{"id":410,"date":"2025-09-15T17:40:31","date_gmt":"2025-09-15T15:40:31","guid":{"rendered":"https:\/\/ingeflex.com\/?page_id=410"},"modified":"2026-04-01T06:53:49","modified_gmt":"2026-04-01T04:53:49","slug":"conception-tier-0-1-2","status":"publish","type":"page","link":"https:\/\/ingeflex.com\/index.php\/conception-tier-0-1-2\/","title":{"rendered":"Design MS Tier 0 \/ Tier 1 \/ Tier 2"},"content":{"rendered":"\n<p>Le mod\u00e8le de niveaux (Tiering Model) de Microsoft est une approche de s\u00e9curit\u00e9 con\u00e7ue pour prot\u00e9ger les infrastructures Active Directory en segmentant les composants critiques en trois couches distinctes : Tier 0, Tier 1 et Tier 2. Cette segmentation vise \u00e0 limiter les d\u00e9placements lat\u00e9raux d&rsquo;un attaquant en cas de compromission d&rsquo;une couche, en restreignant les acc\u00e8s administratifs aux seules ressources de leur niveau correspondant.&nbsp;Le Tier 0, le plus critique, comprend les contr\u00f4leurs de domaine, la PKI interne et les composants li\u00e9s \u00e0 la gestion des identit\u00e9s, tels que AAD Connect ; seul un petit nombre d&rsquo;administrateurs y a acc\u00e8s, et ils doivent utiliser un compte d\u00e9di\u00e9 pour se connecter uniquement \u00e0 ces ressources.&nbsp;Le Tier 1 regroupe les serveurs applicatifs et les middlewares de l&rsquo;entreprise, comme SCCM ou WSUS, dont les administrateurs ont un acc\u00e8s restreint \u00e0 leur propre niveau et \u00e0 Tier 0 pour les op\u00e9rations de gestion, mais ne peuvent pas acc\u00e9der \u00e0 Tier 2.&nbsp;Enfin, le Tier 2 englobe les postes de travail des utilisateurs, les terminaux mobiles et les serveurs d&rsquo;acc\u00e8s g\u00e9n\u00e9ral, comme ceux utilis\u00e9s par le service d&rsquo;assistance, o\u00f9 les administrateurs ont des privil\u00e8ges limit\u00e9s \u00e0 leur propre niveau.<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Tier 0<\/strong>&nbsp;: Comprend les \u00e9l\u00e9ments les plus critiques de l&rsquo;infrastructure, notamment les contr\u00f4leurs de domaine et les syst\u00e8mes de gestion des identit\u00e9s. L&rsquo;acc\u00e8s \u00e0 ces ressources est strictement r\u00e9serv\u00e9 aux administrateurs de Tier 0, qui ne doivent pas se connecter de mani\u00e8re interactive \u00e0 des ressources de niveaux inf\u00e9rieurs.&nbsp;Cette couche est prot\u00e9g\u00e9e par des postes d&rsquo;administration privil\u00e9gi\u00e9s (PAW) et des politiques de groupe (GPO) qui bloquent les connexions non autoris\u00e9es.<\/li>\n\n\n\n<li><strong>Tier 1<\/strong>&nbsp;: Constitu\u00e9 des serveurs applicatifs et des services de gestion d&rsquo;entreprise. Les administrateurs de Tier 1 peuvent acc\u00e9der aux ressources de Tier 1 et de Tier 0 pour des op\u00e9rations de gestion, mais leur acc\u00e8s interactif est limit\u00e9 \u00e0 Tier 1.&nbsp;Cette couche est souvent s\u00e9par\u00e9e par des machines de rebond ou des PAW d\u00e9di\u00e9es pour garantir la s\u00e9curit\u00e9.<\/li>\n\n\n\n<li><strong>Tier 2<\/strong>&nbsp;: Comprend les postes de travail des utilisateurs et les p\u00e9riph\u00e9riques mobiles, repr\u00e9sentant le niveau le plus expos\u00e9 aux menaces comme le phishing ou les logiciels malveillants. Les administrateurs de Tier 2 ont des privil\u00e8ges limit\u00e9s \u00e0 leurs propres ressources et ne peuvent pas acc\u00e9der aux niveaux sup\u00e9rieurs.&nbsp;L&rsquo;acc\u00e8s \u00e0 Tier 0 ou Tier 1 est interdit pour ces comptes, m\u00eame en mode r\u00e9seau.