Skip to main content
Microsoft
separator
https://catalogartifact.azureedge.net/publicartifacts/azuresentinel.azure-sentinel-solution-microsoftadtiermodel-fad2f474-2dc4-460f-aaa2-8b2d8fba01ef/image0_logo.png

Microsoft Active Directory Tier Model

by Microsoft Sentinel, Microsoft Corporation

Need custom pricing or terms? Request a private offer directly from the seller - tailored for your organization.

Microsoft Active Directory Tier Model for Sentinel

Note: Please refer to the following before installing the solution:

• Review the solution Release Notes

• There may be known issues pertaining to this Solution, please refer to them before installing.

The Microsoft Active Directory Tier Model solution for Microsoft Sentinel provides detection, triage automation, and reporting for the Active Directory (AD) administrative tier model - Tier 0 (T0), Tier 1 (T1), and Tier 2 (T2) - across Active Directory Domain Services (AD DS / ADDS). It monitors tier-sensitive changes on Domain Controllers, including group membership, object creation and deletion, ACL modifications, Group Policy (GPO) links and enforcement, organizational unit (OU) changes, block inheritance, domain trusts, child-domain promotion, BitLocker recovery keys, and LAPS activity, using Windows Security Event logs.

The analytic rules dynamically build each alert title from the affected object's tier and type, which keeps the number of rules low instead of duplicating a rule per tier. Automation rules then tag Tier Model incidents and automatically set severity or close expected, low-value activity, and a workbook provides Tier Model metrics.

Important: The analytic rules, automation rules, and workbook are linked by the rule names - each alert title carries a (TMxxx.1) identifier that the automation rules and workbook depend on. Do not rename or modify the default analytic and automation rule names, or the automation rules and workbook will not function correctly.

Prerequisites:

  1. Active Directory Tier Model deployed. This solution monitors an existing Tier Model and expects the standard Tier 0 / Tier 1 / Tier 2 organizational unit (OU) structure (for example, OU=Tier 0 Accounts, OU=Tier 1 Member Servers, OU=Tier 0 PAW, OU=Tier 0 Groups). If your OU names differ, adjust the analytic rule queries to match. To deploy and audit the Tier Model, see the Microsoft Active Directory Tier Model project and its documentation.

  2. Domain Controller telemetry. All Domain Controllers must run as Azure virtual machines or be onboarded to Azure Arc, with a Data Collection Rule (DCR) that collects Security event logs from every Domain Controller into the Microsoft Sentinel workspace.

  3. Automation rules (required). The solution's automation rules are provided as an ARM template in the solution's Playbooks folder (MicrosoftADTierModelAutomationRules) and must be deployed as a required post-installation step for incident tagging, severity assignment, and the workbook to function correctly. See the automation rules README for one-click deployment.

Underlying Microsoft Technologies used:

This solution takes a dependency on the following technologies, and some of these dependencies either may be in Preview state or might result in additional ingestion or operational costs:

  1. Azure Monitor Agent (AMA) and Data Collection Rules

  2. Windows Security Events via AMA

Workbooks: 1, Analytic Rules: 19

Learn more about Microsoft Sentinel | Learn more about Solutions

English (United States)
Your Privacy Choices Opt-Out Icon Your Privacy Choices
Consumer Health Privacy Sitemap Contact Us Privacy & Cookies Terms of Use Trademarks About our ads Manage cookies