Security principals with dangerous replication permissions

Active Directory security principals with Replicate Changes All permission enable attackers to execute DCSync attacks, exposing all user passwords.
Microsoft Entra tenant with Certificate-Based Authentication enabled for all users

A Microsoft Entra tenant with Certificate-Based Authentication enabled for all users exposes users to unauthorized certificate issuance, enabling attackers to impersonate any user without a password.
Microsoft Entra application registration with dangling URI

Attackers can exploit dangling Microsoft Entra application registration URIs to obtain user sessions’ authorization tokens, enabling lateral movement or privilege escalation.
Microsoft Entra app with risky read permissions

Microsoft Entra apps with excessive read permissions expose sensitive data through OAuth 2.0 consent grants.
Microsoft Entra tenant where regular users can create Microsoft 365 groups

Regular user group creation exposes tenant-wide access, enabling attackers to collect sensitive information through group membership enumeration.
Microsoft Entra tenant with unsecure configuration of user risk policy

An unsecure user risk policy in Microsoft Entra tenant exposes users to unnecessary access risks due to inadequate password change requirements, enabling attackers to gather information and plan future malicious operations.
Entra ID tenant without policy to show geographic location context in Microsoft Authenticator notifications

Entra ID tenant without a policy to show geographic location context in Microsoft Authenticator notifications exposes users to authentication requests that may be confirmed by mistake due to lack of contextual information, enabling attackers to gain unauthorized access.
Stale Microsoft Entra service principal

A stale Microsoft Entra service principal can lead to unauthorized access and data breaches if not properly managed, exposing your organization to attack paths through compromised credentials and permissions.
AD domain allowing NTLM authentication

AD domains using NTLM authentication expose sensitive information, enabling attackers to gather domain details through unauthorized access.
Microsoft Entra ID Administrative Units are not being used

Not using Administrative Units in Microsoft Entra ID exposes privileged access broadly scoped, enabling unauthorized access and lateral movement through reconnaissance and administrative scope.