Regular Microsoft Entra user with Exchange Online PowerShell enabled

A non-administrative Microsoft Entra user with Exchange Online PowerShell enabled expands remote mailbox automation access if the account is compromised, increasing exposure to attack paths.
Constrained delegation with protocol transition to the krbtgt account
Constrained delegation with protocol transition to the krbtgt account enables attackers to compromise the trusted krbtgt account, impersonate users, and access network resources through Kerberos authentication mechanisms.
Microsoft Intune Multi Admin Approval access policies not configured
Intune tenant without Multi Admin Approval access policies exposes sensitive actions to unauthorized administrators, enabling attackers to perform malicious activities with ease.
Conditional Access policy in Entra ID missing Continuous Access Evaluation (CAE)
Conditional Access policy in Entra ID missing Continuous Access Evaluation (CAE) exposes users to extended session duration after privilege elevation or credential compromise, enabling attackers to maintain access to sensitive resources for an extended period.
AD account configured or modified to use RC4 encryption
Active Directory accounts using RC4 encryption are vulnerable to password cracking and forged Kerberos tickets, enabling lateral movement and data breach.
NTLM auditing not enabled in Active Directory
NTLM auditing not enabled in Active Directory exposes organizations to credential relay and lateral movement attacks through legacy protocol weaknesses.
Microsoft Entra Organizational Messages Writer and Approver roles assigned to the same user or group
A user with both Entra ID organizational message writer and approver roles can create and approve messages without oversight, exposing an attack path due to compromised dual control.
Entra privileged account password reset
Unauthorized Entra ID account password resets can indicate exposure to attack paths, persistence, and reconnaissance opportunities.
AD privileged account password reset or unlock
Unauthorized password reset or account unlock for a privileged Active Directory account can expose sensitive data and enable attackers to escalate privileges.
AD domain with misconfigured PowerShell logging policies
A misconfigured PowerShell logging policy exposes an Active Directory domain to attackers who can evade detection through PowerShell-based reconnaissance and persistence.