Nyx Learning AD Tiering & Privileged Access · Part 1 of 2
AD Tiering & Privileged Access · Part 1 of 2

AD tiering & privileged access design

Part 1 — The model: containing credential theft with Tier 0 and the Enterprise Access Model

Generated Thursday, October 8, 2026 · Depth: deep · Oct 2026, against Microsoft Learn: Enterprise access model (supersedes the legacy tier model), ESAE retirement page (ESAE retired as default 2021; RaMP is the modern default), Authentication policies & silos / Protected Users requirements, Windows LAPS built in since the April 11 2023 update, and Entra PIM. Tooling (BloodHound, SharpHound, Mimikatz, Impacket, NetExec, Rubeus, PingCastle) named by current practitioner usage.

01

Start here

Roadmap for this series

This series is about privileged access design: how to arrange Active Directory (AD) so that compromising one machine doesn't compromise everything.

  1. Part 1 (this page): the model. Why tiering exists, the Tier 0 / 1 / 2 model, what really counts as Tier 0, Microsoft's Enterprise Access Model (EAM) that superseded it, the clean source principle, and why the Enhanced Security Administrative Environment (ESAE) "Red Forest" was retired.
  2. Part 2: the implementation. Privileged Access Workstations (PAWs), Authentication Policies and Silos, Protected Users, Windows Local Administrator Password Solution (LAPS), just-in-time access with Entra Privileged Identity Management (PIM), enforcing cross-tier logon boundaries, monitoring for drift, and the Rapid Modernization Plan (RaMP) rollout.

It pairs directly with the AD CS abuse series: there, the recurring line was "the Certificate Authority is Tier 0." This series explains what that sentence means and how to act on it.

Highlight key
the term being defined
Key term: bold with a highlighter swash. A concept's defining phrase.
how something works
Mechanism: wavy underline. How a piece works or relates to another.
Risk: what makes an attack possible
Risk: warm highlight with a dashed edge. Attack prerequisites and dangerous conditions.
Fix: the mitigation to apply
Fix: solid green underline. A mitigation or configuration change.
Verify: how to confirm it worked
Verify: green underline with a check. How to prove a fix works.
only if, by default
Qualifier: bold italic. A word that changes the claim.
4769
Technical literal: monospace chip. Commands, settings, event IDs, exactly as typed.

Plain English first

Active Directory decides who you are and what you can touch across a Windows network. If an attacker gains control of it, they control the whole organization: every server, every mailbox, every file.

Here's the uncomfortable part. When an administrator signs in to any computer, a reusable copy of their credential sits in that computer's memory for the session. Whoever controls that computer can copy the credential and become that administrator — no password-guessing, no cracking. So the real question for any powerful account isn't "is the password strong?" It's Risk: "which machines has it touched?"

Tiering is the design discipline that answers that question. It sorts everything into levels by how much damage its compromise causes, and enforces one rule: powerful credentials may only ever appear on equally-protected machines. Get it right and one phished laptop stays one phished laptop. Get it wrong and your network is flat — one laptop, a few hops, game over.

The analogy: the master key and where you carry it

A domain admin credential is a master key to the building. The lock it opens is strong — that's your password policy and Multi-Factor Authentication (MFA). But a master key can be copied by anyone who gets their hands on it, even for a moment.

Tiering is the rule that the master key Fix: never leaves the secure key room (a hardened admin workstation), and is never carried out onto the shop floor (an ordinary laptop) where a pickpocket might copy it. The lock being strong doesn't help if you hand the key around. Risk: Where you carry the key matters more than how good the lock is.

Why it matters now

Attacker

For an attacker, a flat domain is a gift. Phish one user, gain local admin on their laptop, and there's a good chance a privileged credential has been left in memory somewhere nearby. Tools like BloodHound turn "somewhere nearby" into a precise, shortest-path map from the foothold to Domain Admins. In most un-tiered environments that path is Risk: only a few hops long, and credential theft (pass-the-hash, pass-the-ticket) needs no exploit and trips few alarms.

Defender

For a defender, tiering is the highest-leverage architectural control you can apply to AD — and most of the first wins are policy, not spend. You can't stop every phish, so you design so the first foothold is Fix: low-value and far from the crown jewels. Done well, it converts "instant domain takeover" into "a contained endpoint incident you have time to catch." The hard part isn't the concept; it's finding the Risk: hidden Tier 0 dependencies and holding the line on where admins log on.

If you remember only 5 things

  1. A credential can be stolen by whoever controls the machine it's used on. Where an account logs on decides where it can be stolen — that single fact is the reason tiering exists.
  2. Control flows down, exposure never up. A higher-tier credential must Fix: never appear on a lower-tier machine; break this one rule and the tiers collapse into a flat domain.
  3. Tier 0 is defined by control, not by label. It's the Domain Controllers (DCs) plus anything that can impersonate them — the Certificate Authority (CA), backups, the hypervisor, the sync account. Risk: The ones you miss are the ones that get used.
  4. The payoff is containment, not prevention. Tiering doesn't stop the first compromise; it stops that compromise from becoming domain-wide and buys you time to respond.
  5. The old Red Forest (ESAE) is retired. Microsoft's modern default is lighter and cloud-aware: separate tiered accounts, PAWs, and just-in-time access via RaMP — Fix: not a whole separate forest.
02

Core concepts

Thirteen ideas, built in order. The first three establish why a flat domain is dangerous; the middle set defines the tiers and what really belongs in Tier 0; the last set covers the modern model, the clean source principle, and how tiering relates to the hands-on controls in Part 2.

01Where you log on is where you can be robbedTiering exists because a credential can be stolen by whoever controls the machine it's used on.
In plain terms

When you sign in to a Windows computer, your credential (a hash or a Kerberos ticket) lives in that machine's memory for the session. If an attacker already controls that machine, they can lift your credential and become you. So the single most important question for any admin account is not how strong its password is, but Risk: which machines it has touched.

Example

A domain admin who remotes into a helpdesk laptop to fix a problem leaves a usable domain-admin ticket on that laptop. Whoever owns the laptop now effectively owns the domain.

TechnicalGo deeper

This is the mechanism behind pass-the-hash and pass-the-ticket. NT LAN Manager (NTLM) hashes and Kerberos Ticket-Granting Tickets (TGTs) are cached in Local Security Authority Subsystem Service (LSASS); with local admin (or kernel access) on the host an attacker reads them and replays them. Crucially, this does not require cracking the password and is not stopped by a long password or by Multi-Factor Authentication (MFA) at first logon once the secret is resident. Tiering's entire job is to make sure high-value credentials are only ever resident on equally-protected machines.

