Microsoft Active Directory Tier Model

Microsoft Active Directory Tier Model Logo

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

Back to Solutions Index


Attribute Value
Publisher Microsoft Corporation
Support Tier Microsoft
Support Link https://support.microsoft.com
Categories Identity,Security - Threat Protection
Version 3.0.0
Author Microsoft - support@microsoft.com
First Published 2026-07-14
Last Updated 2026-07-31
Solution Folder Microsoft Active Directory Tier Model
Marketplace Azure Marketplace · Popularity: ⚪ Very Low (0%)

The Microsoft Active Directory Tier Model solution for Microsoft Sentinel provides detection, triage automation, and reporting for the Active Directory (AD) administrative tier model - Tier 0 (T0), Tier 1 (T1), and Tier 2 (T2) - across Active Directory Domain Services (AD DS / ADDS). It monitors tier-sensitive changes on Domain Controllers, including group membership, object creation and deletion, ACL modifications, Group Policy (GPO) links and enforcement, organizational unit (OU) changes, block inheritance, domain trusts, child-domain promotion, BitLocker recovery keys, and LAPS activity, using Windows Security Event logs.

The analytic rules dynamically build each alert title from the affected object's tier and type, which keeps the number of rules low instead of duplicating a rule per tier. Automation rules then tag Tier Model incidents and automatically set severity or close expected, low-value activity, and a workbook provides Tier Model metrics.

Important: The analytic rules, automation rules, and workbook are linked by the rule names - each alert title carries a (TMxxx.1) identifier that the automation rules and workbook depend on. Do not rename or modify the default analytic and automation rule names, or the automation rules and workbook will not function correctly.

Prerequisites:

  1. Active Directory Tier Model deployed. This solution monitors an existing Tier Model and expects the standard Tier 0 / Tier 1 / Tier 2 organizational unit (OU) structure (for example, OU=Tier 0 Accounts, OU=Tier 1 Member Servers, OU=Tier 0 PAW, OU=Tier 0 Groups). If your OU names differ, adjust the analytic rule queries to match. To deploy and audit the Tier Model, see the Microsoft Active Directory Tier Model project and its documentation.

  2. Domain Controller telemetry. All Domain Controllers must run as Azure virtual machines or be onboarded to Azure Arc, with a Data Collection Rule (DCR) that collects Security event logs from every Domain Controller into the Microsoft Sentinel workspace.

  3. Automation rules (required). The solution's automation rules are provided as an ARM template in the solution's Playbooks folder (MicrosoftADTierModelAutomationRules) and must be deployed as a required post-installation step for incident tagging, severity assignment, and the workbook to function correctly. See the automation rules README for one-click deployment.

Underlying Microsoft Technologies used:

This solution takes a dependency on the following technologies, and some of these dependencies either may be in Preview state or might result in additional ingestion or operational costs:

  1. Azure Monitor Agent (AMA) and Data Collection Rules

  2. Windows Security Events via AMA

Contents

Data Connectors

This solution does not include data connectors.

This solution may contain other components such as analytics rules, workbooks, hunting queries, or playbooks.

Tables Used

This solution queries 1 table(s) from its content items:

Table Used By Content
SecurityEvent Analytics

Internal Tables

The following 2 table(s) are used internally by this solution's content items:

Table Used By Content
SecurityAlert Workbooks
SecurityIncident Workbooks

Content Items

This solution includes 21 content item(s) (20 in solution, 1 discovered 🔍):

