Configuring Domain-Based Access Control to Workflow Functionality
You can use active directory universal or global groups to control access to Workflow functionality.
By mapping an active directory group to a Workflow group, you give the key sets and corresponding permissions defined for the Workflow group to all members of the active directory group at the same time. An active directory group can be mapped to many Workflow groups, and a Workflow group can have many active directory groups mapped to it. The operator must have permission to query Windows domains.
Note: For Vision, when using the Predix token (Windows user) to access the Workflow account that runs the Proficy Server service, an operator must have permission to query the domain(s); otherwise, authentication will fail as no group information can be retrieved from the domain.
For more information about universal groups, see http://technet.microsoft.com/en-us/library/cc755692(v=ws.10).