Establish identity and scope
Identify industrial applications, production security zones, engineering workstations, approved partner or remote access; validate participating Endlets before admission.
Connected factory segmentation · Architecture
Apply least-privilege policy across industrial automation and control system security zones and conduits.
Primary capability
Zero Trust
How it works
Limit lateral movement while preserving required production and support workflows.
Identify industrial applications, production security zones, engineering workstations, approved partner or remote access; validate participating Endlets before admission.
validated identity and machine state → fabric admission → approved service policy → enforcement across a workload or zone conduit
Review identity evidence, policy decisions, allowed and denied flows, service reachability, session state with the responsible teams.
Architecture flow
Inputs
industrial applications, production security zones, engineering workstations, approved partner or remote access, identity services, Endlets
Path
validated identity and machine state → fabric admission → approved service policy → enforcement across a workload or zone conduit
Evidence
identity evidence, policy decisions, allowed and denied flows, service reachability, session state, and revocation
Quick answers
validated identity and machine state → fabric admission → approved service policy → enforcement across a workload or zone conduit
identity evidence, policy decisions, allowed and denied flows, service reachability, session state, and revocation
OT security, plant operations, network security, application owners
Continue the evaluation path
Determine whether each approved role and workload receives only the service access permitted through the defined zone conduits.
Continue to Evaluation