SCADA Windows 10 version and configuration

Discussion in 'Windows 10' started by domyrat, May 12, 2021.

  1. domyrat

    domyrat MDL Novice

    Joined:
    Aug 20, 2009
    Messages:
    5
    Likes Received:
    0
    Trophy Points:
    0
    How would you stabilize/standardize/protect internet connected (non-negotiable) Windows 10 based computers (HMI, engineering workstations) that are connected to ICS network? We all know that Windows 10 wants to update very often, which sometimes disables/interferes with ICS/SCADA standard operation applications and services. Imagine there is no central AD, or some other central service to manage the machines, machines are used everyday but cannot be accessed by IT admins for management once put in place. Machines should be protected enough not to interfere with ICS/SCADA.
    Maybe some LTSC version with correct settings?
    Please advise :)
    At best there would be 2 solutions:
    1. Windows 10 LTSC/LTSB without internet connection and "industrial configuration" with SCADA in mind
    2. Windows 10 LTSC/LTSB with internet connection and "industrial configuration" with SCADA in mind

    Thank you!
     
  2. JakeBickel

    JakeBickel MDL Junior Member

    Joined:
    Nov 9, 2009
    Messages:
    91
    Likes Received:
    41
    Trophy Points:
    0
    What is "industrial configuration?"
     
  3. domyrat

    domyrat MDL Novice

    Joined:
    Aug 20, 2009
    Messages:
    5
    Likes Received:
    0
    Trophy Points:
    0
    #3 domyrat, May 13, 2021
    Last edited: May 13, 2021
    (OP)
    Is to be debated also. That's why it's quoted :)
    In general, workstation should be set as a machine which does operational management and overview of SCADA, bulletproof, foolproof specific purpose machine instead of typical desktop computer. Something like workplace machine with gpo's but with more gpo's that help keep it stable (24/7) without IT helpdesk intervention. Something like a server but with clickable applications with gui.
     
  4. EeroS

    EeroS MDL Senior Member

    Joined:
    Jul 28, 2018
    Messages:
    298
    Likes Received:
    133
    Trophy Points:
    10
    Enterprise LTSC is really designed to applications like this. It's meant for industrial automation etc.
     
  5. domyrat

    domyrat MDL Novice

    Joined:
    Aug 20, 2009
    Messages:
    5
    Likes Received:
    0
    Trophy Points:
    0
    I agree, so we need some configuration examples or hints what to do to complete this.
     
  6. sebus

    sebus MDL Guru

    Joined:
    Jul 23, 2008
    Messages:
    6,201
    Likes Received:
    1,945
    Trophy Points:
    210
    Sadly Windows is not suitable for such use. Unless you never ever connect to even local network, disable updates and connect whatever it needs to connect via USB only. And never change that setup
    Once you stick network cable to to, it is all over.

    That is why most appliances run some flavour of Linux