<\/li>\n<\/ul>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"975\" height=\"547\" src=\"https:\/\/ingeflex.com\/wp-content\/uploads\/2025\/09\/Tiering.jpg\" alt=\"\" class=\"wp-image-423\" srcset=\"https:\/\/ingeflex.com\/wp-content\/uploads\/2025\/09\/Tiering.jpg 975w, https:\/\/ingeflex.com\/wp-content\/uploads\/2025\/09\/Tiering-300x168.jpg 300w, https:\/\/ingeflex.com\/wp-content\/uploads\/2025\/09\/Tiering-768x431.jpg 768w\" sizes=\"auto, (max-width: 975px) 100vw, 975px\" \/><\/figure>\n\n\n\n<p><\/p>\n\n\n\n<p>Ce mod\u00e8le est un concept flexible, sans d\u00e9finition rigide, et peut \u00eatre adapt\u00e9 \u00e0 des environnements plus complexes avec plus de niveaux ou int\u00e9grant des services cloud, comme dans le mod\u00e8le d&rsquo;acc\u00e8s entreprise qui remplace les tiers par des plans (contr\u00f4le, gestion, donn\u00e9es, acc\u00e8s utilisateur).&nbsp;L&rsquo;impl\u00e9mentation repose sur des principes comme le privil\u00e8ge minimum, l&rsquo;acc\u00e8s Just-in-Time (JIT) et l&rsquo;utilisation de machines PAW ou SAW s\u00e9curis\u00e9es.<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h3 class=\"wp-block-heading\">\ud83d\udcac <strong>Nous contacter<\/strong><\/h3>\n\n\n\n<p>Un ing\u00e9nieur commercial \u00e0 votre \u00e9coute, quel que soit votre niveau informatique, vous accompagnera pour sur tous vos sujets et sans aucune obligation de votre part.<br>Un seul num\u00e9ro en moins d une minute, le 01 85 83 04 00  ou via le chat en ligne (infobulle bleue en bas a droite)<\/p>\n\n\n\n<div class=\"wp-block-buttons is-layout-flex wp-block-buttons-is-layout-flex\">\n<div class=\"wp-block-button\"><a class=\"wp-block-button__link wp-element-button\" href=\"https:\/\/ingeflex.com\/index.php\/contact\/\">\ud83d\udc49 Contactez nous<\/a><\/div>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>Le mod\u00e8le de niveaux (Tiering Model) de Microsoft est une approche de s\u00e9curit\u00e9 con\u00e7ue pour prot\u00e9ger les infrastructures Active Directory en segmentant les composants critiques en trois couches distinctes : Tier 0, Tier 1 et Tier 2. Cette segmentation vise \u00e0 limiter les d\u00e9placements lat\u00e9raux d&rsquo;un attaquant en cas de&#8230;<\/p>\n","protected":false},"author":1,"featured_media":0,"parent":0,"menu_order":0,"comment_status":"closed","ping_status":"closed","template":"","meta":{"footnotes":""},"class_list":["post-410","page","type-page","status-publish","hentry"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.5 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>La s\u00e9curit\u00e9 par le design de votre infrastructure IT - INGEFLEX<\/title>\n<meta name=\"description\" content=\"Cloisonnement physique et logiciel pour un meilleur contr\u00f4le des acc\u00e8s. Une conception applicable \u00e0 tout syst\u00e8me informatique Microsoft\/Linux\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/ingeflex.com\/index.php\/conception-tier-0-1-2\/\" \/>\n<meta property=\"og:locale\" content=\"fr_FR\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"La s\u00e9curit\u00e9 par le design de votre infrastructure IT - INGEFLEX\" \/>\n<meta property=\"og:description\" content=\"Cloisonnement physique et logiciel pour un meilleur contr\u00f4le des acc\u00e8s. Une conception applicable \u00e0 tout syst\u00e8me informatique Microsoft\/Linux\" \/>\n<meta property=\"og:url\" content=\"https:\/\/ingeflex.com\/index.php\/conception-tier-0-1-2\/\" \/>\n<meta property=\"og:site_name\" content=\"INGEFLEX\" \/>\n<meta property=\"article:modified_time\" content=\"2026-04-01T04:53:49+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/ingeflex.com\/wp-content\/uploads\/2025\/09\/Tiering.