{"id":1008007,"date":"2026-09-02T14:16:46","date_gmt":"2026-09-02T12:16:46","guid":{"rendered":"https:\/\/www.teal-consulting.de\/2026\/09\/02\/tiering-ist-nicht-tot\/"},"modified":"2026-09-24T09:42:52","modified_gmt":"2026-09-24T07:42:52","slug":"tiering-isnt-dead","status":"publish","type":"post","link":"https:\/\/www.teal-consulting.de\/en\/2026\/09\/02\/tiering-isnt-dead\/","title":{"rendered":"Microsoft is backtracking: Tiering isn&#8217;t dead\u2014it&#8217;s essential for survival"},"content":{"rendered":"<div class=\"wpb-content-wrapper\">[vc_row css_animation=&#8221;&#8221; row_type=&#8221;row&#8221; use_row_as_full_screen_section=&#8221;no&#8221; type=&#8221;full_width&#8221; angled_section=&#8221;no&#8221; text_align=&#8221;left&#8221; background_image_as_pattern=&#8221;without_pattern&#8221;][vc_column][vc_empty_space height=&#8221;30&#8243;][vc_row_inner row_type=&#8221;row&#8221; type=&#8221;full_width&#8221; text_align=&#8221;left&#8221; css_animation=&#8221;&#8221;][vc_column_inner][vc_column_text][\/vc_column_text][\/vc_column_inner][\/vc_row_inner][\/vc_column][\/vc_row][vc_row css_animation=&#8221;&#8221; row_type=&#8221;row&#8221; use_row_as_full_screen_section=&#8221;no&#8221; type=&#8221;full_width&#8221; angled_section=&#8221;no&#8221; text_align=&#8221;left&#8221; background_image_as_pattern=&#8221;without_pattern&#8221;][vc_column][vc_empty_space height=&#8221;50&#8243;][vc_row_inner row_type=&#8221;row&#8221; type=&#8221;full_width&#8221; text_align=&#8221;left&#8221; css_animation=&#8221;&#8221;][vc_column_inner][vc_column_text css=&#8221;&#8221;]<strong>Microsoft releases an Active Directory Tier Model on GitHub. To many, this sounds like just another tool. For us, it\u2019s official proof of something we\u2019ve been saying for years: if you don\u2019t strictly isolate your privileged identities, you\u2019re playing with complete system outage.<\/strong><\/p>\n<p>A few years ago, it sounded as if the classic ESAE or tiering model was on its way out. Cloud, Zero Trust, modern identity platforms, new security architectures. Everything was supposed to become more modern, flexible, and less &#8220;legacy.&#8221;<\/p>\n<p>And yes, the cloud has changed a lot. Entra ID, Conditional Access, modern authentication, Privileged Identity Management, and Zero Trust are essential building blocks of a modern security architecture. But the core question remains the same:<\/p>\n<p><span style=\"color: #008081;\"><strong>Who is actually allowed to access what, and what happens if that exact identity is compromised?<\/strong><\/span><\/p>\n<p>That is precisely why the new <a href=\"https:\/\/github.com\/microsoft\/ActiveDirectoryTierModel\" target=\"_blank\" rel=\"noopener\">Active Directory Tier Model from Microsoft<\/a> (published on GitHub) is so exciting. Microsoft provides a declarative PowerShell framework designed to <strong>deploy and audit an Active Directory tiering model for Tier 0, Tier 1, and Tier 2<\/strong>. The repository describes OUs, groups, users, ACL delegations, GPOs, ADMX, Managed Service Accounts, Windows LAPS permissions, idempotent re-runs, drift detection, and reproducible builds via a versioned JSON configuration.<\/p>\n<p>Or in less technical terms: <strong>Microsoft is bringing tiering prominently back onto the stage.<\/strong><\/p>\n<p>And that is no minor side note. It\u2019s a very clear statement.[\/vc_column_text][\/vc_column_inner][\/vc_row_inner][\/vc_column][\/vc_row][vc_row css_animation=&#8221;&#8221; row_type=&#8221;row&#8221; use_row_as_full_screen_section=&#8221;no&#8221; type=&#8221;full_width&#8221; angled_section=&#8221;no&#8221; text_align=&#8221;left&#8221; background_image_as_pattern=&#8221;without_pattern&#8221;][vc_column][vc_empty_space height=&#8221;50&#8243;][vc_row_inner row_type=&#8221;row&#8221; type=&#8221;full_width&#8221; text_align=&#8221;left&#8221; css_animation=&#8221;&#8221;][vc_column_inner][vc_column_text css=&#8221;&#8221;]\n<h2>Tiering Was Never Really Gone<\/h2>\n[\/vc_column_text][vc_empty_space height=&#8221;20&#8243;][vc_column_text css=&#8221;&#8221;]When looking at the discussions around ESAE, Red Forest, and tiering, a lot has been mixed up over recent years. In our earlier article <a href=\"https:\/\/www.teal-consulting.de\/en\/2022\/02\/28\/esae-is-dead\/\" target=\"_blank\" rel=\"noopener\">ESAE is dead \u2013 Long live SAE, or do the dead live longer?