Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊
| Attribute | Value |
|---|---|
| Publisher | Microsoft Corporation |
| Support Tier | Microsoft |
| Support Link | https://support.microsoft.com |
| Categories | Identity,Security - Threat Protection |
| Version | 3.0.0 |
| Author | Microsoft - support@microsoft.com |
| First Published | 2026-07-14 |
| Last Updated | 2026-07-31 |
| Solution Folder | Microsoft Active Directory Tier Model |
| Marketplace | Azure Marketplace · Popularity: ⚪ Very Low (0%) |
The Microsoft Active Directory Tier Model solution for Microsoft Sentinel provides detection, triage automation, and reporting for the Active Directory (AD) administrative tier model - Tier 0 (T0), Tier 1 (T1), and Tier 2 (T2) - across Active Directory Domain Services (AD DS / ADDS). It monitors tier-sensitive changes on Domain Controllers, including group membership, object creation and deletion, ACL modifications, Group Policy (GPO) links and enforcement, organizational unit (OU) changes, block inheritance, domain trusts, child-domain promotion, BitLocker recovery keys, and LAPS activity, using Windows Security Event logs.
The analytic rules dynamically build each alert title from the affected object's tier and type, which keeps the number of rules low instead of duplicating a rule per tier. Automation rules then tag Tier Model incidents and automatically set severity or close expected, low-value activity, and a workbook provides Tier Model metrics.
Important: The analytic rules, automation rules, and workbook are linked by the rule names - each alert title carries a (TMxxx.1) identifier that the automation rules and workbook depend on. Do not rename or modify the default analytic and automation rule names, or the automation rules and workbook will not function correctly.
Prerequisites:
Active Directory Tier Model deployed. This solution monitors an existing Tier Model and expects the standard Tier 0 / Tier 1 / Tier 2 organizational unit (OU) structure (for example, OU=Tier 0 Accounts, OU=Tier 1 Member Servers, OU=Tier 0 PAW, OU=Tier 0 Groups). If your OU names differ, adjust the analytic rule queries to match. To deploy and audit the Tier Model, see the Microsoft Active Directory Tier Model project and its documentation.
Domain Controller telemetry. All Domain Controllers must run as Azure virtual machines or be onboarded to Azure Arc, with a Data Collection Rule (DCR) that collects Security event logs from every Domain Controller into the Microsoft Sentinel workspace.
Automation rules (required). The solution's automation rules are provided as an ARM template in the solution's Playbooks folder (MicrosoftADTierModelAutomationRules) and must be deployed as a required post-installation step for incident tagging, severity assignment, and the workbook to function correctly. See the automation rules README for one-click deployment.
Underlying Microsoft Technologies used:
This solution takes a dependency on the following technologies, and some of these dependencies either may be in Preview state or might result in additional ingestion or operational costs:
This solution does not include data connectors.
This solution may contain other components such as analytics rules, workbooks, hunting queries, or playbooks.
This solution queries 1 table(s) from its content items:
| Table | Used By Content |
|---|---|
SecurityEvent |
Analytics |
The following 2 table(s) are used internally by this solution's content items:
| Table | Used By Content |
|---|---|
SecurityAlert |
Workbooks |
SecurityIncident |
Workbooks |
This solution includes 21 content item(s) (20 in solution, 1 discovered 🔍):
| Content Type | Total | In Solution | Discovered |
|---|---|---|---|
| Analytic Rules | 19 | 19 | - |
| Workbooks | 2 | 1 | 1 |
| Name | Tables Used |
|---|---|
| MicrosoftADTierModel | Internal use:SecurityAlertSecurityIncident |
| workbooksMetadata ⚠️ | - |
⚠️ Items marked with ⚠️ are not listed in the Solution JSON file. They were discovered by scanning the solution folder and may be legacy items, under development, or excluded from the official solution package.
The Microsoft Active Directory Tier Model solution for Microsoft Sentinel provides detection, triage automation, and reporting for the Active Directory (AD) administrative tier model - Tier 0 (T0), Tier 1 (T1), and Tier 2 (T2) - across Active Directory Domain Services (AD DS / ADDS). It monitors tier-sensitive changes on Domain Controllers using Windows Security Event logs, tags and triages the resulting incidents with automation rules, and visualizes Tier Model activity in a workbook.
This solution contains:
You can deploy the solution by clicking on the buttons below:

This solution monitors an existing Active Directory Tier Model deployment. Without the Tier Model deployed, the analytic rules will not match any activity and the solution provides no value. The rules key off the standard Tier 0 / Tier 1 / Tier 2 organizational unit (OU) structure (for example OU=Tier 0 Accounts, OU=Tier 1 Member Servers, OU=Tier 0 PAW, OU=Tier 0 Groups).
Important - do not rename the default rule names. The analytic rules, automation rules, and workbook are tied together by the rule names. Each analytic rule stamps its alert title with a
(TMxxx.1)identifier (for example(TM002.1)), and that identifier is the shared key across all three components:
- The automation rules match incidents by the
(TMxxx.1)title tag to apply tagging, severity changes, and closures.- The workbook filters and groups Tier Model incidents by these alert names.
Because the analytic rule number, the automation rule, and the alert name are all linked, renaming or modifying the default names will break the automation rules and the workbook. Keep the default names as shipped. If you must customize a rule, preserve its
(TMxxx.1)prefix so the dependencies continue to function.
[Content truncated...]
| Version | Date Modified (DD-MM-YYYY) | Change History |
|---|---|---|
| 3.0.0 | 14-07-2026 | Initial solution release |
Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