AD tiering & privileged access design
Part 1 — The model: containing credential theft with Tier 0 and the Enterprise Access Model
Start here
This series is about privileged access design: how to arrange Active Directory (AD) so that compromising one machine doesn't compromise everything.
- Part 1 (this page): the model. Why tiering exists, the Tier 0 / 1 / 2 model, what really counts as Tier 0, Microsoft's Enterprise Access Model (EAM) that superseded it, the clean source principle, and why the Enhanced Security Administrative Environment (ESAE) "Red Forest" was retired.
- Part 2: the implementation. Privileged Access Workstations (PAWs), Authentication Policies and Silos, Protected Users, Windows Local Administrator Password Solution (LAPS), just-in-time access with Entra Privileged Identity Management (PIM), enforcing cross-tier logon boundaries, monitoring for drift, and the Rapid Modernization Plan (RaMP) rollout.
It pairs directly with the AD CS abuse series: there, the recurring line was "the Certificate Authority is Tier 0." This series explains what that sentence means and how to act on it.
Highlight key
- the term being defined
- Key term: bold with a highlighter swash. A concept's defining phrase.
- how something works
- Mechanism: wavy underline. How a piece works or relates to another.
- Risk: what makes an attack possible
- Risk: warm highlight with a dashed edge. Attack prerequisites and dangerous conditions.
- Fix: the mitigation to apply
- Fix: solid green underline. A mitigation or configuration change.
- Verify: how to confirm it worked
- Verify: green underline with a check. How to prove a fix works.
- only if, by default
- Qualifier: bold italic. A word that changes the claim.
4769- Technical literal: monospace chip. Commands, settings, event IDs, exactly as typed.
Plain English first
Active Directory decides who you are and what you can touch across a Windows network. If an attacker gains control of it, they control the whole organization: every server, every mailbox, every file.
Here's the uncomfortable part. When an administrator signs in to any computer, a reusable copy of their credential sits in that computer's memory for the session. Whoever controls that computer can copy the credential and become that administrator — no password-guessing, no cracking. So the real question for any powerful account isn't "is the password strong?" It's Risk: "which machines has it touched?"
Tiering is the design discipline that answers that question. It sorts everything into levels by how much damage its compromise causes, and enforces one rule: powerful credentials may only ever appear on equally-protected machines. Get it right and one phished laptop stays one phished laptop. Get it wrong and your network is flat — one laptop, a few hops, game over.
The analogy: the master key and where you carry it
A domain admin credential is a master key to the building. The lock it opens is strong — that's your password policy and Multi-Factor Authentication (MFA). But a master key can be copied by anyone who gets their hands on it, even for a moment.
Tiering is the rule that the master key Fix: never leaves the secure key room (a hardened admin workstation), and is never carried out onto the shop floor (an ordinary laptop) where a pickpocket might copy it. The lock being strong doesn't help if you hand the key around. Risk: Where you carry the key matters more than how good the lock is.
Why it matters now
For an attacker, a flat domain is a gift. Phish one user, gain local admin on their laptop, and there's a good chance a privileged credential has been left in memory somewhere nearby. Tools like BloodHound turn "somewhere nearby" into a precise, shortest-path map from the foothold to Domain Admins. In most un-tiered environments that path is Risk: only a few hops long, and credential theft (pass-the-hash, pass-the-ticket) needs no exploit and trips few alarms.
For a defender, tiering is the highest-leverage architectural control you can apply to AD — and most of the first wins are policy, not spend. You can't stop every phish, so you design so the first foothold is Fix: low-value and far from the crown jewels. Done well, it converts "instant domain takeover" into "a contained endpoint incident you have time to catch." The hard part isn't the concept; it's finding the Risk: hidden Tier 0 dependencies and holding the line on where admins log on.
If you remember only 5 things
- A credential can be stolen by whoever controls the machine it's used on. Where an account logs on decides where it can be stolen — that single fact is the reason tiering exists.
- Control flows down, exposure never up. A higher-tier credential must Fix: never appear on a lower-tier machine; break this one rule and the tiers collapse into a flat domain.
- Tier 0 is defined by control, not by label. It's the Domain Controllers (DCs) plus anything that can impersonate them — the Certificate Authority (CA), backups, the hypervisor, the sync account. Risk: The ones you miss are the ones that get used.
- The payoff is containment, not prevention. Tiering doesn't stop the first compromise; it stops that compromise from becoming domain-wide and buys you time to respond.
- The old Red Forest (ESAE) is retired. Microsoft's modern default is lighter and cloud-aware: separate tiered accounts, PAWs, and just-in-time access via RaMP — Fix: not a whole separate forest.
Core concepts
Thirteen ideas, built in order. The first three establish why a flat domain is dangerous; the middle set defines the tiers and what really belongs in Tier 0; the last set covers the modern model, the clean source principle, and how tiering relates to the hands-on controls in Part 2.
01Where you log on is where you can be robbedTiering exists because a credential can be stolen by whoever controls the machine it's used on.
When you sign in to a Windows computer, your credential (a hash or a Kerberos ticket) lives in that machine's memory for the session. If an attacker already controls that machine, they can lift your credential and become you. So the single most important question for any admin account is not how strong its password is, but Risk: which machines it has touched.
A domain admin who remotes into a helpdesk laptop to fix a problem leaves a usable domain-admin ticket on that laptop. Whoever owns the laptop now effectively owns the domain.
TechnicalGo deeper
This is the mechanism behind pass-the-hash and pass-the-ticket. NT LAN Manager (NTLM) hashes and Kerberos Ticket-Granting Tickets (TGTs) are cached in Local Security Authority Subsystem Service (LSASS); with local admin (or kernel access) on the host an attacker reads them and replays them. Crucially, this does not require cracking the password and is not stopped by a long password or by Multi-Factor Authentication (MFA) at first logon once the secret is resident. Tiering's entire job is to make sure high-value credentials are only ever resident on equally-protected machines.
02Security dependency: you are only as safe as what controls youA security dependency is anything that can take control of an object; the object is only as secure as its least-secure dependency.
Think of everything that can affect an account or a server: the machine it runs on, the admins who manage it, the software that updates it, the backup that can restore it. Each of those is a path to the object. An attacker doesn't need to attack the Domain Controller (DC) directly if they can attack Risk: something that controls the DC.
A DC is patched and hardened, but its backups are written to a file server any helpdesk tech can access. The file server is now a path to the DC's secrets, so it inherits the DC's sensitivity.
TechnicalGo deeper
Microsoft frames this as 'control relationships' and tools like BloodHound make them explicit as attack-path graphs (edges such as GenericAll, WriteDACL, AddMember, session and admin-to relationships). The design consequence is the clean source principle: any subject in control of an object is a security dependency of that object, and must be held to at least the object's security level. Ignoring an indirect dependency is how 'hardened' DCs still fall.
03The three-tier modelThe classic model sorts assets into Tier 0 (identity), Tier 1 (servers/data) and Tier 2 (workstations/users) by blast radius.
Group everything by how much damage its compromise causes. Tier 0 is anything that can control the identity system itself. Tier 1 is the servers and applications that run the business. Tier 2 is the end-user devices and the accounts people use day to day. The point of the labels is to decide which credentials may appear on which machines.
A payroll app server is Tier 1. The laptop of the HR clerk who uses it is Tier 2. The Domain Controller (DC) that authenticates both, and the admin who runs it, are Tier 0.
TechnicalGo deeper
Microsoft's original 'Active Directory administrative tier model' defined exactly these three tiers and one hard rule between them (next card). The tiers are about administrative control, not data classification: a Tier 1 server may hold the most sensitive business data in the company, but it is still Tier 1 because compromising it does not by itself hand over the identity fabric. Tier numbering goes the opposite way to trust: Tier 0 is the most privileged, Tier 2 the least.
