The PI AF Link went out of sync. After resynching, it seems like the process created some AF identities that do not seem to be used in the AF database security. Are these AF identities created for a reason?

I know these identities correspond to our PI identities on the PI Modules security table, I just don't understand why they are created on the AF server since they are not used on the AF server or the PI MDB database.

AF identity format:

PIAFLINK%PISERVER%AD-group-name

Parents
  • I would like to resume this topic.

    Doing a security audit of one of our PI AF Servers, found 16 !! identities with this format, (one created for each identity account and active directory group) with the corresponding mappings to similar accounts and active directory groups.

    Security screen is weird, and worst, I believe these are not used at all, just adding confusion to an administrator.

    Do you think I can just DELETE all these PIAFLINK%server... identities+mappings without risk ?

    ​ maybe you have a good answer already?

    Many thanks!

    Josep

     

Reply
  • I would like to resume this topic.

    Doing a security audit of one of our PI AF Servers, found 16 !! identities with this format, (one created for each identity account and active directory group) with the corresponding mappings to similar accounts and active directory groups.

    Security screen is weird, and worst, I believe these are not used at all, just adding confusion to an administrator.

    Do you think I can just DELETE all these PIAFLINK%server... identities+mappings without risk ?

    ​ maybe you have a good answer already?

    Many thanks!

    Josep

     

Children