AD forest with Recycle Bin not enabled

Active Directory

A disabled Active Directory Recycle Bin exposes deleted objects to permanent loss through lack of restoration capabilities, enabling attackers to delete critical objects without fear of recovery.

Exchange-related AD group with excessive permissions

Active Directory

Attackers exploiting Exchange-related AD group with excessive permissions can reset passwords, add accounts to sensitive groups, or modify ACLs due to assigned FullControl, WriteDACL, ForceChangePassword, or AddMember permissions.