I am coming from using the old ActiveX web client to now using Access Anywhere (Plant SCADA 2023 R2, Windows Server 2022), and since the latter now creates an RDP session to the server, users now have access to the file system, for example, from save/open dialogues.
We are exploring GPOs to lock down these sessions but some scenarios are tricky. The biggest issue is that all users (even view-only) need read/write access to certain Plant SCADA folders (such as C:\ProgramData\AVEVA Plant SCADA 2023 R2\Data), for the runtime to function properly. But this also means they can delete these files if they get access to the File Explorer or other dialogues.
Has anyone solved this security? I can't imagine I'm the only one running into this. Maybe I'm missing something in my configuration, or maybe there is a known workaround. Any help would be greatly appreciated!