Open cardosec

Case 9B998A · Identity & AD · L4 Advanced

AD Tiering Model

Practise as: Explain it · Deep dive
  1. 01 What is it?
  2. 02 How is it abused?
  3. 03 How do you stop it?
What a strong answer covers

Try it out loud first. Then check yourself:

  1. Separate admin accounts by tier: Tier 0 (DCs, AD, identity), Tier 1 (servers), Tier 2 (workstations)
  2. Rule: higher-tier credentials never log on to lower-tier machines, so a compromised laptop cannot leak DA creds
  3. Enforce with logon restrictions (GPO deny logon rights), Protected Users group and Authentication Policy Silos
  4. Admins use Privileged Access Workstations (PAWs) for Tier 0 work, not their daily email/browsing machine
  5. Microsoft now frames this as the Enterprise Access Model, extending the idea to cloud control planes

If the interviewer pushes back

  • Which non-obvious systems belong in Tier 0 because they can control AD (think backup, AD CS, sync)?

cardosec draws a security topic and gives you a clock: explain it out loud with no notes, then see what you covered and what you missed. Free during early access.