v1.1.0
ADTierKit 1.1.0
Hardening and documentation release. The three code changes came out of an external review of
1.0.0 — none changes what a converged directory looks like.
Security
InstallTask now checks who can modify the files it schedules. The sync task runs the
script and configuration as SYSTEM on a domain controller. Registration now refuses paths that
principals outside SYSTEM, Administrators, TrustedInstaller and the Domain/Enterprise Admins
can write to — including the parent directories — and names the offending principals.
-SkipAclCheck bypasses the check deliberately. If your kit lives somewhere like C:\Temp,
move it (e.g. under Program Files) before re-registering the task; existing tasks keep
running unchanged.
Fixed
- The password generator's Fisher-Yates shuffle now uses the same rejection-sampled randomness
as the character picks, removing a (practically negligible) positional modulo bias. - LAPS reset permissions are now verified against the OU ACL instead of
Find-LapsADExtendedRights(which only reports read holders), so they no longer get
re-granted and reported asCreatedon every run.
Added
- Operator's Guide — the complete change inventory (every setting and
default value the tool writes), the working model, day-two operations, the rollout playbook
with per-phase checks, and a verification checklist. - README: What belongs in Tier 0 — the classification
test and the systems most deployments forget (PKI, Entra Connect, backup, hypervisors
hosting DCs, endpoint management, the kit's own directory). - README: silo pre-enforcement warning — PAWs must be in
memberComputerOusand synced
before enforcing, and theAuthenticationPolicyFailures-DomainControllerlog is disabled by
default and must be enabled on every DC for the audit phase to prove anything.
Upgrading from 1.0.0
Drop-in: replace the files, no configuration schema change (schemaVersion unchanged,
Update-TierConfiguration.ps1 not needed). Run -Mode Deploy without -Apply once — the plan
should show no pending changes for an already-converged directory. The only behavioural
difference you may notice: -Mode InstallTask can now refuse (see above), and the LAPS stage
stops reporting Created for reset permissions that were already in place.
Full changelog: CHANGELOG.md