How to Tier Your Active Directory Admin Accounts to Contain Lateral Movement
Retrospective: this article looks back at events from June 2017, written in 2026 with the benefit of hindsight.
NotPetya spread by stealing administrator credentials from memory and reusing them across the network. Tiering your Active Directory admin accounts stops one compromised machine from exposing the keys to everything. The same principles apply in hybrid environments connected to Entra ID.
The idea
Separate administrative accounts by what they control:
- Tier 0: identity infrastructure — domain controllers, Entra Connect servers, AD FS, PKI.
- Tier 1: servers and applications.
- Tier 2: workstations and user devices.
An account from a higher tier never signs in to a lower-tier machine, so its credentials never sit in memory on a device an attacker is likely to compromise first. Microsoft's current guidance describes this as the enterprise access model, built on privileged access workstations.
Step 1: Inventory privileged accounts
List members of Domain Admins, Enterprise Admins, Administrators and other privileged groups. Most organizations find far more than expected.
Step 2: Create separate admin accounts
Each administrator gets a normal user account plus separate tier-specific admin accounts. No email, no web browsing on admin accounts.
Step 3: Enforce logon restrictions
Use Group Policy "deny log on" rights so Tier 0 accounts cannot log on to servers or workstations, and Tier 1 accounts cannot log on to workstations.
Step 4: Unique local admin passwords
Deploy Windows LAPS so every machine has a unique, rotated local administrator password.
Step 5: Protect Tier 0
- Treat Entra Connect and AD FS servers as Tier 0 — they can compromise your cloud identity.
- Add privileged accounts to the Protected Users group.
- Manage Tier 0 only from hardened privileged access workstations.
Verify
Tools such as Microsoft Defender for Identity can show lateral movement paths. If a standard user's workstation leads to a Domain Admin credential in two hops, the tiering is not finished.