Tiered administration separates privilege contexts
The core idea is simple: a credential that controls everything should never be typed into a machine that is not equally protected.
Administrators get separate accounts for separate tiers, and the powerful ones are only ever used from hardened systems. It is the single most effective structural defence against the pattern where one phished workstation ends up with domain administrator. It is also disruptive to adopt, which is why it is widely recommended and unevenly implemented.
More on Windows and Active Directory
- Domain Admin is a forest-scale keyOne root under the whole forest
- Kerberos tickets are credentialsWhoever holds it, gets in
- Golden Ticket attacks target the ticket authorityThey took the press, not a ticket
- Group Policy is a fleet control planeOne dial, every desk
- LAPS reduces shared local-admin secretsOne secret, or one each
- NTLM fallback preserves older trust assumptionsThe hatch nobody bricked up
