Microsoft Entra tenant with unsecure app consent policy configuration

A tenant policy allowing any user to grant app access without admin consent exposes users to consent phishing via unsecured app permissions.
Microsoft Entra guest account with unredeemed invite

Unredeemed Microsoft Entra guest account invitations can be exploited by attackers to create persistence, increasing risk of credential exposure through authentication and authorization mechanisms.
Password hash synchronization not enabled in hybrid environment

Password hash synchronization not enabled in hybrid environment exposes user credentials to attackers attempting unauthorized access through compromised credentials.
Microsoft Intune Multi Admin Approval access policies not configured
Intune tenant without Multi Admin Approval access policies exposes sensitive actions to unauthorized administrators, enabling attackers to perform malicious activities with ease.
Microsoft Entra Organizational Messages Writer and Approver roles assigned to the same user or group
A user with both Entra ID organizational message writer and approver roles can create and approve messages without oversight, exposing an attack path due to compromised dual control.
AD domain controller allowing authentication with keys vulnerable to ROCA
Insecure ACLs on Service Connection Points in Active Directory
Insecure ACLs on Service Connection Points in Active Directory expose sensitive data and enable man-in-the-middle attacks through unauthorized attribute modifications.
AD object with schema update permissions
Attackers can exploit AD object with schema update permissions to compromise forest integrity through unauthorized attribute and object creation.
Microsoft Entra tenant where regular users can register applications

High-risk exposure in Microsoft Entra tenant where regular users can register applications, enabling attackers to expand their reach and gain persistence.
AD domain with built-in domain Guest account enabled

An enabled domain guest account exposes the Active Directory environment to unauthorized access, enabling attackers to gather information for potential future attacks.