Active Directory Certificate Services auditing not configured
Unconfigured Active Directory Certificate Services (AD CS) auditing increases risk of privilege escalation, credential theft, and persistence due to undetected certificate operations.
AD CS server vulnerable to NTLM relay attacks

An NTLM relay attack exploits the NTLM challenge-response mechanism, allowing attackers to authenticate as legitimate users and gain unauthorized access.
Microsoft Entra tenant with auditing disabled

A disabled auditing feature in Microsoft Entra tenant exposes attackers to undetected activity, allowing them to persist and evade detection.
AD Delegated Managed Service Account (dMSA) object takeover by computer object
Attackers exploit dMSA delegation in Active Directory, gaining write access and escalating privileges through computer object impersonation, allowing them to modify sensitive objects and maintain persistence.
Backup location with unencrypted AD backups

Unencrypted AD backups expose sensitive data to unauthorized access, enabling attackers to gather credentials and plan future attacks.
Entra ID tenant vulnerable to MFA fatigue attacks via voice authentication method

Entra ID tenants vulnerable to voice authentication-based MFA fatigue attacks expose users to unauthorized access risk through compromised credentials and permissions.
AD domain with unsecure configuration of Cloud Kerberos Trust

A hybrid AD environment’s unsecure Cloud Kerberos Trust configuration exposes sensitive resources to unauthorized access via Microsoft Entra ID.
Microsoft Entra user with authentication phone details modified by another user

Microsoft Entra users with modified authentication phone details may indicate unauthorized access or compromise, allowing attackers to receive multifactor authentication messages for a compromised account. This vulnerability exposes sensitive information and enables attack paths through administrative scope and credentials.
AD-integrated DNS zone with WINS forward lookup enabled

AD-integrated DNS zones with WINS forward lookup enabled expose users to forged DNS responses that can compromise account authentication, enabling attackers to bypass authentication or steal credentials.
AD forest with Java schema extension

Active Directory forests with Java schema extensions are exposed to malicious code injection through extended attributes, enabling attackers to escalate privileges and execute arbitrary commands.