Exchange-related AD group with excessive permissions

Attackers exploiting Exchange-related AD group with excessive permissions can reset passwords, add accounts to sensitive groups, or modify ACLs due to assigned FullControl, WriteDACL, ForceChangePassword, or AddMember permissions.
Dangerous ACLs expose DPAPI key objects

Critical exposure of DPAPI key objects in Active Directory due to misconfigured ACLs allows attackers to decrypt sensitive data through unauthorized access.
Dangerous ACLs expose Certificate Templates container

Critical: Non-default principals with elevated permissions on the Certificate Templates container can introduce a malicious CA, escalating privileges and compromising the domain through attack paths that exploit administrative scope and credentials.
AD Domain where Enterprise Key Admins group has full access to the domain

Attackers can exploit a domain group with excessive permissions in Active Directory to perform DCSync attacks and compromise the forest.
AD domain controller using unsecure encryption type

Domain controllers using outdated or insecure encryption types expose sensitive data to attackers, enabling privilege escalation and credential access through Kerberos protocol exploitation.
AD domain account’s password set to never expire

Attackers can maintain persistence and reuse compromised credentials when a domain account has a non-expiring password in Active Directory.
Entra ID tenant without policy to show application name context in Microsoft Authenticator notifications

Entra ID tenant without policy to show application name context in Microsoft Authenticator notifications exposes users to potential account compromise through authentication requests, enabling attackers to exploit this via misleading or generic names.
AD domain without group policy restricting anonymous enumeration of SAM accounts and shared resources

Attackers can gather reconnaissance data through unauthorized access in an AD domain without group policy restricting anonymous enumeration of SAM accounts and shared resources.
Inactive AD domain controller

Inactive AD domain controllers expose authentication and authorization risks due to potential secrets expiration, enabling attackers to exploit expired tickets for unauthorized access.
AD domain with non-default permissions on krbtgt account

A domain with non-default permissions on the krbtgt account exposes attackers to creating a Golden Ticket, granting unauthorized Kerberos authentication.