Resolving STEP 7 Access Protection Error After System Restore
1. Problem Overview
After performing a Windows system image restore, engineers frequently encounter the following error when attempting to open an existing SIMATIC STEP 7 project in SIMATIC Manager (STEP 7 V5.x) or the TIA Portal:
"The project or library was changed using tools of the Windows explorer. The data for access protection has been modified to such an extent that it is no longer possible to open the project or library."
This error is generated by the STEP 7 project kernel when it detects that the on-disk metadata governing project access protection no longer matches an internally stored checksum. The integrity violation is not necessarily a corruption of the project logic (OBs, FBs, FCs, DBs), but a mismatch between the project's access-protection layer and the host operating system's security identifiers (SIDs), file ownership, or folder permissions.
The error applies to all of the following STEP 7 artifacts:
-
*.s7p– STEP 7 project files (V5.x) -
*.s7l– STEP 7 library files (V5.x) -
*.s7f– S7 folder / container files -
*.s7k– archived project packages -
*.ap15,*.ap16,*.ap17,*.ap18,*.ap19,*.ap20– TIA Portal project archives
2. Root Cause Analysis
The root cause of this error is a mismatch between the Windows NTFS security descriptors of the project files and the access-protection data embedded in the STEP 7 project. Several underlying conditions can produce the same symptom:
2.1 SID Invalidation After Image Restore
Windows assigns every user account a Security Identifier (SID) of the form S-1-5-21-XXXXXXXXXX-XXXXXXXXXX-XXXXXXXXXX. When a disk image is restored to:
- A new machine,
- The same machine after a clean OS install that created new user accounts, or
- A cloned disk where the original SID store was wiped,
the new local user receives a different SID. STEP 7's DP (Data Protection) subsystem binds the access-protection fields to the SID of the user that originally created or last modified the project. The mismatch is detected at project open time and the project is refused.
2.2 File Ownership Rewriting
System image software (Acronis, Veeam, Macrium Reflect, Windows built-in wbadmin) frequently resets the Owner field on restored files to Administrators or SYSTEM rather than preserving the original user. STEP 7's access protection record still references the previous owner's SID. The result is identical to 2.1.
2.3 UTC Timestamp Skew
The Modify timestamp of files inside the project folder is compared against a stamp stored in the project header. Image restore can shift timestamps by hours or roll them back to the image creation date, breaking the consistency check. The "changed using tools of the Windows Explorer" wording is the generic catch-all for this category.
2.4 Filesystem Migration or Repair
Operations that change the underlying file system signature without preserving all NTFS streams (chkdsk /f with security descriptors lost, NTFS→ReFS conversion, defragmenter that strips alternate data streams, antivirus quarantine) can destroy the project's hidden protection data without touching user-visible files.
2.5 Cloud Sync / Backup Software
OneDrive, Dropbox, Google Drive, Veeam, or Windows Backup that hooks file changes can rewrite the project files. The STEP 7 kernel sees the modification as external and flags it. This is the same error class even when no image restore is involved.
3. Affected Versions
| STEP 7 / TIA Portal Version | Project Format | Behavior |
|---|---|---|
| STEP 7 V5.4 SP5 | *.s7p / *.s7l | Error reproduced; sometimes recoverable with permission repair |
| STEP 7 V5.5 SP3 / SP4 | *.s7p / *.s7l | Error reproduced; Hotfix available |
| STEP 7 V5.6 (incl. SP1/SP2) | *.s7p / *.s7l | Error reproduced; final V5.x line |
| TIA Portal V13 / V14 | *.ap13 / *.ap14 | Different error wording; same root cause |
| TIA Portal V15 / V15.1 | *.ap15 | Error reproduced; integrity check tightened |
| TIA Portal V16 | *.ap16 | Error reproduced |
| TIA Portal V17 / V17 Hotfix | *.ap17 | Error reproduced; partial recovery via "Manage global libraries" |
| TIA Portal V18 | *.ap18 | Error reproduced |
| TIA Portal V19 / V20 | *.ap19 / *.ap20 | Error reproduced; "Retrieve" path stricter |
4. Quick Diagnostic Procedure
Before applying any destructive repair, run these checks to confirm the failure mode.