<\/a>, we put this confusion into perspective: Microsoft re-evaluated ESAE within the context of the Red Forest model, but the underlying security principles remained fully relevant. From TEAL\u2019s perspective, securing Tier-0 systems, privileged identities, and administrative access paths remains absolutely paramount.<\/p>\n<p>The new Microsoft project re-emphasizes this point very clearly. Tiering is not a nostalgic on-premise idea from old Active Directory days\u2014tiering is a fundamental security principle.<\/p>\n<p>It\u2019s about separating critical systems, identities, and administrative privileges in a way that prevents a compromised client from automatically becoming the first step toward Domain Admin.<\/p>\n<p><strong><u>Typical examples:<\/u><\/strong><\/p>\n<ul>\n<li style=\"list-style-type: none;\">\n<ul>\n<li>A Tier-0 admin does not log in to a standard client machine.<\/li>\n<li>Highly privileged credentials are not left behind on unsecure systems.<\/li>\n<li>Critical identity systems receive maximum protection.<\/li>\n<li>Permissions are deliberately modeled rather than grown historically.<\/li>\n<li>Attack paths between tiers are exposed and minimized.<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n[\/vc_column_text][vc_empty_space height=&#8221;20&#8243;][vc_column_text css=&#8221;&#8221;]We described this exact core concept in our article <a href=\"https:\/\/www.teal-consulting.de\/en\/2024\/10\/16\/data-security-with-tiering\/\" target=\"_blank\" rel=\"noopener\">Data Security Through Tiering \u2013 Protection at Every Level<\/a>: Microsoft Tiering divides IT systems into different levels to separate highly critical systems from less critical resources and make it harder for attackers to move through the environment.[\/vc_column_text][\/vc_column_inner][\/vc_row_inner][\/vc_column][\/vc_row][vc_row css_animation=&#8221;&#8221; row_type=&#8221;row&#8221; use_row_as_full_screen_section=&#8221;no&#8221; type=&#8221;full_width&#8221; angled_section=&#8221;no&#8221; text_align=&#8221;left&#8221; background_image_as_pattern=&#8221;without_pattern&#8221;][vc_column][vc_empty_space height=&#8221;50&#8243;][vc_row_inner row_type=&#8221;row&#8221; type=&#8221;full_width&#8221; text_align=&#8221;left&#8221; css_animation=&#8221;&#8221;][vc_column_inner][vc_column_text css=&#8221;&#8221;]\n<h2>The Problem: Excessive Rights, Lack of Structure<\/h2>\n[\/vc_column_text][vc_empty_space height=&#8221;20&#8243;][vc_column_text css=&#8221;&#8221;]In theory, tiering sounds logical&#8230; in practice, reality often looks very different. Many organizations have Active Directory structures that grew organically over years, legacy groups, old service accounts, local administrator privileges, special permissions, and &#8220;temporary&#8221; exceptions that were never revoked. The result is rarely a clean tiering model, but rather a tangled carpet of permissions. <strong>And that is precisely what attackers love.<\/strong><\/p>\n<p>An attack doesn&#8217;t need to start directly on the Domain Controller. Often, a single compromised client, an overly powerful local admin, a poorly secured server, or an account with access where it shouldn&#8217;t have it is enough. <strong>A small problem quickly becomes an attack path.<\/strong><\/p>\n<p><span style=\"color: #008081;\"><strong>And in the worst case, an attack path leads to a full compromise of the entire environment.<\/strong><\/span><\/p>\n<p>The danger rarely lies in a single misconfiguration alone. It becomes dangerous when multiple seemingly minor weaknesses combine into a chain. This exact perspective plays a central role in Attack Path Management, as we previously highlighted in the context of <a href=\"https:\/\/www.teal-consulting.de\/en\/?p=1007929\" target=\"_blank\" rel=\"noopener\">BloodHound OpenGraph<\/a>: The crucial question is not just whether an individual system is secure, but which chain of identities, permissions, and trust relationships leads to critical systems.