Microsoft Entra user with authentication phone details modified by another user

Active Directory

Microsoft Entra users with modified authentication phone details may indicate unauthorized access or compromise, allowing attackers to receive multifactor authentication messages for a compromised account. This vulnerability exposes sensitive information and enables attack paths through administrative scope and credentials.

AD user with identical password

Attackers can access multiple AD user accounts with identical passwords without additional authentication efforts, increasing exposure and attack paths.

AD user with blank password

Active Directory user accounts without passwords are exposed to unauthorized access due to authentication bypass.