Skip to Main Content
AVEVA™ PI System™ Feedback Portal

Welcome to our feedback site!


We created this site to hear your enhancement ideas, suggestions and feedback about AVEVA products and services. All of the feedback you share here is monitored and reviewed by the AVEVA product managers.

To start, take a look at the ideas in the list below and VOTE for your favorite ideas submitted by other users. POST your own idea if it hasn’t been suggested yet. Include COMMENTS and share relevant business case details that will help our product team get more information on the suggestion. Please note that your ideas and comments are visible to all other users.


This page is for feedback specifically for AVEVA PI System. For links to our other feedback portals, please see the tab RESOURCES below.

Status No status
Categories Security
Created by Kenneth Barber
Created on Oct 4, 2026

Include the port number in service principal names (SPNs) when the port number is not (and never will be) configurable

In particular, the PI Data Archive's port 5450 is not configurable and the PI Asset Framework's port 5457 is not configurable, and both programs require SPNs.

The SPNs that are expected to be assigned to the service account of the PI Data Archive's PI Network Manger are:

  • PIServer/<host name>

  • PIServer/<FQDN>

The SPNs that are expected to be assigned to the service account of the PI AF Application Service are:

  • AFServer/<host name>

  • AFServer/<FQDN>

I feel that these should instead be:

  • PIServer/<host name>:5450

  • PIServer/<FQDN>:5450

  • AFServer/<host name>:5457

  • AFServer/<FQDN>:5457

There are several reasons why I think that this change is good:

  • It is clearer, more specific, and follows the principle of least privilege

  • The PI services will not even receive traffic if the wrong port number is used

  • This futureproofs the PI services if extra functionality is ever added that uses the same service class but different service accounts

If the PI Server install kit tries to register SPNs, then it should use the versions with port numbers. Similarly, the documentation of any PI programs that mention these SPNs (e.g. PI Data Archive, PI Asset Framework, PI Vision, and PI Web API) should use the versions with port numbers. The PI SQL Data Access Server (RTQP Engine) is a good example of using SPNs with port numbers when the port number is not configurable (see this).

However, this suggestion is not just for the SPNs of the PI Data Archive and of the PI Asset Framework. Those are just the examples that come to mind. This suggestion should be implemented whenever SPNs are needed and the ports that are used are not configurable.

  • Attach files