What is AD tiering, and which attack does it stop?
Tiering sorts accounts, groups and computers by criticality into tiers (Tier 0 most critical, Tier 2 endpoints), and accounts of one tier may never log on to machines of another.
* Accounts stay inside their tier, so a compromised workstation never holds Tier 0 credentials. *
| Tier | Typical content |
|---|---|
| Tier 0 | Domain controllers, AD admin accounts, identity systems: whoever controls these controls everything |
| Tier 1 | Servers and business applications |
| Tier 2 | Workstations and other end-user devices |
The attack it stops is credential theft followed by lateral movement. When an admin logs on to a machine, their credentials are left in its memory. If a domain admin logs on to an ordinary workstation and that workstation is compromised, an attacker can harvest the domain admin credentials (e.g. with Mimikatz) and take over the whole domain.
With tiering, a domain admin account is simply not allowed to log on to Tier 2, so a compromised workstation only exposes Tier 2 credentials. A compromise in one tier cannot directly spill into another.
Go deeper:
itm8: Fundamentals of AD tiering — the three tiers and how GPO logon restrictions enforce them.
Microsoft Learn: Enterprise access model — Microsoft's successor to the classic tier model.
Wikipedia: Mimikatz — the credential-dumping tool that makes tiering necessary.