Windows LAPS not configured or AD prerequisites missing
Exposure to static or reused local administrator passwords increases risk of credential reuse and lateral movement due to missing Windows LAPS configuration or incomplete Active Directory prerequisites.
Constrained authentication delegation to a domain controller service

Constrained authentication delegation to a domain controller service exposes sensitive resources to exploitation via Kerberos protocol vulnerabilities.
AD CS server vulnerable to NTLM relay attacks

An NTLM relay attack exploits the NTLM challenge-response mechanism, allowing attackers to authenticate as legitimate users and gain unauthorized access.
AD Delegated Managed Service Account (dMSA) object takeover by computer object
Attackers exploit dMSA delegation in Active Directory, gaining write access and escalating privileges through computer object impersonation, allowing them to modify sensitive objects and maintain persistence.
Service Principal promoted a service principal to privileged role members

Attackers can persist and elevate privileges when a service principal is promoted to a privileged role member.
AD computer with suspicious change of sAMAccountName
A suspicious sAMAccountName change on an AD computer can enable attackers to escalate privileges, compromising domain security through attack paths that exploit administrative scope and credentials.
Microsoft Entra tenant with partner access via Delegated Administrative Privileges

A Microsoft Entra tenant configured for partner access through Delegated Administrative Privileges exposes sensitive resources to potential unauthorized access and lateral movement.
Regular AD user with permission to link GPOs

A regular AD user with permission to link GPOs can exploit group membership to elevate their permissions, exposing Active Directory domain security to potential attack paths.
Read-Only Domain Controller (RODC) in Inconsistent State

Inconsistent Read-Only Domain Controllers (RODCs) expose authentication and authorization vulnerabilities, allowing attackers to exploit outdated or incorrect credentials.
Unauthorized changes to compliance policies

Unauthorized changes to compliance policies expose devices to security risks by allowing non-compliant or compromised devices to access corporate resources through modified configuration settings.