4.1 Differentiate Project Corruption from Access-Protection Mismatch
- Open SIMATIC Manager as Administrator: right-click → Run as administrator.
- Attempt to open the same project from a different physical path (e.g.,
D:\Temp\ProjectCopy). - Create a new empty project (File → New → Project) and verify it opens without error. If new projects open but old ones fail, the failure is isolated to the project files and not the STEP 7 installation.
4.2 Inspect File Ownership
Open a command prompt as Administrator and run:
icacls "C:\Path\To\YourProject.s7p"
Look at the owner line. A healthy project shows your current Windows user as Owner. After an image restore, the Owner is often:
NT SERVICE\TrustedInstallerBUILTIN\Administrators- A SID terminated with a number that does not match your current user
4.3 Inspect File Permissions
Run the same icacls command on every *.s7p and the project root folder. Expected: (F) or (M) for your current user. Failure mode: (N) No access, or entries containing S-1-5-21-... referring to a SID that no longer resolves.
4.4 Check the Event Log
Open Event Viewer → Windows Logs → Application and filter on Source = S7WB or Siemens.Automation.Portal. The application log often contains a more specific error code (e.g., 0x80070005 E_ACCESSDENIED, 0x80004005 E_FAIL) than the dialog message.
4.5 Test the Same Project on a Second Workstation
Copy the entire project folder (not just the .s7p file) to another PC with a working STEP 7 installation. If it opens there, the problem is local to the restored OS, not the project data.
5. Solution Matrix
| Symptom | Best-First Action | Fallback | Last Resort |
|---|---|---|---|
| Old project fails, new project opens | Reset NTFS ownership and permissions on the project folder (Section 6.1) | Repair STEP 7 installation (Section 6.2) | Open on second workstation, re-archive |
| All projects fail to open | Reinstall or repair STEP 7 (Section 6.2) | Check if running as Admin resolves (Section 6.3) | Reinstall Windows user profile |
| Archive (*.s7k, *.ap1x) fails to retrieve | Use STEP 7 "Retrieve" with Admin rights | Use 7-Zip to peek inside the archive (TIA Portal archives are ZIP-based); extract Project.xml manually |
Send archive to Siemens Hotline |
| Project on a network share fails | Move local, repair, then return to share | Disable offline files and client-side caching | Re-share with full NTFS + share permissions to Everyone |
| Project on a OneDrive/SharePoint sync folder fails | Pause sync, copy to local non-synced path, open there | Exclude *.s7p, *.s7l, *.ap* from sync client |
Migrate to TIA Portal V19 with native cloud projects |
6. Primary Repair Procedures
6.1 Reset NTFS Ownership and Permissions (Most Common Fix)
This procedure is the highest-yield repair for post-image-restore failures.
- Close SIMATIC Manager and TIA Portal completely.
- Open Command Prompt as Administrator (Start → type
cmd→ Ctrl+Shift+Enter). - Take ownership of the project folder and all subfolders:
takeown /F "C:\Projects\MyPlant" /R /D YThe
/Rflag recurses;/D Yauto-answers "No" to permission prompts for read-only files. - Reset permissions and grant the current user Full Control:
icacls "C:\Projects\MyPlant" /reset /T icacls "C:\Projects\MyPlant" /grant %USERNAME%:(OI)(CI)F /TReplace
%USERNAME%with the literal Windows account name (e.g.,DOMAIN\jdoe) if needed. - Remove any inherited deny or conflicting ACEs from non-existent SIDs:
icacls "C:\Projects\MyPlant" /remove *S-1-5-21-* /T - Re-open SIMATIC Manager as Administrator and try to open the project.
icacls /grant Everyone:(F) /T on a production network share. Use the most restrictive grant that still allows the project to open.6.2 Reinstall or Repair STEP 7
- Open Control Panel → Programs and Features (Win10/11) or Settings → Apps → Installed apps.
- Locate SIMATIC STEP 7 (or TIA Portal). Click → Modify or Repair.