02Security dependency: you are only as safe as what controls youA security dependency is anything that can take control of an object; the object is only as secure as its least-secure dependency.
In plain terms

Think of everything that can affect an account or a server: the machine it runs on, the admins who manage it, the software that updates it, the backup that can restore it. Each of those is a path to the object. An attacker doesn't need to attack the Domain Controller (DC) directly if they can attack Risk: something that controls the DC.

Example

A DC is patched and hardened, but its backups are written to a file server any helpdesk tech can access. The file server is now a path to the DC's secrets, so it inherits the DC's sensitivity.

TechnicalGo deeper

Microsoft frames this as 'control relationships' and tools like BloodHound make them explicit as attack-path graphs (edges such as GenericAll, WriteDACL, AddMember, session and admin-to relationships). The design consequence is the clean source principle: any subject in control of an object is a security dependency of that object, and must be held to at least the object's security level. Ignoring an indirect dependency is how 'hardened' DCs still fall.

03The three-tier modelThe classic model sorts assets into Tier 0 (identity), Tier 1 (servers/data) and Tier 2 (workstations/users) by blast radius.
In plain terms

Group everything by how much damage its compromise causes. Tier 0 is anything that can control the identity system itself. Tier 1 is the servers and applications that run the business. Tier 2 is the end-user devices and the accounts people use day to day. The point of the labels is to decide which credentials may appear on which machines.

Example

A payroll app server is Tier 1. The laptop of the HR clerk who uses it is Tier 2. The Domain Controller (DC) that authenticates both, and the admin who runs it, are Tier 0.

TechnicalGo deeper

Microsoft's original 'Active Directory administrative tier model' defined exactly these three tiers and one hard rule between them (next card). The tiers are about administrative control, not data classification: a Tier 1 server may hold the most sensitive business data in the company, but it is still Tier 1 because compromising it does not by itself hand over the identity fabric. Tier numbering goes the opposite way to trust: Tier 0 is the most privileged, Tier 2 the least.

04The cardinal rule: control flows down, exposure never upA credential from a higher tier must never be exposed on a lower-tier asset; lower tiers never control higher ones.
In plain terms

Higher tiers are allowed to manage lower tiers (Tier 0 can administer everything). What is forbidden is the reverse exposure: a Tier 0 credential appearing in the memory of a Tier 1 or Tier 2 machine, where a lower-tier compromise could steal it. Break this one rule and the tiers collapse into a flat domain.

Example

A domain admin may build a new server, but must do it from a Tier 0 admin host, never by typing Domain Admins (DA) credentials into an Remote Desktop Protocol (RDP) session on the Tier 1 server itself.

TechnicalGo deeper

Concretely this means: no logging a Tier 0 account onto a Tier 1/2 host (interactive, RDP, RunAs, or service); no Tier 0 service accounts running on lower-tier machines; and no lower-tier account holding admin rights over a Tier 0 asset. Enforcement uses logon-right Group Policy Objects (GPOs) (Deny log on locally/through Remote Desktop), the Protected Users group, and authentication policy silos (Part 2). Verify: A clean BloodHound graph with no path from Tier 2 to Tier 0 is the proof.

05What counts as Tier 0Tier 0 is anything that can take control of the identity system, not just the domain controllers.
In plain terms

People assume Tier 0 means 'the Domain Controllers (DCs)'. It means the DCs plus every account, group, server and system that can seize equivalent control. If a thing can read the Active Directory (AD) password database, mint credentials, or change who is a domain admin, it is Tier 0 no matter what it's called.

Example

The enterprise Certificate Authority can forge a logon certificate for any user, so the Certificate Authority (CA) is Tier 0 even though it isn't a DC. (That was the whole point of the AD CS series.)

TechnicalGo deeper

A working Tier 0 inventory typically includes: DCs and the AD database; Domain/Enterprise Admins and equivalent groups; the enterprise Public Key Infrastructure (PKI)/CA; Active Directory Federation Services (ADFS) and its token-signing keys; directory-sync accounts (Entra Connect) with replication rights; the backup system that protects DCs; the hypervisor and storage hosting DC virtual disks; and any account with DCSync/Replicating Directory Changes, WriteDACL on the domain, or membership-write over a Tier 0 group. Risk: Miss one and it becomes the attacker's quiet path in.

06Tier 0 is bigger than you think (hidden dependencies)The hard part of tiering is finding the non-obvious Tier 0 assets that control Domain Controllers (DCs) indirectly.
In plain terms

Every organization's DCs are guarded. Few guard the backup server, the virtualization admin, or the sync account to the same standard, yet each one can reach the DC's secrets by a side door. These hidden dependencies are where tiering programs quietly fail.

Example

DCs are virtual machines on the general VMware cluster. A Tier 1 virtualization admin can snapshot a DC's disk, mount it offline, and extract NT Directory Services database (NTDS).dit, no domain-admin logon required.

TechnicalGo deeper

The usual suspects: backup/restore systems, hypervisor and storage admins, image/deployment systems, Endpoint Detection and Response (EDR) and management agents that run as SYSTEM on DCs, monitoring tools with write access, and software-distribution servers that can push code to DCs. Each is a transitive control path into Tier 0. The remedy is the clean source principle applied honestly: either bring the dependency into Tier 0 and protect it accordingly, or remove its control over Tier 0 assets.

07Tier 1 and Tier 2Tier 1 is servers, applications and their data; Tier 2 is user workstations and the accounts people use daily.
In plain terms

Tier 1 is where the business runs: file, database, application and member servers, plus the server-operations admins who manage them. Tier 2 is the end-user estate: laptops, desktops, and ordinary user and helpdesk accounts. Each tier gets its own admin accounts and its own management hosts, and the same no-upward-exposure rule applies between Tier 1 and Tier 2.

Example

A server admin uses a Tier 1 admin account from a Tier 1 jump host to patch application servers, and a completely separate ordinary account on their Tier 2 laptop for email.

TechnicalGo deeper

Tiers can be subdivided (Tier 1 'silos' per application or business unit) to contain blast radius further, which is exactly where the Enterprise Access Model's management and data/workload planes come from. The discipline is the same at every boundary: Fix: separate identities, separate admin hosts, no credential reuse across the line. Most organizations get Tier 0 right first and mature Tier 1 segmentation over time.

08Blast radius and containmentTiering converts a flat domain where one laptop equals the whole company into contained zones where a compromise stays local.
In plain terms

Without tiering, Active Directory (AD) is effectively flat: because admins log on everywhere, a single compromised workstation usually has a credential-theft path all the way to domain admin. Tiering's payoff is that a Tier 2 compromise stays in Tier 2, buying defenders detection and response time instead of instant game-over.