[\/vc_column_text][\/vc_column_inner][\/vc_row_inner][\/vc_column][\/vc_row][vc_row css_animation=&#8221;&#8221; row_type=&#8221;row&#8221; use_row_as_full_screen_section=&#8221;no&#8221; type=&#8221;full_width&#8221; angled_section=&#8221;no&#8221; text_align=&#8221;left&#8221; background_image_as_pattern=&#8221;without_pattern&#8221;][vc_column][vc_empty_space height=&#8221;50&#8243;][vc_row_inner row_type=&#8221;row&#8221; type=&#8221;full_width&#8221; text_align=&#8221;left&#8221; css_animation=&#8221;&#8221;][vc_column_inner][vc_column_text css=&#8221;&#8221;]\n<h2><span class=\"TextRun SCXW48580129 BCX0\" lang=\"EN-US\" xml:lang=\"EN-US\" data-contrast=\"auto\"><span class=\"NormalTextRun SCXW48580129 BCX0\" data-ccp-parastyle=\"heading 2\">What Microsoft Is Actually Delivering <\/span><\/span><\/h2>\n[\/vc_column_text][vc_empty_space height=&#8221;20&#8243;][vc_column_text css=&#8221;&#8221;]With the new Active Directory Tier Model, Microsoft isn&#8217;t delivering a magical &#8220;one-click and everything is secure&#8221; product.<\/p>\n<p>However, Microsoft is providing a framework that makes many technical tasks surrounding the design, deployment, and auditing of a tiering model far more structured and repeatable.<\/p>\n<p>According to the repository, it is a PowerShell framework that can deploy and audit an <a href=\"https:\/\/github.com\/microsoft\/ActiveDirectoryTierModel\" target=\"_blank\" rel=\"noopener\">Active Directory Tier Model<\/a> from a versioned JSON configuration. It supports repeatable deployments, drift auditing, structured findings, and modular tests.<\/p>\n<p>This is particularly interesting for organizations looking to systematically build a tiering model according to Microsoft guidelines or benchmark existing structures against it.<\/p>\n<p>What\u2019s especially exciting is not just the deployment, but the auditing function.<\/p>\n<p>Microsoft documents drift detection for the framework via Audit-TierModel.ps1. This script analyzes the current Active Directory state against the declarative tier model configuration, identifying missing objects, configuration drifts, and structured <a href=\"https:\/\/microsoft.github.io\/ActiveDirectoryTierModel\/drift-detection-details\/\" target=\"_blank\" rel=\"noopener\">drift findings<\/a> for further remediation.[\/vc_column_text][\/vc_column_inner][\/vc_row_inner][\/vc_column][\/vc_row][vc_row css_animation=&#8221;&#8221; row_type=&#8221;row&#8221; use_row_as_full_screen_section=&#8221;no&#8221; type=&#8221;full_width&#8221; angled_section=&#8221;no&#8221; text_align=&#8221;left&#8221; background_image_as_pattern=&#8221;without_pattern&#8221;][vc_column][vc_empty_space height=&#8221;50&#8243;][vc_row_inner row_type=&#8221;row&#8221; type=&#8221;full_width&#8221; text_align=&#8221;left&#8221; css_animation=&#8221;&#8221;][vc_column_inner][vc_column_text css=&#8221;&#8221;]\n<h2>Drift Detection Is Great \u2013 But It Doesn&#8217;t Replace Attack Path Management<\/h2>\n[\/vc_column_text][vc_empty_space height=&#8221;20&#8243;][vc_column_text css=&#8221;&#8221;]Drift detection has a major limitation&#8230; it checks against the model you defined.<\/p>\n<p>If you strictly follow Microsoft guidelines, it will help make deviations visible. However, if your environment is heavily customized, featuring custom processes, special roles, tailored delegations, or historically grown structures, a simple comparison against a standard model won&#8217;t cut it.<\/p>\n<p>When custom configurations enter the picture, you quickly arrive at Attack Path Management\u2014because it reveals actual attack vectors, regardless of where they originate.<\/p>\n<p>Drift detection can show you whether specific OUs, groups, ACLs, or GPOs deviate from the intended state. For this purpose, Microsoft documentation highlights audit results with summaries, warnings, errors, and drift findings, alongside outputs as JSON, HTML, or NUnit XML.