User account with old passwords

Old Active Directory passwords expose users to unauthorized access if not regularly updated.
Microsoft Entra tenant with Certificate-Based Authentication enabled for all users

A Microsoft Entra tenant with Certificate-Based Authentication enabled for all users exposes users to unauthorized certificate issuance, enabling attackers to impersonate any user without a password.
Stale Microsoft Entra service principal

A stale Microsoft Entra service principal can lead to unauthorized access and data breaches if not properly managed, exposing your organization to attack paths through compromised credentials and permissions.
AD forest is not protected against forest-wide failure by Cayosoft Guardian

A high-severity threat where an AD forest lacks a safeguard to quickly recover from catastrophic events like ransomware attacks or directory data corruption, exposing it to prolonged downtime, significant data loss, and substantial business disruption.
Persistent membership detected in Active Directory Schema Admins group

Active Directory Schema Admins group membership persistence exposes forest-wide schema modification capabilities to attackers.
Microsoft Entra ID Administrative Units are not being used

Not using Administrative Units in Microsoft Entra ID exposes privileged access broadly scoped, enabling unauthorized access and lateral movement through reconnaissance and administrative scope.
AD object with non-default primary group

Attackers can silently inherit elevated permissions and hide persistence in Active Directory through group membership manipulation by targeting a domain account with non-default primary group membership.
Microsoft Entra role with permanent eligible members

A Microsoft Entra role with permanent eligible members exposes administrative privileges to unauthorized access if an account is compromised, enabling attack paths through reconnaissance and persistence.
Microsoft Entra tenant with unsecure delegation of Global Admin role

An unsecure delegation of the Global Admin role in a Microsoft Entra tenant exposes sensitive administrative functions to unauthorized access.
Exchange Online mailbox with SMTP forwarding address

Exchange Online mailbox with an SMTP forwarding address exposes the organization to potential email interception by threat actors.