04The cardinal rule: control flows down, exposure never upA credential from a higher tier must never be exposed on a lower-tier asset; lower tiers never control higher ones.
Higher tiers are allowed to manage lower tiers (Tier 0 can administer everything). What is forbidden is the reverse exposure: a Tier 0 credential appearing in the memory of a Tier 1 or Tier 2 machine, where a lower-tier compromise could steal it. Break this one rule and the tiers collapse into a flat domain.
A domain admin may build a new server, but must do it from a Tier 0 admin host, never by typing Domain Admins (DA) credentials into an Remote Desktop Protocol (RDP) session on the Tier 1 server itself.
TechnicalGo deeper
Concretely this means: no logging a Tier 0 account onto a Tier 1/2 host (interactive, RDP, RunAs, or service); no Tier 0 service accounts running on lower-tier machines; and no lower-tier account holding admin rights over a Tier 0 asset. Enforcement uses logon-right Group Policy Objects (GPOs) (Deny log on locally/through Remote Desktop), the Protected Users group, and authentication policy silos (Part 2). Verify: A clean BloodHound graph with no path from Tier 2 to Tier 0 is the proof.
05What counts as Tier 0Tier 0 is anything that can take control of the identity system, not just the domain controllers.
People assume Tier 0 means 'the Domain Controllers (DCs)'. It means the DCs plus every account, group, server and system that can seize equivalent control. If a thing can read the Active Directory (AD) password database, mint credentials, or change who is a domain admin, it is Tier 0 no matter what it's called.
The enterprise Certificate Authority can forge a logon certificate for any user, so the Certificate Authority (CA) is Tier 0 even though it isn't a DC. (That was the whole point of the AD CS series.)
TechnicalGo deeper
A working Tier 0 inventory typically includes: DCs and the AD database; Domain/Enterprise Admins and equivalent groups; the enterprise Public Key Infrastructure (PKI)/CA; Active Directory Federation Services (ADFS) and its token-signing keys; directory-sync accounts (Entra Connect) with replication rights; the backup system that protects DCs; the hypervisor and storage hosting DC virtual disks; and any account with DCSync/Replicating Directory Changes, WriteDACL on the domain, or membership-write over a Tier 0 group. Risk: Miss one and it becomes the attacker's quiet path in.
06Tier 0 is bigger than you think (hidden dependencies)The hard part of tiering is finding the non-obvious Tier 0 assets that control Domain Controllers (DCs) indirectly.
Every organization's DCs are guarded. Few guard the backup server, the virtualization admin, or the sync account to the same standard, yet each one can reach the DC's secrets by a side door. These hidden dependencies are where tiering programs quietly fail.
DCs are virtual machines on the general VMware cluster. A Tier 1 virtualization admin can snapshot a DC's disk, mount it offline, and extract NT Directory Services database (NTDS).dit, no domain-admin logon required.
TechnicalGo deeper
The usual suspects: backup/restore systems, hypervisor and storage admins, image/deployment systems, Endpoint Detection and Response (EDR) and management agents that run as SYSTEM on DCs, monitoring tools with write access, and software-distribution servers that can push code to DCs. Each is a transitive control path into Tier 0. The remedy is the clean source principle applied honestly: either bring the dependency into Tier 0 and protect it accordingly, or remove its control over Tier 0 assets.
07Tier 1 and Tier 2Tier 1 is servers, applications and their data; Tier 2 is user workstations and the accounts people use daily.
Tier 1 is where the business runs: file, database, application and member servers, plus the server-operations admins who manage them. Tier 2 is the end-user estate: laptops, desktops, and ordinary user and helpdesk accounts. Each tier gets its own admin accounts and its own management hosts, and the same no-upward-exposure rule applies between Tier 1 and Tier 2.
A server admin uses a Tier 1 admin account from a Tier 1 jump host to patch application servers, and a completely separate ordinary account on their Tier 2 laptop for email.
TechnicalGo deeper
Tiers can be subdivided (Tier 1 'silos' per application or business unit) to contain blast radius further, which is exactly where the Enterprise Access Model's management and data/workload planes come from. The discipline is the same at every boundary: Fix: separate identities, separate admin hosts, no credential reuse across the line. Most organizations get Tier 0 right first and mature Tier 1 segmentation over time.
08Blast radius and containmentTiering converts a flat domain where one laptop equals the whole company into contained zones where a compromise stays local.
Without tiering, Active Directory (AD) is effectively flat: because admins log on everywhere, a single compromised workstation usually has a credential-theft path all the way to domain admin. Tiering's payoff is that a Tier 2 compromise stays in Tier 2, buying defenders detection and response time instead of instant game-over.
Attacker phishes a user laptop. In a flat domain they find a cached Domain Admins (DA) token within hours. In a tiered domain they find only Tier 2 credentials, and the path to Tier 0 is missing.
TechnicalGo deeper
This is the assume-breach mindset: you will not stop every phish, so you design so the first foothold is low-value and far from the crown jewels. It is the same logic as watertight compartments in a ship's hull. Tiering doesn't prevent compromise; it caps the damage and slows propagation, which is what turns a breach into an incident instead of a catastrophe.
09The Enterprise Access Model (planes)Microsoft's current model reshapes the tiers into a control plane, a management plane and a data/workload plane, extended to cloud.
The three-tier model was built for on-prem Active Directory (AD). As identity moved to the cloud, Microsoft generalized it: the control plane is everything that governs access (the old Tier 0, now including cloud identity and networking), the management plane is the infrastructure that operates workloads, and the data/workload plane is the applications and data themselves. The principle is unchanged; the scope is wider.
In Enterprise Access Model (EAM), Entra ID and Conditional Access join on-prem Tier 0 in the control plane, because a Global Administrator in the cloud can be just as total as a domain admin on-prem.
TechnicalGo deeper
EAM explicitly supersedes the legacy tier model and adds user-access and app-access models for a hybrid, multicloud estate. The control plane maps to old Tier 0; the former Tier 1 split into management and data/workload planes; Tier 2 concerns map to user and app access. Practitioners note the underlying principles are effectively identical; the shift is that control is no longer rooted solely in on-prem AD. Use EAM's vocabulary with cloud-aware clients and the Tier 0/1/2 vocabulary with classic on-prem teams.
10The clean source principleAdminister an asset only from a source at least as trusted as the asset itself.
If you manage a highly-trusted system from a less-trusted one, the less-trusted one becomes a way to compromise it. So the device, the account and the network path used to administer Tier 0 must all be Tier 0-grade. This single principle is why Privileged Access Workstations exist.
Managing a Domain Controller (DC) from an admin's everyday laptop violates clean source: the laptop browses the web and reads email, so it is a weaker, exposed source controlling a Tier 0 asset.
TechnicalGo deeper
Microsoft's wording: the security of an object depends on the security of all the subjects in control of it, so all security dependencies must be held at or above the object's level. In practice clean source governs three things for every admin action: Fix: a clean device (the Privileged Access Workstation (PAW)), a clean account (a dedicated Tier 0 admin account), and a clean path (direct, not proxied through lower-tier jump hosts). Part 2 is largely the implementation of this one idea.
11Separate identities per tierEach administrator uses a distinct account per tier, with no account holding rights in more than one tier.
A person may be trusted to administer all tiers, but they must do it with different accounts: a Tier 0 account for Tier 0 work, a Tier 1 account for servers, and an ordinary account for daily email and browsing. One human, several identities, each confined to its tier.
Jordan has adm0-jordan (Tier 0, used only from a Privileged Access Workstation (PAW)), adm1-jordan (Tier 1 servers), and jordan (everyday mailbox and laptop). None of the three can log on in another tier's zone.