<\/p>\n<p>Attack Path Management goes a step further by evaluating which actual combinations of permissions, identities, and trust relationships present a real danger. This view is essential when environments are not cleanly standardized or when AD, Entra ID, cloud, SaaS, and other platforms need to be considered holistically.[\/vc_column_text][\/vc_column_inner][\/vc_row_inner][\/vc_column][\/vc_row][vc_row css_animation=&#8221;&#8221; row_type=&#8221;row&#8221; use_row_as_full_screen_section=&#8221;no&#8221; type=&#8221;full_width&#8221; angled_section=&#8221;no&#8221; text_align=&#8221;left&#8221; background_image_as_pattern=&#8221;without_pattern&#8221;][vc_column][vc_empty_space height=&#8221;50&#8243;][vc_row_inner row_type=&#8221;row&#8221; type=&#8221;full_width&#8221; text_align=&#8221;left&#8221; css_animation=&#8221;&#8221;][vc_column_inner][vc_column_text css=&#8221;&#8221;]\n<h2><span class=\"TextRun SCXW250457141 BCX0\" lang=\"EN-US\" xml:lang=\"EN-US\" data-contrast=\"auto\"><span class=\"NormalTextRun SCXW250457141 BCX0\" data-ccp-parastyle=\"heading 2\">Microsoft Is Visibly Taking Tiering Seriously Again <\/span><\/span><\/h2>\n[\/vc_column_text][vc_empty_space height=&#8221;20&#8243;][vc_column_text css=&#8221;&#8221;]Microsoft is once again visibly documenting, automating, and auditing tiering. The repository outlines the goal of deploying and auditing an Active Directory Tier Model structure across Tier 0, Tier 1, and Tier 2. Furthermore, it references documentation on deployment, drift detection, logging, GPO management, ADMX management, conditional principals, CI\/CD integration, test coverage, and Sentinel monitoring.<\/p>\n<p>This makes one thing crystal clear: <strong>Tiering is not a relic of the past. Tiering remains state of the art.<\/strong><\/p>\n<p>Tools have evolved, and the cloud has undeniably gained importance. Entra ID, Privileged Access, Conditional Access, Zero Trust, and modern identity security must all be factored in.<\/p>\n<p><strong><u>Yet the underlying principles remain the same:<\/u><\/strong><\/p>\n<ul>\n<li style=\"list-style-type: none;\">\n<ul>\n<li>Privileged identities require maximum protection.<\/li>\n<li>Administrative access must be strictly isolated.<\/li>\n<li>Tier-0 systems must not be compromiseable via lower tiers.<\/li>\n<li>Login and admin paths must be designed intentionally.<\/li>\n<li>Implementation must be audited on a regular basis.<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n[\/vc_column_text][\/vc_column_inner][\/vc_row_inner][\/vc_column][\/vc_row][vc_row css_animation=&#8221;&#8221; row_type=&#8221;row&#8221; use_row_as_full_screen_section=&#8221;no&#8221; type=&#8221;full_width&#8221; angled_section=&#8221;no&#8221; text_align=&#8221;left&#8221; background_image_as_pattern=&#8221;without_pattern&#8221;][vc_column][vc_empty_space height=&#8221;50&#8243;][vc_row_inner row_type=&#8221;row&#8221; type=&#8221;full_width&#8221; text_align=&#8221;left&#8221; css_animation=&#8221;&#8221;][vc_column_inner][vc_column_text css=&#8221;&#8221;]\n<h2><span class=\"TextRun SCXW143938091 BCX0\" lang=\"EN-US\" xml:lang=\"EN-US\" data-contrast=\"auto\"><span class=\"NormalTextRun SCXW143938091 BCX0\" data-ccp-parastyle=\"heading 2\">What This Means for Organizations <\/span><\/span><\/h2>\n[\/vc_column_text][vc_empty_space height=&#8221;20&#8243;][vc_column_text css=&#8221;&#8221;]For organizations, this new Microsoft framework serves above all as a great opportunity to review their own tiering strategy. Not eventually. NOW!<\/p>\n<p>Tiering is not a project you complete once and check off your list. Tiering is an operating model.<\/p>\n<p>The TEAL approach outlined in our <a href=\"https:\/\/www.teal-consulting.de\/en\/2024\/10\/16\/data-security-with-tiering\/\" target=\"_blank\" rel=\"noopener\">Tiering Article<\/a> remains as valid as ever: analyze attack paths, classify systems and users, implement protective controls, migrate permissions cleanly, and continuously validate the environment. The article breaks this approach down into four phases: preparation with attack path analysis and classification, implementation of protective controls, migration and re-assignment of permissions, and ongoing validation and control.