Administrative Tier Model

Enhancing Active Directory security through structured administration

Introduction to the Administrative Tier Model

The Administrative Tier Model is a security framework designed to protect privileged access within an Active Directory environment. It segregates administrative duties and accounts into distinct tiers, reducing the risk of privilege escalation and lateral movement by potential attackers.

The Three Tiers

Tier 0: Enterprise Admins, Domain Admins Tier 1: Server Admins Tier 2: Workstation Admins

Tier 0: Domain Controllers and Critical Assets

Tier 1: Servers and Applications

Tier 2: Workstations and User Devices

Implementing the Administrative Tier Model

  1. Identify and categorize assets into appropriate tiers
  2. Create separate administrative accounts for each tier
  3. Implement strict access controls between tiers
  4. Use Privileged Access Management (PAM) in Active Directory for Tier 0 administration
  5. Implement Just-In-Time (JIT) and Just-Enough-Administration (JEA) principles
  6. Regularly audit and review tier memberships and permissions
Tip: Use naming conventions for administrative accounts that clearly indicate their tier (e.g., T0-AdminJohnDoe, T1-AdminJaneSmith).

Best Practices for Tier Model Security

Warning: Never use Tier 0 accounts for daily administrative tasks or to log into lower-tier systems.

Challenges and Considerations

Additional Resources






Scroll to Top