Windows LAPS not configured or AD prerequisites missing
Exposure to static or reused local administrator passwords increases risk of credential reuse and lateral movement due to missing Windows LAPS configuration or incomplete Active Directory prerequisites.
Constrained authentication delegation to a domain controller service

Constrained authentication delegation to a domain controller service exposes sensitive resources to exploitation via Kerberos protocol vulnerabilities.
External trust without SID filtering enabled

External trusts without SID filtering enabled expose Active Directory to spoofed Security Identifiers (SIDs) in access requests, allowing attackers to gain unauthorized access.
Constrained delegation with protocol transition to the krbtgt account
Constrained delegation with protocol transition to the krbtgt account enables attackers to compromise the trusted krbtgt account, impersonate users, and access network resources through Kerberos authentication mechanisms.
Active Directory SMB signing not enforced on domain controller
Active Directory SMB signing not enforced on domain controllers exposes SMB traffic to tampering and relay-style attacks, enabling attackers to bypass authentication and access sensitive data.
AD account configured or modified to use RC4 encryption
Active Directory accounts using RC4 encryption are vulnerable to password cracking and forged Kerberos tickets, enabling lateral movement and data breach.
NTLM auditing not enabled in Active Directory
NTLM auditing not enabled in Active Directory exposes organizations to credential relay and lateral movement attacks through legacy protocol weaknesses.
Entra privileged account password reset
Unauthorized Entra ID account password resets can indicate exposure to attack paths, persistence, and reconnaissance opportunities.
Suspicious Global Administrator sign-in in Entra ID
A sign-in from a Global Administrator account in Entra ID indicates potential credential compromise or malicious reconnaissance, warranting immediate investigation.
AD privileged account password reset or unlock
Unauthorized password reset or account unlock for a privileged Active Directory account can expose sensitive data and enable attackers to escalate privileges.