Enterprise access model: control plane vs management plane vs data/workload plane

Verdict: Lower planes must never control higher planes. Identity systems, including on-premises AD DS, sit in the control plane. Former Tier 1 splits into management plane (enterprise-wide IT) and data/workload plane (per-workload, sometimes business-unit owned).

CriterionControl planeManagement planeData/workload plane
What it governsIdentity and access control for the whole estateEnterprise-wide IT infrastructure managementPer-workload administration, sometimes owned by business units
Where AD DS sitsAD DS provides centralized authentication, so it belongs hereNot AD DS - AD DS is not general IT infrastructure managementNot AD DS - storing objects does not make it a workload asset
Escalation ruleMust never be reachable from management or data/workload planesCannot gain standing control over control plane resourcesCannot gain standing control over control plane resources

Rules

Traps