Server
Domain Controller in OT
Directory services dedicated to the OT environment, providing authentication for OT hosts.
Critical criticalityLevel 3
What it does
Authenticates OT users and computers, applies policy, and should remain independent of the enterprise forest where feasible.
Typically locatedSite operations zone, usually redundant.
At a glance
PurdueLevel 3
CategoryServer
Protocols
Talks toOT servers and workstations, Jump hosts, OT applications
Common vendorsMicrosoft
Why should I care?
Domain Controller in OT sits at Level 3. Compromise here is not just a data problem — it changes what the physical process does or what operators can see and control.
Common security problems
- Trusts back to the enterprise forest
- Shared administrator credentials with IT
- Unpatched due to change constraints
If it is compromised
- Enterprise-style domain compromise inside OT, enabling widescale access
What to monitor
- Privileged group changes
- Kerberos anomalies
- Replication and trust changes
- Authentication from unexpected hosts
How to defend it
- Separate OT identity from IT where the operating model allows
- Tiered administration
- Independent, tested backups
Hunting
Hunt ideas for this component
Related