Area 01 / 12
Tier 0 & Privileged Access
Almost every domain compromise ends with a privileged credential exposed on a machine an attacker already controls. This area removes that exposure: a tightly scoped Tier 0, separate admin accounts, logon restrictions and privileged access workstations.
Start the pathLearning path
0/4 done- 01Tier 0 and privileged access: locking down Domain AdminsBuild a working Tier 0 boundary in Active Directory with separate admin accounts, logon restrictions, PAWs, and authentication policy silos.
- 02Identify Tier 0 assets: a complete AD inventory methodInventory every Tier 0 asset in Active Directory: DCs, AD CS, Entra Connect, backup, hypervisors, and the groups and ACLs that give indirect control.
- 03Building privileged access workstations (PAWs) for ADDesign and build PAWs for Tier 0 admins: hardware, clean image, App Control allowlisting, no internet or email, and when a jump server is not enough.
- 04Authentication policies and silos for Tier 0 accountsRestrict where Tier 0 admins can authenticate with AD authentication policies and silos: prerequisites, claims, TGT lifetime, audit mode and enforcement.