Skip to content

Eguibar IT

Over a decade of expertise in Active Directory, infrastructure, and security. Deep dive into AD Tier Model, RBAC and PowerShell automation

  • Home
  • Microsoft
    • Windows Server
      • Static IPv6 Address in Windows Server
    • Active Directory
      • AD Delegation Model (RBAC) – Tier-Based Least‑Privilege Access
        • AD Delegation Model – Admin Area or Tier0
          • Building Admin Area (Tier0)
          • Delegating Admin Area (Tier0)
          • Configuring Admin Area (Tier0) with Powershell
        • Delegation Model – Servers Area or Tier1
        • Delegation Model – Sites Area or Tier2
      • Active Directory Tier Model– Secure Tier‑based Architecture
      • Role Based Access Control
      • PAW – Secure Admin Workstation for AD and Azure
      • Tier Model & Delegation Model questions
    • Hyper-V
  • AD-Paradigm
  • Other Assets
    • Network
    • TCP/IP
  • Powershell
    • Complete Housekeeping by using Powershell
      • New Random Password
      • Powershell Semi-Privileged user provisioning
    • Delegation Model PowerShell Scripts
      • EguibarIT PowerShell Module
      • EguibarIT.Delegation PowerShell Module AD Delegation Automation
      • EguibarIT.Housekeeping PowerShell Module for AD Housekeeping
  • AD Hyper-V LAB
    • Use Hyper-V and Powershell to provision new Virtual Machine
  • About

Category: Delegation Model

The AD Delegation Model  will help us organize and secure our directory. This is done based on standard best practices and security guidance. Main goal is to provide a stable service, while maintaining security.

The model itself is built in top of some, well known recommendations, like Least Privileged Access, Segregation of Duties and 0 Admin model, just to name some.

AD Security Boundary

0 (Zero) Admin Model

Posted on April 3, 2018July 7, 2025 by Vicente Posted in Active Directory, Delegation Model, Security Tagged Active Directory, AD, AD Delegation Model, Pass-the-hash, Pass-the-ticket, Tier Model

A crazy idea? 0 (Zero) Admin Model in your production environment? Personally, I don’t think is crazy. First thing to check when running a security audit, is the number of privileged users. Remember that a privileged user is a member […]

Read More
Least Privileged Access

Least Privileged Access

Posted on November 24, 2017August 14, 2019 by Vicente Posted in Active Directory, Delegation Model, Security Tagged Active Directory, AD Delegation Model, Least Privileged Access, SecurityLeave a Comment on Least Privileged Access

Why 7 if we can do it with 3 Least privileged access is to have nothing more than the permissions you need to complete your task. Every time I get to a new customer, and I need administrative access to […]

Read More

Active Directory Paradigm

Posted on September 27, 2017July 7, 2025 by Vicente Posted in Active Directory, AD Tier Model, Delegation Model, Security Tagged Active Directory, AD, AD Delegation Model, Pass-the-hash, Pass-the-ticket, Tier Model

Active Directory Paradigm Blog Merriam-Webster defines Paradigm as “an outstandingly clear or typical example or archetype. Regard science as the paradigm of true knowledge”. And this is exactly what Active Directory Paradigm blog is about. Of course this is not […]

Read More

Recent Posts

  • 0 (Zero) Admin Model
  • Least Privileged Access
  • Privileged and Semi-Privileged Users
  • Segregation of Duties
  • Logical Perimetral Security

Recent Comments

No comments to show.

Archives

  • April 2018
  • November 2017
  • October 2017
  • September 2017

Categories

  • Active Directory
  • AD Tier Model
  • Delegation Model
  • Security

Copyright 2025. All rights reserved.


Back To Top