Active Directory Certificate Services auditing not configured
Unconfigured Active Directory Certificate Services (AD CS) auditing increases risk of privilege escalation, credential theft, and persistence due to undetected certificate operations.
Unusual device wipe activity

Bulk device wipes within a short time frame indicate potential unauthorized access or malicious activity, exposing an organization’s devices and data integrity.
Microsoft Entra tenant with bulk changes of devices

Bulk device changes in a Microsoft Entra tenant can indicate unauthorized activity or mistakes, exposing attackers to sensitive areas and potential service disruptions.
AD domain with bulk changes of groups

Active Directory bulk group changes can indicate malicious activity or errors, leading to service disruptions and unauthorized access.
AD domain with bulk changes of computers

Active Directory bulk changes can indicate unauthorized modifications or mistakes, impacting service availability and exposing attack paths.
Microsoft Entra tenant with bulk changes of users

Bulk user changes in Microsoft Entra tenant may indicate unauthorized access, administrative mistakes, or malicious activity.
Password hash synchronization not enabled in hybrid environment

Password hash synchronization not enabled in hybrid environment exposes user credentials to attackers attempting unauthorized access through compromised credentials.
Microsoft Entra Organizational Messages Writer and Approver roles assigned to the same user or group
A user with both Entra ID organizational message writer and approver roles can create and approve messages without oversight, exposing an attack path due to compromised dual control.
Microsoft Intune Multi Admin Approval access policies not configured
Intune tenant without Multi Admin Approval access policies exposes sensitive actions to unauthorized administrators, enabling attackers to perform malicious activities with ease.
AD object with schema update permissions
Attackers can exploit AD object with schema update permissions to compromise forest integrity through unauthorized attribute and object creation.