Hello
In Active Directory (AD), an object is considered part of Tier 0 if it meets the following criteria:
Direct or Indirect Administrative Control: The object should have direct or indirect administrative control of the Active Directory forest, domains, or domain controllers.
Control Over All Assets: The object should have control over all the assets in the AD environment.
Domain Control Groups: Objects that maintain full control of a domain or have the (effectively) irrevocable ability to gain access to those groups. This includes the domain head object, built-in administrator accounts, domain admins, domain controllers, schema and enterprise admins, enterprise domain controllers, key and enterprise key admins, and administrators overall.
Remember, the security sensitivity of all Tier 0 assets is equivalent as they are all effectively in control of each other. The final Tier 0 group will be custom to each organization. It’s important to inspect any privileged group membership in AD to identify any nested groups, since group permissions are inherited.