Windows LAPS not configured or AD prerequisites missing
Exposure to static or reused local administrator passwords increases risk of credential reuse and lateral movement due to missing Windows LAPS configuration or incomplete Active Directory prerequisites.
AD user has a password that matches its sAMAccountName

Predictable password pattern in Active Directory exposes users to brute-force attacks, compromising account security and allowing unauthorized access.
AD CS server vulnerable to NTLM relay attacks

An NTLM relay attack exploits the NTLM challenge-response mechanism, allowing attackers to authenticate as legitimate users and gain unauthorized access.
AD Delegated Managed Service Account (dMSA) object takeover by computer object
Attackers exploit dMSA delegation in Active Directory, gaining write access and escalating privileges through computer object impersonation, allowing them to modify sensitive objects and maintain persistence.
AD computer with suspicious change of sAMAccountName
A suspicious sAMAccountName change on an AD computer can enable attackers to escalate privileges, compromising domain security through attack paths that exploit administrative scope and credentials.
AD forest with the Azure SSO computer account not changing its password

Attackers can exploit a misconfigured Azure SSO computer account in an Active Directory forest, allowing them to authenticate as any user with access to Microsoft Entra ID using the static password.
Backup location with unencrypted AD backups

Unencrypted AD backups expose sensitive data to unauthorized access, enabling attackers to gather credentials and plan future attacks.
Entra ID tenant vulnerable to MFA fatigue attacks via voice authentication method

Entra ID tenants vulnerable to voice authentication-based MFA fatigue attacks expose users to unauthorized access risk through compromised credentials and permissions.
AD domain with unsecure configuration of Cloud Kerberos Trust

A hybrid AD environment’s unsecure Cloud Kerberos Trust configuration exposes sensitive resources to unauthorized access via Microsoft Entra ID.
AD object with modified msDS-KeyCredentialLink
Active Directory objects with modified msDS-KeyCredentialLink expose users to persistent access attacks through unauthorized key pair creation and encryption, enabling attackers to bypass normal authentication controls.