TechnicalGo deeper
This defeats the most common real-world failure: a single powerful account used for everything, whose hash ends up on a user workstation. Separation is enforced by logon-right Group Policy Objects (GPOs) and silos, and daily-driver accounts must never be privileged. Risk: The classic anti-pattern is a domain admin reading email: one malicious link and the most powerful credential in the environment is resident on an internet-exposed, phishing-reachable device.
12Enhanced Security Administrative Environment (ESAE) / the Red Forest, and why it was retiredESAE ('Red Forest') was a separate hardened admin forest; Microsoft retired it as a default in 2021 in favor of the modern privileged access strategy and Rapid Modernization Plan (RaMP).
For years the gold standard was a dedicated administrative forest that held your Tier 0 admin accounts, trusted one-way by production. It worked but was heavy and often half-built. Microsoft retired it as the default recommendation, replacing it with a cloud-aware strategy (Privileged Access Workstations (PAWs), Privileged Identity Management (PIM), Conditional Access) delivered via the Rapid Modernization Plan.
A team that spent two years standing up a Red Forest and never finished was, in the meantime, less secure than one that had simply deployed PAWs and separated admin accounts.
TechnicalGo deeper
Microsoft's guidance: there is no urgency to tear down a correctly-run ESAE, but a hardened admin forest is now a custom, exception-only configuration, not the starting point. New builds should adopt the modern strategy via RaMP directly. The tier model's logic survives intact inside Enterprise Access Model (EAM); it was the specific heavyweight implementation (a whole separate forest) that fell out of favor, because partial deployments left organizations stranded for years.
13Tiering vs. privileged access managementTiering says where credentials may appear; privileged access management (Just-In-Time (JIT), Privileged Access Workstations (PAWs), Multi-Factor Authentication (MFA)) is how you enforce and shrink that exposure.
Tiering is the map. Privileged access management is the set of controls that make the map real: Privileged Access Workstations (clean devices), just-in-time activation so admin rights don't stand idle, phishing-resistant MFA, and session brokering. You need both; a tier model with no enforcement is just a diagram.
Tiering says the Domain Admins (DA) account may only appear on a PAW. Privileged Identity Management (PIM) makes sure the account isn't even a domain admin until someone activates the role for two hours with approval, so most of the time there is nothing to steal.
TechnicalGo deeper
The strongest version combines them: separate tiered identities, JIT so standing privilege approaches zero, PAWs as the only clean source, and MFA plus Conditional Access gating activation. This is the content of Part 2. The key mental model: tiering limits blast radius, JIT limits the time window, PAWs limit the exposure surface, and together they make a stolen credential rare, short-lived and hard to capture.
Visual map
Three step-throughs. The first is tiering working as designed. The next two are the attacks it exists to stop: classic flat-domain credential theft, and the quieter "hidden Tier 0" path where the domain falls without anyone ever logging on as a domain admin. Step through each and watch where the credential lives.
Legacy tier model vs. the Enterprise Access Model
The vocabulary is shifting. Classic on-prem teams still say "Tier 0/1/2"; cloud-aware guidance uses the Enterprise Access Model's "planes." They describe the same principle at different scope — use whichever your audience knows.
| Aspect | Legacy three-tier model | Enterprise Access Model (EAM) |
|---|---|---|
| Origin | Active Directory (AD) administrative tier model (on-prem) | Current Microsoft model; supersedes the tier model |
| Top level | Tier 0 (identity / Domain Controllers (DCs)) | Control plane (identity + access control, on-prem and cloud) |
| Middle | Tier 1 (servers, apps, data) | Management plane + data/workload plane (Tier 1 split in two) |
| User level | Tier 2 (workstations, users) | User access + app access models |
| Scope | On-prem Windows AD | Hybrid and multicloud (Entra ID, Software as a Service (SaaS), Conditional Access) |
| Underlying principle | Contain privilege escalation | Identical — control never sourced from a lower plane |
Where Tier 0 actually lives
A quick reference for the inventory conversation. If a thing can read NTDS.dit, mint credentials, or change who is a domain admin, it is Tier 0 — whatever it's called.
| Asset | Tier 0? | Why |
|---|---|---|
| Domain controllers | Yes (obvious) | Host AD and the Key Distribution Center (KDC) |
| Enterprise Certificate Authority (CA) (AD CS) | Yes (missed) | Can forge a logon certificate for anyone |
| Active Directory Federation Services (ADFS) token-signing keys | Yes (missed) | Can mint tokens for any user |
| Entra Connect / sync account | Yes (missed) | Often holds directory-replication rights |
| DC backup system | Yes (missed) | Can restore and read the AD database |
| Hypervisor / storage for DC Virtual Machines (VMs) | Yes (missed) | Can mount a DC's virtual disk offline |
Agent running as SYSTEM on DCs | Yes (missed) | Executes code on the DC |
| A file server holding business data | No | Sensitive, but can't control identity → Tier 1 |
Technical deep dive
TechnicalUnder the hood
The three planes as control relationships
The deepest way to think about tiering is as a directed graph of control. An edge A → B means "A can take control of B." Membership in Domain Admins is one such edge, but so are WriteDACL on the domain object, GenericAll on a Domain Controller (DC) computer object, local-admin-on-a-DC, "can edit a Group Policy Object (GPO) linked to the Domain Controllers Organizational Unit (OU)," and "can restore the DC's backup." Tiering is simply the rule that Fix: no edge may point from a lower tier into a higher one without that lower-tier object being promoted into the higher tier.
This is exactly what BloodHound computes. The tool ingests group membership, Access Control Lists (ACLs), sessions, and local-admin rights, then finds shortest paths to Tier 0. A "clean" tiered environment is one where the graph has Verify: no inbound path to Tier 0 from Tier 1 or Tier 2.
Why credential exposure is unavoidable within a session
Windows single sign-on requires that your credential material be usable for the life of your session without re-prompting. That means secrets live in Local Security Authority Subsystem Service (LSASS): for Kerberos, your Ticket-Granting Ticket (TGT) and session keys; for NT LAN Manager (NTLM), your NTLM hash. This is a feature, not a bug — but it means that Risk: any interactive or RemoteInteractive logon leaves reusable material on the destination host. With local admin there, an attacker reads it. The defensive answer is never "stop caching" (you can't, fully); it's "only ever expose high-value credentials on high-value hosts," plus the Part 2 controls (Protected Users caps ticket lifetime and blocks NTLM; Credential Guard isolates secrets).
Defaults and limitations
- Active Directory (AD) ships flat. There is no Tier 0 OU, no logon restriction, and Domain Admins can log on anywhere out of the box. Tiering is something you impose; nothing enforces it by default.
AdminSDHolderandSDPropre-stamp ACLs on protected groups hourly — useful, but it only protects a fixed set of "protected groups," not your custom Tier 0 assets.- Tiering is organizational, not just technical. It fails most often on process (an admin "just Remote Desktop Protocols (RDPs) in") rather than on a missing GPO.
- It doesn't stop the initial breach or insider abuse by a legitimately-Tier-0 admin. It bounds blast radius; pair it with detection and least privilege.
Common misconceptions
| Misconception | Reality |
|---|---|
| "Tier 0 means the domain controllers." | Tier 0 is anything that can control the DCs, including backups, hypervisors, sync accounts and the Certificate Authority (CA). |
| "Tiering is about classifying sensitive data." | It's about administrative control. A Tier 1 server can hold the crown-jewel data and still be Tier 1. |
| "A jump box solves it." | Only if the jump host is itself Tier 0-grade (clean source). A shared jump box everyone RDPs through is a bigger target. |
| "Strong passwords + Multi-Factor Authentication (MFA) replace tiering." | Those stop guessing; tiering stops theft-and-reuse of a credential already in memory. |
| "We built a Red Forest, so we're done." | Enhanced Security Administrative Environment (ESAE) was retired as the default in 2021; verify completeness and whether Privileged Access Workstations (PAWs)/Privileged Identity Management (PIM) fit better now. |
| "Higher tier numbers are more secure." | Inverted: Tier 0 is the most privileged and most protected. |
Troubleshooting the design
- "Enforcing silos broke a service account." Protected Users and silos don't suit all service/computer accounts; scope carefully and test (Part 2 details the pitfalls).
