Entra user added to a privileged role

Unauthorized access control changes can indicate privilege escalation or sensitive system access via Entra user added to a privileged role.
AD user added to privileged group

Attackers can escalate privileges and access sensitive data through unauthorized access when a user is added to a privileged Active Directory group.
AD forest is not protected against forest-wide failure by Cayosoft Guardian

A high-severity threat where an AD forest lacks a safeguard to quickly recover from catastrophic events like ransomware attacks or directory data corruption, exposing it to prolonged downtime, significant data loss, and substantial business disruption.