Microsoft Entra tenant with bulk changes of devices

Bulk device changes in a Microsoft Entra tenant can indicate unauthorized activity or mistakes, exposing attackers to sensitive areas and potential service disruptions.
Regular AD object with Migrate SID history permission

Attackers can migrate high-privilege SIDs into their own accounts via a regular AD object with Migrate SID history permission, gaining elevated access and privileges.
AD domain with bulk changes of groups

Active Directory bulk group changes can indicate malicious activity or errors, leading to service disruptions and unauthorized access.
AD domain with bulk changes of computers

Active Directory bulk changes can indicate unauthorized modifications or mistakes, impacting service availability and exposing attack paths.
Microsoft Entra tenant with bulk changes of users

Bulk user changes in Microsoft Entra tenant may indicate unauthorized access, administrative mistakes, or malicious activity.
Regular Microsoft Entra user with Exchange Online PowerShell enabled

A non-administrative Microsoft Entra user with Exchange Online PowerShell enabled expands remote mailbox automation access if the account is compromised, increasing exposure to attack paths.
AD object with privileged SIDs in the sIDHistory

Active Directory objects with privileged SIDs in their SIDHistory attribute can be exploited by attackers for privilege escalation and unauthorized access. Cayosoft Guardian detects and alerts on this critical security risk, providing visibility into attack paths and persistence.
Privileged AD user account with associated SPNs

Attackers can exploit Privileged AD user accounts with associated SPNs for lateral movement and credential access due to elevated privileges and Kerberos Service Ticket capabilities.
Microsoft Entra tenant with bulk changes of groups

Bulk group changes in your Microsoft Entra tenant may indicate unauthorized access or service disruptions.
Privileged AD user synced to Microsoft Entra ID

Privileged AD users are synced to Microsoft Entra ID, exposing sensitive resources to unauthorized access.