- "We can't find all our Tier 0." Start from control, not labels: run SharpHound, then audit who holds
Replicating Directory Changes, who is local admin on DCs (including agents), and who administers DC backups and virtualization. - "Admins revolt over separate accounts." Pre-build the PAW and jump path so the new workflow is a couple of clicks; sell it as "same power, fewer places to lose it."
Attacker's view
AttackerTiering isn't an abstract maturity goal — it exists to break specific, repeatable attacks that show up in nearly every Active Directory (AD) assessment. Each technique below is described at the level needed to recognize, test for, and report it; the commands are recognition- and scoping-level only, never weaponized payloads. The throughline: every one of these is either the credential-theft engine or a way a flat/weak-tier design hands an attacker a short path to Tier 0.
Credential theft and reuse (pass-the-hash / pass-the-ticket)ATT&CKT1003.001 LSASS Memory · T1550.002 Pass the Hash · T1550.003 Pass the Ticket
With local admin on a host, the attacker reads cached secrets from Local Security Authority Subsystem Service (LSASS), then replays a hash or Kerberos ticket to authenticate elsewhere as that user, without ever knowing the password. This is the engine tiering is built to contain.
Risk: Local admin (or SYSTEM) on a host where a higher-value credential is resident, and a reachable target that trusts that credential.
Flat domains where Risk: privileged accounts log on to ordinary workstations and servers, no Protected Users, no Local Administrator Password Solution (LAPS) (so one local-admin hash unlocks the fleet), and unrestricted Server Message Block (SMB)/Windows Management Instrumentation (WMI) between hosts.
Mimikatz, Impacket (secretsdump, psexec, wmiexec), Rubeus, CrackMapExec/NetExec. BloodHound maps where theft leads.
# Recognition-level only: map exposure, don't dump
bloodhound-python -c Session,LoggedOn ... # where do privileged sessions exist?
Verify: LSASS handle access (Sysmon event 10), logon type 9 (NewCredentials/overpass-the-hash), 4624/4625 patterns, and service-ticket requests (4769) for accounts that never log on interactively.
Reported as the concrete realization of a flat-tier design: severity is driven by how short the path from a user workstation to Domain Admins is. Business impact is full domain compromise from a single endpoint. Retest criterion: Verify: no credential-theft path from Tier 2 to Tier 0 in BloodHound, Protected Users and logon restrictions enforced.
Privileged logon to a lower tier (the exposure that breaks tiering)ATT&CKT1078.002 Valid Accounts: Domain Accounts · T1021.001 Remote Services: RDP
The attack is really a misconfiguration the attacker harvests: an admin interactively logs a Tier 0/1 account onto a Tier 2 host (Remote Desktop Protocol (RDP), RunAs, a scheduled task, or a service), leaving that credential in the host's memory for later theft.
Risk: A higher-tier credential cached on a lower-tier machine the attacker can reach or already holds.
Help-desk and ops cultures where admins 'just RDP in' with powerful accounts, service accounts from Tier 0 running on Tier 1 servers, and no Deny log on restrictions separating the tiers.
No special tooling needed; the attacker uses the same Mimikatz/Impacket once the credential is present. Discovery via BloodHound sessions and qwinsta/event-log review.
# Find where privileged accounts have live sessions
# (Event 4624 by account + source host; BloodHound HasSession edges)
Verify: Interactive or RemoteInteractive logons (4624 type 2/10) by a Tier 0 account on a non-Tier 0 host, RunAs (4648) events, and services/tasks configured with privileged identities.
Often the single highest-leverage finding in an Active Directory (AD) assessment. Severity driven by the tier gap crossed (Domain Admins (DA) on a workstation is critical). Impact: collapses the tier model to flat. Retest: Verify: logon-right Group Policy Objects (GPOs) and silos deny the cross-tier logon, proven by attempting it.
Tier 0 'creep' via control-path escalationATT&CKT1098 Account Manipulation · T1484.001 Group Policy Modification
The attacker chains ordinary-looking rights, AddMember, WriteDACL, GenericAll, Group Policy Object (GPO) edit, or admin-to a Tier 0 host, into a path that ends at Domain Admins, without any single step looking privileged.
Risk: A delegated right or nested group membership that transitively controls a Tier 0 object, reachable from a lower tier.
Environments with years of accreted delegation: helpdesk groups with reset rights on admins, over-broad GPO delegation, nested groups nobody has audited, and local-admin-on-DC granted to Tier 1 agents.
BloodHound / SharpHound (the attack-path graph), PingCastle and Purple Knight for posture, PowerView for ad-hoc Access Control List (ACL) enumeration.
# Enumerate control paths, then read shortest path to Tier 0
SharpHound.exe -c All # collection only; analysis in BloodHound
Verify: Changes to Tier 0 group membership (4728/4732/4756), Discretionary Access Control List (DACL) modifications on the domain or AdminSDHolder (5136), and new GPO links on Tier 0 Organizational Units (OUs).
Reported with the exact path graph as evidence; executives understand 'this helpdesk group can become domain admin in three steps'. Retest: Verify: the path is broken in BloodHound and Tier 0 objects have only Tier 0 principals in their ACLs.
Hidden Tier 0: backup, hypervisor and identity-syncATT&CKT1003.003 NTDS · T1003.006 DCSync · T1550 Use Alternate Material
Rather than attack a Domain Controller (DC), the attacker takes a system that controls the DC indirectly: restore a DC backup, mount a DC's virtual disk to extract NT Directory Services database (NTDS).dit, or abuse a directory-sync account's replication rights to Directory replication abuse (DCSync).
Risk: Control of a backup system, hypervisor/storage admin, or an account with replication rights, none of which is guarded as Tier 0.
DCs virtualized on a general cluster, DC backups on shared storage, Entra Connect/sync accounts with Replicating Directory Changes All, and Endpoint Detection and Response (EDR)/management agents running as SYSTEM on DCs from a Tier 1 console.
Native backup/hypervisor consoles, ntdsutil/secretsdump for offline NTDS, Mimikatz/Impacket for DCSync, BloodHound to surface the sync-account edge.
# Recognition: who can replicate directory changes?
# Audit members/ACLs holding 'Replicating Directory Changes All'
Verify: Replication requested by a non-DC principal (4662 with the DS-Replication Globally Unique Identifier (GUID)), DC backup/restore and snapshot operations, and offline volume mounts of DC disks.
The highest-impact and most commonly-missed Tier 0 gap. Severity: critical (full domain compromise with no Domain Admins (DA) logon). Retest: Verify: every system that can read or restore DC data is inventoried and protected as Tier 0, sync-account rights scoped and monitored.
Shared local admin and lateral movement (no Local Administrator Password Solution (LAPS))ATT&CKT1550.002 Pass the Hash · T1021.002 SMB/Admin Shares · T1078.003 Local Accounts
A single local Administrator password is reused across many machines, so one stolen local-admin hash passes to the entire fleet, letting the attacker hop host to host harvesting credentials until a privileged one appears.
Risk: A common local-admin secret across hosts and no host-to-host Server Message Block (SMB) restriction.
Gold-image deployments that bake in one local-admin password, environments without Windows LAPS, and flat networks where any workstation can reach any other over SMB.
NetExec/CrackMapExec (spray a hash across a subnet), Impacket, Mimikatz. Detectable with BloodHound local-admin collection.
