Glossary
Authentication policy silo
An authentication policy silo groups privileged accounts and hosts so those accounts can only obtain Kerberos tickets from approved devices.
Authentication policies and authentication policy silos arrived with the Windows Server 2012 R2 domain functional level. An authentication policy defines conditions for Kerberos: TGT lifetime, and access control conditions that say from which devices an account may request a TGT, or which accounts may access a service. A silo ties a set of users, computers and service accounts to such policies, so membership can be expressed as a claim. Enforcement relies on Kerberos armoring (FAST) and on compound claims support, and silos can run in audit mode before enforcement.
It matters because it turns the tier model from a guideline into a control. If Tier 0 administrators can only obtain tickets from Tier 0 PAWs and domain controllers, a stolen password or hash is useless from a compromised workstation, and short TGT lifetimes shrink the window for ticket reuse. Roll out in audit mode first, review events in the Authentication Policies logs on DCs, keep a break-glass account outside the silo, and add Protected Users membership for the same accounts.
See Authentication policies and silos for Tier 0 and Tier 0 and privileged access.