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"975\" \/>\n\t<meta property=\"og:image:height\" content=\"547\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Dur\u00e9e de lecture estim\u00e9e\" \/>\n\t<meta name=\"twitter:data1\" content=\"3 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/ingeflex.com\\\/index.php\\\/conception-tier-0-1-2\\\/\",\"url\":\"https:\\\/\\\/ingeflex.com\\\/index.php\\\/conception-tier-0-1-2\\\/\",\"name\":\"La s\u00e9curit\u00e9 par le design de votre infrastructure IT - INGEFLEX\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/ingeflex.com\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/ingeflex.com\\\/index.php\\\/conception-tier-0-1-2\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/ingeflex.com\\\/index.php\\\/conception-tier-0-1-2\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/ingeflex.com\\\/wp-content\\\/uploads\\\/2025\\\/09\\\/Tiering.jpg\",\"datePublished\":\"2025-09-15T15:40:31+00:00\",\"dateModified\":\"2026-04-01T04:53:49+00:00\",\"description\":\"Cloisonnement physique et logiciel pour un meilleur contr\u00f4le des acc\u00e8s. Une conception applicable \u00e0 tout syst\u00e8me informatique Microsoft\\\/Linux\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/ingeflex.com\\\/index.php\\\/conception-tier-0-1-2\\\/#breadcrumb\"},\"inLanguage\":\"fr-FR\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/ingeflex.com\\\/index.php\\\/conception-tier-0-1-2\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"fr-FR\",\"@id\":\"https:\\\/\\\/ingeflex.com\\\/index.php\\\/conception-tier-0-1-2\\\/#primaryimage\",\"url\":\"https:\\\/\\\/ingeflex.com\\\/wp-content\\\/uploads\\\/2025\\\/09\\\/Tiering.jpg\",\"contentUrl\":\"https:\\\/\\\/ingeflex.com\\\/wp-content\\\/uploads\\\/2025\\\/09\\\/Tiering.jpg\",\"width\":975,\"height\":547},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/ingeflex.com\\\/index.php\\\/conception-tier-0-1-2\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Accueil\",\"item\":\"https:\\\/\\\/ingeflex.com\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Design MS Tier 0 \\\/ Tier 1 \\\/ Tier 2\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/ingeflex.com\\\/#website\",\"url\":\"https:\\\/\\\/ingeflex.com\\\/\",\"name\":\"INGEFLEX\",\"description\":\"met en oeuvre votre cr\u00e9ativit\u00e9\",\"publisher\":{\"@id\":\"https:\\\/\\\/ingeflex.com\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/ingeflex.com\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"fr-FR\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/ingeflex.com\\\/#organization\",\"name\":\"INGEFLEX\",\"url\":\"https:\\\/\\\/ingeflex.com\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"fr-FR\",\"@id\":\"https:\\\/\\\/ingeflex.com\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/ingeflex.com\\\/wp-content\\\/uploads\\\/2021\\\/07\\\/ing-logosite.png\",\"contentUrl\":\"https:\\\/\\\/ingeflex.com\\\/wp-content\\\/uploads\\\/2021\\\/07\\\/ing-logosite.png\",\"width\":512,\"height\":512,\"caption\":\"INGEFLEX\"},\"image\":{\"@id\":\"https:\\\/\\\/ingeflex.com\\\/#\\\/schema\\\/logo\\\/image\\\/\"}}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"La s\u00e9curit\u00e9 par le design de votre infrastructure IT - INGEFLEX","description":"Cloisonnement physique et logiciel pour un meilleur contr\u00f4le des acc\u00e8s. Une conception applicable \u00e0 tout syst\u00e8me informatique Microsoft\/Linux","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/ingeflex.com\/index.php\/conception-tier-0-1-2\/","og_locale":"fr_FR","og_type":"article","og_title":"La s\u00e9curit\u00e9 par le design de votre infrastructure IT - INGEFLEX","og_description":"Cloisonnement physique et logiciel pour un meilleur contr\u00f4le des acc\u00e8s. Une conception applicable \u00e0 tout syst\u00e8me informatique