be edited or deleted. Only its password can be changed, or an additional administrator user can be added. See the official manual: Changing the default credentials – SIMATIC WinCC Unified Runtime.

Users can change their own password at runtime from the home page or the menu by selecting User profileChange Password. This dialog is documented at Changing your password (RT Unified) – TIA Portal V20.

5. Recovery Path A — Factory Reset via TIA Portal

This is the recommended recovery path because it works without physical access to a keyboard or USB port on the panel, and it does not require knowledge of the current password.

5.1 Prerequisites

  • TIA Portal V17, V18, V19, or V20 installed and licensed on the engineering station.
  • Ethernet connection between the engineering station and the Unified HMI on the same subnet (or routed with the panel's MAC reachable).
  • The panel's MAC address (printed on the rear label, e.g., 00-0E-8C-xx-xx-xx).
  • A TIA Portal project that contains the target HMI device (or a new project with the matching device type added).

5.2 Step-by-Step Procedure

  1. Open the TIA Portal project containing the Unified HMI device.
  2. Expand the project tree: Project > Devices & Networks > [HMI Device].
  3. Right-click the HMI device and select Extended download to device.
  4. In the Extended Download dialog, set the Type of PG/PC interface to PN/IE.
  5. Set the PG/PC interface to the network adapter connected to the panel.
  6. Click Refresh and select the target HMI from the Accessible devices in target subnet list. Match by MAC address.
  7. In the Slots selection, ensure only Configuration is selected (deselect Firmware if listed to avoid an image reload).
  8. Click Load. The download will fail because the HMI is in a non-matching state — this is expected.
  9. When the transfer error appears, click Close. The HMI will retain the IP address that was defined in the TIA project.
  10. In the project tree, right-click the HMI device and choose Online & diagnostics.
  11. Expand Online & diagnostics > Functions > Reset to factory settings.
  12. Click the Reset button and confirm the prompt. The panel will reboot with factory defaults.
  13. After reboot, the panel returns to the standard Service and Commissioning menu with no password prompt.
A factory reset erases all project data, recipes, logs, and user accounts stored on the panel. Back up any data that must be retained using the standard backup mechanism before triggering the reset. The reset operation is irreversible from the panel side.

6. Recovery Path B — Reset via HMI Touch Sequence

When the engineering station is unavailable or the panel cannot be reached on Ethernet, the operator can force a factory reset directly on the device.

6.1 Unified Comfort Panels (MTP)

  1. Power off the panel.
  2. Press and hold the Service button (recessed, on the rear of the unit) or the touch area at the upper-left corner during power-up — refer to the panel's operating instructions for the exact gesture, which varies by form factor.
  3. Apply 24 V DC power while continuing to hold the service button for ~10 seconds.
  4. The panel boots into the Service & Commissioning menu directly, bypassing the runtime startup.
  5. Navigate to Settings > Reset to factory settings.
  6. Confirm the reset. The panel restarts with default image and no user database.

6.2 Unified Basic Panels

The Unified Basic panels do not have a dedicated service button. The recovery is performed through TIA Portal (Path A) or by reloading the firmware image using a USB stick with the ProSave-style image file exported from TIA Portal. See the panel's operating instructions manual for the specific USB recovery sequence.

7. Restoring Service and Commissioning Access

After the factory reset, the Service and Commissioning menu is reachable without credentials. Use the menu to set the transfer channel (PROFINET, Ethernet, USB), assign the IP address and subnet mask, and configure the time and date. Typical parameters:

Parameter Default Recommended (commissioning)
IP address 0.0.0.0 (DHCP) Static per plant addressing plan
Subnet mask 0.0.0.0 255.255.255.0 (Class C)
Default gateway 0.0.0.0 Router IP per plant
Transfer channel PROFINET PROFINET for plant, USB for lab
Control Panel password Disabled Disabled (commissioning) / Enabled with strong password (production)
Time zone UTC Local plant time zone

8. Configuring User Management for Production

Once commissioning is complete, configure user administration in the TIA Portal project to lock down the Control Panel and runtime.

  1. In the TIA Portal project tree, select the HMI device.
  2. Open Security > User administration.
  3. Add a new user with the role Administrator. Set a strong password (≥ 12 characters, mixed case, numeric, special).
  4. The built-in admin account cannot be renamed or removed — only its password can be rotated. This is documented in Changing the default credentials – SIMATIC WinCC Unified Runtime.
  5. Compile the project and transfer it to the panel. The Control Panel password is now active.
  6. For lost-password recovery, store the project backup including the UMC export in a secure location (encrypted, access-controlled).
If the runtime user database becomes corrupted and no administrative credentials are recoverable, only a factory reset (Path A or Path B above) will restore access. The local user database is not separately exportable from the panel side in a way that can be re-imported after a reset.

