Backup location with unencrypted AD backups

Unencrypted AD backups expose sensitive data to unauthorized access, enabling attackers to gather credentials and plan future attacks.
Multiple inbox rules created in an Exchange Online mailbox within a short period

Attackers use multiple inbox rules in Exchange Online mailboxes within a short period to evade detection and maintain unauthorized access, indicating high severity.
Detected a malicious inbox rule to conceal email in Exchange Online

A malicious inbox rule in Exchange Online conceals emails, aiding Business Email Compromise attacks, exposing your organization to unauthorized data access and financial losses.
Regular Microsoft Entra user with Exchange Online PowerShell enabled

A non-administrative Microsoft Entra user with Exchange Online PowerShell enabled expands remote mailbox automation access if the account is compromised, increasing exposure to attack paths.
AD computer with traces of DCShadow attack

Active Directory computer objects with DCShadow attack traces expose potential unauthorized access and manipulation of security settings through attacker-controlled domain controllers.
Microsoft Entra app with risky read permissions

Microsoft Entra apps with excessive read permissions expose sensitive data through OAuth 2.0 consent grants.
Microsoft Entra tenant where regular users can create Microsoft 365 groups

Regular user group creation exposes tenant-wide access, enabling attackers to collect sensitive information through group membership enumeration.
Exchange Online mailbox with Full Access permission assigned

Exchange Online mailboxes with assigned Full Access permissions may indicate misconfigured permissions, allowing attackers to access compromised mailboxes undetected. This can lead to data exposure and unauthorized access.
Entra ID tenant allowing multicast name resolution (LLMNR)

Enabling multicast name resolution (LLMNR) in Entra ID tenant exposes your network to authentication bypass and credential-harvesting attacks, allowing attackers to intercept and manipulate requests.
Microsoft Entra app with risky write permissions

Microsoft Entra apps with write permissions expose your tenant to unauthorized modifications and data tampering.