PI Nexus+ / Administration Guide
Administration Overview
This chapter shows where each setting lives in the Admin area and how to give people access to PI Nexus+.
Overview
This chapter shows where each setting lives in the Admin area and how to give people access to PI Nexus+.
The Admin pages
Users with the Admin role open the Admin area from the main navigation. At the bottom of the Admin navigation, Admin Guide opens this guide and Installation Guide opens the Installation Guide.
| Page | What you set there | Chapter |
|---|---|---|
| Sites | Sites that group servers by plant | Sites |
| PI Data Archives | PI Data Archive targets, PI Interface tracking, tuning writes | PI Data Archives |
| AF Servers | AF servers, AF databases, recalculation permission | AF Servers and Databases |
| PI Vision Instances | PI Vision web address and SQL database | PI Vision Instances |
| PI Adapters | AF databases that receive PI Adapter health | PI Adapter Monitoring |
| Hosts | Windows servers to monitor | Host Monitoring |
| PI Point Rules | Which PI Points are inventoried and checked | PI Point Rules |
| External Systems | Systems that feed or receive PI data | External Systems |
| Scan Automation | Automatic scanning | Scan Automation |
| Change Tracking | Inventory change history | This chapter |
| Notifications | Mail server, recipients, email types | Notifications |
| Security | Role mappings, security health, audit | This chapter |
| OpenID Connect | Client for OpenID Connect targets; listed once a target uses it | OpenID Connect |
| SQL Server, Inventory Maintenance | Database connection, retention, cleanup | Inventory Maintenance and SQL Admin UI |
| License | License key | Open PI Nexus+ and Install the License (Installation Guide) |
| Support | Readiness, diagnostics, support bundle | Support and Diagnostics |
How target changes take effect
For PI Data Archives, AF servers, AF databases and PI Vision instances:
- Discovered and added targets start disabled. Nothing is scanned until you enable it.
- Enable tests the connection first and enables only if the test passes. It applies at once; with Scan Automation active, the first scan is queued.
- Disable keeps the inventory but marks it Excluded. Purge Inventory deletes it after confirmation.
Give users access
PI Nexus+ signs users in with Windows authentication and maps Windows or AD groups to three roles: Viewer reads, Operator also scans, exports and handles issues, Admin also configures. Each role includes the ones below it.


- Open Admin > Security.
- On Role Mappings, choose Add Mapping.
- Choose the Role, enter the Windows / AD Group as
DOMAIN\Group, leave Enabled ticked and choose Add Mapping. It applies at once. - Map the Admin group first, and check that the mapping's Current User column confirms your membership.
Note: While no Admin mapping is enabled, local administrators of the web server are Admins (Bootstrap admin is active). PI Nexus+ refuses to disable or remove the last enabled Admin mapping. If the Admin group is lost, for example renamed in AD, run C:\Program Files\Software Athlete\PI Nexus+\Admin\Recover-AdminAccess.bat on the web server as an account that can write to the PI Nexus+ database.
Security Health flags protected files that broad groups can write to. Security Audit lists who changed settings or started scans, exports and support actions.
Record inventory changes
Change tracking records created, renamed, moved, updated, deleted and excluded inventory objects. It is off on a new installation.

- Open Admin > Change Tracking and choose Enable tracking. Once tracking is on, the same button reads Pause tracking.
- Set the Retention and Max history events, and choose Save.
Pause tracking keeps the stored history; Purge history deletes it. Values are in Sites and Change Tracking Settings in the Reference. Users read it as described in Change History, Missing Inventory and Exports in the User Guide.
Reference: Roles and Permissions
