Active directory dangerous user rights assignments on domain controllers

High-severity Active Directory user rights assignments on domain controllers expose sensitive privileges to non-admin users, enabling privilege escalation and persistence.
AD domain with non-default permissions on krbtgt account

A domain with non-default permissions on the krbtgt account exposes attackers to creating a Golden Ticket, granting unauthorized Kerberos authentication.
Regular AD user account with permissions to modify DNS server objects

A regular AD user with DNS modification permissions exposes a high risk of privilege escalation and unauthorized access through attack paths involving DNS server object modifications.
Microsoft Entra role with permanent active members

A permanent active role in Microsoft Entra grants immediate administrative privileges if an account with this membership is compromised, exposing a significant attack path.
Microsoft Entra tenant with unsecure access to Azure management

Unsecured Azure management access in Microsoft Entra tenant exposes sensitive resources to unauthorized users, enabling potential privilege escalation through bypassed multifactor authentication (MFA) requirements.
Microsoft Entra Global Administrator with elevated access to Azure Resources

Elevated Azure resource access by a Global Admin exposes sensitive data to potential attacks through unfiltered access.
AD no fine-grained password policy found or weak settings detected

Active Directory lacks a fine-grained password policy, exposing attackers to weak passwords and escalated privileges.
Privileged AD user not protected against delegation

A high-severity threat where a privileged AD user’s credentials are vulnerable to unauthorized delegation, enabling privilege escalation through Kerberos protocol exploitation.
Privileged AD object with permissions allowing takeover by regular user

A privileged Active Directory object with misconfigured permissions allows regular users to take control, exposing sensitive resources and escalating privileges.
AD domain controller with enabled print spooler

A domain controller with enabled print spooler exposes domain credentials to remote connections, enabling attackers to compromise the domain controller or other systems through Kerberos authentication attacks.