Active Directory Certificate Services auditing not configured
Unconfigured Active Directory Certificate Services (AD CS) auditing increases risk of privilege escalation, credential theft, and persistence due to undetected certificate operations.
Honey account targeted with Kerberos pre-authentication attempts

Kerberos pre-authentication attempts against honey accounts expose credentials to attackers, enabling reconnaissance and potential compromise.
AD domain allowing multicast name resolution (LLMNR)
Active Directory domains enabling Multicast Name Resolution (LLMNR) expose networks to spoofing and credential-harvesting attacks via intercepted DNS requests, allowing attackers to gather user credentials or redirect traffic.
AD user account with compromised password
Exposure of Active Directory user account passwords allows attackers to authenticate, but not necessarily escalate privileges.
Entra user account with compromised password
Entra user account with compromised password exposes internal domains to public breaches, enabling attackers to exploit exposed credentials and gain unauthorized access.
Suspicious Global Administrator sign-in in Entra ID
A sign-in from a Global Administrator account in Entra ID indicates potential credential compromise or malicious reconnaissance, warranting immediate investigation.
Failed logon attempts targeting honey account

Failed logon attempts targeting honey accounts in Active Directory may indicate brute-force attacks or reconnaissance activity, exposing administrative scope and attacker capability.
AD domain with built-in domain Guest account enabled

An enabled domain guest account exposes the Active Directory environment to unauthorized access, enabling attackers to gather information for potential future attacks.
Anonymous access enabled in AD forest

Enabled anonymous access in Active Directory (AD) forest exposes sensitive information via LDAP queries, allowing unauthenticated users to gather user and group details.
Microsoft Entra tenant with Microsoft 365 groups exposed to the whole organization

Microsoft Entra tenant exposes users to unauthorized access due to misconfigured permissions in Microsoft 365 groups, enabling attackers to exploit sensitive resources.