<\/p>\n<p>If you want to use the new Microsoft Tiering Framework as an occasion to evaluate your environment, don&#8217;t start with scripts right away.<\/p>\n<p><strong><u>Start with the right questions:<\/u><\/strong><\/p>\n<ul>\n<li style=\"list-style-type: none;\">\n<ul>\n<li>Which systems in your environment are truly Tier 0?<\/li>\n<li>Which accounts have direct or indirect impact on these systems?<\/li>\n<li>Where do privileged users actually log in?<\/li>\n<li>Which legacy admin accounts still exist?<\/li>\n<li>Which service accounts possess overly broad permissions?<\/li>\n<li>Which groups have been nested over years and never cleaned up?<\/li>\n<li>Are technical logon restrictions between tiers strictly enforced?<\/li>\n<li>Is there regular auditing to check whether new attack paths have emerged?<\/li>\n<li>Do you have a target baseline state to measure deviations against?<\/li>\n<li>Are you leveraging Attack Path Management to expose real attack vectors?<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n[\/vc_column_text][vc_empty_space height=&#8221;20&#8243;][vc_column_text css=&#8221;&#8221;]Only when these questions are answered does a framework provide real value. Because tools can only automate what has been understood beforehand.[\/vc_column_text][\/vc_column_inner][\/vc_row_inner][\/vc_column][\/vc_row][vc_row css_animation=&#8221;&#8221; row_type=&#8221;row&#8221; use_row_as_full_screen_section=&#8221;no&#8221; type=&#8221;full_width&#8221; angled_section=&#8221;no&#8221; text_align=&#8221;left&#8221; background_image_as_pattern=&#8221;without_pattern&#8221;][vc_column][vc_empty_space height=&#8221;50&#8243;][vc_row_inner row_type=&#8221;row&#8221; type=&#8221;full_width&#8221; text_align=&#8221;left&#8221; css_animation=&#8221;&#8221;][vc_column_inner][vc_column_text css=&#8221;&#8221;]\n<h2><span class=\"TextRun SCXW143938091 BCX0\" lang=\"EN-US\" xml:lang=\"EN-US\" data-contrast=\"auto\"><span class=\"NormalTextRun SCXW143938091 BCX0\" data-ccp-parastyle=\"heading 2\">Our Opinion &amp; Conclusion<\/span><\/span><\/h2>\n[\/vc_column_text][vc_empty_space height=&#8221;20&#8243;][vc_column_text css=&#8221;&#8221;]From TEAL\u2019s perspective, the release of the Active Directory Tier Model is a strong positive signal.<\/p>\n<p>Not because everything is suddenly brand new, but because Microsoft is bringing a foundational security principle back into focus\u2014one that too many organizations dismissed for too long as an &#8220;old AD topic.&#8221;<\/p>\n<p><span style=\"color: #008081;\"><em>&#8220;Rumors of its death were greatly exaggerated\u2014I told you so!&#8221;<\/em> <\/span>\u2013 Fabian B\u00f6hm (CEO &amp; Security Architect at TEAL Consulting) following Microsoft\u2019s release.<\/p>\n<p>With these new scripts and documentation, Microsoft has certainly lowered the barrier to adopting tiering, which we explicitly welcome. At the same time, the fundamental roadmap remains unchanged: classify, segregate, implement technical protections, migrate permissions cleanly, and validate regularly.<\/p>\n<p><strong>Tiering is not dead. Tiering is mandatory.<\/strong>[\/vc_column_text][\/vc_column_inner][\/vc_row_inner][\/vc_column][\/vc_row][vc_row css_animation=&#8221;&#8221; row_type=&#8221;row&#8221; use_row_as_full_screen_section=&#8221;no&#8221; type=&#8221;full_width&#8221; angled_section=&#8221;no&#8221; text_align=&#8221;center&#8221; background_image_as_pattern=&#8221;without_pattern&#8221; z_index=&#8221;&#8221;][vc_column width=&#8221;1\/6&#8243;][\/vc_column][vc_column width=&#8221;2\/3&#8243;][vc_empty_space height=&#8221;100&#8243;][vc_column_text css=&#8221;&#8221;]\n<h4 style=\"text-align: center;\">Would you like to learn more about this blog post and discuss it with a TEAL expert? Book a consultation session here!