Microsoft Entra tenant with partner access via Delegated Administrative Privileges

A Microsoft Entra tenant configured for partner access through Delegated Administrative Privileges exposes sensitive resources to potential unauthorized access and lateral movement.
Multiple inbox rules created in an Exchange Online mailbox within a short period

Attackers use multiple inbox rules in Exchange Online mailboxes within a short period to evade detection and maintain unauthorized access, indicating high severity.
Detected a malicious inbox rule to conceal email in Exchange Online

A malicious inbox rule in Exchange Online conceals emails, aiding Business Email Compromise attacks, exposing your organization to unauthorized data access and financial losses.
AD domain allowing multicast name resolution (LLMNR)
Active Directory domains enabling Multicast Name Resolution (LLMNR) expose networks to spoofing and credential-harvesting attacks via intercepted DNS requests, allowing attackers to gather user credentials or redirect traffic.
AD domain with misconfigured PowerShell logging policies
A misconfigured PowerShell logging policy exposes an Active Directory domain to attackers who can evade detection through PowerShell-based reconnaissance and persistence.
Conditional Access policy in Entra ID missing Continuous Access Evaluation (CAE)
Conditional Access policy in Entra ID missing Continuous Access Evaluation (CAE) exposes users to extended session duration after privilege elevation or credential compromise, enabling attackers to maintain access to sensitive resources for an extended period.
Entra ID application owner attribute populated with a hybrid user account

A hybrid user account set as Entra ID application owner attribute may lead to unauthorized access and privilege escalation through compromised credentials or exploited permissions.
AD domain with misconfigured LDAP signing policy on the domain controllers

A misconfigured LDAP signing policy on Active Directory domain controllers exposes the environment to man-in-the-middle attacks, allowing attackers to intercept authentication traffic.
Active Directory missing KDS root key required for gMSA support

Active Directory missing KDS root key required for gMSA support exposes services to weak or stale credentials due to reliance on traditional accounts, enabling attackers to exploit Kerberos authentication and escalate privileges.
AD domain with misconfigured UNC paths policies

Active Directory misconfigurations expose authentication traffic, allowing attackers to intercept credentials or impersonate domain controllers via NTLM relay and SMB downgrade vulnerabilities.