Securing Sideways: Thwarting Lateral Movement by Implementing Active Directory Tiering
Tyler Schroder, Sohee Kim Park

TL;DR
This paper discusses strategies to enhance Active Directory security by implementing tiering to prevent lateral movement of cyber threats, combining technical guidelines with theoretical support to improve organizational cybersecurity defenses.
Contribution
It introduces a tiering approach for Active Directory environments, integrating practical scenarios and theoretical arguments to prevent credential theft and lateral movement.
Findings
Tiering can effectively halt lateral movement in AD environments.
Implementing tiering reduces the risk of privilege escalation and credential theft.
The approach complements existing security measures to strengthen cybersecurity posture.
Abstract
The advancement of computing equipment and the advances in services over the Internet has allowed corporations, higher education, and many other organizations to pursue the shared computing network environment. A requirement for shared computing environments is a centralized identity system to authenticate and authorize user access. An organization's digital identity plane is a prime target for cyber threat actors. When compromised, identities can be exploited to steal credentials, create unauthorized accounts, and manipulate permissions-enabling attackers to gain control of the network and undermine its confidentiality, availability, and integrity. Cybercrime losses reached a record of 16.6 B in the United States in 2024. For organizations using Microsoft software, Active Directory is the on-premises identity system of choice. In this article, we examine the challenge of security…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsUser Authentication and Security Systems
