ORDR + Elisity: AI-Powered Asset Intelligence for Dynamic Microsegmentation
ORDR discovers and profiles every connected asset across IT, IoT, OT, and IoMT environments, tracking more than 2,500 attributes per device. Elisity carries that intelligence into the Elisity IdentityGraph™ and enforces identity-based microsegmentation through the network infrastructure you already own. Together, you get risk-aware policies built on real device context, including risk scores, PHI indicators, and “Known in ORDR” trust status.
Support Documentation
Connect ORDR
Step-by-step guide to connecting ORDR to Elisity IdentityGraph with API credentials in the Elisity Cloud Control Center.
ORDR Classification Details
View the 19 ORDR device attributes mapped to Elisity policy groups, including device profile, ORDR category, risk state, and PHI indicators.
Challenge
Unmanaged IT, IoT, and IoMT Devices You Cannot See or Classify
A hospital floor runs infusion pumps, patient monitors, ultrasound carts, and nurse call systems. A plant floor runs PLCs, HMIs, and building automation controllers. None of them accept an endpoint agent, and in most inventories none of them resolve to anything richer than a MAC address, a DHCP fingerprint, and a VLAN assignment. Security teams are left with a list that confirms a device exists without saying what it is, who manufactured it, what operating system it runs, or what it normally communicates with. Policy work stalls there. You cannot write a least-privilege rule for an asset you can only describe as an address on VLAN 40, so unmanaged devices land in broad permissive zones by default, which are exactly the zones an attacker uses to move laterally. Manufacturer, model, operating system, and behavioral profile are the minimum context required before identity-based microsegmentation becomes something more than a diagram.
Elisity Solution
ORDR Collectors Enrich Elisity IdentityGraph With 2,500+ Asset Attributes
ORDR profiles every connected asset, and Elisity turns that profile into enforceable policy. ORDR Collectors deployed on premises combine passive flow collection with safe active probing to discover and classify IT, IoT, OT, and IoMT devices, tracking more than 2,500 attributes per asset. That intelligence flows into the Elisity IdentityGraph through an API connection configured in the Elisity Cloud Control Center, where manufacturer, model, operating system, FQDN, device type, device profile, and ORDR category arrive as first-class identity attributes rather than entries in a separate console. Your team stops exporting spreadsheets between platforms and stops maintaining a second inventory that drifts out of date the week after it is finished. ORDR establishes what each asset is and how it behaves. Elisity uses that identity to decide what the asset is permitted to reach, north-south and east-west, and enforces the decision through the network infrastructure you already own. No agents on the endpoint, no new appliances in the path.
Challenge
Risk-Blind Segmentation Treats Every Device of a Type the Same
Knowing that a device is an infusion pump is not the same as knowing it runs an operating system with an unpatched CVE, that it is clinically critical during a code, or that it handles protected health information. Most segmentation projects flatten those distinctions. Every pump lands in the pump group, every controller lands in the controller group, and the resulting policy is only as tight as the weakest member of the set. When a vulnerability advisory arrives on a Friday afternoon, the team has no attribute to pivot on: risk scoring lives in one platform, policy lives in another, and reconciling the two is a manual exercise measured in weeks. Compliance reviewers ask a version of the same question and get the same answer. Which controls apply to the devices that touch PHI, and how do you prove those controls followed a device when it moved to another floor, another building, or another clinic?
Elisity Solution
Risk Scores, PHI Indicators, and Known in ORDR Status Drive Elisity Policy
Elisity policy groups match on ORDR risk attributes directly, so segmentation reflects device risk rather than device type alone. Risk score, risk state, criticality, ORDR category, PHI indicator, and the “Known in ORDR” trust status are all available as policy group criteria in the Elisity Cloud Control Center. That makes rules like these routine to build and defend: any asset where “Known in ORDR” is false receives a restricted profile until it is identified; any device flagged as handling protected health information is limited to the clinical application servers it actually needs; any asset whose risk state rises moves into a tighter policy group without a change ticket or a maintenance window. Because the Elisity IdentityGraph re-evaluates attributes continuously, a device that gets remediated relaxes back into its normal group on its own. Auditors get a defensible answer: the control is bound to the asset’s identity and risk posture, not to the subnet it happens to occupy today.
Challenge
Manual Classification Cannot Keep Pace With Specialized Device Fleets
Healthcare, manufacturing, and industrial organizations run thousands of device models that a generic classifier has never seen. Heart pump controllers, sterilizers, telemetry gateways, PLCs, and building automation systems all look like ordinary hosts on the wire until someone with domain knowledge labels them by hand. So teams build the inventory manually: a biomedical engineering spreadsheet here, a facilities list there, a network export nobody has refreshed since the last audit. It is accurate the day it is finished and stale a quarter later, because assets are added, replaced, re-imaged, and moved between buildings continuously. The result is a classification layer that cannot support automated policy. Every new device becomes a ticket, every acquired clinic or new production line multiplies the work, and the segmentation program advances at the speed of the people doing data entry instead of the speed of the network.
