Industries / Oil and gas
Microsoft security for an industry where IT and OT sit closer than they should.
Upstream, midstream, and downstream energy operators run Microsoft 365 as the corporate backbone while OT sits on parallel networks that IT is not supposed to touch. In practice engineers reach OT from corporate laptops, vendors remote in through the corporate VPN, and the SCADA-adjacent workstations hold both. Identra configures the Microsoft 365 controls that reduce the corporate-to-OT blast radius, satisfy the TSA Security Directives for pipelines, and give the CISO a documented answer to the auditor question about IT/OT boundary posture.
- Regulation
- TSA Pipeline SD-02, API 1164, NIST CSF
- Vertical scope
- Upstream, midstream, downstream, LNG
- License footprint
- M365 E5 recommended (Global Secure Access)
- Delivery
- Fixed scope, fixed price
01 / What we configure
Four patterns for a plant environment that IT does not fully control.
- 01
OT-adjacent workstation isolation
Engineering laptops that touch SCADA jump-hosts identified as a distinct Intune device class with restricted internet, no personal email, and no non-approved software. Conditional Access blocks the OT-adjacent class from consumer OneDrive, Dropbox, and social apps.
Intune device classRestricted browsingApp control - 02
Vendor and contractor remote access
Third-party engineers reach OT via Entra Global Secure Access with per-application policy, MFA, session recording, and time-boxed access windows. Vendor accounts provisioned via B2B with restrictive Conditional Access, not left dormant.
Global Secure AccessB2BTime-boxed - 03
TSA SD-02 alignment
Cybersecurity Coordinator role formalised inside Entra. Incident reporting workflow inside Sentinel maps to the TSA 24-hour reporting window. Annual cybersecurity assessment findings tracked as Purview compliance items with owner and target date.
TSA SD-02Sentinel workflowsCompliance items - 04
Corporate-side threat detection
Defender XDR correlates endpoint, identity, email, and cloud app alerts on the corporate side. Sentinel workbook flags any communication path between corporate and OT-adjacent segments that is not on the documented list. Alerts route to the plant SOC (or the shared CSOC where operations are centralised).
Defender XDRSentinelCorporate/OT boundary
02 / What it looks like
Three energy engagements.
Different segments of the energy value chain, same corporate-OT boundary problem.
CISO at a midstream pipeline operator
Situation. TSA Security Directive SD-02 obligation to demonstrate segmentation between IT and OT. Engineering laptops moved freely between corporate email and SCADA jump-hosts. No documented control preventing lateral movement.
Outcome. OT-adjacent laptops moved to a distinct Intune class with Conditional Access blocking consumer file-sharing apps. Sentinel workbook alerts on any workstation session that touches both corporate email and the SCADA jump host in the same 24-hour window. SD-02 evidence pack delivered to the TSA in the next annual filing.
IT Director at an upstream operator
Situation. Frac and workover crews use personal devices to reach corporate email and job-ticket apps. Some crews are contract labour rotating quarterly. No consistent MFA or device compliance across the field.
Outcome. App protection policy lets personal devices reach Outlook and the job-ticket app without device enrolment. Contract-labour accounts auto-expire at quarter end via Entra Lifecycle Workflows. Sign-in risk policy adds step-up MFA on high-risk signals.
CSO at a downstream refining operator
Situation. Multiple third-party engineering firms remote in for maintenance windows. Each vendor uses its own laptop with unmanaged patch status. Legacy VPN allows broad network access once authenticated.
Outcome. Vendors migrated to Global Secure Access with per-application policy. VPN retired for third-party access. Session recording configured for high-privilege maintenance sessions. Vendor access windows time-boxed to the approved change window.
03 / Frequently asked
What buyers ask first.
- Does TSA Security Directive SD-02 apply to us?
- SD-02 applies to owner and operators of TSA-designated critical pipelines and liquefied natural gas facilities. If your organisation received a Security Directive from TSA (typically through the Corporate Security Officer) you are in scope. The Directive requires specific technical controls (segmentation, MFA, incident reporting) plus annual assessment and reporting to TSA. Identra covers the Microsoft 365 side of the technical controls, not the physical or industrial control system side.
- What is API Standard 1164?
- API 1164 is the American Petroleum Institute standard for pipeline SCADA security. Now in its third edition (2021), it references NIST 800-82 (industrial control system security) and CSF (cybersecurity framework), and aligns broadly with the TSA SD-02 technical controls. Many operators use API 1164 as the internal reference standard and TSA SD-02 as the reporting obligation.
- How do you handle IT/OT convergence risk?
- The corporate-side controls Identra configures reduce the blast radius on the IT side of the boundary but do not extend into the OT network. Real OT/IT segmentation requires a network-layer control (data diode, firewall, unidirectional gateway) plus governance discipline (documented paths, no engineering back-doors, vendor access via jump-host only). Identra scoping calls out where the Microsoft 365 side ends and where an OT security engagement takes over.
- Do we need to go to Microsoft 365 GCC?
- Most commercial energy operators do not. GCC is appropriate for federal or state government customers, defense contractors, and CJIS-scoped organisations. Commercial energy operators typically run in commercial cloud and layer on the CIS Microsoft 365 benchmark or the CIS Critical Security Controls as the reference frame. If you sell to DoD (fuel supply, base services) that specific line of business may need to run in GCC or GCC High.
- How long does an energy sector engagement take?
- Typical engagement runs 10 to 16 weeks depending on the number of OT-adjacent workstations and vendor access relationships. Weeks 1 to 3 map corporate/OT boundary and identify OT-adjacent workstations. Weeks 4 to 10 configure Intune classes, Conditional Access, and Global Secure Access. Weeks 11 to 16 build the SD-02 or API 1164 evidence pack.
04 / Related
Where this fits.
Identity
Microsoft Entra consulting
Conditional Access, PIM, ID Protection turned on to enforcement.
Threat detection
Defender XDR deployment
Endpoint, identity, email and cloud alerts correlated into single incidents.
Framework
NIST 800-53 Rev 5 mapping
Control-by-control mapping of tenant settings to NIST 800-53 for regulated workloads.