LOGBOOK

HELP

Quiz Entry - updated: 2026.09.29

What is AD tiering, and which attack does it stop?

Tiering sorts accounts, groups and computers by criticality into tiers (Tier 0 most critical, Tier 2 endpoints), and accounts of one tier may never log on to machines of another.

AD tiering: Tier 0, 1 and 2 with admins logging on only within their tier

* Accounts stay inside their tier, so a compromised workstation never holds Tier 0 credentials. *

Tier Typical content
Tier 0 Domain controllers, AD admin accounts, identity systems: whoever controls these controls everything
Tier 1 Servers and business applications
Tier 2 Workstations and other end-user devices

The attack it stops is credential theft followed by lateral movement. When an admin logs on to a machine, their credentials are left in its memory. If a domain admin logs on to an ordinary workstation and that workstation is compromised, an attacker can harvest the domain admin credentials (e.g. with Mimikatz) and take over the whole domain.

With tiering, a domain admin account is simply not allowed to log on to Tier 2, so a compromised workstation only exposes Tier 2 credentials. A compromise in one tier cannot directly spill into another.

Go deeper:

From Quiz: ISLAB / Access Management with Active Directory | Updated: Sep 29, 2026