Microsoft Entra user with authentication phone details modified by another user

Microsoft Entra users with modified authentication phone details may indicate unauthorized access or compromise, allowing attackers to receive multifactor authentication messages for a compromised account. This vulnerability exposes sensitive information and enables attack paths through administrative scope and credentials.
Entra user attempted to access LAPS password

An Entra user accessed LAPS password, exposing local admin credentials and enabling lateral movement through administrative account access.
Privileged AD user with failed logon attempts

A Privileged AD user with failed logon attempts may indicate an unauthorized access attempt against a high-value domain account, exposing attack paths and administrative scope.
AD user with identical password
Attackers can access multiple AD user accounts with identical passwords without additional authentication efforts, increasing exposure and attack paths.
AD user with blank password
Active Directory user accounts without passwords are exposed to unauthorized access due to authentication bypass.
AD domain with misconfigured PowerShell logging policies
A misconfigured PowerShell logging policy exposes an Active Directory domain to attackers who can evade detection through PowerShell-based reconnaissance and persistence.
Suspicious Global Administrator sign-in in Entra ID
A sign-in from a Global Administrator account in Entra ID indicates potential credential compromise or malicious reconnaissance, warranting immediate investigation.
AD privileged account password reset or unlock
Unauthorized password reset or account unlock for a privileged Active Directory account can expose sensitive data and enable attackers to escalate privileges.
Entra privileged account password reset
Unauthorized Entra ID account password resets can indicate exposure to attack paths, persistence, and reconnaissance opportunities.
AD account configured or modified to use RC4 encryption
Active Directory accounts using RC4 encryption are vulnerable to password cracking and forged Kerberos tickets, enabling lateral movement and data breach.