Missing Conditional Access Policies for blocking legacy authentication

Legacy authentication protocols are not blocked in your Entra ID environment, exposing it to credential stuffing and brute force attacks.
Exchange-related AD group with excessive permissions

Attackers exploiting Exchange-related AD group with excessive permissions can reset passwords, add accounts to sensitive groups, or modify ACLs due to assigned FullControl, WriteDACL, ForceChangePassword, or AddMember permissions.
Active Directory Dangerous ACLs expose DFSR settings objects of the SYSVOL share

Active Directory Dangerous ACLs expose SYSVOL share replication settings, allowing attackers to exploit privilege escalation or persistence through unauthorized DFSR modifications.
Active directory dangerous user rights assignments on domain controllers

High-severity Active Directory user rights assignments on domain controllers expose sensitive privileges to non-admin users, enabling privilege escalation and persistence.
AD domain with non-default permissions on krbtgt account

A domain with non-default permissions on the krbtgt account exposes attackers to creating a Golden Ticket, granting unauthorized Kerberos authentication.
Microsoft Entra role with permanent active members

A permanent active role in Microsoft Entra grants immediate administrative privileges if an account with this membership is compromised, exposing a significant attack path.
Privileged AD object with permissions allowing takeover by regular user

A privileged Active Directory object with misconfigured permissions allows regular users to take control, exposing sensitive resources and escalating privileges.
AD computer account that is a member of privileged groups

A compromised AD computer account in a privileged group enables persistent lateral movement within the domain.
AD Domain Controller with non-admin owner

A non-administrator owning an AD Domain Controller poses a significant risk due to potential privilege escalation through unauthorized group membership, exposing attack paths and administrative scope.