What it does. Implement Microsoft's Enhanced Security Admin Environment (ESAE) tiered Part of mukul975/Anthropic-Cybersecurity-Skills (817 security skills) (mukul975/Anthropic-Cybersecurity-Skills).
Install
npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill configuring-active-directory-tiered-model, or copy the skill folder into ~/.claude/skills/configuring-active-directory-tiered-model/.
- Raw file:
curl -sL https://raw.githubusercontent.com/mukul975/Anthropic-Cybersecurity-Skills/HEAD/skills/configuring-active-directory-tiered-model/SKILL.md
SKILL.md (verbatim)
name: configuring-active-directory-tiered-model
description: Implement Microsoft's Enhanced Security Admin Environment (ESAE) tiered
administration model for Active Directory, covering Tier 0/1/2 separation, privileged
access workstations (PAWs), administrative forest design, and authentication policy
silos. Use when designing or hardening AD privileged-access architecture, segmenting
Domain/Enterprise Admin accounts into tiers, or containing lateral movement and
credential theft (pass-the-hash, Kerberoasting, golden tickets).
domain: cybersecurity
subdomain: identity-access-management
tags:
- iam
- identity
- access-control
- active-directory
- tiered-model
- paw
- esae
version: '1.0'
author: mahipal
license: Apache-2.0
nist_csf:
- PR.AA-01
- PR.AA-02
- PR.AA-05
- PR.AA-06
mitre_attack:
- T1078.002
- T1550.002
- T1550.003
- T1003.001
- T1021
Configuring Active Directory Tiered Model
Overview
Implement Microsoft's Enhanced Security Admin Environment (ESAE) tiered administration model for Active Directory. Covers Tier 0/1/2 separation, privileged access workstations (PAWs), administrative forest design, authentication policy silos, and credential theft mitigation.
When to Use
- When deploying or configuring configuring active directory tiered model capabilities in your environment
- When establishing security controls aligned to compliance requirements
- When building or improving security architecture for this domain
- When conducting security assessments that require this implementation
Prerequisites
- Familiarity with identity access management concepts and tools
- Access to a test or lab environment for safe execution
- Python 3.8+ with required dependencies installed
- Appropriate authorization for any testing activities
Objectives
- Implement comprehensive configuring active directory tiered model capability
- Establish automated discovery and monitoring processes
- Integrate with enterprise IAM and security tools
- Generate compliance-ready documentation and reports
- Align with NIST 800-53 access control requirements
Security Controls
| Control |
NIST 800-53 |
Description |
| Account Management |
AC-2 |
Lifecycle management |
| Access Enforcement |
AC-3 |
Policy-based access control |
| Least Privilege |
AC-6 |
Minimum necessary permissions |
| Audit Logging |
AU-3 |
Authentication and access events |
| Identification |
IA-2 |
User and service identification |
Verification
Other files in this skill
references/api-reference.md (verbatim)
Active Directory Tiered Model — API Reference
Libraries
| Library |
Install |
Purpose |
| ldap3 |
pip install ldap3 |
LDAP queries for AD group and account enumeration |
| pyad |
pip install pyad |
Windows AD object manipulation |
Key ldap3 Methods
| Method |
Description |
Connection(server, user, password, authentication=NTLM) |
NTLM-authenticated LDAP bind |
conn.search(base_dn, filter, attributes) |
Search AD objects |
conn.entries |
Result entries from search |
AD Tier Definitions (Microsoft ESAE)
| Tier |
Assets |
Admin Accounts |
| Tier 0 |
Domain Controllers, AD, PKI, ADFS |
Domain Admins, Enterprise Admins |
| Tier 1 |
Member servers, applications |
Server admins, app admins |
| Tier 2 |
Workstations, end users |
Help desk, workstation admins |
Critical AD Groups (Tier 0)
| Group |
SID Suffix |
| Domain Admins |
-512 |
| Enterprise Admins |
-519 |
| Schema Admins |
-518 |
| Administrators |
-544 |
| Account Operators |
-548 |
| Backup Operators |
-551 |
UserAccountControl Flags
| Flag |
Value |
Description |
| ACCOUNTDISABLE |
0x2 |
Account is disabled |
| DONT_EXPIRE_PASSWORD |
0x10000 |
Password never expires |
| NOT_DELEGATED |
0x100000 |
Account is sensitive for delegation |
External References
Back to mukul975/Anthropic-Cybersecurity-Skills (817 security skills) or Agent skills.