NTLM auditing not enabled in Active Directory
NTLM auditing not enabled in Active Directory exposes organizations to credential relay and lateral movement attacks through legacy protocol weaknesses.
AD account configured or modified to use RC4 encryption
Active Directory accounts using RC4 encryption are vulnerable to password cracking and forged Kerberos tickets, enabling lateral movement and data breach.
AD privileged account password reset or unlock
Unauthorized password reset or account unlock for a privileged Active Directory account can expose sensitive data and enable attackers to escalate privileges.
AD user with blank password
Active Directory user accounts without passwords are exposed to unauthorized access due to authentication bypass.
Active Directory SMB signing not enforced on domain controller
AD domain controller not changing its password

Domain controllers with outdated passwords expose sensitive information to attackers, enabling unauthorized access and potential breaches through pass-the-ticket (PtT) or pass-the-hash (PtH) attacks.
Failed logon attempts targeting honey account

Failed logon attempts targeting honey accounts in Active Directory may indicate brute-force attacks or reconnaissance activity, exposing administrative scope and attacker capability.
Dangerous ACLs expose certificate containers

Critical: Non-default principals with elevated permissions on the NTAuthCertificates container expose certificate containers, enabling privilege escalation and CA compromise through attack paths.
Dangerous enrollment permission on authentication certificate templates

Misconfigured certificate templates expose Active Directory Certificate Services to unauthorized users obtaining high-privilege certificates due to excessive enrollment permission.
Privileged Microsoft Entra account not registered for MFA

Privileged Microsoft Entra accounts without multi-factor authentication (MFA) expose organizations to identity-based attacks via password-only authentication.