- Follow the installer through Repair. This rewrites the registry keys, restores
HKLM\SOFTWARE\Siemens\Automation\entries, and refreshesS7HCOM.DLL,SIMATICManager.exemanifest, and the access-protection COM component. - Restart the workstation. Required: image-restore changes to
HKLMandHKCU\SOFTWARE\Siemensare not visible to a running STEP 7 process. - Retry project open.
If repair fails, uninstall and reinstall. Capture the installation logs at C:\ProgramData\Siemens\Automation\Log\ for support escalation.
6.3 Run as Administrator
The simplest viable workaround is right-clicking SIMATIC Manager and selecting Run as administrator. If this works, the project is reachable but the current user lacks the necessary NTFS privilege. Set the compatibility flag permanently:
- Right-click
S7WIN.EXE(orS7MANEX.EXEfor STEP 7 V5.x) atC:\Program Files\Siemens\Automation\SIMATIC Manager\. - Properties → Compatibility → check Run this program as an administrator → OK.
For TIA Portal: set compatibility on C:\Program Files\Siemens\Automation\Portal V1x\bin\Siemens.Automation.Portal.exe.
6.4 Use the SIMATIC Manager "Restore" Path
STEP 7 V5.x supports restoring from a *.s7k archive created with File → Archive:
- File → Retrieve → select the
*.s7karchive. - Choose a fresh folder (e.g.,
D:\Recovered\MyPlant). - Allow STEP 7 to extract. The retrieved copy often opens cleanly because the archiving process rebuilds the access-protection record.
*.s7k archive, you may have one anyway: SIMATIC Manager auto-archives to %APPDATA%\Siemens\Automation\S7Backup\ if configured. Check this folder before giving up.6.5 TIA Portal-Specific Repair
TIA Portal stores access protection in Project\<ProjectName>\System\ProjectInfo.xml and a hash in the .ap1x archive root. If only the in-place project fails (not the archive):
- Close TIA Portal.
- Locate the most recent automatic backup at
%USERPROFILE%\AppData\Local\Siemens\Automation\Portal Vxx\Backup\. - Copy the backup folder to a new location.
- Open TIA Portal → Open existing project → navigate to the backup.
If the project was stored in a TIA Portal Multiuser Server, re-sync via Project → Server → Synchronize with Server to pull a clean copy from the server's authoritative state.
7. Last-Resort Recovery Options
7.1 Contact Siemens Simatic Hotline
The Siemens Simatic Hotline (per country, see Siemens Industry Online Support) maintains a project-repair service. Provide:
- The complete project folder (compressed with 7-Zip, not WinRAR, due to alternate data streams)
- The exact STEP 7 / TIA Portal version
- Event log excerpts with the
0x...error code - The exact error text from the dialog
Recovery is chargeable but typically 24–72 hours turnaround.
7.2 Manual Block Extraction
If the project opens on a different workstation, you can:
- Re-archive from the working machine (File → Archive).
- Retrieve on the broken machine into a new folder.
- Cross-load blocks to a physical S7 CPU (S7-300/400/1200/1500) using PLC → Download to device if hardware is available — the on-PLC source is unaffected by the project-side corruption.
7.3 Hardware as the Source of Truth
If the project represents a deployed machine and the CPU is online, the CPU's Online view contains an intact copy of all blocks:
- Open SIMATIC Manager → PLC → Upload Station to PG.
- This rebuilds a fresh project from the CPU's MMC / SIMATIC Memory Card.
- Save and re-archive immediately.
For S7-1200/1500: Online → Backup in TIA Portal produces a complete project backup directly from the CPU.
8. Prevention and Best Practices
8.1 Maintain Off-Project Archives
Configure SIMATIC Manager to auto-archive after every save: Options → Customize → Archive. Path: %USERPROFILE%\Documents\Siemens\Automation\S7Archive\.
8.2 Pre-Image Checklist
Before any disk image operation on a STEP 7 workstation:
- Close SIMATIC Manager and TIA Portal.
- Stop services:
SIMATIC RSLinx,S7OLE,SIMATIC LOGON,Siemens Automation License Manager. - Archive all
*.s7pand*.ap*projects to an external drive. - Export STEP 7 environment: Options → Global Settings → Export.
