Microsoft Entra tenant with bulk changes of groups

Bulk group changes in your Microsoft Entra tenant may indicate unauthorized access or service disruptions.
AD domain with bulk changes of users

Active Directory bulk user changes can indicate unauthorized access or administrative errors, potentially leading to service disruptions through lateral movement or privilege escalation.
AD forest is not protected against forest-wide failure by Cayosoft Guardian

A high-severity threat where an AD forest lacks a safeguard to quickly recover from catastrophic events like ransomware attacks or directory data corruption, exposing it to prolonged downtime, significant data loss, and substantial business disruption.
AD forest with Recycle Bin not enabled

A disabled Active Directory Recycle Bin exposes deleted objects to permanent loss through lack of restoration capabilities, enabling attackers to delete critical objects without fear of recovery.
Inactive AD domain controller

Inactive AD domain controllers expose authentication and authorization risks due to potential secrets expiration, enabling attackers to exploit expired tickets for unauthorized access.