Documentation PI Nexus+ Documentation

PI Nexus+ / Administration Guide

Administration Overview

This chapter shows where each setting lives in the Admin area and how to give people access to PI Nexus+.

Overview

This chapter shows where each setting lives in the Admin area and how to give people access to PI Nexus+.

The Admin pages

Users with the Admin role open the Admin area from the main navigation. At the bottom of the Admin navigation, Admin Guide opens this guide and Installation Guide opens the Installation Guide.

PageWhat you set thereChapter
SitesSites that group servers by plantSites
PI Data ArchivesPI Data Archive targets, PI Interface tracking, tuning writesPI Data Archives
AF ServersAF servers, AF databases, recalculation permissionAF Servers and Databases
PI Vision InstancesPI Vision web address and SQL databasePI Vision Instances
PI AdaptersAF databases that receive PI Adapter healthPI Adapter Monitoring
HostsWindows servers to monitorHost Monitoring
PI Point RulesWhich PI Points are inventoried and checkedPI Point Rules
External SystemsSystems that feed or receive PI dataExternal Systems
Scan AutomationAutomatic scanningScan Automation
Change TrackingInventory change historyThis chapter
NotificationsMail server, recipients, email typesNotifications
SecurityRole mappings, security health, auditThis chapter
OpenID ConnectClient for OpenID Connect targets; listed once a target uses itOpenID Connect
SQL Server, Inventory MaintenanceDatabase connection, retention, cleanupInventory Maintenance and SQL Admin UI
LicenseLicense keyOpen PI Nexus+ and Install the License (Installation Guide)
SupportReadiness, diagnostics, support bundleSupport and Diagnostics

How target changes take effect

For PI Data Archives, AF servers, AF databases and PI Vision instances:

  • Discovered and added targets start disabled. Nothing is scanned until you enable it.
  • Enable tests the connection first and enables only if the test passes. It applies at once; with Scan Automation active, the first scan is queued.
  • Disable keeps the inventory but marks it Excluded. Purge Inventory deletes it after confirmation.

Give users access

PI Nexus+ signs users in with Windows authentication and maps Windows or AD groups to three roles: Viewer reads, Operator also scans, exports and handles issues, Admin also configures. Each role includes the ones below it.

Admin > Security with the current user's roles, the bootstrap state and the Role Mappings tab
Add Mapping dialog with Role, Windows / AD Group, Enabled and Add Mapping
  1. Open Admin > Security.
  2. On Role Mappings, choose Add Mapping.
  3. Choose the Role, enter the Windows / AD Group as DOMAIN\Group, leave Enabled ticked and choose Add Mapping. It applies at once.
  4. Map the Admin group first, and check that the mapping's Current User column confirms your membership.

Note: While no Admin mapping is enabled, local administrators of the web server are Admins (Bootstrap admin is active). PI Nexus+ refuses to disable or remove the last enabled Admin mapping. If the Admin group is lost, for example renamed in AD, run C:\Program Files\Software Athlete\PI Nexus+\Admin\Recover-AdminAccess.bat on the web server as an account that can write to the PI Nexus+ database.

Security Health flags protected files that broad groups can write to. Security Audit lists who changed settings or started scans, exports and support actions.

Record inventory changes

Change tracking records created, renamed, moved, updated, deleted and excluded inventory objects. It is off on a new installation.

Admin > Change Tracking with the tracking state and its button, Retention, Max history events, Save and Purge history
  1. Open Admin > Change Tracking and choose Enable tracking. Once tracking is on, the same button reads Pause tracking.
  2. Set the Retention and Max history events, and choose Save.

Pause tracking keeps the stored history; Purge history deletes it. Values are in Sites and Change Tracking Settings in the Reference. Users read it as described in Change History, Missing Inventory and Exports in the User Guide.

Reference: Roles and Permissions