Persistent membership detected in Active Directory Schema Admins group

Active Directory Schema Admins group membership persistence exposes forest-wide schema modification capabilities to attackers.
AD domain without group policy restricting anonymous enumeration of SAM accounts and shared resources

Attackers can gather reconnaissance data through unauthorized access in an AD domain without group policy restricting anonymous enumeration of SAM accounts and shared resources.