Failed logon attempts targeting honey account

Failed logon attempts targeting honey accounts in Active Directory may indicate brute-force attacks or reconnaissance activity, exposing administrative scope and attacker capability.
Entra user added to a privileged role

Unauthorized access control changes can indicate privilege escalation or sensitive system access via Entra user added to a privileged role.
Service principal promoted to privileged role via OAuth consent attack

Attackers exploit OAuth consent to promote malicious service principals, enabling long-term persistence in Entra ID. Cayosoft Guardian detects and mitigates this threat by monitoring OAuth consent logs and service principal permissions.
AD user added to privileged group

Attackers can escalate privileges and access sensitive data through unauthorized access when a user is added to a privileged Active Directory group.
Microsoft Entra user with multiple MFA failures

Multiple Entra ID user MFA failures in a short period may indicate an attacker attempting to bypass MFA through brute-force or fatigue attacks, increasing account takeover risk.
AD domain with multiple failed authentication attempts via process

Multiple failed authentication attempts via process in an Active Directory domain expose attack paths and allow attackers to obtain initial access or elevate privileges.
Insufficient Active Directory domain controller auditing policy configuration

A missing or inadequate Active Directory domain controller auditing policy configuration exposes your environment to lateral movement attacks.
Exchange-related AD group with excessive permissions

Attackers exploiting Exchange-related AD group with excessive permissions can reset passwords, add accounts to sensitive groups, or modify ACLs due to assigned FullControl, WriteDACL, ForceChangePassword, or AddMember permissions.
Microsoft Entra Global Administrator with elevated access to Azure Resources

Elevated Azure resource access by a Global Admin exposes sensitive data to potential attacks through unfiltered access.
AD user with compromised password

Attackers can exploit exposed password hashes in Active Directory user accounts, enabling unauthorized access and potential privilege escalation.