Glossary
Tier model
The AD tier model separates administration into Tier 0, 1 and 2 by blast radius so privileged credentials never touch less-trusted systems.
The tier model is Microsoft's administrative segmentation approach for Active Directory. Tier 0 contains everything that controls identity itself — domain controllers, AD CS, AD FS, Entra Connect, backup systems and the accounts that administer them. Tier 1 covers servers and applications; Tier 2 covers workstations and end-user devices. The core rule is directional: an account from a higher tier must never sign in to a lower-tier system, because any credential exposed on a compromised machine is only as safe as that machine. Microsoft now describes this within the broader Enterprise Access Model, which adds cloud and user access planes.
It matters because most domain compromises follow the same pattern: a privileged credential is harvested from a machine that was never meant to hold it. Enforcing tiers with separate admin accounts, logon restriction GPOs, privileged access workstations and authentication policy silos turns that path from a single mistake into something the environment blocks by design. Start by inventorying Tier 0 accurately; the rest of the model depends on it.