Microsoft\/Linux","og_url":"https:\/\/ingeflex.com\/index.php\/conception-tier-0-1-2\/","og_site_name":"INGEFLEX","article_modified_time":"2026-04-01T04:53:49+00:00","og_image":[{"width":975,"height":547,"url":"https:\/\/ingeflex.com\/wp-content\/uploads\/2025\/09\/Tiering.jpg","type":"image\/jpeg"}],"twitter_card":"summary_large_image","twitter_misc":{"Dur\u00e9e de lecture estim\u00e9e":"3 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/ingeflex.com\/index.php\/conception-tier-0-1-2\/","url":"https:\/\/ingeflex.com\/index.php\/conception-tier-0-1-2\/","name":"La s\u00e9curit\u00e9 par le design de votre infrastructure IT - INGEFLEX","isPartOf":{"@id":"https:\/\/ingeflex.com\/#website"},"primaryImageOfPage":{"@id":"https:\/\/ingeflex.com\/index.php\/conception-tier-0-1-2\/#primaryimage"},"image":{"@id":"https:\/\/ingeflex.com\/index.php\/conception-tier-0-1-2\/#primaryimage"},"thumbnailUrl":"https:\/\/ingeflex.com\/wp-content\/uploads\/2025\/09\/Tiering.jpg","datePublished":"2025-09-15T15:40:31+00:00","dateModified":"2026-04-01T04:53:49+00:00","description":"Cloisonnement physique et logiciel pour un meilleur contr\u00f4le des acc\u00e8s. Une conception applicable \u00e0 tout syst\u00e8me informatique Microsoft\/Linux","breadcrumb":{"@id":"https:\/\/ingeflex.com\/index.php\/conception-tier-0-1-2\/#breadcrumb"},"inLanguage":"fr-FR","potentialAction":[{"@type":"ReadAction","target":["https:\/\/ingeflex.com\/index.php\/conception-tier-0-1-2\/"]}]},{"@type":"ImageObject","inLanguage":"fr-FR","@id":"https:\/\/ingeflex.com\/index.php\/conception-tier-0-1-2\/#primaryimage","url":"https:\/\/ingeflex.com\/wp-content\/uploads\/2025\/09\/Tiering.jpg","contentUrl":"https:\/\/ingeflex.com\/wp-content\/uploads\/2025\/09\/Tiering.jpg","width":975,"height":547},{"@type":"BreadcrumbList","@id":"https:\/\/ingeflex.com\/index.php\/conception-tier-0-1-2\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Accueil","item":"https:\/\/ingeflex.com\/"},{"@type":"ListItem","position":2,"name":"Design MS Tier 0 \/ Tier 1 \/ Tier 2"}]},{"@type":"WebSite","@id":"https:\/\/ingeflex.com\/#website","url":"https:\/\/ingeflex.com\/","name":"INGEFLEX","description":"met en oeuvre votre cr\u00e9ativit\u00e9","publisher":{"@id":"https:\/\/ingeflex.com\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/ingeflex.com\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"fr-FR"},{"@type":"Organization","@id":"https:\/\/ingeflex.com\/#organization","name":"INGEFLEX","url":"https:\/\/ingeflex.com\/","logo":{"@type":"ImageObject","inLanguage":"fr-FR","@id":"https:\/\/ingeflex.com\/#\/schema\/logo\/image\/","url":"https:\/\/ingeflex.com\/wp-content\/uploads\/2021\/07\/ing-logosite.png","contentUrl":"https:\/\/ingeflex.com\/wp-content\/uploads\/2021\/07\/ing-logosite.png","width":512,"height":512,"caption":"INGEFLEX"},"image":{"@id":"https:\/\/ingeflex.com\/#\/schema\/logo\/image\/"}}]}},"_links":{"self":[{"href":"https:\/\/ingeflex.com\/index.php\/wp-json\/wp\/v2\/pages\/410","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ingeflex.com\/index.php\/wp-json\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/ingeflex.com\/index.php\/wp-json\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/ingeflex.com\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/ingeflex.com\/index.php\/wp-json\/wp\/v2\/comments?post=410"}],"version-history":[{"count":8,"href":"https:\/\/ingeflex.com\/index.php\/wp-json\/wp\/v2\/pages\/410\/revisions"}],"predecessor-version":[{"id":775,"href":"https:\/\/ingeflex.com\/index.php\/wp-json\/wp\/v2\/pages\/410\/revisions\/775"}],"wp:attachment":[{"href":"https:\/\/ingeflex.com\/index.php\/wp-json\/wp\/v2\/media?parent=410"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}