Introduction > Derived Access Control
Migrating User
Accounts to Derived Access Control
You can migrate existing user accounts to Derived Access Control mode. There are two approaches to this: migrate them one group at a time or migrate them all at once.
For examples of migrating user accounts to Derived Access Control, see the below video.
Procedure
Decide which approach you want to use.
| If you want to ... | Do the following; |
|---|---|
| Set up user groups and migrate user accounts one group at a time (staged approach). | Create a user group. See Creating and Editing a User Group. Assign user accounts to the user group. See Assigning and Editing User Accounts in a User Group. Assign roles to the user group. See Assigning and Editing Roles in a User Group. Assign read-write, read-only domains to user group. See Assigning and Editing Domains in a User Group. Right-click the User Groups folder in the browser tree and choose Convert All Included Accounts to Derived Access Control; a progress bar displays. Repeat the previous steps for each user group. |
| Migrate all user accounts in one step (if you have created all user groups and assigned user accounts already). | Right-click the User Accounts folder in the browser tree and choose Convert All Existing Accounts to Derived Access Control; a progress bar displays. Note If you want to undo this migration, you can right-click the User Accounts folder in the browser tree and choose Convert All Existing Accounts to User Access Control. |
Note
If a migration fails due to data corruption, the migration will stop with no user data migrated.
Results
The user groups (and their assigned roles) to which the accounts now belong enforce the accounts’ permissions, read/write access to domains, license policies and change policies.
The Derived Access Control option on the Login tab of the user accounts is now selected.
The Roles, Read-Only Domains, Read-Write Domains, License Policy and Permissions tabs for the user accounts become read-only.
The system automatically propagates any changes to the groups and their roles to the user accounts.
If a user account inherits settings from multiple groups: The settings for permissions, domains, and license policy are merged for the user account.
In the case of domains, if a domain is read-only in one group but read-write in another group, the user account has the domain as read-write.
A superuser account will have all defined domains as read-write by default.
A user in DAC mode has a modified icon in the Capital Access Manager browser tree (). A user not in DAC mode has the standard icon ().
Parent Topic:
Derived Access Control
Capital Access Manager User Guide, 2512.2606
Unpublished work. © 2026 Siemens
Source: https://docs.sw.siemens.com/en-US/doc/861057055/202511026.capital_am_user/id731c2617-a042-4cd9-bd22-25ad13b75869 · retrieved 2026-07-18