Deploy, audit and maintain an Active Directory tier model — from one script and one JSON file.
wizard ──▶ config/tiermodel.json ◀── the source of truth
│ │ │
deploy │ audit │ sync │
▼ ▼ ▼
converges reports keeps membership
the directory drift current
A guided wizard asks for your naming convention, previews every object it would create and writes one configuration file. From then on that file is the source of truth: Deploy converges the directory to it, Audit reports every drift, Sync keeps memberships current. Everything is idempotent, and nothing is written without a plan first. One PowerShell script, one JSON file - no module, no build step.
Caution
Logon rights are tattooed. Disabling a GPO link does not give a removed logon right back.
Never enable the logon restrictions on a domain controller without a second way in (console,
another machine, DSRM). Repair-TierLockout.ps1 is the way back.
Warning
Lab-tested, not production-tested. Run end to end against a Windows Server 2025 lab domain, never against a production directory. Take a system state backup of a DC before the first enforced deployment.
Note
Built with AI assistance. Requirements defined and reviewed by a human, most of the code and documentation written by an AI model. Review it before running it in production.
- Structure - a tier OU tree, AGDLP groups, template and break-glass accounts, and delegation
that lets each tier administer only its own branch (no
WriteDacl, noWriteOwner). - Isolation - per-tier logon restriction GPOs, a Domain Controller baseline, Kerberos authentication policy silos and a neutral staging OU for machines not yet classified.
- Hardening - Windows LAPS (DSRM included),
MachineAccountQuota, Recycle Bin, KDS root key, SACL auditing, Kerberos armoring. - Audit - privileged group membership, object ownership, undeclared access group members, and the attack paths into Tier 0: DCSync rights, dangerous ACEs, editable Tier 0 GPOs, RBCD, Kerberoastable admins, krbtgt age.
- Upkeep - a daily sync task (optionally signed and configuration-pinned), run-over-run reports that show what is new, and a lockout recovery script.
Requires domain functional level 2012 R2+ (2016+ recommended), the ActiveDirectory and
GroupPolicy modules and an elevated session as Domain Admin.
Get-ChildItem C:\ADTierKit -Recurse | Unblock-File
cd C:\ADTierKit
.\ADTierKit.ps1 # wizard: naming, preview, configuration
.\ADTierKit.ps1 -Mode Check # prerequisites
.\ADTierKit.ps1 -Mode Deploy # plan only - nothing is written
.\ADTierKit.ps1 -Mode Deploy -Apply -Stage RecycleBin,OU,Domain,Group,Nesting,Account,Delegation,Auditing
.\ADTierKit.ps1 -Mode Deploy -Apply -Stage GPO,Laps,KDS,Silo
.\ADTierKit.ps1 -Mode Audit # read-only drift and attack path report
.\ADTierKit.ps1 -Mode InstallTask # daily Sync as SYSTEMUpgrading an existing configuration: run .\Update-TierConfiguration.ps1 first, then plan a deploy.
| Mode | Writes | Purpose |
|---|---|---|
| (none) | Interactive wizard - start here | |
Deploy |
Converges the directory. Plans by default, writes only with -Apply |
|
Audit |
— | Read-only drift, hygiene and attack path report |
Sync |
✅ | Membership, account hygiene and silo assignment - safe to schedule |
InstallTask |
✅ | Registers the daily Sync task |
Check |
— | Prerequisite check |
-Apply · ✅ writes · — read-only. Exit codes and every option: see the Guide.
| Guide | The complete reference - what gets deployed, roles, ownership, guardrails, configuration, reports, troubleshooting, recovery |
| Operator's Guide | The walkthrough - every setting the tool writes, day-to-day work, the rollout playbook |
| Changelog | What changed in each release |
