Skip to Main Content
AVEVA Product Feedback


ADD A NEW IDEA

Security

Move Auditviewer function away from local PI System access

I want to run the Auditviewer function as a unprivileged remote user, moving away from the current requirement to run as a local user on the PI Data Archive Server.  This is so I can minimize security risk associated with local user access on...
Guest almost 4 years ago in Security 1 Declined

PI SMT should use OIDC for authentication

PI SMT should be able to authenticate users by using OIDC.
Guest 9 months ago in Security 0 No status

Officially test compatibility with Windows Security Baselines

As a PI System administrator, I need to harden the OS of my servers consistent with industry best practices so that they are resilient to attack and random disruption. Official testing of compatibility with industry standards such as the Windows ...
Guest almost 4 years ago in Security 0 No status

Do not require permission to PIPOINT if the permission is already covered by Point Security or Data Security

https://docs.osisoft.com/bundle/pi-server/page/permissions-required-for-tasks.html According to the documentation linked above, when permission to Point Security or Data Security is required, the same permission to PIPOINT is also required. This i...
Guest almost 4 years ago in Security 2 No status

Add Kerberos Authentication for PI Asset Analytics

Currently, PI Asset Analytics utilizes NTLM authentication. My customer's MSFT Windows Ops team does not recommend using NTLM and by default have this deactivated. Request is to add support for Kerberos authentication for PI Asset Analytics as ...
Guest almost 4 years ago in Security 0 No status

AVEVA Identity Manager should have a different description for button "Windows integrated login"

Although Windows AD is always a default identity provider for AIM, in certain security plans it is desired for Windows credentials not to be used by any general PI users for authentication, but instead for credentials from a different preferred id...
Guest over 1 year ago in Security 1 No status

Have pre-made PI Identities with minimum permissions by default

It currently takes more effort to follow AVEVA's recommendation of setting minimum permissions for all PI service accounts than it is to use fewer service accounts with more permissions. To help steer PI administrators in the right direction, plea...
Guest almost 4 years ago in Security 2 No status

Ability to manage non-impersonated linked tables without PI AF Server Admin privilegies

PI AF Admin would like grant permissions for users that are not level server admins to create and edit non-impersonated linked tables. Currently this only allowed for AF server admins or using impersonated linked tables. User guide: https://liv...
Guest almost 4 years ago in Security 3 No status

OIDC authentication with federated accounts (through CONNECT) requires too many steps

Currently, it is a 5-step process to get authenticated. After the first authentication, it is only a 3-step process, but still clunky.
Laurie Dieffenbach over 1 year ago in Security 0 No status

Allow Federation of ClientIDs and tokens from Entra ID into AVEVA Identity Manager

For clients who previously relied on claims authentication with PI Web API, it would be useful to be able to reproduce a similar authentication flow with bearer authentication and the AVEVA Identity Manager in PI Server 2023. Currently, federation...
Guest almost 2 years ago in Security 1 No status