Module 16 · AD Tier-0 Hardening — The Defender’s Playbook

Manish Garg
Manish Garg Associate of (ISC)² · RingSafe
Apr 27, 2026
4 min read
Read as

Last updated: April 29, 2026

100% Free

No signup. No paywall. No catch. One of our 10 most-requested practitioner modules — published in full so anyone can learn for free. We earn through consulting, not by gating knowledge.

See all 10 free modules →

Why this module exists. Most AD breaches succeed because Domain Admin credentials end up exposed on workstations or member servers. Microsoft’s Tiered Administration Model (originally “Securing Privileged Access” / “Enterprise Access Model”) is the structural fix. It’s well-documented and rarely implemented in full.

Why this module exists. Most AD breaches succeed because Domain Admin credentials end up exposed on workstations or member servers. Microsoft’s Tiered Administration Model (originally “Securing Privileged Access” / “Enterprise Access Model”) is the structural fix. It’s well-documented and rarely implemented in full. This module is the practical playbook.

The model

Three tiers, in increasing sensitivity:

  • Tier 2 — workstations. User devices. Where most attackers land first.
  • Tier 1 — member servers, applications. Web servers, file servers, SQL servers, Exchange.
  • Tier 0 — identity infrastructure. Domain controllers, AD Connect, ADFS, certificate authorities, the systems that are the kingdom.

The hardening rule: credentials never flow downward. Tier-0 admins log into Tier-0 systems only. Tier-1 admins handle Tier-1, never log into Tier-2. Workstation admins handle Tier-2 only.

Why this matters mathematically

Without tiering: a single compromised workstation where a Domain Admin logged on yesterday → mimikatz extracts their credentials → game over for the entire domain. Tiering: the Domain Admin never logged onto that workstation, so their credentials aren’t there.

What “Tier 0” actually includes

  • Domain Controllers
  • AD Connect / Entra Connect server
  • ADFS / federation servers
  • Active Directory Certificate Services (PKI)
  • Privileged Access Workstations (PAWs) used by Tier-0 admins
  • Backup systems for any of the above
  • Tier-0 service accounts
  • Group Policies linked to the Domain Controllers OU

Anyone with admin rights to any of these is effectively a Domain Admin.

The 12-step Tier-0 hardening checklist

1. Inventory Tier 0

List every system in the categories above. If you can’t list them in 30 minutes, you can’t protect them.

2. Create Tier-0 admin accounts

Separate from each admin’s daily-driver account. jane.tier0 is for DC management; jane is for email and Slack.

3. Privileged Access Workstations (PAWs)

Dedicated, hardened machines for Tier-0 admin work. Internet-blocked. No email, no Office, no browser to general internet. Whitelisted apps only. Tier-0 admin logons happen only from these machines.

4. Block Tier-0 logon to lower tiers

Group Policy Deny log on locally for Tier-0 accounts on Tier-1 and Tier-2 machines. Same for Deny log on through Remote Desktop Services and Deny log on as a service.

5. Restrict who can log onto DCs

“Allow log on locally” on Domain Controllers: only Domain Admins. Remove all other principals (Print Operators, Account Operators, etc — even though Microsoft default has them).

6. Smart-card-required for Tier 0

Set SmartcardLogonRequired on every Tier-0 admin account. Even if their hash leaks, no smart card = no logon.

7. Add to Protected Users group

Tier-0 admins join “Protected Users” — disables NTLM, disables credential delegation, requires AES-only Kerberos.

8. Mark accounts “Sensitive and cannot be delegated”

Set NOT_DELEGATED flag (UAC bit 0x100000). Prevents Kerberos delegation tickets being usable.

9. Reset krbtgt twice annually

Use Microsoft’s Reset-KrbTgt script. Reset, wait 24 hours, reset again. Forged Golden Tickets become invalid.

10. Audit Tier-0 group memberships weekly

Domain Admins, Enterprise Admins, Schema Admins, Built-in Administrators, Account Operators, Backup Operators. Compare to last week. Investigate any change.

11. LAPS for every workstation and member server

Local admin password is random, 25+ chars, rotated every 30 days. Stored encrypted in AD. Retrievable only by authorised users. Now PtH at Tier 2 doesn’t propagate.

12. Microsoft Defender for Identity (or equivalent)

Native AD-aware EDR. Detects DCSync, Pass-the-Hash, Golden Ticket, Skeleton Key, lateral movement patterns. Shouldn’t be optional in 2026.

How to roll this out — the realistic 90-day plan

Days 1-15: Inventory Tier 0. Create separate Tier-0 admin accounts for everyone. Build first PAW.

Days 15-30: Deploy Defender for Identity. Establish baseline detections. Find existing concerning behaviour.

Days 30-45: Deploy LAPS to all workstations. Resolve service-account password issues that LAPS surfaces.

Days 45-60: Apply “Deny log on” GPOs. Test everything. Roll back GPOs that break operations and remediate the underlying dependency.

Days 60-75: Smart-card enforcement on Tier-0 admins. Protected Users membership. Sensitive/cannot-be-delegated flag.

Days 75-90: First krbtgt rotation. Audit Tier-0 group memberships. Document the model and brief the team.

What this prevents — measured

An attacker who lands on a workstation can no longer:

  • Find Tier-0 credentials in LSASS (they’re not there — Tier-0 admins don’t log on to workstations)
  • Pass-the-Hash to a DC (Tier-0 admins are smart-card-only)
  • Move laterally to other workstations using the local admin password (LAPS — every machine has a different one)
  • Wait for a Domain Admin to RDP in (they don’t — they use PAW)

The attacker has to find an alternative path. There usually are some, but they’re harder, slower, and more visible.

Defender’s audit checklist

  • Walk a hypothetical attacker’s path from any workstation to Domain Admin. Time each step. If >4 hours, you’re doing well.
  • Run BloodHound’s “shortest path from Authenticated Users to Domain Admins” query. The result should require multiple steps and at least one privileged credential.
  • Run Purple Team exercises quarterly. Hire a red team or use internal staff with permission to test.
  • Map every step in this checklist to a SIEM detection. The bypass should not be silent.
🧠
Check your understanding

Module Quiz · 6 questions

Pass with 80%+ to mark this module complete. Unlimited retries. Each question shows an explanation.

Want this for your team?

Custom team training + practitioner advisory

Beyond the free academy — we run private workshops, vCISO advisory, and red-team exercises tailored to your stack. For Indian SMBs scaling past their first hire.

Book team training call Replies in 4 working hrs · India-only · Senior consultants