Modified federation settings in Microsoft Entra domain

Modified federation settings in Microsoft Entra domain expose sensitive access to attackers who can exploit the change for unauthorized access and persistence.
AD Delegated Managed Service Account (dMSA) object takeover by computer object
Attackers exploit dMSA delegation in Active Directory, gaining write access and escalating privileges through computer object impersonation, allowing them to modify sensitive objects and maintain persistence.
Microsoft Entra cloud-only user with immutable ID set

Attackers can exploit a Microsoft Entra cloud-only user with an immutable ID set to gain direct access to sensitive data and systems, bypassing normal authentication and authorization controls.
Microsoft Entra tenant with partner access via Delegated Administrative Privileges

A Microsoft Entra tenant configured for partner access through Delegated Administrative Privileges exposes sensitive resources to potential unauthorized access and lateral movement.
Regular AD user with permission to link GPOs

A regular AD user with permission to link GPOs can exploit group membership to elevate their permissions, exposing Active Directory domain security to potential attack paths.
Read-Only Domain Controller (RODC) in Inconsistent State

Inconsistent Read-Only Domain Controllers (RODCs) expose authentication and authorization vulnerabilities, allowing attackers to exploit outdated or incorrect credentials.
Unauthorized changes to compliance policies

Unauthorized changes to compliance policies expose devices to security risks by allowing non-compliant or compromised devices to access corporate resources through modified configuration settings.
Regular AD object with Migrate SID history permission

Attackers can migrate high-privilege SIDs into their own accounts via a regular AD object with Migrate SID history permission, gaining elevated access and privileges.
Microsoft Entra tenant with unsecure app consent policy configuration

A tenant policy allowing any user to grant app access without admin consent exposes users to consent phishing via unsecured app permissions.
Computer with unsupported OS version in AD domain

Outdated OS versions in AD domains expose systems to security vulnerabilities, enabling attackers to exploit unpatched weaknesses.