8.3 Post-Image Checklist
- Re-apply the same Windows user name and password used before the restore (critical for SID stability if the image tool supports it).
- Run
icaclsreset on all project folders immediately. - Reinstall all Siemens software or run Repair.
- Test open on a throwaway copy before working on production projects.
8.4 Exclude from Sync and AV
Add the following to OneDrive / Dropbox / Google Drive exclusion lists and Windows Defender exclusion paths:
\*.s7p;\*.s7l;\*.s7f;\*.s7k;\*.ap1*;\*.ap2*;\*.tpz
8.5 Project Location Rules
- Never store live projects in
C:\Users\<name>\on a roaming profile (SID drift is more frequent). - Avoid
D:\on a BitLocker-encrypted volume that is suspended/auto-unlocked — protection descriptors may be rewritten on resume. - Preferred: a fixed local NTFS volume with stable ownership, e.g.,
D:\Engineering\.
9. Related Error Codes and Their Meaning
| Error Code | Meaning | Action |
|---|---|---|
0x80070005 |
Access denied (NTFS) | Reset ownership and grant current user Full Control |
0x80004005 |
Unspecified failure | Repair STEP 7; check disk for errors |
0x80070057 |
Invalid parameter (corrupt XML) | Retrieve from *.s7k archive |
0x80030002 |
STG_E_FILENOTFOUND / access-protection record missing | Recover from automatic backup; contact Hotline |
0x80030003 |
STG_E_PATHNOTFOUND | Verify folder structure; project may need re-archive |
0xC0000043 |
STATUS_SHARING_VIOLATION | Close all file handles; stop antivirus on-access scan |
0xC0000061 |
STATUS_PRIVILEGE_NOT_HELD | Run as Administrator |
10. Verification Procedure
After applying any repair, verify recovery with this checklist:
- Open the project in SIMATIC Manager / TIA Portal without the error dialog.
- Compile all blocks: Program → Compile All. If compile completes with no errors, the project is functionally intact.
- Cross-reference check: Options → Cross-reference. Resolve any unresolved cross-references to confirm symbol table is intact.
- Consistency check (TIA Portal): Project → Compile → Software (rebuild all). A clean rebuild confirms the integrity layer is repaired.
- Save a fresh archive immediately. This re-establishes a known-good access-protection record.
- Test the archive by retrieving it to a separate folder and opening.
11. Escalation Path
- Tier 1: Run Section 6.1 (NTFS reset) and 6.2 (Repair install).
- Tier 2: If still failing, follow Section 4.5 to test on second workstation — this isolates the failure.
- Tier 3: If failing everywhere, the project is genuinely corrupted. Move to Section 7.1 (Siemens Hotline) or 7.3 (CPU as source of truth).
- Tier 4: For multi-project plants, also raise a request via Siemens Industry Online Support (SIOS) and attach the support logs. Use the Support Request number in the Hotline call to skip the queue.
Why does STEP 7 say "changed using tools of the Windows Explorer" when I never opened it in Explorer?
The message is STEP 7's generic detection for any external write that altered NTFS metadata (ownership, ACL, timestamps, or alternate data streams). Image-restore, antivirus, and cloud sync all trigger the same detector.
Will a Windows system image restore always break STEP 7 projects?
Yes, if the original Windows SID is not preserved 1:1. Use Sysprep with the generalize option, or use the same exact username/password after restore, to keep SID stability.
Can I open a STEP 7 V5.x project in TIA Portal after recovery?
Yes, use TIA Portal → Project → Migrate project. TIA Portal will re-create the access-protection record in the new project format. The original *.s7p file is not modified.
Does changing the Windows password break STEP 7 project access protection?
No, the SID is bound to the user account identifier, not the password. Changing the password preserves the SID. Deleting and recreating the user account does break it.
How do I extract blocks if the project itself cannot be opened?
Go online to the S7 CPU: in SIMATIC Manager use PLC → Upload Station to PG; in TIA Portal use Online → Backup or Online → Download device as new station. The CPU's MMC holds an intact copy of all blocks.