Skip to Main Content
AVEVA™ Products Feedback Portal

Welcome to our new feedback site!


We created this site to hear your enhancement ideas, suggestions and feedback about AVEVA products and services. All of the feedback you share here is monitored and reviewed by the AVEVA product managers.

To start, select the product of your interest in the left column. Then take a look at the ideas in the list below and VOTE for your favorite ideas submitted by other users. POST your own idea if it hasn’t been suggested yet. Include COMMENTS and share relevant business case details that will help our product team get more information on the suggestion. Please note that your ideas will first be moderated before they are made visible to other users of this portal.

This page is for feedback for specific AVEVA solutions, excluding PI Systems and Data Hub. For links to these other feedback portals, please see the tab RESOURCES below.

Portfolio area Application Server
Created by Peter Rosenberger
Created on May 20, 2025

OPC UA Server - Restricting Client Access

Hi,

My OEM customer currently uses TOP Server 6 instead of AVEVA OPC UA Server for different reasons. One of them is that it's possible in TOP Server 6 to have different users access different parts of the OPC UA Server via No Access, Read Only or Read Write. This can be done group based.

Clients should not see the whole OPC UA Server structure / variables. Different OEM customers expect different structures, e.g. certain structures are needed by all, certain structures are only needed by a few end customers and certain structures / variables should not be visible at all. For visibilty and security purposes this should be adressed quickly. In addition to that it’s required to give variables and / or structures different access rights (e.g. no access as described, read/write, read only) for certain users.

We expect that we can create users for MES, Maintenance, Administration etc... and these users to have access only to the variables that we define and only the way we define, read only/write only/ both this should be possible to define for each variable separately like on TOP Server 6.x.

It would have a high impact for the customer to have this feature for the OPC UA Server.

Thanks
Peter

  • ADMIN RESPONSE
    Jul 20, 2025

    This idea is possbly submitted against an incorrect product. For now, it has been marked as public to allow voting to take place, but it may be moved to the Communications Drivers/Device Integration Ideas portal when it becomes active.

    The idea has been reviewed and the title and description may have been edited in an attempt to more accurately state the idea or requirement. It is now publicly visible for others to see and vote on. Additional edits may have been performed to remove any perceived sensitive information.

    If you are uncomfortable with this or do not agree with the modifications, please contact us.

  • Attach files
  • Michal Tauchman
    Aug 6, 2025

    I fully comply with this suggestion, it pertains mainly to AVEVA Application Server's OPC UA interface. We need to have an option to publish only selected attributes with ReadOnly/ReadWrite and No Access (= even not Read) for the rest. Today, if OPC UA Server is enabled, all attributes are available for Read and there's no option how to set permissions for individual user against specific attributes.