Unauthorized certificate addition to Entra ID Enterprise Application

Unauthorized Entra ID Enterprise Application certificates can be added by attackers, allowing them to authenticate without MFA due to compromised credentials.
Entra ID tenant allowing multicast name resolution (LLMNR)

Enabling multicast name resolution (LLMNR) in Entra ID tenant exposes your network to authentication bypass and credential-harvesting attacks, allowing attackers to intercept and manipulate requests.
Microsoft Entra tenant with unsecure access to Azure management

Unsecured Azure management access in Microsoft Entra tenant exposes sensitive resources to unauthorized users, enabling potential privilege escalation through bypassed multifactor authentication (MFA) requirements.
Microsoft Entra app with risky write permissions

Microsoft Entra apps with write permissions expose your tenant to unauthorized modifications and data tampering.
Privileged AD user not protected against delegation

A high-severity threat where a privileged AD user’s credentials are vulnerable to unauthorized delegation, enabling privilege escalation through Kerberos protocol exploitation.
Privileged AD object with permissions allowing takeover by regular user

A privileged Active Directory object with misconfigured permissions allows regular users to take control, exposing sensitive resources and escalating privileges.
AD domain controller with enabled print spooler

A domain controller with enabled print spooler exposes domain credentials to remote connections, enabling attackers to compromise the domain controller or other systems through Kerberos authentication attacks.
DNS zone allowing unsecure update

A DNS zone allowing unsecure update enables attackers to modify records without authentication, exposing users to malicious servers via DNS spoofing and cache poisoning.
Privileged group members with weak password policy

Weak passwords in privileged group members expose accounts to authentication bypass, enabling attackers to gain unauthorized access.