Privileged access in Active Directory: tiers, admin accounts and protected groups
How Microsoft's enterprise access model grew out of the AD tier model, why Tier 0 (the control plane) must never be exposed to lower tiers, how to run with separate admin accounts and empty Domain Admins, what Protected Users and AdminSDHolder actually do, and the supporting controls: Windows LAPS, gMSAs, krbtgt resets and membership reviews.
- Level
- Advanced
- Length
- About 75 minutes
- Contents
- 4 lessons · final exam
- Status
- Published · updated 1 Oct 2026
Skills you'll practise
- Classify systems and accounts into the control plane (Tier 0), management/workload planes and user access, and explain why control must never flow upward
- Design day-to-day administration that uses separate admin accounts, delegation and temporary membership instead of standing Domain Admins or Enterprise Admins
- Explain what the Protected Users group and AdminSDHolder/SDProp do, including the side effects that cause lockouts or broken delegation
- Choose the right control for local admin and service account passwords (Windows LAPS, gMSA) and for a krbtgt password reset
- Review privileged group membership and record findings and changes so they can be audited
Course outline
- 1.From the AD tier model to the enterprise access modelLesson · 18 min
- 2.Admin accounts, privileged groups and privileged access workstationsLesson · 20 min
- 3.Protected Users, AdminSDHolder and their side effectsLesson · 17 min
- 4.Local admin, service accounts, krbtgt and reviewsLesson · 20 min
- 5.Privileged access in Active Directory: tiers, admin accounts and protected groups: knowledge checkKnowledge check · 14 questions
- 6.Privileged access in Active Directory: tiers, admin accounts and protected groups: practical exerciseKnowledge check · 1 question
- 7.Final exam8 questions · passing it completes the course, so people who already know the material can test out
Sources it draws on
The lessons and questions are written from these references, so learners can go back to the original.
- Microsoft Learn: Securing privileged access: enterprise access model
- Microsoft Learn: Why are privileged access devices important
- Microsoft Learn: Implementing least-privilege administrative models
- Microsoft Learn: Active Directory privileged accounts and groups guide (Appendix B)
- Microsoft Learn: Appendix C: Protected accounts and groups in Active Directory
- Microsoft Learn: Appendix E: Securing Enterprise Admins groups in Active Directory
- Microsoft Learn: Protected Users security group
- Microsoft Learn: Five common questions about AdminSdHolder and SDProp (archived AskDS blog)
- Microsoft Learn: AD forest recovery: reset the krbtgt password
- Microsoft Learn: Group Managed Service Accounts overview
- Microsoft Learn: Windows LAPS overview
See it with your own jobs and topics
Tell us about your team and we'll walk you through setup, from choosing jobs to your first skills check.