Anti-Islanding and Protection Settings: What the Utility Is Protecting Against

Grid & Compliance   5 min read

Every grid-connected inverter has to disconnect when the grid goes away. The requirement is universal, the reasoning is sound, and the settings that implement it cause a surprising amount of operational trouble.

What islanding means

An island forms when a section of network becomes isolated from the main supply but remains energised by a local generator. If your solar continues supplying a circuit the utility believes is dead, several bad things follow.

The safety case is the primary one: line workers may approach an isolated conductor expecting it to be de-energised. This alone justifies the requirement.

There are technical reasons too. An island has no reference for voltage and frequency control, so both drift. Equipment on the island can be damaged. And reconnection to the main grid out of synchronism can cause severe mechanical stress on rotating plant and damage to equipment.

How inverters detect it

Passive methods monitor voltage and frequency at the connection point and trip outside defined windows. Straightforward, but there is a detection blind spot: if local generation happens to closely match local load, voltage and frequency may stay within limits for a period even after the grid is gone.

Active methods address that. The inverter continuously injects a small perturbation – a slight frequency shift, a small reactive power variation – and observes the response. Connected to a stiff grid, the perturbation is absorbed with no measurable effect. In an island, it causes a detectable drift, which trips the inverter.

Certified inverters implement these to standards such as IEEE 1547 and UL 1741 in North America, or EN 50549 and national requirements in Europe. Testing verifies detection within a specified time, typically around two seconds.

Why settings cause nuisance trips

Protection settings are a compromise. Tight settings detect genuine islands quickly but trip on normal grid disturbances. Loose settings ride through disturbances but risk slow island detection.

Common causes of repeated tripping:

  • Voltage rise from your own generation. On a weak circuit, exporting raises local voltage. If it approaches the upper limit, the inverter trips – and this happens most on bright days at low load, which is when you least want it.
  • Settings inherited from a different context. Installer defaults for another jurisdiction or an earlier revision of the code.
  • Genuine grid instability. Some networks are simply noisy. Frequency excursions from a nearby industrial load can trip generators repeatedly.
  • Ride-through not enabled. Modern codes increasingly require inverters to ride through short disturbances rather than trip – because mass disconnection of distributed generation during a disturbance makes the disturbance worse. If ride-through is available but not configured, you trip on events the code expects you to survive.

Diagnosing repeated trips

Get the inverter event log. Modern units record the trip reason and usually the measured value that caused it. That single step distinguishes overvoltage from underfrequency from a genuine loss-of-mains event, and the remedies are entirely different.

If it is overvoltage, and it correlates with high generation and low site load, the cause is usually voltage rise from your own export. Options include tap changes on the transformer, reactive power absorption by the inverters to counteract the rise, or negotiating a revised set point with the network operator.

Do not simply widen the trip settings to stop the alarms. Those settings are usually a condition of your connection agreement, and altering them without approval can breach it. Where a change is genuinely appropriate, the operator can authorise it.

What to establish at commissioning

  • Which grid code profile is loaded in each inverter, confirmed in writing.
  • The actual settings, recorded in the commissioning pack.
  • Confirmation that ride-through is configured as the code requires.
  • Who holds authority to change settings later, and the approval route.

Recording this at handover costs nothing. Reconstructing it three years later, when nobody remembers who configured what, costs a service visit and an argument.