# Recognition: does one local hash authenticate widely?
netexec smb <subnet> -u Administrator -H <hash> # scope only
Verify: The same local-admin logon (4624 type 3) succeeding across many hosts in a short window, and SMB admin-share access patterns.
A force-multiplier that turns a single endpoint into fleet-wide movement. Severity: high. Retest: Verify: Windows LAPS enforced with unique, rotated local passwords and host isolation; confirm the hash no longer authenticates on a second machine.
Tier 0 service-account exposure (Kerberoasting / Service Principal Name (SPN) abuse)ATT&CKT1558.003 Kerberoasting · T1078.002 Valid Accounts
A Tier 0 service runs under a user account with an SPN; any domain user can request its service ticket and crack the account's password offline, or the account's credential is simply harvested from the Tier 1 host it runs on.
Risk: A privileged account with an SPN and a crackable password, or a Tier 0 service account resident on a lower-tier host.
Legacy service accounts in Domain Admins with weak, non-rotated passwords, and Tier 0 services deployed onto Tier 1 servers instead of being isolated.
Rubeus and Impacket (GetUserSPNs) to request tickets, Hashcat to crack offline, BloodHound to flag privileged SPN accounts.
# Recognition: which privileged accounts expose an SPN?
GetUserSPNs.py <domain>/<user> # enumerate; cracking is offline
Verify: A burst of service-ticket requests (4769) with Rivest Cipher 4 (RC4) encryption for a privileged SPN account, and privileged services running on non-Tier-0 hosts.
Ties credential hygiene to tiering: a Tier 0 service account is only as safe as its password and its host. Severity scales with the account's rights. Retest: Verify: privileged service accounts moved to group Managed Service Accounts (gMSAs) or strong rotated secrets, isolated to Tier 0 hosts, AES-only.
Defender's playbook
DefenderThe strategy for Part 1 is design-level: find your real Tier 0, stop high-value credentials appearing on low-value hosts, and kill the two force-multipliers (shared local admin, unprotected Tier 0 dependencies). The hands-on enforcement controls — Privileged Access Workstations (PAWs), silos, Protected Users, Local Administrator Password Solution (LAPS), Privileged Identity Management (PIM) — are Part 2; here we set the targets they'll implement.
Quick wins (days)
- Map your control paths. Run SharpHound and review the shortest paths to Domain Admins. Verify: The path length from a user workstation to Tier 0 is your headline metric; drive it toward "no path."
SharpHound.exe -c All # collect; analyze in BloodHound - Stop Tier 0 logons on lower tiers. Add Domain/Enterprise Admins (and equivalents) to Protected Users, and plan
Deny log onGroup Policy Objects (GPOs) so Fix: Tier 0 accounts can't log on to Tier 1/2 hosts.# Protected Users blocks NTLM and caps TGT lifetime for members (test first) Add-ADGroupMember "Protected Users" -Members adm0-jordan - Turn on Windows LAPS. It's built into Windows since the April 2023 update — no agent — and Fix: gives every machine a unique, rotated local admin password, killing fleet-wide pass-the-hash.
- Separate admin accounts from daily-driver accounts. No account used for email/web should hold admin rights anywhere; Fix: no domain admin should ever read email.
- Inventory hidden Tier 0. Identify who can restore/read Domain Controller (DC) backups, who administers the DC hypervisor/storage, and which accounts hold
Replicating Directory Changes All. Risk: Protect each as Tier 0 or remove its control over Tier 0.
Longer-term fixes (weeks to months)
- Stand up the tier structure. Tier 0/1/2 Organizational Units (OUs), scoped delegation, and per-tier admin accounts; subdivide Tier 1 into silos as you mature.
- Deploy PAWs and enforce clean source. Admin work for a tier happens only from that tier's hardened workstation, over a clean path (Part 2).
- Enforce boundaries technically. Authentication Policies and Silos plus
Deny log onGPOs make the cardinal rule self-enforcing, not just documented (Part 2). - Cut standing privilege with Just-In-Time (JIT). Entra PIM / a Privileged Access Management (PAM) tool so accounts aren't privileged until activated with approval and a time limit — most of the time there's nothing to steal (Part 2).
- Bring hidden Tier 0 into the fold. Isolate DCs onto dedicated virtualization/backup pipelines that only Tier 0 admins can touch; move Tier 0 service accounts to group Managed Service Accounts (gMSAs).
- Monitor for drift. Alert on new Tier 0 group members, new control edges, and any Tier 0 logon on a lower-tier host.
Detection signals
| Event or signal | Source | Alert on |
|---|---|---|
| Local Security Authority Subsystem Service (LSASS) handle access | Sysmon event 10 / Endpoint Detection and Response (EDR) | Verify: A non-system process opening LSASS — credential dumping |
| 4624 logon type 2/10 by a Tier 0 account on a non-Tier-0 host | DC / host Security log | Verify: Any Tier 0 credential appearing off a Tier 0 host — a cardinal-rule break |
| 4728 / 4732 / 4756 | DC Security log | A member added to a Tier 0 group (Domain/Enterprise Admins, Administrators) |
| 5136 on the domain object / AdminSDHolder | DC Security log | A new Access Control Entry (ACE) granting control of Tier 0 (Discretionary Access Control List (DACL) change) |
| 4662 with the DS-Replication-Get-Changes Globally Unique Identifier (GUID) | DC Security log | Replication requested by a principal that isn't a DC — Directory replication abuse (DCSync) |
| 4769 Rivest Cipher 4 (RC4) bursts for a privileged Service Principal Name (SPN) | DC Security log | Possible Kerberoasting of a Tier 0 service account |
| Same local-admin logon (4624 type 3) across many hosts | Security Information and Event Management (SIEM) | Shared-local-admin lateral movement (missing LAPS) |
Verify the fix worked
- Verify: Re-run SharpHound and confirm no control path from Tier 2 (or Tier 1) into Tier 0.
- Attempt a Tier 0 logon on a Tier 1/2 host and confirm it's denied by GPO/silo.
- Confirm Windows LAPS is enforced: the same local-admin hash Verify: no longer authenticates on a second machine.
- List everything that can read or restore DC data and confirm each is protected as Tier 0.
- Confirm no privileged account is used for daily email/web, and no Tier 0 service runs on a lower-tier host.
Why remediation stalls, and workable compromises
| Objection | Workable compromise |
|---|---|
| "Admins need to Remote Desktop Protocol (RDP) everywhere to do their jobs." | Give per-tier admin accounts and a PAW/jump path; Fix: same power, scoped to the tier, workflow pre-built so it's painless. |
| "We can't isolate the DCs' virtualization right now." | At minimum restrict who can snapshot/mount DC disks and who can restore DC backups to Tier 0 admins; isolate hosts next. |
| "A full tier model is a multi-year program." | Sequence by leverage: account separation, stop-DA-on-workstations, LAPS, and hidden-Tier-0 protection first; PAWs/PIM next. |
| "The helpdesk needs admin to support users." | Delegate precise Tier 2 rights (password reset on an OU) instead of domain admin; Fix: a phished helpdesk account then stays Tier 2. |
| "We already did Enhanced Security Administrative Environment (ESAE) years ago." | Verify it's complete; map it to the modern model and adopt PAWs/PIM where lighter and sufficient. |
| "Separate accounts double our account count." | That's expected and fine; enforce with naming + silos, and use PIM so the privileged ones are dormant until activated. |
Executive brief
ExecutiveThe risk in plain language
Our network has a set of all-powerful administrative credentials — the digital equivalent of a master key to every room. The danger isn't mainly that someone guesses the password; it's that Risk: every time one of those credentials is used on an ordinary computer, a reusable copy is left behind in that computer's memory. An attacker who compromises that computer can copy the credential and reuse it, with no password and no second-factor prompt, until they reach the systems that run everything. Tiering is the design rule that keeps those master-key credentials off ordinary computers, so that one hacked laptop stays one hacked laptop.
