Missing Conditional Access Policy for requiring compliant devices in Entra ID

A missing Conditional Access Policy in Entra ID exposes corporate resources to non-compliant devices, enabling unauthorized access and malicious actions.
AD forest with recent changes to default security descriptor in schema

Active Directory schema modifications expose attack paths and persistence risks.
Short-lived privileged AD object

Elevated permissions can be temporarily gained through short-lived privileged AD objects, exposing sensitive resources to unauthorized access.
Anonymous access enabled in AD forest

Enabled anonymous access in Active Directory (AD) forest exposes sensitive information via LDAP queries, allowing unauthenticated users to gather user and group details.
Microsoft Entra tenant with Certificate-Based Authentication enabled for all users

A Microsoft Entra tenant with Certificate-Based Authentication enabled for all users exposes users to unauthorized certificate issuance, enabling attackers to impersonate any user without a password.
Microsoft Entra app with risky read permissions

Microsoft Entra apps with excessive read permissions expose sensitive data through OAuth 2.0 consent grants.
Stale Microsoft Entra service principal

A stale Microsoft Entra service principal can lead to unauthorized access and data breaches if not properly managed, exposing your organization to attack paths through compromised credentials and permissions.
AD domain allowing NTLM authentication

AD domains using NTLM authentication expose sensitive information, enabling attackers to gather domain details through unauthorized access.
AD object created by unusual Initiator

Cayosoft Guardian detects anomalous Active Directory account creation by unusual Initiators, exposing potential attack paths and helping administrators investigate and remediate security issues.
AD domain with misconfigured LDAP signing policy on the domain controllers

A misconfigured LDAP signing policy on Active Directory domain controllers exposes the environment to man-in-the-middle attacks, allowing attackers to intercept authentication traffic.