Active › Module 7 › Lesson 1
Tiering PAW
Admin tiering and Privileged Access Workstations (PAW) literacy — reduce blast radius on $LAB_AD and production design discussions.
Visual · t25_tiering_paw
Tiering + PAW = separate admin tiers and hardened workstations. Original Cyberlium.
Opening
Domain Admin from a helpdesk laptop is a design failure — tiering and PAW fix the architecture, not the attacker.
Tiering model literacy: Tier 0 (forest/domain controllers, identity systems), Tier 1 (servers), Tier 2 (workstations/end-user). Privileged Access Workstations (PAW) are dedicated hardened hosts for Tier 0/1 admin tasks — no email, no browsing, strict jump access. Analyst maps why DCSync and ACL paths hurt more when Tier 0 creds touch Tier 2 daily drivers. Defenders: separate admin accounts, deny interactive logon for Tier 0 on lower tiers, deploy PAW or equivalent controls, monitor tier violations (4624 logon type anomalies). Cyberlium teaches tier/PAW design on YOUR $LAB_AD diagrams and architecture notes — NOT bypassing tier controls on stranger domains, NOT using employer workstation as DA login homework. Document one tier violation scenario on lab and the PAW fix.
1. Three tiers
Tier 0: identity/DC — highest protection. Tier 1: servers. Tier 2: users/workstations.
Credential flow should descend tiers only through controlled jump/PAW — not daily driver DA.
Command guide
Try these commands — Three tiers
═══ WINDOWS / POWERSHELL (Active Directory Lab) ═══
Check current user, domain context, and security privileges
Command — copy this
whoami /user /groups /priv
Query active Domain Controller and trust relationships
Command — copy this
nltest /dsgetdc:$env:USERDOMAIN nltest /domain_trusts
List password policy across the domain
Command — copy this
net accounts /domain
Check Kerberos ticket cache
Command — copy this
klist
═══ LINUX / BASH (Lab Network) ═══ Test DNS SRV resolution for Active Directory services
Command — copy this
dig _ldap._tcp.dc._msdcs.lab.local SRV +short dig _kerberos._tcp.dc._msdcs.lab.local SRV +short
Primary tools to practice this lesson: curl, python3. Reference sites: Microsoft PAW (https://learn.microsoft.com/en-us/security/privileged-access-workstations/privileged-access-workstations); Microsoft tiering model (https://learn.microsoft.com/en-us/security/privileged-access-workstations/privileged-access-access-model); CISA AD best practices (https://www.cisa.gov/resources-tools/resources/active-directory-security-best-practices). Run every command in the box — install first, then the usage lines — only on YOUR lab / program scope.
2. PAW purpose
Dedicated admin workstation hardened — reduces malware and token theft on privileged sessions.
Pair with Credential Guard and LSA protection in next lessons.
3. Lab mapping
Sketch $LAB_AD with tier labels on VMs — which host should never hold Tier 0 session.
Finding: helpdesk user in Domain Admins on workstation tier — remediate with tiering split.
4. What you ship: tiering PAW diagram
Tier 0/1/2 definitions + PAW one-liner + lab topology sketch + one violation fix.
5. What you record before the next lesson
Tiering PAW diagram path.
6. Wrong vs right: stranger-domain attacks vs lab AD literacy
Worked failure — same MSF word, opposite target. Right never needs a café Wi-Fi or classmate laptop.
Wrong
Log in Domain Admin on daily driver 'because lab is faster.'
Right
Tiering PAW diagram for $LAB_AD. Next: gMSA SPN Hygiene.
Mission: tiering PAW diagram
1) Define three tiers. 2) Define PAW in one line. 3) Sketch $LAB_AD tier labels. 4) One violation + fix row.
Stuck? Ask Cyberlium AI Mentor
Ask Mentor: “Tier 0 interactive logon deny — GPO literacy?”
Knowledge Check
APPLY: Tier 0 includes:
Multiple choice
Knowledge Check
APPLY: True or False: DA login on Tier 2 workstation is best practice.
True or False
Knowledge Check
APPLY: PAW purpose:
Multiple choice