Example

Attacker phishes a user laptop. In a flat domain they find a cached Domain Admins (DA) token within hours. In a tiered domain they find only Tier 2 credentials, and the path to Tier 0 is missing.

TechnicalGo deeper

This is the assume-breach mindset: you will not stop every phish, so you design so the first foothold is low-value and far from the crown jewels. It is the same logic as watertight compartments in a ship's hull. Tiering doesn't prevent compromise; it caps the damage and slows propagation, which is what turns a breach into an incident instead of a catastrophe.

09The Enterprise Access Model (planes)Microsoft's current model reshapes the tiers into a control plane, a management plane and a data/workload plane, extended to cloud.
In plain terms

The three-tier model was built for on-prem Active Directory (AD). As identity moved to the cloud, Microsoft generalized it: the control plane is everything that governs access (the old Tier 0, now including cloud identity and networking), the management plane is the infrastructure that operates workloads, and the data/workload plane is the applications and data themselves. The principle is unchanged; the scope is wider.

Example

In Enterprise Access Model (EAM), Entra ID and Conditional Access join on-prem Tier 0 in the control plane, because a Global Administrator in the cloud can be just as total as a domain admin on-prem.

TechnicalGo deeper

EAM explicitly supersedes the legacy tier model and adds user-access and app-access models for a hybrid, multicloud estate. The control plane maps to old Tier 0; the former Tier 1 split into management and data/workload planes; Tier 2 concerns map to user and app access. Practitioners note the underlying principles are effectively identical; the shift is that control is no longer rooted solely in on-prem AD. Use EAM's vocabulary with cloud-aware clients and the Tier 0/1/2 vocabulary with classic on-prem teams.

10The clean source principleAdminister an asset only from a source at least as trusted as the asset itself.
In plain terms

If you manage a highly-trusted system from a less-trusted one, the less-trusted one becomes a way to compromise it. So the device, the account and the network path used to administer Tier 0 must all be Tier 0-grade. This single principle is why Privileged Access Workstations exist.

Example

Managing a Domain Controller (DC) from an admin's everyday laptop violates clean source: the laptop browses the web and reads email, so it is a weaker, exposed source controlling a Tier 0 asset.

TechnicalGo deeper

Microsoft's wording: the security of an object depends on the security of all the subjects in control of it, so all security dependencies must be held at or above the object's level. In practice clean source governs three things for every admin action: Fix: a clean device (the Privileged Access Workstation (PAW)), a clean account (a dedicated Tier 0 admin account), and a clean path (direct, not proxied through lower-tier jump hosts). Part 2 is largely the implementation of this one idea.

11Separate identities per tierEach administrator uses a distinct account per tier, with no account holding rights in more than one tier.
In plain terms

A person may be trusted to administer all tiers, but they must do it with different accounts: a Tier 0 account for Tier 0 work, a Tier 1 account for servers, and an ordinary account for daily email and browsing. One human, several identities, each confined to its tier.

Example

Jordan has adm0-jordan (Tier 0, used only from a Privileged Access Workstation (PAW)), adm1-jordan (Tier 1 servers), and jordan (everyday mailbox and laptop). None of the three can log on in another tier's zone.

TechnicalGo deeper

This defeats the most common real-world failure: a single powerful account used for everything, whose hash ends up on a user workstation. Separation is enforced by logon-right Group Policy Objects (GPOs) and silos, and daily-driver accounts must never be privileged. Risk: The classic anti-pattern is a domain admin reading email: one malicious link and the most powerful credential in the environment is resident on an internet-exposed, phishing-reachable device.

12Enhanced Security Administrative Environment (ESAE) / the Red Forest, and why it was retiredESAE ('Red Forest') was a separate hardened admin forest; Microsoft retired it as a default in 2021 in favor of the modern privileged access strategy and Rapid Modernization Plan (RaMP).
In plain terms

For years the gold standard was a dedicated administrative forest that held your Tier 0 admin accounts, trusted one-way by production. It worked but was heavy and often half-built. Microsoft retired it as the default recommendation, replacing it with a cloud-aware strategy (Privileged Access Workstations (PAWs), Privileged Identity Management (PIM), Conditional Access) delivered via the Rapid Modernization Plan.

Example

A team that spent two years standing up a Red Forest and never finished was, in the meantime, less secure than one that had simply deployed PAWs and separated admin accounts.

TechnicalGo deeper

Microsoft's guidance: there is no urgency to tear down a correctly-run ESAE, but a hardened admin forest is now a custom, exception-only configuration, not the starting point. New builds should adopt the modern strategy via RaMP directly. The tier model's logic survives intact inside Enterprise Access Model (EAM); it was the specific heavyweight implementation (a whole separate forest) that fell out of favor, because partial deployments left organizations stranded for years.

13Tiering vs. privileged access managementTiering says where credentials may appear; privileged access management (Just-In-Time (JIT), Privileged Access Workstations (PAWs), Multi-Factor Authentication (MFA)) is how you enforce and shrink that exposure.
In plain terms

Tiering is the map. Privileged access management is the set of controls that make the map real: Privileged Access Workstations (clean devices), just-in-time activation so admin rights don't stand idle, phishing-resistant MFA, and session brokering. You need both; a tier model with no enforcement is just a diagram.

Example

Tiering says the Domain Admins (DA) account may only appear on a PAW. Privileged Identity Management (PIM) makes sure the account isn't even a domain admin until someone activates the role for two hours with approval, so most of the time there is nothing to steal.

TechnicalGo deeper

The strongest version combines them: separate tiered identities, JIT so standing privilege approaches zero, PAWs as the only clean source, and MFA plus Conditional Access gating activation. This is the content of Part 2. The key mental model: tiering limits blast radius, JIT limits the time window, PAWs limit the exposure surface, and together they make a stolen credential rare, short-lived and hard to capture.

03

Visual map

Three step-throughs. The first is tiering working as designed. The next two are the attacks it exists to stop: classic flat-domain credential theft, and the quieter "hidden Tier 0" path where the domain falls without anyone ever logging on as a domain admin. Step through each and watch where the credential lives.

Legacy tier model vs. the Enterprise Access Model

The vocabulary is shifting. Classic on-prem teams still say "Tier 0/1/2"; cloud-aware guidance uses the Enterprise Access Model's "planes." They describe the same principle at different scope — use whichever your audience knows.

