Microsoft Entra tenant with Privileged Identity Management not being used

A Microsoft Entra tenant without Privileged Identity Management (PIM) exposes powerful roles to immediate access by attackers, escalating privileges and accessing sensitive resources.
Microsoft Entra tenant configured to allow guests to invite other guests

A tenant-wide guest invitation configuration exposes data on other users, enabling attack paths through information gathering.
Microsoft Entra tenant with Microsoft 365 groups exposed to the whole organization

Microsoft Entra tenant exposes users to unauthorized access due to misconfigured permissions in Microsoft 365 groups, enabling attackers to exploit sensitive resources.
Insufficient Active Directory domain controller auditing policy configuration

A missing or inadequate Active Directory domain controller auditing policy configuration exposes your environment to lateral movement attacks.
AD domain allows unprivileged users to add computer accounts

Attackers can exploit AD domain settings to create legitimate-looking computer accounts for non-existent devices, enabling them to bypass security controls and gain unauthorized access.
Exchange Online mailbox with SMTP forwarding address

Exchange Online mailbox with an SMTP forwarding address exposes the organization to potential email interception by threat actors.
Privileged AD user not protected from using unsecure authentication methods

Privileged AD user accounts exposed to credential access attacks due to unsecure authentication methods, enabling attackers to exploit weaknesses and gain elevated privileges.
AD domain with unsecure RBCD delegation on domain controllers

Attackers can impersonate any user via unsecure Resource-Based Constrained Delegation (RBCD) on domain controllers, enabling unauthorized access to sensitive resources and data.
AD forest with Recycle Bin not enabled

A disabled Active Directory Recycle Bin exposes deleted objects to permanent loss through lack of restoration capabilities, enabling attackers to delete critical objects without fear of recovery.
Exchange-related AD group with excessive permissions

Attackers exploiting Exchange-related AD group with excessive permissions can reset passwords, add accounts to sensitive groups, or modify ACLs due to assigned FullControl, WriteDACL, ForceChangePassword, or AddMember permissions.