AD domain with misconfigured UNC paths policies

Active Directory misconfigurations expose authentication traffic, allowing attackers to intercept credentials or impersonate domain controllers via NTLM relay and SMB downgrade vulnerabilities.
Microsoft Entra tenant configured to allow guests to invite other guests

A tenant-wide guest invitation configuration exposes data on other users, enabling attack paths through information gathering.
AD domain allows unprivileged users to add computer accounts

Attackers can exploit AD domain settings to create legitimate-looking computer accounts for non-existent devices, enabling them to bypass security controls and gain unauthorized access.
Exchange-related AD group with excessive permissions

Attackers exploiting Exchange-related AD group with excessive permissions can reset passwords, add accounts to sensitive groups, or modify ACLs due to assigned FullControl, WriteDACL, ForceChangePassword, or AddMember permissions.
AD domain without group policy restricting anonymous enumeration of SAM accounts and shared resources

Attackers can gather reconnaissance data through unauthorized access in an AD domain without group policy restricting anonymous enumeration of SAM accounts and shared resources.
Microsoft Entra tenant with device settings allowing brute force attacks

A Windows device with disabled password attempt restrictions exposes attackers to repeated login attempts, increasing the risk of successful access.
Entra ID Missing Conditional Access Policy for blocking access for untrusted locations

Entra ID’s missing Conditional Access policy exposes credentials to unauthorized access via untrusted locations.
AD user with compromised password

Attackers can exploit exposed password hashes in Active Directory user accounts, enabling unauthorized access and potential privilege escalation.
Privileged AD user not protected against delegation

A high-severity threat where a privileged AD user’s credentials are vulnerable to unauthorized delegation, enabling privilege escalation through Kerberos protocol exploitation.