Content Type Total In Solution Discovered
Analytic Rules 19 19 -
Workbooks 2 1 1

Analytic Rules

Name Severity Tactics Tables Used
PROD (TM001.1) - GROUP - Added to Group Outside the Object Tier Level High PrivilegeEscalation SecurityEvent
PROD (TM002.1) - OBJECT - Created or Deleted a Tier Level Object Low InitialAccess SecurityEvent
PROD (TM003.1) - OBJECT - Moved or Recovered a Tier Level Account Medium Persistence SecurityEvent
PROD (TM004.1) - OBJECT - Enabled, Disabled, Unlocked, or Password Reset of a Tier Level Object High Persistence SecurityEvent
PROD (TM005.1) - GPO - Linked, Unlinked, or Enforced at Tier Level OU High DefenseEvasion SecurityEvent
PROD (TM006.1) - ACL - Modified at Tier Level OU High DefenseEvasion SecurityEvent
PROD (TM007.1) - OU - Created or Deleted at Tier Level High DefenseEvasion SecurityEvent
PROD (TM008.1) - GPO - Linked, Unlinked, or Enforced at Root of Domain High DefenseEvasion SecurityEvent
PROD (TM009.1) - ACL - Modified at Root of the Domain High DefenseEvasion SecurityEvent
PROD (TM010.1) - BITLOCKER - Stored Bitlocker Recovery Key to Tier Level Computer Object Informational CredentialAccess SecurityEvent
PROD (TM011.1) - LAPS - Tier Level Computer Object LAPS Password Expiration Time Set Manually Low Discovery SecurityEvent
PROD (TM012.1) - GPO - Enforced Outside of Tier Model High DefenseEvasion SecurityEvent
PROD (TM013.1) - OU - Block Inheritance was Enabled on an OU High DefenseEvasion SecurityEvent
PROD (TM014.1) - GPO - Linked, Unlinked, or Enforced at the AD Site Level High DefenseEvasion SecurityEvent
PROD (TM015.1) - ACL - Modified at KRBTGT or AdminSDHolder Object Level High Persistence SecurityEvent
PROD (TM016.1) - GROUP - Added to Well-Known or Tier Model Group High PrivilegeEscalation SecurityEvent
PROD (TM017.1) - GROUP - Tier 0 Added to Allow RODC Password Replication Group High PrivilegeEscalation SecurityEvent
PROD (TM018.1) - DOMAIN - Child Domain promoted within the Forest High PrivilegeEscalation SecurityEvent
PROD (TM019.1) - TRUST - A new AD Trust has been established High PrivilegeEscalation SecurityEvent

Workbooks

Name Tables Used
MicrosoftADTierModel Internal use:
SecurityAlert
SecurityIncident
workbooksMetadata ⚠️ -

⚠️ Items marked with ⚠️ are not listed in the Solution JSON file. They were discovered by scanning the solution folder and may be legacy items, under development, or excluded from the official solution package.

Additional Documentation

📄 Source: Microsoft Active Directory Tier Model/README.md

Overview


Microsoft Sentinel: Microsoft Active Directory Tier Model Solution

The Microsoft Active Directory Tier Model solution for Microsoft Sentinel provides detection, triage automation, and reporting for the Active Directory (AD) administrative tier model - Tier 0 (T0), Tier 1 (T1), and Tier 2 (T2) - across Active Directory Domain Services (AD DS / ADDS). It monitors tier-sensitive changes on Domain Controllers using Windows Security Event logs, tags and triages the resulting incidents with automation rules, and visualizes Tier Model activity in a workbook.

This solution contains:

Try on Portal

You can deploy the solution by clicking on the buttons below:

Workbook Overview

Getting Started

This solution monitors an existing Active Directory Tier Model deployment. Without the Tier Model deployed, the analytic rules will not match any activity and the solution provides no value. The rules key off the standard Tier 0 / Tier 1 / Tier 2 organizational unit (OU) structure (for example OU=Tier 0 Accounts, OU=Tier 1 Member Servers, OU=Tier 0 PAW, OU=Tier 0 Groups).

Important - do not rename the default rule names. The analytic rules, automation rules, and workbook are tied together by the rule names. Each analytic rule stamps its alert title with a (TMxxx.1) identifier (for example (TM002.1)), and that identifier is the shared key across all three components:

Because the analytic rule number, the automation rule, and the alert name are all linked, renaming or modifying the default names will break the automation rules and the workbook. Keep the default names as shipped. If you must customize a rule, preserve its (TMxxx.1) prefix so the dependencies continue to function.

[Content truncated...]

Release Notes

Version Date Modified (DD-MM-YYYY) Change History
3.0.0 14-07-2026 Initial solution release

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

Back to Solutions Index