Active Directory Certificate Services auditing not configured
Unconfigured Active Directory Certificate Services (AD CS) auditing increases risk of privilege escalation, credential theft, and persistence due to undetected certificate operations.
Constrained authentication delegation to a domain controller service

Constrained authentication delegation to a domain controller service exposes sensitive resources to exploitation via Kerberos protocol vulnerabilities.
Microsoft Entra tenant with auditing disabled

A disabled auditing feature in Microsoft Entra tenant exposes attackers to undetected activity, allowing them to persist and evade detection.
AD Delegated Managed Service Account (dMSA) object takeover by computer object
Attackers exploit dMSA delegation in Active Directory, gaining write access and escalating privileges through computer object impersonation, allowing them to modify sensitive objects and maintain persistence.
Service Principal promoted a service principal to privileged role members

Attackers can persist and elevate privileges when a service principal is promoted to a privileged role member.
Microsoft Entra tenant with partner access via Delegated Administrative Privileges

A Microsoft Entra tenant configured for partner access through Delegated Administrative Privileges exposes sensitive resources to potential unauthorized access and lateral movement.
Regular AD user with permission to link GPOs

A regular AD user with permission to link GPOs can exploit group membership to elevate their permissions, exposing Active Directory domain security to potential attack paths.
Read-Only Domain Controller (RODC) in Inconsistent State

Inconsistent Read-Only Domain Controllers (RODCs) expose authentication and authorization vulnerabilities, allowing attackers to exploit outdated or incorrect credentials.
Unauthorized changes to compliance policies

Unauthorized changes to compliance policies expose devices to security risks by allowing non-compliant or compromised devices to access corporate resources through modified configuration settings.
Multiple inbox rules created in an Exchange Online mailbox within a short period

Attackers use multiple inbox rules in Exchange Online mailboxes within a short period to evade detection and maintain unauthorized access, indicating high severity.