Microsoft Entra tenant with Privileged Identity Management not being used

A Microsoft Entra tenant without Privileged Identity Management (PIM) exposes powerful roles to immediate access by attackers, escalating privileges and accessing sensitive resources.
AD object with non-default primary group

Attackers can silently inherit elevated permissions and hide persistence in Active Directory through group membership manipulation by targeting a domain account with non-default primary group membership.
Microsoft Entra role with permanent eligible members

A Microsoft Entra role with permanent eligible members exposes administrative privileges to unauthorized access if an account is compromised, enabling attack paths through reconnaissance and persistence.
Guest account with Microsoft Entra role membership

A guest account with Microsoft Entra role membership exposes the environment to potential privilege escalation and external identity exposure through unmanaged identities.
Dangerous ACLs expose GPOs applied to privileged group members

Critical: Misconfigured ACLs expose GPOs applied to privileged group members, allowing attackers to execute code on workstations of those accounts through unauthorized access to sensitive settings and permissions.
Exchange-related AD group with excessive permissions

Attackers exploiting Exchange-related AD group with excessive permissions can reset passwords, add accounts to sensitive groups, or modify ACLs due to assigned FullControl, WriteDACL, ForceChangePassword, or AddMember permissions.
AD forest with high numbers of privileged group accounts

A high number of privileged group accounts in an Active Directory forest exposes administrators to unauthorized access and privilege escalation through lateral movement.
AD domain controller using unsecure encryption type

Domain controllers using outdated or insecure encryption types expose sensitive data to attackers, enabling privilege escalation and credential access through Kerberos protocol exploitation.
Active Directory Dangerous ACLs expose DFSR settings objects of the SYSVOL share

Active Directory Dangerous ACLs expose SYSVOL share replication settings, allowing attackers to exploit privilege escalation or persistence through unauthorized DFSR modifications.
AD domain controller deployed as a VM without drive encryption

Deploying Active Directory domain controllers as virtual machines without drive encryption exposes sensitive data at rest to unauthorized access via compromised virtual machine.