<\/h4>\n[\/vc_column_text][vc_empty_space height=&#8221;50&#8243;][vc_raw_html css=&#8221;&#8221;]JTNDZGl2JTIwY2xhc3MlM0QlMjJmcmFtZSUyMiUzRSUwQSUyMCUwQSUyMCUzQ2ElMjBocmVmJTNEJTIyaHR0cHMlM0ElMkYlMkZvdXRsb29rLm9mZmljZTM2NS5jb20lMkZib29rJTJGQmVyYXR1bmdzZ2VzcHJjaCU0MHRlYWwtY29uc3VsdGluZy5kZSUyRiUyMiUyMHRhcmdldCUzRCUyMl9ibGFuayUyMiUzRSUzQ2J1dHRvbiUyMGNsYXNzJTNEJTIyY3VzdG9tLWJ0biUyMGJ0bi0zJTIyJTNFJTNDc3BhbiUzRUFwcG9pbnRtZW50JTIwJTNFJTNFJTNDJTJGc3BhbiUzRSUzQyUyRmJ1dHRvbiUzRSUzQyUyRmElM0UlMEElMjAlMjAlMEElM0MlMkZkaXYlM0U=[\/vc_raw_html][\/vc_column][vc_column width=&#8221;1\/6&#8243;][\/vc_column][\/vc_row][vc_row css_animation=&#8221;&#8221; row_type=&#8221;row&#8221; use_row_as_full_screen_section=&#8221;no&#8221; type=&#8221;full_width&#8221; angled_section=&#8221;no&#8221; text_align=&#8221;left&#8221; background_image_as_pattern=&#8221;without_pattern&#8221;][vc_column][vc_empty_space height=&#8221;100&#8243;][vc_raw_html]JTNDYSUyMGhyZWYlM0QlMjJqYXZhc2NyaXB0JTNBaGlzdG9yeS5iYWNrJTI4JTI5JTIyJTNFJTNDc3BhbiUyMHN0eWxlJTNEJTIyY29sb3IlM0ElMjAlMjNmZjIwNzAlM0IlMjIlM0UlM0MlM0MlMjBCYWNrJTNDJTJGc3BhbiUzRSUzQyUyRmElM0U=[\/vc_raw_html][vc_empty_space height=&#8221;50&#8243;][vc_separator type=&#8221;small&#8221; position=&#8221;center&#8221; color=&#8221;#eeeeee&#8221; thickness=&#8221;2&#8243; width=&#8221;1100&#8243;][vc_empty_space height=&#8221;50&#8243;][\/vc_column][\/vc_row][vc_row css_animation=&#8221;&#8221; row_type=&#8221;row&#8221; use_row_as_full_screen_section=&#8221;no&#8221; type=&#8221;full_width&#8221; angled_section=&#8221;no&#8221; text_align=&#8221;left&#8221; background_image_as_pattern=&#8221;without_pattern&#8221;][vc_column][vc_empty_space height=&#8221;30&#8243;][vc_column_text]\n<h4>LATEST POSTS<\/h4>\n[\/vc_column_text][vc_empty_space height=&#8221;30&#8243;]\n<div class='latest_post_holder boxes three_columns one_row' >\n    <ul>\n    \n        <li class=\"clearfix\">\n            <div class=\"boxes_image\">\n                                <a itemprop=\"url\" href=\"https:\/\/www.teal-consulting.de\/en\/2026\/09\/02\/tiering-isnt-dead\/\"><img decoding=\"async\" width=\"539\" height=\"303\" data-src=\"https:\/\/www.teal-consulting.de\/wp-content\/uploads\/2025\/10\/blog_header_microsoft-windows-539x303.jpg\" class=\"attachment-latest_post_boxes size-latest_post_boxes wp-post-image lazyload\" alt=\"\" data-srcset=\"https:\/\/www.teal-consulting.de\/wp-content\/uploads\/2025\/10\/blog_header_microsoft-windows-539x303.jpg 539w, https:\/\/www.teal-consulting.de\/wp-content\/uploads\/2025\/10\/blog_header_microsoft-windows-300x169.jpg 300w, https:\/\/www.teal-consulting.de\/wp-content\/uploads\/2025\/10\/blog_header_microsoft-windows-1024x575.jpg 1024w, https:\/\/www.teal-consulting.de\/wp-content\/uploads\/2025\/10\/blog_header_microsoft-windows-768x432.jpg 768w, https:\/\/www.teal-consulting.de\/wp-content\/uploads\/2025\/10\/blog_header_microsoft-windows-1536x863.jpg 1536w, https:\/\/www.teal-consulting.de\/wp-content\/uploads\/2025\/10\/blog_header_microsoft-windows-700x393.jpg 700w, https:\/\/www.teal-consulting.de\/wp-content\/uploads\/2025\/10\/blog_header_microsoft-windows.jpg 1920w\" data-sizes=\"(max-width: 539px) 100vw, 539px\" src=\"data:image\/svg+xml;base64,PHN2ZyB3aWR0aD0iMSIgaGVpZ2h0PSIxIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjwvc3ZnPg==\" style=\"--smush-placeholder-width: 539px; --smush-placeholder-aspect-ratio: 539\/303;\"><\/a>\n            <\/div>\n            <div class=\"latest_post\"  >\n                <div class=\"latest_post_text\">\n                    <div class=\"latest_post_inner\">\n                        <div class=\"latest_post_text_inner\">\n                            <h4 itemprop=\"name\" class=\"latest_post_title entry_title\"><a itemprop=\"url\" href=\"https:\/\/www.teal-consulting.de\/en\/2026\/09\/02\/tiering-isnt-dead\/\">Microsoft is backtracking: Tiering isn&#8217;t dead\u2014it&#8217;s essential for survival<\/a><\/h4>\n                            <p class=\"excerpt\">Microsoft releases an Active Directory Tier Model on GitHub. To many, this sounds like just another tool. For us, it\u2019s official proof of something we\u2019ve been saying for years: if you don\u2019t strictly isolate ...