Constrained authentication delegation to a domain controller service

Constrained authentication delegation to a domain controller service exposes sensitive resources to exploitation via Kerberos protocol vulnerabilities.
Service Principal promoted a service principal to privileged role members

Attackers can persist and elevate privileges when a service principal is promoted to a privileged role member.
AD computer with suspicious change of sAMAccountName
A suspicious sAMAccountName change on an AD computer can enable attackers to escalate privileges, compromising domain security through attack paths that exploit administrative scope and credentials.
Microsoft Entra cloud-only user with immutable ID set

Attackers can exploit a Microsoft Entra cloud-only user with an immutable ID set to gain direct access to sensitive data and systems, bypassing normal authentication and authorization controls.
AD forest with the Azure SSO computer account not changing its password

Attackers can exploit a misconfigured Azure SSO computer account in an Active Directory forest, allowing them to authenticate as any user with access to Microsoft Entra ID using the static password.
Regular AD user with permission to link GPOs

A regular AD user with permission to link GPOs can exploit group membership to elevate their permissions, exposing Active Directory domain security to potential attack paths.
AD object with modified msDS-KeyCredentialLink
Active Directory objects with modified msDS-KeyCredentialLink expose users to persistent access attacks through unauthorized key pair creation and encryption, enabling attackers to bypass normal authentication controls.
Honey account targeted with Kerberos pre-authentication attempts

Kerberos pre-authentication attempts against honey accounts expose credentials to attackers, enabling reconnaissance and potential compromise.
AD user with suspicious password refresh

Active Directory user with suspicious password refresh exposes organization to potential password policy compromise, allowing attackers to manipulate settings.
Entra user attempted to access LAPS password

An Entra user accessed LAPS password, exposing local admin credentials and enabling lateral movement through administrative account access.