Microsoft Entra app with client secrets

Entra ID

A Microsoft Entra app with client secrets increases exposure due to potential secret disclosure and enables attackers to access permissions granted to the service principal.

Built-in domain Administrator account used recently

Active Directory

Built-in domain Administrator account usage indicates potential unauthorized access to high-privilege credentials, exposing the organization to attack paths through administrative scope and credential misuse.

DNS zone allowing unsecure update

Active Directory

A DNS zone allowing unsecure update enables attackers to modify records without authentication, exposing users to malicious servers via DNS spoofing and cache poisoning.