Business impact
- In a network without tiering, Risk: a single phished laptop can escalate to full control of the company within hours — all data, all systems, all accounts.
- That "full control" is what ransomware crews buy and sell; it's the difference between an isolated incident and an enterprise-wide outage.
- The weak point is often not a server we guard, but Risk: a backup system or virtualization platform nobody classified as critical — yet either can impersonate the systems that run our identity.
What drives likelihood
- Admins who log on everywhere with powerful accounts, scattering reusable credentials across the estate.
- A "flat" network where any workstation can reach any other and shared local passwords let one break-in spread.
- Unprotected hidden dependencies — backups, the virtualization platform, identity-sync and the certificate system.
- Half-finished past projects that were assumed to have solved this but never completed.
Cost of inaction
The highest-value fixes are mostly policy and built-in features, not new spend: separate admin accounts from everyday ones, stop using master-key credentials on ordinary machines, switch on a free built-in password feature, and protect the few systems that can impersonate our identity servers. Leaving these means we are Risk: one unlucky click away from a company-wide event, and our existing investments in antivirus and multi-factor don't cover this gap — they stop the break-in, not the spread.
What good looks like
- There is Fix: no technical path from an ordinary device to full domain control — and we can prove it with the same tools attackers use.
- Administrators use Fix: separate accounts on dedicated, hardened machines; no one reads email with a master-key account.
- The systems that can impersonate our identity servers (backups, virtualization, sync, certificates) are Fix: protected to the same standard as those servers.
- Powerful access is Fix: granted only when needed, not left standing idle, and we're alerted when any of this drifts.
Questions executives ask
In one sentence, what is tiering and why do we need it?
"Tiering is a design rule that keeps our most powerful admin credentials off ordinary computers, so that one hacked laptop can't snowball into control of the entire company. Without it, our network is effectively flat: a single phishing victim can often reach total control within a day."
Are we exposed right now?
"The honest test is a control-path assessment. In most environments we've seen, there is a short, unintended path from an everyday workstation to full domain control, usually through an admin who logs on everywhere or a backup/virtualization system nobody treated as critical. Fix: We can measure our specific path length and close it; that number is the headline metric."
How is this different from having strong passwords and Multi-Factor Authentication (MFA)?
"Strong passwords and MFA stop someone guessing their way in. Tiering addresses a different attack: once a credential is used on a machine, it can be stolen from that machine's memory and reused, no password or MFA prompt required. So the two are complementary; tiering controls where our powerful credentials are allowed to appear."
This sounds expensive and disruptive. What's the minimum that moves the needle?
"The highest-value steps are mostly policy, not purchase: separate admin accounts from everyday accounts, Fix: stop logging domain-admin credentials onto workstations, turn on the free built-in Local Administrator Password Solution (LAPS), and protect the backup and virtualization systems like the domain controllers they can impersonate. A couple of hardened admin workstations come next. The heavy tooling is optional and phased."
Didn't we already do this with the 'Red Forest' project years ago?
"Possibly in part. Microsoft actually retired that specific heavyweight design in 2021 because so many of them were never finished. Fix: The modern approach is lighter and cloud-aware, hardened admin workstations and just-in-time access, and we'd verify whether what was built is complete and still the right pattern."
What does 'good' look like, and how will we know we got there?
"Good means there is Verify: no technical path from an ordinary device to domain control, admins use separate accounts on dedicated hardened machines, and the systems that can impersonate our domain controllers are protected to the same standard. We prove it with the same control-path tooling attackers use: the path simply isn't there anymore."
Presenting this finding to leadership
- Headline: "There is a short, unintended path from an ordinary laptop to full control of the company, and Risk: most of the fix is policy, not spend."
- Make it concrete: show the actual control-path graph — "this helpdesk group reaches domain admin in three steps" lands harder than any statistic.
- Frame the metric: path length from a user device to full control; today it's a handful of steps, the goal is "no path."
- The ask: fund account separation and hidden-Tier-0 protection now (low cost), then phase in hardened admin workstations and just-in-time access.
Talk the talk
Jargon decoder
The identity control plane: Domain Controllers (DCs), Active Directory (AD), and anything that can seize equivalent control.
"The Certificate Authority (CA) is Tier 0, so it goes behind the same wall as the domain controllers."
How far a single compromise can spread before something stops it.
"Tiering shrinks the blast radius of a phished laptop from 'everything' to 'that laptop'."
The rule that you administer an asset only from an equally-trusted device, account and path.
"Managing a Domain Controller (DC) from your email laptop breaks clean source."
Anything that can take control of an object; the object is only as secure as its weakest one.
"The backup server is a security dependency of every Domain Controller (DC) it protects."
A chain of rights or sessions that leads from a low-privilege foothold to a high-privilege target.
"BloodHound found a four-hop control path from helpdesk to Domain Admins."
An Active Directory (AD) where credentials and admin rights are reused so widely that tiers don't exist in practice.
"It's a flat domain, one workstation to Domain Admins (DA) in three hops."
A credential being resident in a machine's memory where it could be stolen.
"Every Remote Desktop Protocol (RDP) session is a credential exposure on the destination host."
Admin rights that are permanently assigned rather than activated just-in-time.
"Cut standing privilege with Privileged Identity Management (PIM) so there's nothing to steal most of the time."
The retired hardened administrative-forest design.
"We're not building a Red Forest; Microsoft moved to Privileged Access Workstations (PAWs) and Privileged Identity Management (PIM)."
Microsoft's current control/management/data-plane model that superseded the tier model.
"In Enterprise Access Model (EAM) terms the Domain Controllers (DCs) and Entra Global Admins are both control plane."
A hardened, single-purpose workstation used only for privileged admin.
"Tier 0 tasks happen on the PAW, nowhere else."
Granting a privileged role only for a limited, approved window.
"With JIT she isn't a domain admin until she activates the role for two hours."
The tendency for the Tier 0 boundary to quietly expand through forgotten dependencies.
"That monitoring agent running as SYSTEM on the Domain Controllers (DCs) is Tier 0 creep."
Designing so a compromise stays local instead of propagating.
"We can't prevent every phish, so we design for containment."
Smart questions to ask
Sysadmins
- Do any Tier 0 accounts (Domain/Enterprise Admins) Risk: ever log on to servers or workstations, via Remote Desktop Protocol (RDP), RunAs, services or tasks?
- Who can Risk: restore or read our Domain Controller (DC) backups, and who administers the hypervisor and storage hosting the DCs?
- Which accounts hold
Replicating Directory Changes All, and are any of them service/sync accounts? - Is Windows Local Administrator Password Solution (LAPS) enforced so Fix: every machine has a unique local admin password?
- Do we have a Verify: current BloodHound graph, and what's the shortest path from a workstation to Domain Admins?
Executives
- If one employee laptop were compromised today, Risk: how many steps to full company control?
- Are the systems that can impersonate our identity servers protected as heavily as the servers themselves?
- Did our past "admin security" project actually get finished, and is it still the right approach?
Coworkers
- Is this finding a direct Tier 0 exposure or a multi-hop control path? That drives the severity.
- Did we enumerate the Risk: hidden Tier 0 dependencies, not just the DCs?
- Are we speaking Enterprise Access Model (EAM) "planes" or legacy "tiers" for this client's team?
Say this, not that
"We have domain admins, so access is controlled."
"The question isn't who's a domain admin, it's which machines those credentials have touched, because that's where they can be stolen."
"Tier 0 is the domain controllers."