AspectLegacy three-tier modelEnterprise Access Model (EAM)
OriginActive Directory (AD) administrative tier model (on-prem)Current Microsoft model; supersedes the tier model
Top levelTier 0 (identity / Domain Controllers (DCs))Control plane (identity + access control, on-prem and cloud)
MiddleTier 1 (servers, apps, data)Management plane + data/workload plane (Tier 1 split in two)
User levelTier 2 (workstations, users)User access + app access models
ScopeOn-prem Windows ADHybrid and multicloud (Entra ID, Software as a Service (SaaS), Conditional Access)
Underlying principleContain privilege escalationIdentical — control never sourced from a lower plane

Where Tier 0 actually lives

A quick reference for the inventory conversation. If a thing can read NTDS.dit, mint credentials, or change who is a domain admin, it is Tier 0 — whatever it's called.

AssetTier 0?Why
Domain controllersYes (obvious)Host AD and the Key Distribution Center (KDC)
Enterprise Certificate Authority (CA) (AD CS)Yes (missed)Can forge a logon certificate for anyone
Active Directory Federation Services (ADFS) token-signing keysYes (missed)Can mint tokens for any user
Entra Connect / sync accountYes (missed)Often holds directory-replication rights
DC backup systemYes (missed)Can restore and read the AD database
Hypervisor / storage for DC Virtual Machines (VMs)Yes (missed)Can mount a DC's virtual disk offline
Agent running as SYSTEM on DCsYes (missed)Executes code on the DC
A file server holding business dataNoSensitive, but can't control identity → Tier 1
04

Technical deep dive

Technical

Under the hood

The three planes as control relationships

The deepest way to think about tiering is as a directed graph of control. An edge A → B means "A can take control of B." Membership in Domain Admins is one such edge, but so are WriteDACL on the domain object, GenericAll on a Domain Controller (DC) computer object, local-admin-on-a-DC, "can edit a Group Policy Object (GPO) linked to the Domain Controllers Organizational Unit (OU)," and "can restore the DC's backup." Tiering is simply the rule that Fix: no edge may point from a lower tier into a higher one without that lower-tier object being promoted into the higher tier.

This is exactly what BloodHound computes. The tool ingests group membership, Access Control Lists (ACLs), sessions, and local-admin rights, then finds shortest paths to Tier 0. A "clean" tiered environment is one where the graph has Verify: no inbound path to Tier 0 from Tier 1 or Tier 2.

Why credential exposure is unavoidable within a session

Windows single sign-on requires that your credential material be usable for the life of your session without re-prompting. That means secrets live in Local Security Authority Subsystem Service (LSASS): for Kerberos, your Ticket-Granting Ticket (TGT) and session keys; for NT LAN Manager (NTLM), your NTLM hash. This is a feature, not a bug — but it means that Risk: any interactive or RemoteInteractive logon leaves reusable material on the destination host. With local admin there, an attacker reads it. The defensive answer is never "stop caching" (you can't, fully); it's "only ever expose high-value credentials on high-value hosts," plus the Part 2 controls (Protected Users caps ticket lifetime and blocks NTLM; Credential Guard isolates secrets).

Defaults and limitations

  • Active Directory (AD) ships flat. There is no Tier 0 OU, no logon restriction, and Domain Admins can log on anywhere out of the box. Tiering is something you impose; nothing enforces it by default.
  • AdminSDHolder and SDProp re-stamp ACLs on protected groups hourly — useful, but it only protects a fixed set of "protected groups," not your custom Tier 0 assets.
  • Tiering is organizational, not just technical. It fails most often on process (an admin "just Remote Desktop Protocols (RDPs) in") rather than on a missing GPO.
  • It doesn't stop the initial breach or insider abuse by a legitimately-Tier-0 admin. It bounds blast radius; pair it with detection and least privilege.

Common misconceptions

MisconceptionReality
"Tier 0 means the domain controllers."Tier 0 is anything that can control the DCs, including backups, hypervisors, sync accounts and the Certificate Authority (CA).
"Tiering is about classifying sensitive data."It's about administrative control. A Tier 1 server can hold the crown-jewel data and still be Tier 1.
"A jump box solves it."Only if the jump host is itself Tier 0-grade (clean source). A shared jump box everyone RDPs through is a bigger target.
"Strong passwords + Multi-Factor Authentication (MFA) replace tiering."Those stop guessing; tiering stops theft-and-reuse of a credential already in memory.
"We built a Red Forest, so we're done."Enhanced Security Administrative Environment (ESAE) was retired as the default in 2021; verify completeness and whether Privileged Access Workstations (PAWs)/Privileged Identity Management (PIM) fit better now.
"Higher tier numbers are more secure."Inverted: Tier 0 is the most privileged and most protected.

Troubleshooting the design

  • "Enforcing silos broke a service account." Protected Users and silos don't suit all service/computer accounts; scope carefully and test (Part 2 details the pitfalls).
  • "We can't find all our Tier 0." Start from control, not labels: run SharpHound, then audit who holds Replicating Directory Changes, who is local admin on DCs (including agents), and who administers DC backups and virtualization.
  • "Admins revolt over separate accounts." Pre-build the PAW and jump path so the new workflow is a couple of clicks; sell it as "same power, fewer places to lose it."
05

Attacker's view

Attacker

Tiering isn't an abstract maturity goal — it exists to break specific, repeatable attacks that show up in nearly every Active Directory (AD) assessment. Each technique below is described at the level needed to recognize, test for, and report it; the commands are recognition- and scoping-level only, never weaponized payloads. The throughline: every one of these is either the credential-theft engine or a way a flat/weak-tier design hands an attacker a short path to Tier 0.

Credential theft and reuse (pass-the-hash / pass-the-ticket)ATT&CKT1003.001 LSASS Memory · T1550.002 Pass the Hash · T1550.003 Pass the Ticket
How it works

With local admin on a host, the attacker reads cached secrets from Local Security Authority Subsystem Service (LSASS), then replays a hash or Kerberos ticket to authenticate elsewhere as that user, without ever knowing the password. This is the engine tiering is built to contain.

Prerequisites

Risk: Local admin (or SYSTEM) on a host where a higher-value credential is resident, and a reachable target that trusts that credential.

What makes an environment vulnerable

Flat domains where Risk: privileged accounts log on to ordinary workstations and servers, no Protected Users, no Local Administrator Password Solution (LAPS) (so one local-admin hash unlocks the fleet), and unrestricted Server Message Block (SMB)/Windows Management Instrumentation (WMI) between hosts.

Tools

Mimikatz, Impacket (secretsdump, psexec, wmiexec), Rubeus, CrackMapExec/NetExec. BloodHound maps where theft leads.

