End Shared Passwords In OT.
Named logins for every operator, engineer, and vendor, tied to your directories and enforced at the network. No agents, no equipment changes.
Shared HMI logins, vendor passwords on panels, and service accounts everyone knows mean you cannot prove who did what. NIS2, NERC CIP, and CMMC now require individual accountability. Access Gate gives every operator, engineer, and vendor a named login, tied to your directories and enforced at the network, with no agents and no equipment changes.
Keep IT and OT directories side by side, not merged
Best practice is a distinct OT identity store, not corporate Active Directory pushed onto the shop floor. Access Gate lets you federate IT and OT directories side by side, whether that is Entra, Okta, Active Directory, or LDAP, so each side keeps its own lifecycle and blast radius.
No OT directory today? Access Gate can host one, so you get a real OT identity store without standing up separate infrastructure. This is how you enforce identity on the shop floor without making the plant depend on the IT domain.
Put MFA in front of controllers that do not support it
Most controllers cannot do multi-factor authentication, and you cannot change that without replacing them. Access Gate enforces MFA in the network path, in front of the asset. The PLC stays exactly as it is, but no one reaches it without passing the factor at the gate.
This is the practical way to close the CMMC Enduring Exception, and to meet NERC CIP and NIS2 access-control expectations, for legacy equipment that cannot meet the control on its own.
A front door for assets that have no login of their own
Identity is enforced at the network, so every asset gets a named front door, every user is scoped to what they need, and every session is tied to a person.
Internal vs external users
Internal staff authenticate against the OT directory. External vendors get scoped, time-bound access, never added to your directory and never given standing credentials.
Authentication splash page
Every user hits an Access Gate login before the asset. It is a front door for HMIs, PLCs, and SCADA that have no login of their own.
Machine activation, per job or window
Operators self-activate the asset they need for a shift, task, or window, then it auto-revokes. No standing access between jobs.
Personal logs
Every session is tied to an individual: who, what, when, how long. Tamper-evident and audit-ready for NIS2, NERC CIP, and CMMC Level 2.
Named identity is now a requirement, not a nice-to-have
Access control and individual accountability are explicit obligations across the frameworks OT operators answer to. Access Gate produces the identity evidence they ask for.
NIS2
Article 21 access control: individual accountability and controlled access to essential systems.
NERC CIP-004 / 005 / 007
Personnel access, Interactive Remote Access, and system access controls for the bulk electric system.
CMMC L2 / NIST 800-171
The 3.5.x identification and authentication family, including MFA, for controlled environments.
OT identity, answered
Best practice is a distinct OT identity store rather than putting corporate Active Directory on the shop floor. Access Gate lets you federate IT and OT directories side by side (Entra, Okta, AD, LDAP), and if you have no OT directory it can host one.
The factor lives in the network path, in front of the controller, not on the controller. The PLC is untouched, but no one reaches it without passing MFA at the Access Gate. That closes the CMMC Enduring Exception for equipment that cannot do MFA itself.
Vendors get scoped, time-bound access at the gate. They are never added to your directory and never hold standing credentials, so access ends when the job or window does.
Yes. Every user authenticates with a named login at the gate before the asset, and every session is recorded to that individual. Shared HMI logins and panel passwords stop hiding who did what.
No. Identity is enforced in the network path, so there are no agents to install and no changes to the HMIs, PLCs, or SCADA themselves.
Access Gate secures your assets first, then exposes the simple services your teams and vendors actually want, so they run through the sanctioned path, not around it.
OT runs through you, not around you.