Microsoft Entra user with multiple MFA failures

Multiple Entra ID user MFA failures in a short period may indicate an attacker attempting to bypass MFA through brute-force or fatigue attacks, increasing account takeover risk.
Missing Conditional Access Policy for requiring compliant devices in Entra ID

A missing Conditional Access Policy in Entra ID exposes corporate resources to non-compliant devices, enabling unauthorized access and malicious actions.
Microsoft Entra user not registered with MFA

Microsoft Entra user accounts without MFA are exposed to unauthorized access due to lack of identity verification, enabling attackers to gain access through password guessing or theft.
Stale administrative account in AD domain

A stale administrative account in Active Directory exposes elevated privileges and cached credentials, enabling potential privilege escalation and reconnaissance.
AD domain controller with SMB1 enabled

A domain controller with SMB1 enabled exposes a high-risk vulnerability that attackers can exploit for remote code execution via the SMBv1 protocol, allowing lateral movement and privilege escalation within the domain.
Security principals with dangerous replication permissions

Active Directory security principals with Replicate Changes All permission enable attackers to execute DCSync attacks, exposing all user passwords.
User account with old passwords

Old Active Directory passwords expose users to unauthorized access if not regularly updated.
Computer not resetting its password periodically

A non-expiring password on a computer account may indicate unauthorized access or control, allowing attackers to use pass-through authentication and potentially leading to more serious compromise.
Microsoft Entra application registration with dangling URI

Attackers can exploit dangling Microsoft Entra application registration URIs to obtain user sessions’ authorization tokens, enabling lateral movement or privilege escalation.
Microsoft Entra tenant with unsecure configuration of user risk policy

An unsecure user risk policy in Microsoft Entra tenant exposes users to unnecessary access risks due to inadequate password change requirements, enabling attackers to gather information and plan future malicious operations.