# Recognition-level only: map exposure, don't dump
bloodhound-python -c Session,LoggedOn ...   # where do privileged sessions exist?
DefenderEvidence it leaves

Verify: LSASS handle access (Sysmon event 10), logon type 9 (NewCredentials/overpass-the-hash), 4624/4625 patterns, and service-ticket requests (4769) for accounts that never log on interactively.

ExecutiveAs a pentest finding

Reported as the concrete realization of a flat-tier design: severity is driven by how short the path from a user workstation to Domain Admins is. Business impact is full domain compromise from a single endpoint. Retest criterion: Verify: no credential-theft path from Tier 2 to Tier 0 in BloodHound, Protected Users and logon restrictions enforced.

Privileged logon to a lower tier (the exposure that breaks tiering)ATT&CKT1078.002 Valid Accounts: Domain Accounts · T1021.001 Remote Services: RDP
How it works

The attack is really a misconfiguration the attacker harvests: an admin interactively logs a Tier 0/1 account onto a Tier 2 host (Remote Desktop Protocol (RDP), RunAs, a scheduled task, or a service), leaving that credential in the host's memory for later theft.

Prerequisites

Risk: A higher-tier credential cached on a lower-tier machine the attacker can reach or already holds.

What makes an environment vulnerable

Help-desk and ops cultures where admins 'just RDP in' with powerful accounts, service accounts from Tier 0 running on Tier 1 servers, and no Deny log on restrictions separating the tiers.

Tools

No special tooling needed; the attacker uses the same Mimikatz/Impacket once the credential is present. Discovery via BloodHound sessions and qwinsta/event-log review.

# Find where privileged accounts have live sessions
# (Event 4624 by account + source host; BloodHound HasSession edges)
DefenderEvidence it leaves

Verify: Interactive or RemoteInteractive logons (4624 type 2/10) by a Tier 0 account on a non-Tier 0 host, RunAs (4648) events, and services/tasks configured with privileged identities.

ExecutiveAs a pentest finding

Often the single highest-leverage finding in an Active Directory (AD) assessment. Severity driven by the tier gap crossed (Domain Admins (DA) on a workstation is critical). Impact: collapses the tier model to flat. Retest: Verify: logon-right Group Policy Objects (GPOs) and silos deny the cross-tier logon, proven by attempting it.

Tier 0 'creep' via control-path escalationATT&CKT1098 Account Manipulation · T1484.001 Group Policy Modification
How it works

The attacker chains ordinary-looking rights, AddMember, WriteDACL, GenericAll, Group Policy Object (GPO) edit, or admin-to a Tier 0 host, into a path that ends at Domain Admins, without any single step looking privileged.

Prerequisites

Risk: A delegated right or nested group membership that transitively controls a Tier 0 object, reachable from a lower tier.

What makes an environment vulnerable

Environments with years of accreted delegation: helpdesk groups with reset rights on admins, over-broad GPO delegation, nested groups nobody has audited, and local-admin-on-DC granted to Tier 1 agents.

Tools

BloodHound / SharpHound (the attack-path graph), PingCastle and Purple Knight for posture, PowerView for ad-hoc Access Control List (ACL) enumeration.

# Enumerate control paths, then read shortest path to Tier 0
SharpHound.exe -c All   # collection only; analysis in BloodHound
DefenderEvidence it leaves

Verify: Changes to Tier 0 group membership (4728/4732/4756), Discretionary Access Control List (DACL) modifications on the domain or AdminSDHolder (5136), and new GPO links on Tier 0 Organizational Units (OUs).

ExecutiveAs a pentest finding

Reported with the exact path graph as evidence; executives understand 'this helpdesk group can become domain admin in three steps'. Retest: Verify: the path is broken in BloodHound and Tier 0 objects have only Tier 0 principals in their ACLs.

Hidden Tier 0: backup, hypervisor and identity-syncATT&CKT1003.003 NTDS · T1003.006 DCSync · T1550 Use Alternate Material
How it works

Rather than attack a Domain Controller (DC), the attacker takes a system that controls the DC indirectly: restore a DC backup, mount a DC's virtual disk to extract NT Directory Services database (NTDS).dit, or abuse a directory-sync account's replication rights to Directory replication abuse (DCSync).

Prerequisites

Risk: Control of a backup system, hypervisor/storage admin, or an account with replication rights, none of which is guarded as Tier 0.

What makes an environment vulnerable

DCs virtualized on a general cluster, DC backups on shared storage, Entra Connect/sync accounts with Replicating Directory Changes All, and Endpoint Detection and Response (EDR)/management agents running as SYSTEM on DCs from a Tier 1 console.

Tools

Native backup/hypervisor consoles, ntdsutil/secretsdump for offline NTDS, Mimikatz/Impacket for DCSync, BloodHound to surface the sync-account edge.

# Recognition: who can replicate directory changes?
# Audit members/ACLs holding 'Replicating Directory Changes All'
DefenderEvidence it leaves

Verify: Replication requested by a non-DC principal (4662 with the DS-Replication Globally Unique Identifier (GUID)), DC backup/restore and snapshot operations, and offline volume mounts of DC disks.

ExecutiveAs a pentest finding

The highest-impact and most commonly-missed Tier 0 gap. Severity: critical (full domain compromise with no Domain Admins (DA) logon). Retest: Verify: every system that can read or restore DC data is inventoried and protected as Tier 0, sync-account rights scoped and monitored.

Shared local admin and lateral movement (no Local Administrator Password Solution (LAPS))ATT&CKT1550.002 Pass the Hash · T1021.002 SMB/Admin Shares · T1078.003 Local Accounts
How it works

A single local Administrator password is reused across many machines, so one stolen local-admin hash passes to the entire fleet, letting the attacker hop host to host harvesting credentials until a privileged one appears.

Prerequisites

Risk: A common local-admin secret across hosts and no host-to-host Server Message Block (SMB) restriction.

What makes an environment vulnerable

Gold-image deployments that bake in one local-admin password, environments without Windows LAPS, and flat networks where any workstation can reach any other over SMB.

Tools

NetExec/CrackMapExec (spray a hash across a subnet), Impacket, Mimikatz. Detectable with BloodHound local-admin collection.

# Recognition: does one local hash authenticate widely?
netexec smb <subnet> -u Administrator -H <hash>   # scope only
DefenderEvidence it leaves

Verify: The same local-admin logon (4624 type 3) succeeding across many hosts in a short window, and SMB admin-share access patterns.

ExecutiveAs a pentest finding

A force-multiplier that turns a single endpoint into fleet-wide movement. Severity: high. Retest: Verify: Windows LAPS enforced with unique, rotated local passwords and host isolation; confirm the hash no longer authenticates on a second machine.