"Tier 0 is the Domain Controllers (DCs) plus everything that can control them: the Certificate Authority (CA), the sync account, the backups, the hypervisor."
"We'll just put the admins on a jump box."
"A jump box only helps if it's a clean source, Tier 0-grade; a shared jump host that everyone Remote Desktop Protocols (RDPs) through is just a bigger target."
"Strong passwords and Multi-Factor Authentication (MFA) mean we don't need tiering."
"Those stop guessing; tiering stops credential theft and reuse, which needs neither the password nor an MFA prompt."
"We built a Red Forest, so we're done."
"Microsoft retired that as the default in 2021; let's verify it's complete and whether Privileged Access Workstations (PAWs) plus Privileged Identity Management (PIM) are the better fit now."
"The backup server is just infrastructure, it's Tier 1."
"If it can restore a domain controller, it can impersonate one, so it's Tier 0 whether we labeled it that way or not."
"Tiering will stop us getting hacked."
"It won't stop the first foothold; it stops that foothold from becoming a domain-wide disaster, and buys us time to respond."
Same point, two audiences
"Using an all-powerful admin account on an ordinary laptop is like carrying the master key through a crowd: someone can copy it."
"A Domain Admins (DA) logon caches a reusable Ticket-Granting Ticket (TGT)/hash in Local Security Authority Subsystem Service (LSASS) on that host; local admin there means pass-the-ticket to a Domain Controller (DC)."
"Anything that can impersonate our domain controllers is as critical as the controllers themselves."
"Backup, hypervisor, sync accounts with replication rights, and the Certificate Authority (CA) all have transitive control of Active Directory (AD), so they're Tier 0."
"We can't stop every phishing email, so we build so one bad click stays small instead of taking down the company."
"Assume-breach: no Tier 2-to-Tier 0 credential-theft path, so a workstation compromise can't escalate to domain admin."
"We don't need the heavyweight project from years ago; today's approach is a few hardened admin machines plus access that's granted only when needed."
"Skip Enhanced Security Administrative Environment (ESAE); do Rapid Modernization Plan (RaMP): separate tiered accounts, Privileged Access Workstations (PAWs), Protected Users, logon-right Group Policy Objects (GPOs), and Privileged Identity Management (PIM) for Just-In-Time (JIT) activation."
Keep going
What to learn next, in order
- Part 2 of this series — the implementation. Privileged Access Workstations (PAWs), Authentication Policies and Silos, Protected Users, Windows Local Administrator Password Solution (LAPS), Entra Privileged Identity Management (PIM) for just-in-time access, and the Rapid Modernization Plan (RaMP) rollout. This is where the model becomes enforced configuration.
- Attack-path analysis with BloodHound. Learn to read and cut control paths; it's how you both find Tier 0 and prove tiering holds.
- The Active Directory (AD) CS abuse series. The concrete case of a non-obvious Tier 0 asset (the enterprise Certificate Authority (CA)) and how its misconfigurations hand over the domain.
- Credential theft internals. Kerberos and NT LAN Manager (NTLM), Local Security Authority Subsystem Service (LSASS), Credential Guard, and Protected Users — the mechanics of what tiering contains.
- Microsoft's Enterprise Access Model and RaMP docs. The authoritative, cloud-aware framing for hybrid estates.
Resources worth seeking out
- Microsoft Learn: "Enterprise access model," "Securing privileged access" and the Enhanced Security Administrative Environment (ESAE) retirement page — the primary sources for the modern model.
- The BloodHound / SpecterOps material on control paths and security boundaries in AD and Entra.
- An authorized lab (a disposable test forest) to practice building the Organizational Unit (OU)/tier structure and silos safely before touching production.
AD tiering & privileged access design
Acronyms
Every acronym used on this page. Four test modes are below the table.
| Acronym | Expansion | Plain English | Why it matters |
|---|---|---|---|
| ACE | Access Control Entry | A single permission in an Access Control List (ACL): a principal, a right, and allow or deny. | A new Access Control Entry (ACE) granting control of a Tier 0 object is a control edge an attacker can plant or abuse. |
| ACL | Access Control List | The list of permissions on an Active Directory (AD) object or resource. | A write Access Control List (ACL) on a Tier 0 object is itself a Tier 0 control relationship, even without group membership. |
| AD | Active Directory | Microsoft's on-prem directory and identity system for Windows domains. | Tiering is a design discipline layered on top of Active Directory (AD) to contain compromise of it. |
| ADFS | Active Directory Federation Services | A Microsoft service that federates authentication to apps and cloud. | Active Directory Federation Services (ADFS) signing keys can mint tokens for any user, so ADFS is Tier 0. |
| CA | Certificate Authority | The server that issues digital certificates. | An enterprise Certificate Authority (CA) is a Tier 0 asset, the throughline from the Active Directory (AD) CS series. |
| CFO | Chief Financial Officer | The executive responsible for an organization's finances. | The Chief Financial Officer (CFO) is a typical audience for the plain-language 'why one laptop matters' conversation. |
| CISO | Chief Information Security Officer | The executive accountable for an organization's security. | The Chief Information Security Officer (CISO) sponsors the tiering program and absorbs the operational-friction pushback. |
| DA | Domain Admins | The Active Directory (AD) group with full control of a domain. | Domain Admins (DA) is the classic Tier 0 credential whose misuse on low-tier hosts causes most domain takeovers. |
| DACL | Discretionary Access Control List | The part of an object's security descriptor that lists who has which rights. | A WriteDACL right on the domain or AdminSDHolder lets an attacker rewrite who controls Tier 0. |
| DC | Domain Controller | A server that hosts the Active Directory (AD) database and authenticates the domain. | Domain Controllers (DCs) are the heart of Tier 0: control a DC and you control the domain. |
| DCSync | Directory replication abuse | Impersonating a Domain Controller (DC) to pull password hashes via the replication protocol. | An identity-sync or delegated account with replication rights is a hidden Tier 0 asset. |
| EA | Enterprise Admins | The Active Directory (AD) group with full control across every domain in a forest. | Enterprise Admins (EA) is Tier 0 at forest scope; its exposure compromises the whole forest. |
| EAM | Enterprise Access Model | Microsoft's current access model of control, management and data/workload planes. | Enterprise Access Model (EAM) superseded the legacy Tier 0/1/2 model and extends it to cloud and hybrid. |
| EDR | Endpoint Detection and Response | Software that detects and investigates endpoint threats. | Endpoint Detection and Response (EDR) on Tier 0 and admin hosts catches Local Security Authority Subsystem Service (LSASS) access and lateral movement. |
| ESAE | Enhanced Security Administrative Environment | Microsoft's retired hardened administrative-forest design, nicknamed the Red Forest. | Microsoft retired Enhanced Security Administrative Environment (ESAE) as a default in 2021; it is now an exception-only pattern. |
| FIDO2 | Fast Identity Online 2 | A phishing-resistant, public-key authentication standard. | Fast Identity Online 2 (FIDO2) keys are the recommended phishing-resistant Multi-Factor Authentication (MFA) for privileged accounts. |
| gMSA | group Managed Service Account | An AD-managed service account with an automatically rotated password. | group Managed Service Accounts (gMSAs) reduce service-account credential theft; still Tier 0 if the service is Tier 0. |
| GPO | Group Policy Object | A set of Windows and Active Directory (AD) settings applied to Organizational Units (OUs). | Logon restrictions that keep tiers apart are deployed as Group Policy Objects (GPOs). |
| GUID | Globally Unique Identifier | A 128-bit identifier Windows uses to name objects and rights. | Directory replication (DCSync) is detected by the control-access Globally Unique Identifier (GUID) requested in event 4662. |
