An Active Directory tiered administration architecture that structurally breaks credential theft and lateral movement. Clean source principle, Tier 0/1/2 boundaries and logon restrictions, Privileged Access Workstations (PAW), Protected Users group, Authentication Policy Silos, Credential Guard (VBS), and LSA Protection — all in one place. Significantly narrows the attack paths that turn the compromise of a single identity into the compromise of the entire environment.
Technique Library
MITRE ATT&CK-based attack techniques — Exploit · Prevention · Detection
38 techniques