Entra ID tenant without policy to show geographic location context in Microsoft Authenticator notifications

Entra ID tenant without a policy to show geographic location context in Microsoft Authenticator notifications exposes users to authentication requests that may be confirmed by mistake due to lack of contextual information, enabling attackers to gain unauthorized access.
AD domain allowing NTLM authentication

AD domains using NTLM authentication expose sensitive information, enabling attackers to gather domain details through unauthorized access.
AD object created by unusual Initiator

Cayosoft Guardian detects anomalous Active Directory account creation by unusual Initiators, exposing potential attack paths and helping administrators investigate and remediate security issues.
AD domain with misconfigured LDAP signing policy on the domain controllers

A misconfigured LDAP signing policy on Active Directory domain controllers exposes the environment to man-in-the-middle attacks, allowing attackers to intercept authentication traffic.
Active Directory missing KDS root key required for gMSA support

Active Directory missing KDS root key required for gMSA support exposes services to weak or stale credentials due to reliance on traditional accounts, enabling attackers to exploit Kerberos authentication and escalate privileges.
AD domain with misconfigured UNC paths policies

Active Directory misconfigurations expose authentication traffic, allowing attackers to intercept credentials or impersonate domain controllers via NTLM relay and SMB downgrade vulnerabilities.
AD computer using dNSHostName that belongs to another computer account

Attackers can exploit dNSHostName attribute modifications in Active Directory to impersonate computer accounts, compromising certificate-based authentication.
Privileged AD user not protected from using unsecure authentication methods

Privileged AD user accounts exposed to credential access attacks due to unsecure authentication methods, enabling attackers to exploit weaknesses and gain elevated privileges.
AD domain with unsecure RBCD delegation on domain controllers

Attackers can impersonate any user via unsecure Resource-Based Constrained Delegation (RBCD) on domain controllers, enabling unauthorized access to sensitive resources and data.
Missing Conditional Access Policies for blocking legacy authentication

Legacy authentication protocols are not blocked in your Entra ID environment, exposing it to credential stuffing and brute force attacks.