<\/p>\n                            <span class=\"post_infos\">\n                                                                    <span class=\"date_hour_holder\">\n                                        <span itemprop=\"dateCreated\" class=\"date entry_date updated\">02 September, 2026 <meta itemprop=\"interactionCount\" content=\"UserComments: 0\"\/><\/span>\n                                    <\/span>\n                                                                                                \n                                \n                                                            <\/span>\n                        <\/div>\n                    <\/div>\n                <\/div>\n            <\/div>\n        <\/li>\n    \n        <li class=\"clearfix\">\n            <div class=\"boxes_image\">\n                                <a itemprop=\"url\" href=\"https:\/\/www.teal-consulting.de\/en\/2026\/08\/06\/microsoft-sms-mfa-obsolete\/\"><img decoding=\"async\" width=\"539\" height=\"303\" data-src=\"https:\/\/www.teal-consulting.de\/wp-content\/uploads\/2025\/10\/blog_header_microsoft-windows-539x303.jpg\" class=\"attachment-latest_post_boxes size-latest_post_boxes wp-post-image lazyload\" alt=\"\" data-srcset=\"https:\/\/www.teal-consulting.de\/wp-content\/uploads\/2025\/10\/blog_header_microsoft-windows-539x303.jpg 539w, https:\/\/www.teal-consulting.de\/wp-content\/uploads\/2025\/10\/blog_header_microsoft-windows-300x169.jpg 300w, https:\/\/www.teal-consulting.de\/wp-content\/uploads\/2025\/10\/blog_header_microsoft-windows-1024x575.jpg 1024w, https:\/\/www.teal-consulting.de\/wp-content\/uploads\/2025\/10\/blog_header_microsoft-windows-768x432.jpg 768w, https:\/\/www.teal-consulting.de\/wp-content\/uploads\/2025\/10\/blog_header_microsoft-windows-1536x863.jpg 1536w, https:\/\/www.teal-consulting.de\/wp-content\/uploads\/2025\/10\/blog_header_microsoft-windows-700x393.jpg 700w, https:\/\/www.teal-consulting.de\/wp-content\/uploads\/2025\/10\/blog_header_microsoft-windows.jpg 1920w\" data-sizes=\"(max-width: 539px) 100vw, 539px\" src=\"data:image\/svg+xml;base64,PHN2ZyB3aWR0aD0iMSIgaGVpZ2h0PSIxIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjwvc3ZnPg==\" style=\"--smush-placeholder-width: 539px; --smush-placeholder-aspect-ratio: 539\/303;\"><\/a>\n            <\/div>\n            <div class=\"latest_post\"  >\n                <div class=\"latest_post_text\">\n                    <div class=\"latest_post_inner\">\n                        <div class=\"latest_post_text_inner\">\n                            <h4 itemprop=\"name\" class=\"latest_post_title entry_title\"><a itemprop=\"url\" href=\"https:\/\/www.teal-consulting.de\/en\/2026\/08\/06\/microsoft-sms-mfa-obsolete\/\">Microsoft pulls the plug: why SMS MFA is now finally obsolete<\/a><\/h4>\n                            <p class=\"excerpt\">Starting September 1, 2026, passkeys will gradually become the default authentication method in Microsoft Entra ID. At the same time, Microsoft has announced that it will discontinue native support for SMS and voice MFA....<\/p>\n                            <span class=\"post_infos\">\n                                                                    <span class=\"date_hour_holder\">\n                                        <span itemprop=\"dateCreated\" class=\"date entry_date updated\">06 August, 2026 <meta itemprop=\"interactionCount\" content=\"UserComments: 0\"\/><\/span>\n                                    <\/span>\n                                                                                                \n                                \n                                                            <\/span>\n                        <\/div>\n                    <\/div>\n                <\/div>\n            <\/div>\n        <\/li>\n    \n        <li class=\"clearfix\">\n            <div class=\"boxes_image\">\n                                <a itemprop=\"url\" href=\"https:\/\/www.teal-consulting.de\/en\/2026\/07\/01\/one-click-desaster-in-microsoft-365-copilot\/\"><img decoding=\"async\" width=\"539\" height=\"303\" data-src=\"https:\/\/www.teal-consulting.de\/wp-content\/uploads\/2026\/06\/header_blog_teal_copilot-539x303.png\" class=\"attachment-latest_post_boxes size-latest_post_boxes wp-post-image lazyload\" alt=\"\" data-srcset=\"https:\/\/www.teal-consulting.de\/wp-content\/uploads\/2026\/06\/header_blog_teal_copilot-539x303.png 539w, https:\/\/www.teal-consulting.de\/wp-content\/uploads\/2026\/06\/header_blog_teal_copilot-300x169.png 