Tier 0 service-account exposure (Kerberoasting / Service Principal Name (SPN) abuse)ATT&CKT1558.003 Kerberoasting · T1078.002 Valid Accounts
How it works

A Tier 0 service runs under a user account with an SPN; any domain user can request its service ticket and crack the account's password offline, or the account's credential is simply harvested from the Tier 1 host it runs on.

Prerequisites

Risk: A privileged account with an SPN and a crackable password, or a Tier 0 service account resident on a lower-tier host.

What makes an environment vulnerable

Legacy service accounts in Domain Admins with weak, non-rotated passwords, and Tier 0 services deployed onto Tier 1 servers instead of being isolated.

Tools

Rubeus and Impacket (GetUserSPNs) to request tickets, Hashcat to crack offline, BloodHound to flag privileged SPN accounts.

# Recognition: which privileged accounts expose an SPN?
GetUserSPNs.py <domain>/<user>   # enumerate; cracking is offline
DefenderEvidence it leaves

Verify: A burst of service-ticket requests (4769) with Rivest Cipher 4 (RC4) encryption for a privileged SPN account, and privileged services running on non-Tier-0 hosts.

ExecutiveAs a pentest finding

Ties credential hygiene to tiering: a Tier 0 service account is only as safe as its password and its host. Severity scales with the account's rights. Retest: Verify: privileged service accounts moved to group Managed Service Accounts (gMSAs) or strong rotated secrets, isolated to Tier 0 hosts, AES-only.

06

Defender's playbook

Defender

The strategy for Part 1 is design-level: find your real Tier 0, stop high-value credentials appearing on low-value hosts, and kill the two force-multipliers (shared local admin, unprotected Tier 0 dependencies). The hands-on enforcement controls — Privileged Access Workstations (PAWs), silos, Protected Users, Local Administrator Password Solution (LAPS), Privileged Identity Management (PIM) — are Part 2; here we set the targets they'll implement.

Quick wins (days)

  1. Map your control paths. Run SharpHound and review the shortest paths to Domain Admins. Verify: The path length from a user workstation to Tier 0 is your headline metric; drive it toward "no path."
    SharpHound.exe -c All          # collect; analyze in BloodHound
  2. Stop Tier 0 logons on lower tiers. Add Domain/Enterprise Admins (and equivalents) to Protected Users, and plan Deny log on Group Policy Objects (GPOs) so Fix: Tier 0 accounts can't log on to Tier 1/2 hosts.
    # Protected Users blocks NTLM and caps TGT lifetime for members (test first)
    Add-ADGroupMember "Protected Users" -Members adm0-jordan
  3. Turn on Windows LAPS. It's built into Windows since the April 2023 update — no agent — and Fix: gives every machine a unique, rotated local admin password, killing fleet-wide pass-the-hash.
  4. Separate admin accounts from daily-driver accounts. No account used for email/web should hold admin rights anywhere; Fix: no domain admin should ever read email.
  5. Inventory hidden Tier 0. Identify who can restore/read Domain Controller (DC) backups, who administers the DC hypervisor/storage, and which accounts hold Replicating Directory Changes All. Risk: Protect each as Tier 0 or remove its control over Tier 0.

Longer-term fixes (weeks to months)

  1. Stand up the tier structure. Tier 0/1/2 Organizational Units (OUs), scoped delegation, and per-tier admin accounts; subdivide Tier 1 into silos as you mature.
  2. Deploy PAWs and enforce clean source. Admin work for a tier happens only from that tier's hardened workstation, over a clean path (Part 2).
  3. Enforce boundaries technically. Authentication Policies and Silos plus Deny log on GPOs make the cardinal rule self-enforcing, not just documented (Part 2).
  4. Cut standing privilege with Just-In-Time (JIT). Entra PIM / a Privileged Access Management (PAM) tool so accounts aren't privileged until activated with approval and a time limit — most of the time there's nothing to steal (Part 2).
  5. Bring hidden Tier 0 into the fold. Isolate DCs onto dedicated virtualization/backup pipelines that only Tier 0 admins can touch; move Tier 0 service accounts to group Managed Service Accounts (gMSAs).
  6. Monitor for drift. Alert on new Tier 0 group members, new control edges, and any Tier 0 logon on a lower-tier host.

Detection signals

Event or signalSourceAlert on
Local Security Authority Subsystem Service (LSASS) handle accessSysmon event 10 / Endpoint Detection and Response (EDR)Verify: A non-system process opening LSASS — credential dumping
4624 logon type 2/10 by a Tier 0 account on a non-Tier-0 hostDC / host Security logVerify: Any Tier 0 credential appearing off a Tier 0 host — a cardinal-rule break
4728 / 4732 / 4756DC Security logA member added to a Tier 0 group (Domain/Enterprise Admins, Administrators)
5136 on the domain object / AdminSDHolderDC Security logA new Access Control Entry (ACE) granting control of Tier 0 (Discretionary Access Control List (DACL) change)
4662 with the DS-Replication-Get-Changes Globally Unique Identifier (GUID)DC Security logReplication requested by a principal that isn't a DC — Directory replication abuse (DCSync)
4769 Rivest Cipher 4 (RC4) bursts for a privileged Service Principal Name (SPN)DC Security logPossible Kerberoasting of a Tier 0 service account
Same local-admin logon (4624 type 3) across many hostsSecurity Information and Event Management (SIEM)Shared-local-admin lateral movement (missing LAPS)

Verify the fix worked

  1. Verify: Re-run SharpHound and confirm no control path from Tier 2 (or Tier 1) into Tier 0.
  2. Attempt a Tier 0 logon on a Tier 1/2 host and confirm it's denied by GPO/silo.
  3. Confirm Windows LAPS is enforced: the same local-admin hash Verify: no longer authenticates on a second machine.
  4. List everything that can read or restore DC data and confirm each is protected as Tier 0.
  5. Confirm no privileged account is used for daily email/web, and no Tier 0 service runs on a lower-tier host.

