Identity-Aware Microsegmentation¶
Network location alone does not establish industrial authority. L2Proxy Connect carries authenticated user and live session context into the enforcement path so communication can be constrained per person, role, service identity, access domain, and work session.
Decision context¶
An identity-aware policy can combine:

Figure — Identity-aware microsegmentation uses session and role context on protected paths.
- authenticated user and group;
- live session and connection type;
- protected access domain;
- assigned network and destination scope;
- equipment, point, and industrial operation;
- approved work period or maintenance authorization;
- current state and prior activity;
- required Record, Allow, or Block outcome.
From network access to industrial authority¶
| Broad access model | Identity-aware industrial model |
|---|---|
| User can reach the OT network | User can reach only the assigned protected domain |
| Connection is trusted after login | Every relevant operation remains subject to policy |
| All users in one network have similar reachability | Authority differs by user, role, session, equipment, and task |
| Investigation begins with an IP address | Evidence begins with authenticated identity and session |
| A violation requires blocking an entire network | A specific industrial operation can be blocked and the session can be contained when required |
Session-specific least privilege¶
A maintenance engineer can be allowed to read status and diagnostics from one transformer controller while control, configuration, other equipment, and session-to- session communication remain restricted. A protection engineer can receive different authority on the same network without creating a broad shared trust zone.
Identity context is retained with policy decisions and detailed protocol evidence, supporting session review, incident investigation, and accountable remote work.
Example: two engineers, one destination¶
Both engineers connect through authenticated encrypted access, but they do not receive the same authority:
| Identity and purpose | Permitted activity | Restricted activity |
|---|---|---|
| Operations engineer | HMI access and approved supervisory monitoring | Controller programming and unassigned equipment |
| Automation specialist | Diagnostics and approved controller maintenance during the work window | Safety-system changes, unrelated cells, and peer sessions |
L2Proxy Connect evaluates each session independently. An identical destination address can therefore produce a different decision because user, purpose, application, equipment, or industrial operation differs.