Elisity Solution
Automated Classification Maps 19 ORDR Attributes to Elisity Policy Groups
The integration maps 19 ORDR device attributes into Elisity policy group criteria, so classification happens once and policy follows automatically. The ORDR AI and machine learning classification engine identifies specialized equipment by behavior and communication pattern, then passes device type, device profile, device group, ORDR category, manufacturer, model, operating system, FQDN, risk state, and related fields into the Elisity IdentityGraph. A heart pump controller is classified as a heart pump controller, a PLC as a PLC, a building automation controller as a building automation controller, and each one lands in the policy group its role calls for. New assets inherit policy the moment ORDR profiles them, so a newly deployed imaging system is governed on day one instead of after the next inventory cycle. Enforcement runs through the network infrastructure you already own, which is why modern microsegmentation is measured in weeks where a VLAN redesign is measured in years.
Explore Our Integrations
Elisity integrates with leading IT, OT, and IoT asset intelligence platforms. Combine deep device discovery and classification with identity-based microsegmentation enforced through your existing network infrastructure.
Device Intelligence / Risk Status
EDR / Risk Status
CMDB
Network Enforcement Point
User Identity / Device Metadata
SIEM
ORDR + Elisity Integration FAQ
Get answers to common questions about how ORDR integrates with Elisity to deliver AI-powered asset intelligence and identity-based microsegmentation across IT, IoT, OT, and IoMT environments.
ORDR discovers, classifies, and profiles every connected asset using on-premises Collectors that combine passive flow collection with active probing, tracking more than 2,500 attributes per device across IT, IoT, OT, and IoMT environments. You connect ORDR to Elisity by entering API credentials in the Elisity Cloud Control Center, which takes minutes. Once connected, ORDR asset intelligence including manufacturer, model, operating system, FQDN, device type, risk state, and ORDR category flows into the Elisity IdentityGraph, where it becomes policy group criteria. Elisity then enforces identity-based microsegmentation through the network infrastructure you already own, with no new hardware and no endpoint agents.
No. The integration is agentless on both sides. ORDR Collectors discover and profile devices from the network using flow data and safe active probing, so nothing is installed on the asset itself, and Elisity enforces segmentation policy through your existing network infrastructure rather than through an endpoint agent. That matters because the devices most in need of segmentation are the ones least able to run software: infusion pumps, imaging systems, PLCs, building automation controllers, and legacy operating systems under vendor or safety certification restrictions. You get full visibility and enforced microsegmentation without ever touching a production endpoint.
The integration maps 19 ORDR attributes into Elisity policy group criteria. They include device type, device profile, device group, ORDR category, manufacturer, model, operating system, and FQDN for classification, plus risk-oriented fields such as risk score, risk state, criticality, PHI indicator, and the “Known in ORDR” trust status. Security teams combine those attributes into policy groups, for example restricting any asset where “Known in ORDR” is false, or applying tighter controls to devices flagged as handling protected health information. Because the Elisity IdentityGraph re-evaluates attributes continuously, policy follows the device as its classification or risk state changes.
ORDR profiles the full range of enterprise and specialized assets: managed IT endpoints and servers, IoT devices such as cameras and access control panels, OT equipment including PLCs, HMIs, and building automation controllers, and IoMT devices such as infusion pumps, patient monitors, imaging systems, and heart pump controllers. The ORDR AI and machine learning classification engine identifies these devices by behavior and communication pattern rather than by an installed agent. All of that classification flows into the Elisity IdentityGraph, so microsegmentation policies reflect what each device actually is and how it behaves, not just the IP address or VLAN it was assigned.
The API connection takes minutes: you enter ORDR API credentials in the Elisity Cloud Control Center and asset attributes begin enriching the Elisity IdentityGraph immediately. From there, most organizations move from connection to enforced microsegmentation policies in weeks rather than the months or years a traditional VLAN redesign requires. ORDR classification removes the manual device inventory step, and Elisity enforces policy through the network infrastructure you already own, so there is no new hardware to procure, no agents to roll out, and no network re-architecture to schedule around production windows.
Resources

Modern vs. Legacy Microsegmentation: The Evolution of a Critical Zero Trust Requirement

Microsegmentation ROI and KPIs: 2026 Benchmarks and Checklist