| Intune | Microsoft Intune | Microsoft's cloud device-management service. | Microsoft Intune (Intune) enrolls and hardens Privileged Access Workstations (PAWs) in the modern privileged access strategy (Part 2). |
| IR | Incident Response | The process of investigating and containing a security incident. | Assume-breach Incident Response (IR) for Active Directory (AD) starts by scoping which tier the compromise reached. |
| JEA | Just Enough Administration | A PowerShell feature that constrains what an admin session can do. | Just Enough Administration (JEA) narrows Tier 1/2 admin tasks so operators don't need full local admin. |
| JIT | Just-In-Time | Granting privilege only for a limited time when needed. | Just-In-Time (JIT) (with Entra Privileged Identity Management (PIM) or a Privileged Access Management (PAM) tool) removes standing admin rights so there is nothing to steal most of the time. |
| KDC | Key Distribution Center | The Kerberos service on a Domain Controller (DC) that issues tickets. | The Key Distribution Center (KDC) runs on Domain Controllers (DCs), so it lives in Tier 0. |
| LAPS | Local Administrator Password Solution | A tool that sets a unique, rotated local admin password per machine. | Local Administrator Password Solution (LAPS) kills the shared local-admin password that lets one pass-the-hash own the whole fleet; built into Windows since April 2023. |
| LSASS | Local Security Authority Subsystem Service | The Windows process that stores credentials and secrets in memory. | Credential theft means reading secrets from Local Security Authority Subsystem Service (LSASS) on whatever host the admin used. |
| MDE | Microsoft Defender for Endpoint | Microsoft's endpoint detection and response platform. | Microsoft Defender for Endpoint (MDE) on Privileged Access Workstations (PAWs) and Tier 0 hosts provides the monitoring that privileged access relies on. |
| MFA | Multi-Factor Authentication | Requiring more than a password to authenticate. | Phishing-resistant Multi-Factor Authentication (MFA) for admin roles is a pillar of the modern privileged access strategy. |
| MITRE | MITRE Corporation | The non-profit that maintains the ATT&CK knowledge base. | ATT&CK technique IDs give a shared vocabulary for the credential-theft steps tiering blocks. |
| NTDS | NT Directory Services database | The file (ntds.dit) that stores all Active Directory (AD) accounts and password hashes. | Anything that can read NT Directory Services database (NTDS).dit (a Domain Controller (DC), its backup, or its virtual disk) is Tier 0. |
| NTLM | NT LAN Manager | A legacy Windows challenge-response authentication protocol. | NT LAN Manager (NTLM) hashes are the currency of pass-the-hash; Protected Users blocks NTLM for members. |
| OU | Organizational Unit | A container in Active Directory (AD) used to group objects and apply policy. | Tiering is often expressed as a Tier 0/1/2 Organizational Unit (OU) structure with scoped delegation and Group Policy Objects (GPOs). |
| PAM | Privileged Access Management | A category of tools that broker, vault and record privileged sessions. | A Privileged Access Management (PAM) or jump host that administers Tier 0 is itself Tier 0 by the clean source principle. |
| PAW | Privileged Access Workstation | A hardened, single-purpose device used only for privileged administration. | The Privileged Access Workstation (PAW) is where Tier 0 credentials are allowed to appear; it is the clean source for admin work (Part 2). |
| PIM | Privileged Identity Management | Microsoft Entra's just-in-time role activation service. | Privileged Identity Management (PIM) delivers Just-In-Time (JIT) activation, approval and time limits for cloud and hybrid roles (covered in Part 2). |
| PKI | Public Key Infrastructure | The system of certificate authorities and certificates that issues trust. | Active Directory (AD) CS (the enterprise Certificate Authority (CA)) is Tier 0: a CA can forge logon certificates for anyone. |
| PtH | Pass-the-Hash | Reusing a stolen NT LAN Manager (NTLM) password hash to authenticate without the plaintext. | Pass-the-Hash (PtH) is the core credential-theft technique tiering is designed to contain. |
| PtT | Pass-the-Ticket | Reusing a stolen Kerberos ticket to authenticate as its owner. | Pass-the-Ticket (PtT) reuses a Tier 0 Ticket-Granting Ticket (TGT) lifted from a lower-tier host the admin logged on to. |
| RaMP | Rapid Modernization Plan | Microsoft's prioritized checklist for securing privileged access quickly. | Rapid Modernization Plan (RaMP) is the modern rollout guidance that replaced Enhanced Security Administrative Environment (ESAE) as the default recommendation. |
| RBAC | Role-Based Access Control | Granting access by role rather than to individuals. | Tiering plus Role-Based Access Control (RBAC) and least privilege is how you avoid standing Tier 0 rights. |
| RC4 | Rivest Cipher 4 | A legacy stream cipher, here the weak Kerberos encryption type. | A burst of RC4-encrypted service tickets for a privileged Service Principal Name (SPN) is the classic Kerberoasting signal. |
| RDP | Remote Desktop Protocol | Windows interactive remote-session protocol. | Remote Desktop Protocol (RDP) from an admin to a lower-tier host can expose the admin credential on that host. |
| RODC | Read-Only Domain Controller | A Domain Controller (DC) that holds a filtered, read-only copy of Active Directory (AD). | An Read-Only Domain Controller (RODC) narrows but does not remove Tier 0 exposure at a branch. |
| SaaS | Software as a Service | Cloud-hosted applications consumed over the internet. | Enterprise Access Model (EAM) extends tiering to Software as a Service (SaaS) and cloud control planes, not just on-prem Active Directory (AD). |
| SID | Security Identifier | The unique value that identifies a security principal in Windows. | Group membership and access checks resolve to Security Identifiers (SIDs), including the Tier 0 groups. |
| SIEM | Security Information and Event Management | A platform that centralizes and correlates security logs. | Tier-crossing logons and Tier 0 group changes are prime Security Information and Event Management (SIEM) alert sources. |
| SMB | Server Message Block | The Windows file-and-service sharing protocol. | Pass-the-hash most often rides Server Message Block (SMB) to move laterally between hosts. |
| SOC | Security Operations Center | The team that monitors and responds to security alerts. | The Security Operations Center (SOC) must treat any Tier 0 alert as a potential domain-takeover in progress. |
| SPN | Service Principal Name | The identifier that ties a service to an account for Kerberos. | A Tier 0 service account with an Service Principal Name (SPN) can be Kerberoasted if its password is weak. |
| TGT | Ticket-Granting Ticket | The Kerberos ticket that proves identity and is used to request service tickets. | A Tier 0 admin's Ticket-Granting Ticket (TGT) cached on a workstation is a domain-takeover primitive if stolen. |
| UPN | User Principal Name | A logon name in email form, like admin@corp.local. | Separate per-tier admin accounts are usually distinguished by User Principal Name (UPN) and naming convention. |
| VLAN | Virtual Local Area Network | A logically segmented network. | Network segmentation complements tiering by restricting which hosts can even reach Tier 0. |
| VM | Virtual Machine | A software-emulated computer running on a hypervisor. | A Domain Controller (DC) running as a Virtual Machine (VM) makes the hypervisor a Tier 0 asset, because it can read the DC's disk. |
| WMI | Windows Management Instrumentation | A Windows remote management and query interface. | Windows Management Instrumentation (WMI) and PsExec-style lateral movement reuse credentials across hosts in a flat domain. |
Test yourself
Flashcards
Quiz
Fifteen questions, weighted toward judgment calls you'd actually make on an engagement — severity ratings, Tier 0 classification, and advising a client — rather than trivia.
Conversation drills
Say or type your answer first, then compare with the sample.
Export cards
Basic cards (Quizlet and Anki Basic)
Anki cloze cards
My private notebook
Personal notes and bookmarks are private. Unsaved text is temporarily kept in this tab’s browser storage to recover supported sign-in redirects and reloads. Closing the tab may lose unsaved text.
Checking sign-in…