Why remediation stalls, and workable compromises

ObjectionWorkable compromise
"Admins need to Remote Desktop Protocol (RDP) everywhere to do their jobs."Give per-tier admin accounts and a PAW/jump path; Fix: same power, scoped to the tier, workflow pre-built so it's painless.
"We can't isolate the DCs' virtualization right now."At minimum restrict who can snapshot/mount DC disks and who can restore DC backups to Tier 0 admins; isolate hosts next.
"A full tier model is a multi-year program."Sequence by leverage: account separation, stop-DA-on-workstations, LAPS, and hidden-Tier-0 protection first; PAWs/PIM next.
"The helpdesk needs admin to support users."Delegate precise Tier 2 rights (password reset on an OU) instead of domain admin; Fix: a phished helpdesk account then stays Tier 2.
"We already did Enhanced Security Administrative Environment (ESAE) years ago."Verify it's complete; map it to the modern model and adopt PAWs/PIM where lighter and sufficient.
"Separate accounts double our account count."That's expected and fine; enforce with naming + silos, and use PIM so the privileged ones are dormant until activated.
07

Executive brief

Executive

The risk in plain language

Our network has a set of all-powerful administrative credentials — the digital equivalent of a master key to every room. The danger isn't mainly that someone guesses the password; it's that Risk: every time one of those credentials is used on an ordinary computer, a reusable copy is left behind in that computer's memory. An attacker who compromises that computer can copy the credential and reuse it, with no password and no second-factor prompt, until they reach the systems that run everything. Tiering is the design rule that keeps those master-key credentials off ordinary computers, so that one hacked laptop stays one hacked laptop.

Business impact

  • In a network without tiering, Risk: a single phished laptop can escalate to full control of the company within hours — all data, all systems, all accounts.
  • That "full control" is what ransomware crews buy and sell; it's the difference between an isolated incident and an enterprise-wide outage.
  • The weak point is often not a server we guard, but Risk: a backup system or virtualization platform nobody classified as critical — yet either can impersonate the systems that run our identity.

What drives likelihood

  • Admins who log on everywhere with powerful accounts, scattering reusable credentials across the estate.
  • A "flat" network where any workstation can reach any other and shared local passwords let one break-in spread.
  • Unprotected hidden dependencies — backups, the virtualization platform, identity-sync and the certificate system.
  • Half-finished past projects that were assumed to have solved this but never completed.

Cost of inaction

The highest-value fixes are mostly policy and built-in features, not new spend: separate admin accounts from everyday ones, stop using master-key credentials on ordinary machines, switch on a free built-in password feature, and protect the few systems that can impersonate our identity servers. Leaving these means we are Risk: one unlucky click away from a company-wide event, and our existing investments in antivirus and multi-factor don't cover this gap — they stop the break-in, not the spread.

What good looks like

  • There is Fix: no technical path from an ordinary device to full domain control — and we can prove it with the same tools attackers use.
  • Administrators use Fix: separate accounts on dedicated, hardened machines; no one reads email with a master-key account.
  • The systems that can impersonate our identity servers (backups, virtualization, sync, certificates) are Fix: protected to the same standard as those servers.
  • Powerful access is Fix: granted only when needed, not left standing idle, and we're alerted when any of this drifts.

Questions executives ask

In one sentence, what is tiering and why do we need it?

"Tiering is a design rule that keeps our most powerful admin credentials off ordinary computers, so that one hacked laptop can't snowball into control of the entire company. Without it, our network is effectively flat: a single phishing victim can often reach total control within a day."

Are we exposed right now?

"The honest test is a control-path assessment. In most environments we've seen, there is a short, unintended path from an everyday workstation to full domain control, usually through an admin who logs on everywhere or a backup/virtualization system nobody treated as critical. Fix: We can measure our specific path length and close it; that number is the headline metric."

How is this different from having strong passwords and Multi-Factor Authentication (MFA)?

"Strong passwords and MFA stop someone guessing their way in. Tiering addresses a different attack: once a credential is used on a machine, it can be stolen from that machine's memory and reused, no password or MFA prompt required. So the two are complementary; tiering controls where our powerful credentials are allowed to appear."

This sounds expensive and disruptive. What's the minimum that moves the needle?

"The highest-value steps are mostly policy, not purchase: separate admin accounts from everyday accounts, Fix: stop logging domain-admin credentials onto workstations, turn on the free built-in Local Administrator Password Solution (LAPS), and protect the backup and virtualization systems like the domain controllers they can impersonate. A couple of hardened admin workstations come next. The heavy tooling is optional and phased."

Didn't we already do this with the 'Red Forest' project years ago?

"Possibly in part. Microsoft actually retired that specific heavyweight design in 2021 because so many of them were never finished. Fix: The modern approach is lighter and cloud-aware, hardened admin workstations and just-in-time access, and we'd verify whether what was built is complete and still the right pattern."

What does 'good' look like, and how will we know we got there?

"Good means there is Verify: no technical path from an ordinary device to domain control, admins use separate accounts on dedicated hardened machines, and the systems that can impersonate our domain controllers are protected to the same standard. We prove it with the same control-path tooling attackers use: the path simply isn't there anymore."

Presenting this finding to leadership

  1. Headline: "There is a short, unintended path from an ordinary laptop to full control of the company, and Risk: most of the fix is policy, not spend."
  2. Make it concrete: show the actual control-path graph — "this helpdesk group reaches domain admin in three steps" lands harder than any statistic.
  3. Frame the metric: path length from a user device to full control; today it's a handful of steps, the goal is "no path."
  4. The ask: fund account separation and hidden-Tier-0 protection now (low cost), then phase in hardened admin workstations and just-in-time access.
08

Talk the talk

Jargon decoder

Tier 0

The identity control plane: Domain Controllers (DCs), Active Directory (AD), and anything that can seize equivalent control.

"The Certificate Authority (CA) is Tier 0, so it goes behind the same wall as the domain controllers."

Blast radius

How far a single compromise can spread before something stops it.

"Tiering shrinks the blast radius of a phished laptop from 'everything' to 'that laptop'."

Clean source

The rule that you administer an asset only from an equally-trusted device, account and path.

"Managing a Domain Controller (DC) from your email laptop breaks clean source."

Security dependency

Anything that can take control of an object; the object is only as secure as its weakest one.

"The backup server is a security dependency of every Domain Controller (DC) it protects."

Control path

A chain of rights or sessions that leads from a low-privilege foothold to a high-privilege target.

"BloodHound found a four-hop control path from helpdesk to Domain Admins."

Flat domain

An Active Directory (AD) where credentials and admin rights are reused so widely that tiers don't exist in practice.

"It's a flat domain, one workstation to Domain Admins (DA) in three hops."

Credential exposure

A credential being resident in a machine's memory where it could be stolen.

"Every Remote Desktop Protocol (RDP) session is a credential exposure on the destination host."

Standing privilege

Admin rights that are permanently assigned rather than activated just-in-time.

"Cut standing privilege with Privileged Identity Management (PIM) so there's nothing to steal most of the time."

Red Forest / Enhanced Security Administrative Environment (ESAE)

The retired hardened administrative-forest design.

"We're not building a Red Forest; Microsoft moved to Privileged Access Workstations (PAWs) and Privileged Identity Management (PIM)."

