Skip to main content

Server

Domain Controller in OT

Directory services dedicated to the OT environment, providing authentication for OT hosts.

Critical criticalityLevel 3

What it does

Authenticates OT users and computers, applies policy, and should remain independent of the enterprise forest where feasible.

Typically locatedSite operations zone, usually redundant.

At a glance

PurdueLevel 3
CategoryServer
Protocols
Talks toOT servers and workstations, Jump hosts, OT applications
Common vendorsMicrosoft

Why should I care?

Domain Controller in OT sits at Level 3. Compromise here is not just a data problem — it changes what the physical process does or what operators can see and control.

Common security problems

  • Trusts back to the enterprise forest
  • Shared administrator credentials with IT
  • Unpatched due to change constraints

If it is compromised

  • Enterprise-style domain compromise inside OT, enabling widescale access

What to monitor

  • Privileged group changes
  • Kerberos anomalies
  • Replication and trust changes
  • Authentication from unexpected hosts

How to defend it

  • Separate OT identity from IT where the operating model allows
  • Tiered administration
  • Independent, tested backups

Related

Protocols this component speaks