Skip to content

Identity-Aware Microsegmentation

Network location alone does not establish industrial authority. L2Proxy Connect carries authenticated user and live session context into the enforcement path so communication can be constrained per person, role, service identity, access domain, and work session.

Decision context

An identity-aware policy can combine:

Identity-aware microsegmentation decision context across industrial zones

Figure — Identity-aware microsegmentation uses session and role context on protected paths.

  • authenticated user and group;
  • live session and connection type;
  • protected access domain;
  • assigned network and destination scope;
  • equipment, point, and industrial operation;
  • approved work period or maintenance authorization;
  • current state and prior activity;
  • required Record, Allow, or Block outcome.

From network access to industrial authority

Broad access model Identity-aware industrial model
User can reach the OT network User can reach only the assigned protected domain
Connection is trusted after login Every relevant operation remains subject to policy
All users in one network have similar reachability Authority differs by user, role, session, equipment, and task
Investigation begins with an IP address Evidence begins with authenticated identity and session
A violation requires blocking an entire network A specific industrial operation can be blocked and the session can be contained when required

Session-specific least privilege

A maintenance engineer can be allowed to read status and diagnostics from one transformer controller while control, configuration, other equipment, and session-to- session communication remain restricted. A protection engineer can receive different authority on the same network without creating a broad shared trust zone.

Identity context is retained with policy decisions and detailed protocol evidence, supporting session review, incident investigation, and accountable remote work.

Example: two engineers, one destination

Both engineers connect through authenticated encrypted access, but they do not receive the same authority:

Identity and purpose Permitted activity Restricted activity
Operations engineer HMI access and approved supervisory monitoring Controller programming and unassigned equipment
Automation specialist Diagnostics and approved controller maintenance during the work window Safety-system changes, unrelated cells, and peer sessions

L2Proxy Connect evaluates each session independently. An identical destination address can therefore produce a different decision because user, purpose, application, equipment, or industrial operation differs.

Next: Protocol-Aware Microsegmentation.