Not sure I follow you, here, since I think you know differently.   There is windows embedded directly into many SCADA devices, and there is nothing removed from it at all over a standard Windows install.  Metasploit works wonderfully against them.

Actually we only have one embedded Windows device here and it shares
on basic characteristic as all of those at the power plant - they
weren't networked. I can't tell you what's running on them besides the
app because that's all you see and I have no ability to scan them.

As for the rest of the SCADA systems here, we will change their
configuration once we get them back from the OEM.

If the need arise, we're likely to provide the SCADA network with its
own AD environment.