300w, https:\/\/www.teal-consulting.de\/wp-content\/uploads\/2026\/06\/header_blog_teal_copilot-1024x575.png 1024w, https:\/\/www.teal-consulting.de\/wp-content\/uploads\/2026\/06\/header_blog_teal_copilot-768x432.png 768w, https:\/\/www.teal-consulting.de\/wp-content\/uploads\/2026\/06\/header_blog_teal_copilot-1536x863.png 1536w, https:\/\/www.teal-consulting.de\/wp-content\/uploads\/2026\/06\/header_blog_teal_copilot-700x393.png 700w, https:\/\/www.teal-consulting.de\/wp-content\/uploads\/2026\/06\/header_blog_teal_copilot.png 1920w\" data-sizes=\"(max-width: 539px) 100vw, 539px\" src=\"data:image\/svg+xml;base64,PHN2ZyB3aWR0aD0iMSIgaGVpZ2h0PSIxIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjwvc3ZnPg==\" style=\"--smush-placeholder-width: 539px; --smush-placeholder-aspect-ratio: 539\/303;\"><\/a>\n            <\/div>\n            <div class=\"latest_post\"  >\n                <div class=\"latest_post_text\">\n                    <div class=\"latest_post_inner\">\n                        <div class=\"latest_post_text_inner\">\n                            <h4 itemprop=\"name\" class=\"latest_post_title entry_title\"><a itemprop=\"url\" href=\"https:\/\/www.teal-consulting.de\/en\/2026\/07\/01\/one-click-desaster-in-microsoft-365-copilot\/\">One-Click Disaster in Microsoft 365 Copilot: When AI becomes a hacker&#8217;s best friend<\/a><\/h4>\n                            <p class=\"excerpt\">AI agents like Microsoft 365 Copilot are revolutionizing our daily work and promise unprecedented productivity. But what happens if this very smart assistant system quietly turns into the ultimate spy? ...<\/p>\n                            <span class=\"post_infos\">\n                                                                    <span class=\"date_hour_holder\">\n                                        <span itemprop=\"dateCreated\" class=\"date entry_date updated\">01 July, 2026 <meta itemprop=\"interactionCount\" content=\"UserComments: 0\"\/><\/span>\n                                    <\/span>\n                                                                                                \n                                \n                                                            <\/span>\n                        <\/div>\n                    <\/div>\n                <\/div>\n            <\/div>\n        <\/li>\n        <\/ul>\n<\/div>[\/vc_column][\/vc_row]\n<\/div>","protected":false},"excerpt":{"rendered":"<p>Microsoft releases an Active Directory Tier Model on GitHub. To many, this sounds like just another tool. For us, it\u2019s official proof of something we\u2019ve been saying for years: if you don\u2019t strictly isolate <\/p>\n","protected":false},"author":14,"featured_media":1006891,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"inline_featured_image":false,"footnotes":""},"categories":[10],"tags":[],"class_list":["post-1008007","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized"],"_links":{"self":[{"href":"https:\/\/www.teal-consulting.de\/en\/wp-json\/wp\/v2\/posts\/1008007","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.teal-consulting.de\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.teal-consulting.de\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.teal-consulting.de\/en\/wp-json\/wp\/v2\/users\/14"}],"replies":[{"embeddable":true,"href":"https:\/\/www.teal-consulting.de\/en\/wp-json\/wp\/v2\/comments?post=1008007"}],"version-history":[{"count":4,"href":"https:\/\/www.teal-consulting.de\/en\/wp-json\/wp\/v2\/posts\/1008007\/revisions"}],"predecessor-version":[{"id":1008011,"href":"https:\/\/www.teal-consulting.de\/en\/wp-json\/wp\/v2\/posts\/1008007\/revisions\/1008011"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.teal-consulting.de\/en\/wp-json\/wp\/v2\/media\/1006891"}],"wp:attachment":[{"href":"https:\/\/www.teal-consulting.de\/en\/wp-json\/wp\/v2\/media?parent=1008007"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.teal-consulting.de\/en\/wp-json\/wp\/v2\/categories?post=1008007"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.teal-consulting.de\/en\/wp-json\/wp\/v2\/tags?post=1008007"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}