Jump-server administration
Jump server administration in two steps: an offsite engineer authenticates with MFA and an approved work order through a VPN gateway and IT firewall to a hardened IDMZ jump server (10.20.35.10) that logs and records the session, then an approved session from the jump server through Firewall B to a target HMI, with direct access from the engineer laptop blocked.