Skip to content

The Active Directory Tiering Model: Containing Blast Radius in Texas SMBs

By Donovan Brown
July 9, 2026
10 sections
The Active Directory Tiering Model: Containing Blast Radius in Texas SMBs

One compromised laptop should never mean domain takeover. How the Active Directory tier model separates powerful accounts from risky devices — scaled for SMBs.

01

Introduction

The most common way a Texas small business goes from "we had a phishing incident" to "the attacker owns our entire network" is a single flat layer of privilege. A help-desk technician's account is a Domain Admin. That admin logs into a regular workstation to fix a printer. That workstation gets compromised. The attacker scrapes the admin's credentials from memory, and now they hold the keys to every server, every file share, and every backup in the company. This is not a sophisticated attack — it is the default outcome of a flat Active Directory, and it happens to businesses in Houston, Dallas, and Austin every week.

The fix is a tiered administration model: a discipline that separates your most powerful accounts from your riskiest devices so a single compromised laptop can't cascade into a full domain takeover. Microsoft originally called it the "Tier Model"; its successor guidance is the "Enterprise Access Model." Whatever the name, the core idea scales down cleanly to an SMB, and this guide shows you how.

02

Why a Flat Active Directory Is a Transitive Trust Bomb

Active Directory privilege is transitive. If a highly privileged credential is ever present — even briefly, even in memory — on a device an attacker controls, that credential is compromised. Attackers exploit this with credential-theft techniques (pass-the-hash, pass-the-ticket, and outright memory scraping) that turn one foothold into total control. The problem isn't that your admins are careless; it's that the architecture lets a workstation infection reach a Domain Admin token.

Tiering breaks the transitivity. The rule is simple to state and hard to violate once enforced: a credential should never be exposed on a device less trusted than the assets it controls.

03

The Three Tiers

The model divides your environment into three tiers based on the value of what an account controls:

  • Tier 0 — Identity and control plane. Domain Controllers, the AD database, ADFS/Entra Connect servers, PKI/certificate authorities, and any account that can directly or indirectly control them. Compromise of Tier 0 means compromise of everything. These are the crown jewels.
  • Tier 1 — Servers and applications. Member servers, business-critical applications, databases, and the accounts that administer them. A Tier 1 compromise is serious but contained — it doesn't hand over the whole directory.
  • Tier 2 — Workstations and devices. End-user laptops, desktops, and the help-desk accounts that manage them. This is the highest-risk, highest-exposure tier because it's where users click links and open attachments.
04

The Rules That Make Tiering Work

The tiers are just labels until you enforce the movement rules between them. There are two, and they run in opposite directions.

Rule 1: No Credential Exposure Downward

A higher-tier account must never log on to a lower-tier device. A Tier 0 Domain Admin never signs into a Tier 2 workstation or a Tier 1 application server. Why? Because logging on caches the credential on that device, where a lower-tier compromise can steal it. This is the rule that stops the printer-fix scenario cold.

Rule 2: No Control Upward From a Lower Tier

A lower-tier account or device must not be able to control a higher-tier asset. A Tier 2 help-desk account cannot have rights on a Tier 1 server; a Tier 1 admin cannot manage a Domain Controller. Control only flows down the tiers, never up.

Enforce both rules with User Rights Assignment via Group Policy — specifically the "Deny log on locally," "Deny log on through Remote Desktop Services," and "Deny access to this computer from the network" settings, scoped so each tier's admin accounts are blocked from the tiers they shouldn't touch. This is the same category of GPO-driven control we use for network access control.

05

Privileged Access Workstations: Where Tier 0 Admins Actually Work

If a Domain Admin can't log into a normal workstation, where do they work? On a Privileged Access Workstation (PAW) — a hardened, single-purpose device used only for privileged administration. A PAW has no email client, no web browsing to the open internet, no productivity apps. It exists to be a clean surface from which to administer Tier 0. For an SMB, this can be as lean as one or two locked-down machines, or a hardened jump host reached over a controlled path. The point is that the credential that can destroy your company is only ever typed on a device that does nothing but administration.

06

Just-in-Time and Just-Enough Access

Static membership in Domain Admins is the old way. The modern discipline is Just-in-Time (JIT) and Just-Enough-Access (JEA):

  • Empty the privileged groups. Domain Admins, Enterprise Admins, and Schema Admins should be near-empty by default. No one carries Tier 0 rights around day to day.
  • Elevate on demand, for a limited time. When an admin needs Tier 0 rights, they request them, get approved, and hold them for a bounded window — after which membership expires automatically. Microsoft's PIM (Privileged Identity Management) does this for Entra; on-prem you can achieve it with tooling or a PAM platform.
  • Grant the minimum scope. JEA means an account gets exactly the commands and targets it needs, not blanket admin.

This is exactly the ground our privileged access management service covers — and it pairs naturally with the credential discipline in our password manager and credential hygiene guide.

07

Detecting Tier Violations and Credential Theft

Tiering reduces the blast radius; monitoring tells you when someone tests the walls. Watch for:

  • Tier 0 accounts logging on to lower-tier devices — a direct violation and a strong compromise signal.
  • Anomalous use of privileged groups — a Domain Admin membership change outside a JIT window.
  • Credential-theft tradecraft — the memory-access and lateral-movement patterns that precede a domain takeover.

Feeding Domain Controller and endpoint logs into a SIEM makes these patterns visible. See our guides to PowerShell logging and detection and Microsoft Sentinel at SMB scale for the practical build-out.

08

A Realistic Rollout for a 50-Person Texas Business

You do not need an enterprise budget to tier. A pragmatic sequence:

  1. Inventory privilege. Find every account in Domain Admins, Enterprise Admins, and local-admin groups across servers. Most SMBs are shocked by how many there are.
  2. Create separate admin accounts per tier. Every admin gets a normal Tier 2 daily-driver account and distinct Tier 1 / Tier 0 admin accounts. Never one account for everything.
  3. Stand up one PAW for Tier 0 administration.
  4. Apply the Deny-logon GPOs to enforce the tier boundaries.
  5. Empty the privileged groups and move to request-based elevation.
  6. Turn on logging and alerting for tier violations.

Done incrementally, this fits inside a normal quarter without disrupting operations.

09

Where to Start

The first concrete step costs nothing: run an audit of who holds Domain Admin and local-admin rights today, and whether any of those accounts are used to log into everyday workstations. That single query usually surfaces the exact flat-privilege path an attacker would use. From there, separating admin accounts by tier is the highest-leverage change you can make.

If you'd rather have it designed and enforced for you, our managed IT services and IT outsourcing teams build tiered administration into Texas SMB environments as standard practice — and it's a core control for organizations pursuing CMMC or SOC 2. Start with a free IT assessment.

10

Geographic Coverage

LayerLogix hardens Active Directory and identity infrastructure for businesses across Texas, including Houston, Dallas, Austin, San Antonio, and The Woodlands. If your admins log into everyday laptops with domain-wide rights, we should talk before an attacker does.

Back to Blog
Keep Reading

Related Articles

Need Expert IT Support?

Let our team help your Houston business with enterprise-grade IT services and cybersecurity solutions.

Call NowBook a Call