Enterprise Access Model

Microsoft's current control/management/data-plane model that superseded the tier model.

"In Enterprise Access Model (EAM) terms the Domain Controllers (DCs) and Entra Global Admins are both control plane."

Privileged Access Workstation (PAW)

A hardened, single-purpose workstation used only for privileged admin.

"Tier 0 tasks happen on the PAW, nowhere else."

Just-in-time (JIT)

Granting a privileged role only for a limited, approved window.

"With JIT she isn't a domain admin until she activates the role for two hours."

Tier 0 creep

The tendency for the Tier 0 boundary to quietly expand through forgotten dependencies.

"That monitoring agent running as SYSTEM on the Domain Controllers (DCs) is Tier 0 creep."

Containment

Designing so a compromise stays local instead of propagating.

"We can't prevent every phish, so we design for containment."

Smart questions to ask

Sysadmins

  • Do any Tier 0 accounts (Domain/Enterprise Admins) Risk: ever log on to servers or workstations, via Remote Desktop Protocol (RDP), RunAs, services or tasks?
  • Who can Risk: restore or read our Domain Controller (DC) backups, and who administers the hypervisor and storage hosting the DCs?
  • Which accounts hold Replicating Directory Changes All, and are any of them service/sync accounts?
  • Is Windows Local Administrator Password Solution (LAPS) enforced so Fix: every machine has a unique local admin password?
  • Do we have a Verify: current BloodHound graph, and what's the shortest path from a workstation to Domain Admins?

Executives

  • If one employee laptop were compromised today, Risk: how many steps to full company control?
  • Are the systems that can impersonate our identity servers protected as heavily as the servers themselves?
  • Did our past "admin security" project actually get finished, and is it still the right approach?

Coworkers

  • Is this finding a direct Tier 0 exposure or a multi-hop control path? That drives the severity.
  • Did we enumerate the Risk: hidden Tier 0 dependencies, not just the DCs?
  • Are we speaking Enterprise Access Model (EAM) "planes" or legacy "tiers" for this client's team?

Say this, not that

Not this

"We have domain admins, so access is controlled."

Say this

"The question isn't who's a domain admin, it's which machines those credentials have touched, because that's where they can be stolen."

Not this

"Tier 0 is the domain controllers."

Say this

"Tier 0 is the Domain Controllers (DCs) plus everything that can control them: the Certificate Authority (CA), the sync account, the backups, the hypervisor."

Not this

"We'll just put the admins on a jump box."

Say this

"A jump box only helps if it's a clean source, Tier 0-grade; a shared jump host that everyone Remote Desktop Protocols (RDPs) through is just a bigger target."

Not this

"Strong passwords and Multi-Factor Authentication (MFA) mean we don't need tiering."

Say this

"Those stop guessing; tiering stops credential theft and reuse, which needs neither the password nor an MFA prompt."

Not this

"We built a Red Forest, so we're done."

Say this

"Microsoft retired that as the default in 2021; let's verify it's complete and whether Privileged Access Workstations (PAWs) plus Privileged Identity Management (PIM) are the better fit now."

Not this

"The backup server is just infrastructure, it's Tier 1."

Say this

"If it can restore a domain controller, it can impersonate one, so it's Tier 0 whether we labeled it that way or not."

Not this

"Tiering will stop us getting hacked."

Say this

"It won't stop the first foothold; it stops that foothold from becoming a domain-wide disaster, and buys us time to respond."

Same point, two audiences

Where a credential is used determines who can steal it.
Executive

"Using an all-powerful admin account on an ordinary laptop is like carrying the master key through a crowd: someone can copy it."

Sysadmin

"A Domain Admins (DA) logon caches a reusable Ticket-Granting Ticket (TGT)/hash in Local Security Authority Subsystem Service (LSASS) on that host; local admin there means pass-the-ticket to a Domain Controller (DC)."

Tier 0 is defined by control, not by label.
Executive

"Anything that can impersonate our domain controllers is as critical as the controllers themselves."

Sysadmin

"Backup, hypervisor, sync accounts with replication rights, and the Certificate Authority (CA) all have transitive control of Active Directory (AD), so they're Tier 0."

The payoff of tiering is containment, not prevention.
Executive

"We can't stop every phishing email, so we build so one bad click stays small instead of taking down the company."

Sysadmin

"Assume-breach: no Tier 2-to-Tier 0 credential-theft path, so a workstation compromise can't escalate to domain admin."

The modern approach is lighter than the old Red Forest.
Executive

"We don't need the heavyweight project from years ago; today's approach is a few hardened admin machines plus access that's granted only when needed."

Sysadmin

"Skip Enhanced Security Administrative Environment (ESAE); do Rapid Modernization Plan (RaMP): separate tiered accounts, Privileged Access Workstations (PAWs), Protected Users, logon-right Group Policy Objects (GPOs), and Privileged Identity Management (PIM) for Just-In-Time (JIT) activation."

09

Keep going

What to learn next, in order

  1. Part 2 of this series — the implementation. Privileged Access Workstations (PAWs), Authentication Policies and Silos, Protected Users, Windows Local Administrator Password Solution (LAPS), Entra Privileged Identity Management (PIM) for just-in-time access, and the Rapid Modernization Plan (RaMP) rollout. This is where the model becomes enforced configuration.
  2. Attack-path analysis with BloodHound. Learn to read and cut control paths; it's how you both find Tier 0 and prove tiering holds.
  3. The Active Directory (AD) CS abuse series. The concrete case of a non-obvious Tier 0 asset (the enterprise Certificate Authority (CA)) and how its misconfigurations hand over the domain.
  4. Credential theft internals. Kerberos and NT LAN Manager (NTLM), Local Security Authority Subsystem Service (LSASS), Credential Guard, and Protected Users — the mechanics of what tiering contains.
  5. Microsoft's Enterprise Access Model and RaMP docs. The authoritative, cloud-aware framing for hybrid estates.

Resources worth seeking out

  • Microsoft Learn: "Enterprise access model," "Securing privileged access" and the Enhanced Security Administrative Environment (ESAE) retirement page — the primary sources for the modern model.
  • The BloodHound / SpecterOps material on control paths and security boundaries in AD and Entra.
  • An authorized lab (a disposable test forest) to practice building the Organizational Unit (OU)/tier structure and silos safely before touching production.
My private notebook

Personal notes and bookmarks are private. Unsaved text is temporarily kept in this tab’s browser storage to recover supported sign-in redirects and reloads. Closing the tab may lose unsaved text.

Checking sign-in…

Sign in in another tab Sign in in this tab All my notes