New official Tiering Model guide from Microsoft!

๐Ÿ”’ Secure Bits ๐Ÿ’ก

๐—ก๐—ฒ๐˜„ ๐—ผ๐—ณ๐—ณ๐—ถ๐—ฐ๐—ถ๐—ฎ๐—น ๐—ง๐—ถ๐—ฒ๐—ฟ๐—ถ๐—ป๐—ด ๐— ๐—ผ๐—ฑ๐—ฒ๐—น ๐—ด๐˜‚๐—ถ๐—ฑ๐—ฒ ๐—ณ๐—ฟ๐—ผ๐—บ ๐— ๐—ถ๐—ฐ๐—ฟ๐—ผ๐˜€๐—ผ๐—ณ๐˜!

Really, not a joke! I was not expecting to live long enough to see something like this.

Jokes aside, a few months ago Microsoft published not only new ๐—ฑ๐—ผ๐—ฐ๐˜‚๐—บ๐—ฒ๐—ป๐˜๐—ฎ๐˜๐—ถ๐—ผ๐—ป calledย โ€œTier model for Active Directory Domain Servicesโ€, but earlier this year also a ๐—š๐—ถ๐˜๐—›๐˜‚๐—ฏ ๐—ฝ๐—ฟ๐—ผ๐—ท๐—ฒ๐—ฐ๐˜ calledย ActiveDirectoryTierModel.

๐—ง๐—ต๐—ฒ ๐—ฝ๐—ฟ๐—ผ๐—ท๐—ฒ๐—ฐ๐˜ ๐—ฐ๐—ผ๐—ป๐˜๐—ฎ๐—ถ๐—ป๐˜€ ๐˜๐˜„๐—ผ ๐—บ๐—ฎ๐—ถ๐—ป ๐—ฃ๐—ผ๐˜„๐—ฒ๐—ฟ๐—ฆ๐—ต๐—ฒ๐—น๐—น ๐˜€๐—ฐ๐—ฟ๐—ถ๐—ฝ๐˜๐˜€:

1๏ธโƒฃ ๐——๐—ฒ๐—ฝ๐—น๐—ผ๐˜†-๐—ง๐—ถ๐—ฒ๐—ฟ๐— ๐—ผ๐—ฑ๐—ฒ๐—น.๐—ฝ๐˜€๐Ÿญ

This script helps you build the Tiering Model and prepares much more than just a basic OU structure. It can deploy:

โ–ช๏ธ Organizational Units

โ–ช๏ธ Security groups

โ–ช๏ธ Administrative and service accounts

โ–ช๏ธ OU ACL delegations

โ–ช๏ธ Group Policy Objects and links

โ–ช๏ธ Security Baselines

โ–ช๏ธ ADMX templates

โ–ช๏ธ MSA, gMSA, and dMSA ACL delegations

โ–ช๏ธ Windows LAPS ACL delegations and optional LAPS deployment

โ–ช๏ธ Kerberos Armoring support

The deployment can be performed component by component or as a full deployment. Each component follows the same useful process:

Plan โ†’ Deploy โ†’ Audit

The important part is that the invasive configurations and settings are not simply enabled without your control. You can review the plan, deploy individual components, test the result, and continue gradually.

2๏ธโƒฃ ๐—”๐˜‚๐—ฑ๐—ถ๐˜-๐—ง๐—ถ๐—ฒ๐—ฟ๐— ๐—ผ๐—ฑ๐—ฒ๐—น.๐—ฝ๐˜€๐Ÿญ

This script audits the deployment and checks whether the environment still matches the Tiering Model configuration. It can audit individual components or the full deployment, including OU structure, groups, users, ACLs, GPOs, ADMX templates, managed service account delegations, and Windows LAPS configuration.

So far, I have only played with both scripts a little, but I am genuinely ๐—ต๐—ฎ๐—ฝ๐—ฝ๐˜† ๐˜๐—ผ ๐˜€๐—ฒ๐—ฒ ๐˜๐—ต๐—ถ๐˜€ ๐ŸŽ‰

After all these years of Active Directory, this is quite an advancement, especially when many of the older Microsoft Tiering Model resources and links are no longer available. There is ๐—ป๐—ผ๐˜„ ๐—ฎ๐—ป ๐—ผ๐—ณ๐—ณ๐—ถ๐—ฐ๐—ถ๐—ฎ๐—น, documented, and testable starting point for implementing the Tiering Model.

(๐˜ข๐˜ฎ ๐˜ ๐˜ค๐˜ฐ๐˜ฎ๐˜ช๐˜ฏ๐˜จ ๐˜ญ๐˜ข๐˜ต๐˜ฆ ๐˜ต๐˜ฐ ๐˜ต๐˜ฉ๐˜ฆ ๐˜ฑ๐˜ข๐˜ณ๐˜ต๐˜บ, ๐˜ฉ๐˜ฐ๐˜ธ ๐˜ญ๐˜ฐ๐˜ฏ๐˜จ ๐˜ฉ๐˜ข๐˜ด ๐˜ต๐˜ฉ๐˜ช๐˜ด ๐˜ฃ๐˜ฆ๐˜ฆ๐˜ฏ ๐˜ข๐˜ณ๐˜ฐ๐˜ถ๐˜ฏ๐˜ฅ?)

Have you already tested the project?