AD user has a password that matches its sAMAccountName

Predictable password pattern in Active Directory exposes users to brute-force attacks, compromising account security and allowing unauthorized access.
AD CS server vulnerable to NTLM relay attacks

An NTLM relay attack exploits the NTLM challenge-response mechanism, allowing attackers to authenticate as legitimate users and gain unauthorized access.
Microsoft Entra tenant with auditing disabled

A disabled auditing feature in Microsoft Entra tenant exposes attackers to undetected activity, allowing them to persist and evade detection.
Modified federation settings in Microsoft Entra domain

Modified federation settings in Microsoft Entra domain expose sensitive access to attackers who can exploit the change for unauthorized access and persistence.
AD Delegated Managed Service Account (dMSA) object takeover by computer object
Attackers exploit dMSA delegation in Active Directory, gaining write access and escalating privileges through computer object impersonation, allowing them to modify sensitive objects and maintain persistence.
Service Principal promoted a service principal to privileged role members

Attackers can persist and elevate privileges when a service principal is promoted to a privileged role member.
AD computer with suspicious change of sAMAccountName
A suspicious sAMAccountName change on an AD computer can enable attackers to escalate privileges, compromising domain security through attack paths that exploit administrative scope and credentials.
Microsoft Entra cloud-only user with immutable ID set

Attackers can exploit a Microsoft Entra cloud-only user with an immutable ID set to gain direct access to sensitive data and systems, bypassing normal authentication and authorization controls.
AD forest with the Azure SSO computer account not changing its password

Attackers can exploit a misconfigured Azure SSO computer account in an Active Directory forest, allowing them to authenticate as any user with access to Microsoft Entra ID using the static password.
AD domain with multiple failed authentication attempts from invalid users via NTLM

Multiple failed NTLM authentication attempts from invalid users in an Active Directory domain may indicate a Password Spraying attack, exposing the environment to potential reconnaissance and privilege escalation.