Case 9B998A · Identity & AD · L4 Advanced
AD Tiering Model
Practise as: Explain it · Deep dive
- 01 What is it?
- 02 How is it abused?
- 03 How do you stop it?
What a strong answer covers
Try it out loud first. Then check yourself:
- Separate admin accounts by tier: Tier 0 (DCs, AD, identity), Tier 1 (servers), Tier 2 (workstations)
- Rule: higher-tier credentials never log on to lower-tier machines, so a compromised laptop cannot leak DA creds
- Enforce with logon restrictions (GPO deny logon rights), Protected Users group and Authentication Policy Silos
- Admins use Privileged Access Workstations (PAWs) for Tier 0 work, not their daily email/browsing machine
- Microsoft now frames this as the Enterprise Access Model, extending the idea to cloud control planes
If the interviewer pushes back
- Which non-obvious systems belong in Tier 0 because they can control AD (think backup, AD CS, sync)?
cardosec draws a security topic and gives you a clock: explain it out loud with no notes, then see what you covered and what you missed. Free during early access.