9. Transfer Channel Configuration Reference

Channel Port / Interface Typical Use Notes
PROFINET X1 (LAN) Plant-floor programming Default; supports routing through PROFINET
Ethernet (TCP/IP) X1 (LAN) Direct engineering station connection Use when PROFINET is not in scope
USB USB 2.0 host Lab bench / off-line loading Slower; useful for image recovery

10. Verification Steps

After recovery, perform the following functional checks before returning the panel to service:

  1. Boot sequence: Power cycle the panel. Confirm that it boots directly into the project start screen (not the Service and Commissioning menu) within ~30 seconds.
  2. Control Panel access: Touch the Control Panel icon and confirm no password prompt appears (factory default state).
  3. Network reachability: From the engineering station, ping the panel's IP address. A reply within < 5 ms on a direct connection confirms L2/L3 are healthy.
  4. Project transfer: Use TIA Portal's Download to device to push a known-good project. Confirm successful transfer without transfer-error dialogs.
  5. Backup/restore: Trigger a manual backup from the Control Panel and verify the archive is written to the configured location.
  6. Time synchronization: Confirm the panel's RTC and NTP (if configured) match the plant time server to within ± 1 second.

11. Troubleshooting Matrix

Symptom Likely Cause Corrective Action
Password prompt on first power-up Pre-staged project or bench-test residue Factory reset via TIA Portal (Section 5) or on-device sequence (Section 6)
admin / admin12345 rejected Project transferred a custom admin password Factory reset to clear the UMC database
Empty password field rejected Default credential is not blank for this user Use the password set in the project, or factory reset
Reset button greyed out in TIA Portal No online connection to the device Verify PG/PC interface, subnet, and that the panel is reachable (ping)
Panel does not appear in accessible devices Wrong subnet, firewall, or PROFINET name conflict Check subnet, temporarily disable Windows firewall, assign PROFINET name via Primary Setup Tool or TIA Topology
Reset fails with Reset not possible in current operating state Runtime project is running and locked Stop the runtime from the Service and Commissioning menu, then retry the reset
After reset, password still required Reset was not confirmed to completion Verify the panel rebooted; check firmware image version matches the TIA project
Cannot change admin password in runtime UMC configuration locks default users Edit the UMC in TIA Portal, transfer the project, then change password at runtime
Touch calibration off after reset Factory reset clears calibration Recalibrate from Service and Commissioning → Touch → Calibrate
Recipes and logs lost after reset Factory reset erases all runtime data Restore from a backup taken before the reset; rebuild logs from PLC historian if available

12. Safety and Operational Notes

  • A factory reset removes all user data, recipes, logs, and project archives on the panel. Confirm no production-critical data is stored locally before resetting.
  • The default admin account on a Unified panel is a security exposure if the panel is connected to a network with engineering access. Always rotate the default password and assign a strong administrator password before deploying to production.
  • Do not store the UMC export in cleartext on shared drives. Siemens recommends encrypted storage in a controlled project archive.
  • For SIL-rated or safety-relevant HMI applications, coordinate any factory reset with the safety validation process — the reset may invalidate evidence of functional safety configuration.
  • Document the panel's IP address, PROFINET name, and time-of-reset in the plant asset register after every recovery operation.

13. Related Configuration Reference

Configuration Area Path in TIA Portal Default State
Runtime user administration HMI device → Security → User administration Empty / default admin
Control Panel password HMI device → Settings → Control Panel access Disabled (factory)
Transfer settings HMI device → Transfer → Channel selection PROFINET enabled, others disabled
Auto-transfer HMI device → Transfer → Auto-transfer Disabled
UMC connection HMI device → Security → UMC Local (no central server)

What is the default username and password for a SIMATIC Unified HMI?

Siemens Unified panels ship with the Control Panel password deactivated. When password protection is active, the runtime default administrator account is admin with password admin or admin12345 depending on the WinCC Unified version (V17+ uses admin12345). The admin username is reserved and cannot be deleted, but its password should be rotated immediately in production.

How do I reset a SIMATIC Unified HMI to factory settings?

From TIA Portal, right-click the HMI device, choose Online & diagnostics > Functions > Reset to factory settings, and click Reset. The panel must be online (reachable over PROFINET/Ethernet). Alternatively, hold the service button on Unified Comfort panels during power-up to enter the Service menu and select Reset to factory settings. The reset clears all project data, recipes, logs, and user accounts.

Why does my new SIMATIC Unified HMI ask for a password?

New panels from Siemens are configured with password protection disabled. A password prompt on first power-up indicates the panel image was pre-staged, the project includes a User Management Component (UMC) configuration, or the unit was previously used and not fully reset. A factory reset will restore the default unlocked state.

Can I recover a lost admin password without a factory reset?

No. The local UMC database is encrypted on the panel and cannot be extracted or decrypted externally. If no administrative backup of the user list is available, the only recovery path is a factory reset followed by a project transfer that re-establishes the user administration. Always store the TIA project archive including the UMC export in a secure, recoverable location.

Which TIA Portal versions support SIMATIC Unified Comfort panels?

Unified Comfort panels are supported from TIA Portal V17 onward, with continued support in V18, V19, and V20. The recommended pairing is the panel image version matching the TIA Portal version (e.g., V20 panels with TIA V20 projects). Mismatched versions can cause transfer errors and unsupported feature flags.

Back to blog