How to properly organize my Tier Modeling, how does this work?

TechQ 236 Reputation points
2023-05-05T12:51:32.34+00:00

I am planning to use tier for my active directory, i have done many research on it, but I am confused how it actually work.

So what I was thinking is that, can you make tier 0-10 or more? Lets say I have 10 server in 10 different location with different network. Which is basiclly branch. So since I want to assign all location to have administrative work done, i have people there to get in server and do their work, but they can also get in different location server which I want to stop them from having those access.

What should I do to configure this?

i notice people organizeed their tier like:

Tier 0,1,2

  • Group

-device

-service account

  • Computer

And so on, but i am also lost here, I was saying where do they have the location (branch) and other stuff like all the users etc?

If tier 0 only allow administrators to just join this server, then what happen when you have mutilple server? Do you also make another tier with different Administration and assigned them what to do?

Please help me understand this tier situation, thank you.

And please dont send Microsoft learning documents, as it goes over my head. If possible please share a link where it shows me step by step how to configure tier and how does professional have them in there main Active Directory.

Pictures with configuration would have help me better understand.

I am using window server 2022

Thank you.

Windows for business | Windows Client for IT Pros | Directory services | Active Directory
Windows for business | Windows Server | User experience | Other
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. Limitless Technology 44,766 Reputation points
    2023-05-09T11:34:47.5066667+00:00

    Hello

    Thank you for your question and reaching out.

    The legacy tier model, which was aimed at preventing unauthorised privilege escalation in an on-premises Windows Server Active Directory system, is superseded and replaced by the enterprise access model.

    These components, as well as the complete access management needs of a contemporary organisation that cover on-premises, various clouds, internal or external user access, and more, are all included in the enterprise access model.

    https://learn.microsoft.com/en-us/security/privileged-access-workstations/privileged-access-access-model

    https://learn.microsoft.com/en-us/microsoft-identity-manager/pam/tier-model-for-partitioning-administrative-privileges

    --If the reply is helpful, please Upvote and Accept as answer--

    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.