Service access for customers and maintenance partners

Last updated on 29 September 2026

Author: · LinkedIn

A customer, your own service engineer and an external maintenance partner do not necessarily need the same access. Configure remote access by location and task. The Remote Portal helps manage users, groups, routers and locations; your access policy defines what each party may do.

Remote Engineer · Knowledge base · 22 September 2026

How do you give a supplier access only to the agreed machine?

For each party, record the machine, the intended work and who grants approval. Viewing a web page calls for different access than using engineering software. Separate permission to connect from authorisation to change parameters or software.

NCSC guidance for OT includes least privilege, encrypted access, strong authentication and logging. Apply those principles to the actual installation. Explicitly define authentication requirements and additional safeguards; an account name alone does not make access appropriate.

Remote access across customer sites: managing users and permissions

Create recognisable locations and assign the corresponding ServiceGate routers. Then assign users or groups to their authorised locations. Use personal accounts so a connection can be associated with an individual, and review group membership when staff or contracts change.

Use templates for repeatable remote-access settings, but check each customer location separately. A template is not approval to apply the same permissions everywhere. ServiceGate profiles can be defined per customer or location, including firewall policy and any internet access behind the router.

Choose a portal service or a VPN connection

The portal lets you configure remote-access services for VNC, RDP, HTTP and HTTPS. These provide a focused entry point through the secure connection. The target system must offer the relevant service and retain its own authentication and access controls.

With VPN, the user's computer obtains network access to the authorised location. The user starts their own VNC or RDP client when needed. This broader network path requires suitable network and application restrictions. Location authorisation does not automatically make access inside a PLC or HMI read-only.

Example: three parties working on one machine

The customer wants to view an HMI, the machine builder needs diagnostics and a maintenance partner needs extra access for one job. Define these tasks first, then configure locations, groups, services and target-system permissions. This is a design example; it does not imply that every desired permission level is available through a single standard portal setting.

Agree the job's start, end, local contact and allowed actions. Check how temporary access and revocation are implemented in your setup. Do not assume automatically expiring permissions or a built-in approval workflow without verification.

Remote access logging: who connected and what can you demonstrate?

The Remote Portal lets you see which user connected to which location. This supports access review. It is not a complete record of PLC changes, typed commands or screen interactions.

If you need evidence of changes, assess additional logging on the engineering computer, application or controller. Define time synchronisation, retention, access to records and any export requirements. Logging process data at the location and recording service access serve different purposes and each needs its own configuration.

Check access after the engineer has finished

  • Use a representative account to test both permitted and prohibited locations and services.
  • Check connection traceability and agree which actions are recorded elsewhere.
  • Revoke job-specific rights and test termination of existing and new access according to the chosen setup.
  • Review users, groups, templates and third-party access agreements periodically.
  • Keep router, controller and other machine software updated: segmentation does not replace patch management.

Make it workable for your service team

Send an overview of locations, parties and required tasks. Together we determine how to organise access and visibility, which standard functions fit and where custom work is needed. Pricing and implementation are proposed for your specific situation.

Want to apply this approach to your installations? Explore our industrial remote access solution for control systems: ServiceGate, central access management and the choice between VPN and portal services.

Secure access also needs ongoing management

A separate machine segment and appropriate permissions restrict reachability. They do not replace security updates for the router, controller and machine software. Agree firewall rules, permitted actions and local safety procedures with the owner.

Sources and scope

Based on the technical documentation below, consulted on 22 September 2026, and the described Remote Engineer functionality. Manufacturer documentation supports protocol behaviour and requirements, not certification of the ServiceGate integration. Examples are illustrative; confirm model compatibility and settings for your installation.