↳ GitHub sourceWorkbook

Microsoft Active Directory Tier Model

Description

Provides a visual summary of incidents and alerts generated by the Microsoft Active Directory Tier Model analytic rules, broken down by severity and status. Requires all Domain Controllers to forward Security events to Microsoft Sentinel and the Tier Model analytic and automation rules to be active.
Version
1.0.0
Declared author / publisher
Microsoft

Declared sources

Metadata from the source file. No dependencies inferred from KQL.

Connectors

Data types

Related content

Links established from declared identifiers and solution manifests.

Source provenance

GitHub

Displayed values come from files in Azure/Azure-Sentinel. They describe the published template, not your workspace configuration.

Source identifier
MicrosoftADTierModelWorkbook
Additional source files 3Solutions/Microsoft Active Directory Tier Model/Workbooks/MicrosoftADTierModel.jsonsource ↗Solutions/Microsoft Active Directory Tier Model/Workbooks/workbooksMetadata.jsonworkbook-metadata ↗Solutions/Microsoft Active Directory Tier Model/Data/Solution_MicrosoftActiveDirectoryTierModel.jsonsolution-membership ↗
GSTEP / CATALOG TRACKING

Added to catalog : 16 Sept 2026 · 05:49 UTC
Last change observed : 16 Sept 2026 · 05:49 UTC

GSTEP sync dates, separate from the source content’s publication dates.