Skip to content

v1.1.0

Choose a tag to compare

@Nobrac Nobrac released this 24 Aug 08:22
· 2 commits to main since this release

ADTierKit 1.1.0

Hardening and documentation release. The three code changes came out of an external review of
1.0.0 — none changes what a converged directory looks like.

Security

InstallTask now checks who can modify the files it schedules. The sync task runs the
script and configuration as SYSTEM on a domain controller. Registration now refuses paths that
principals outside SYSTEM, Administrators, TrustedInstaller and the Domain/Enterprise Admins
can write to — including the parent directories — and names the offending principals.
-SkipAclCheck bypasses the check deliberately. If your kit lives somewhere like C:\Temp,
move it (e.g. under Program Files) before re-registering the task; existing tasks keep
running unchanged.

Fixed

  • The password generator's Fisher-Yates shuffle now uses the same rejection-sampled randomness
    as the character picks, removing a (practically negligible) positional modulo bias.
  • LAPS reset permissions are now verified against the OU ACL instead of
    Find-LapsADExtendedRights (which only reports read holders), so they no longer get
    re-granted and reported as Created on every run.

Added

  • Operator's Guide — the complete change inventory (every setting and
    default value the tool writes), the working model, day-two operations, the rollout playbook
    with per-phase checks, and a verification checklist.
  • README: What belongs in Tier 0 — the classification
    test and the systems most deployments forget (PKI, Entra Connect, backup, hypervisors
    hosting DCs, endpoint management, the kit's own directory).
  • README: silo pre-enforcement warning — PAWs must be in memberComputerOus and synced
    before enforcing, and the AuthenticationPolicyFailures-DomainController log is disabled by
    default and must be enabled on every DC for the audit phase to prove anything.

Upgrading from 1.0.0

Drop-in: replace the files, no configuration schema change (schemaVersion unchanged,
Update-TierConfiguration.ps1 not needed). Run -Mode Deploy without -Apply once — the plan
should show no pending changes for an already-converged directory. The only behavioural
difference you may notice: -Mode InstallTask can now refuse (see above), and the LAPS stage
stops reporting Created for reset permissions that were already in place.

Full changelog: CHANGELOG.md