AD domain with Operator Groups that are not empty

Attackers can exploit non-empty Operator Groups in an AD domain, gaining unauthorized access and escalating privileges.
AD domain with bulk changes of users

Active Directory bulk user changes can indicate unauthorized access or administrative errors, potentially leading to service disruptions through lateral movement or privilege escalation.
Microsoft Entra role with permanent eligible members

A Microsoft Entra role with permanent eligible members exposes administrative privileges to unauthorized access if an account is compromised, enabling attack paths through reconnaissance and persistence.
Exchange Online mailbox with Full Access permission assigned

Exchange Online mailboxes with assigned Full Access permissions may indicate misconfigured permissions, allowing attackers to access compromised mailboxes undetected. This can lead to data exposure and unauthorized access.
Microsoft Entra tenant with unsecure delegation of Global Admin role

An unsecure delegation of the Global Admin role in a Microsoft Entra tenant exposes sensitive administrative functions to unauthorized access.
Guest account with Microsoft Entra role membership

A guest account with Microsoft Entra role membership exposes the environment to potential privilege escalation and external identity exposure through unmanaged identities.
AD Domain where Enterprise Key Admins group has full access to the domain

Attackers can exploit a domain group with excessive permissions in Active Directory to perform DCSync attacks and compromise the forest.
Microsoft Entra role with permanent active members

A permanent active role in Microsoft Entra grants immediate administrative privileges if an account with this membership is compromised, exposing a significant attack path.
Microsoft Entra Global Administrator with elevated access to Azure Resources

Elevated Azure resource access by a Global Admin exposes sensitive data to potential attacks through unfiltered access.